Cybersecurity Management · Proposed course
Digital Forensics & Incident Response
- Course code
- CSM 609
- Credit hours
- 3
- Program
- MSCM
- Delivery
- Hybrid/Online
Course description
Course overview
This course provides a comprehensive overview of digital forensics principles and incident response methodologies. Students will learn how to identify, collect, preserve, and analyze digital evidence from a variety of systems and networks. Through practical labs and case studies, learners will develop hands-on skills in forensic imaging, evidence documentation, malware analysis, and post-incident reporting using industry-standard tools.
Course content is presented for institutional review and remains subject to approval and revision.
Academic focus
Course objectives
- 01
Understand the fundamentals of digital forensics and its role in cybersecurity operations.
- 02
Apply incident response frameworks to detect, contain, and eradicate cyber incidents.
- 03
Use forensic tools to collect and analyze digital evidence from multiple platforms.
- 04
Develop professional-level incident reports that support legal and organizational processes.
Learning outcomes
Upon completion
- CLO 1
Apply forensic investigation processes and tools in cybersecurity contexts (maps to PLO 4, PLO 3).
- CLO 2
Execute evidence collection, preservation, and chain of custody protocols (maps to PLO 4, PLO 7).
- CLO 3
Develop detailed incident response and recovery plans (maps to PLO 2, PLO 5).
- CLO 4
Produce comprehensive digital forensic and post-incident reports (maps to PLO 1, PLO 4, PLO 7).
Proposed syllabus
Weekly course schedule
The sequence below reflects the current 15-week syllabus and remains subject to institutional review.
- Week 1
Introduction to Digital Forensics and Incident Response
- Week 2
Legal, Ethical, and Regulatory Aspects of Digital Forensics
- Week 3
Incident Response Frameworks (NIST, SANS, ISO 27035)
- Week 4
Digital Evidence Collection and Preservation
- Week 5
Forensic Imaging and Disk Acquisition Techniques
- Week 6
Memory, File System, and Log Analysis
- Week 7
Network Forensics and Traffic Capture (Wireshark, Zeek)
- Week 8
Midterm Exam and Lab Practicum
- Week 9
Malware and Rootkit Analysis Techniques
- Week 10
Cloud and Mobile Device Forensics
- Week 11
Incident Containment, Eradication, and Recovery
- Week 12
Chain of Custody and Evidence Management
- Week 13
Case Study: Real-World Cyber Incidents
- Week 14
Final Project Presentations
- Week 15
Final Exam and Course Reflection
Evaluation
Assessment and grading
- Forensics Lab Assignments – 30%
- Midterm Exam – 20%
- Final Exam – 20%
- Incident Response Project – 20%
- Professional Participation – 10%
Course resources
Required texts and materials
- Nelson, B., Phillips, A., & Steuart, C. (2022). Guide to computer forensics and investigations (7th ed.). Cengage Learning.
- Casey, E. (2020). Digital evidence and computer crime: Forensic science, computers, and the internet (4th ed.). Academic Press.
- Access to forensic software tools (Autopsy, FTK Imager, Wireshark) and virtual lab environments is required.
