Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask English Expert

You are the lead forensics investigator for XYZ, Inc. -- an industry leading cyber forensic company. You have just been notified that a top 5 health care company (HCC Partners in Life) has hired your company to investigate a potential breach of their medical records system.

The HCC Security Operations Center (SOC) identified some "inconsistencies" in the intrusion detection system (IDS) logs that caused the reliability to be questioned. HCC uses Snort IDS' running on Linux systems. In addition, the lead HCC database administrator received a strange e-mail from Human Resources (HR), which contained a benefits attachment. When she opened the attachment, the document was blank. She noticed that her system has been acting "strangely" after opening the attachment. She operates a Microsoft Windows XP workstation.

Your team has been tasked with analyzing the HCC network, database server, and any workstations you suspect to determine if there was a breach and any potential patient data leakage. The database server is a Microsoft Windows 2003 Server running Microsoft SQL Server 2008.

If there is any evidence of a breach, HHC has a history of taking these types of incidents to court for prosecution to the full extent of the law.

A. Describe your plan for processing the potential crime/incident scene. Some of the items you will want to cover include (not all inclusive):

How will your team identify potential digital evidence?

How will you prepare for the search?

What steps will your team take if you need to seize any digital evidence?

What documentation processes will you follow to help support any potential legal proceedings?

How will your team/company ensure proper storage/chain of evidence processes are followed?

B. Discuss how your team will approach and process the database administrator's computer -- considering the potential malware on her system.

Include the steps you will use to image her drive.

The areas on her system you will analyze for potential evidence of infection and/or modification.

C. Discuss how your team will approach and process the database server -- as this is the location for patient medical records.

1. Include the steps you will use to image the server's hard drive.
2. The areas on the server's system you will analyze for potential evidence of infection and/or modification.
3. Other items.

D. Discuss how you prepare your team to be expert witnesses or support any expert testimony court requirements.

English, Academics

  • Category:- English
  • Reference No.:- M91592817
  • Price:- $60

Priced at Now at $60, Verified Solution

Have any Question?


Related Questions in English

Initial response walker henry and jacobs provide stories

Initial response: Walker, Henry, and Jacobs provide stories that surround symbols that are life-changing for the protagonist. In a well-constructed response that is at least two paragraphs, please answer the following pr ...

Question find two potential sources on your topic for essay

Question: Find two potential sources on your topic for Essay 2. One source must be from the web, and the other source must be from the MDC library databases. Note: you are NOT required to use these exact sources in your ...

Read douglas hofstadters recent atlantic magazine article

Read Douglas Hofstadter's recent Atlantic magazine article on Machine Translation and write a 1000 word summary and response. There are three languages that the author picks as case studies - French, German, and Mandarin ...

What would mary wollstonecraft say about only men having to

What would Mary Wollstonecraft say about only men having to register for selective services? This could go several different ways depending on how you apply the information. Note: Make sure to cite the readings, in order ...

Response to melvillecreate an ms word document and attach

Response to Melville Create an MS Word document and attach it to the Assignment Feature in Blackboard Vista. For this response, you are required one short essay. Select one of the questions below and write a two page res ...

Assignment deep ecologythis is the most radical

Assignment : Deep Ecology This is the most "radical" environmental ethic. Remember, I would like you to try to determine where you stand with regard to the different environmental ethics. Also, when you do these assignme ...

Question for our first essay please describe four

Question: For our first essay, please describe four challenges troops may experience after war. Please compose at least one paragraph for each of these challenges. Please use at least four (4) direct quotations (in the p ...

Question you are working on researching your topic for the

Question: You are working on researching your topic for the persuasive essay, which will require you to support your main points with facts, examples, and quotes from secondary sources. This assignment helps you get star ...

Assignmentalmost one hundred years separate lincolns second

Assignment Almost one hundred years separate Lincoln's second inaugural address delivered on March 4, 1865 from Martin Luther King, Jr.'s open letter from Birmingham Jail written April, 16 1963. One hundred years is not ...

Section 66 of the text discusses how we can pick up tips

Section 6.6 of the text discusses how we can pick up tips and techniques from children's media to aid our teaching with this new media-literare generations (Coars, 2013). Create a classroom newsletter that shares how you ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As