Institutional review previewGraduate program information remains subject to final approval.
Course catalog

Cybersecurity Management · Proposed course

Digital Forensics & Incident Response

Course code
CSM 609
Credit hours
3
Program
MSCM
Delivery
Hybrid/Online

Course description

Course overview

This course provides a comprehensive overview of digital forensics principles and incident response methodologies. Students will learn how to identify, collect, preserve, and analyze digital evidence from a variety of systems and networks. Through practical labs and case studies, learners will develop hands-on skills in forensic imaging, evidence documentation, malware analysis, and post-incident reporting using industry-standard tools.

Course content is presented for institutional review and remains subject to approval and revision.

Academic focus

Course objectives

  1. 01

    Understand the fundamentals of digital forensics and its role in cybersecurity operations.

  2. 02

    Apply incident response frameworks to detect, contain, and eradicate cyber incidents.

  3. 03

    Use forensic tools to collect and analyze digital evidence from multiple platforms.

  4. 04

    Develop professional-level incident reports that support legal and organizational processes.

Learning outcomes

Upon completion

  1. CLO 1

    Apply forensic investigation processes and tools in cybersecurity contexts (maps to PLO 4, PLO 3).

  2. CLO 2

    Execute evidence collection, preservation, and chain of custody protocols (maps to PLO 4, PLO 7).

  3. CLO 3

    Develop detailed incident response and recovery plans (maps to PLO 2, PLO 5).

  4. CLO 4

    Produce comprehensive digital forensic and post-incident reports (maps to PLO 1, PLO 4, PLO 7).

Proposed syllabus

Weekly course schedule

The sequence below reflects the current 15-week syllabus and remains subject to institutional review.

  1. Week 1

    Introduction to Digital Forensics and Incident Response

  2. Week 2

    Legal, Ethical, and Regulatory Aspects of Digital Forensics

  3. Week 3

    Incident Response Frameworks (NIST, SANS, ISO 27035)

  4. Week 4

    Digital Evidence Collection and Preservation

  5. Week 5

    Forensic Imaging and Disk Acquisition Techniques

  6. Week 6

    Memory, File System, and Log Analysis

  7. Week 7

    Network Forensics and Traffic Capture (Wireshark, Zeek)

  8. Week 8

    Midterm Exam and Lab Practicum

  9. Week 9

    Malware and Rootkit Analysis Techniques

  10. Week 10

    Cloud and Mobile Device Forensics

  11. Week 11

    Incident Containment, Eradication, and Recovery

  12. Week 12

    Chain of Custody and Evidence Management

  13. Week 13

    Case Study: Real-World Cyber Incidents

  14. Week 14

    Final Project Presentations

  15. Week 15

    Final Exam and Course Reflection

Evaluation

Assessment and grading

  • Forensics Lab Assignments – 30%
  • Midterm Exam – 20%
  • Final Exam – 20%
  • Incident Response Project – 20%
  • Professional Participation – 10%
A = 90–100%B = 80–89%C = 70–79%F = Below 70%

Course resources

Required texts and materials

  • Nelson, B., Phillips, A., & Steuart, C. (2022). Guide to computer forensics and investigations (7th ed.). Cengage Learning.
  • Casey, E. (2020). Digital evidence and computer crime: Forensic science, computers, and the internet (4th ed.). Academic Press.
  • Access to forensic software tools (Autopsy, FTK Imager, Wireshark) and virtual lab environments is required.