Digital forensic report
The scenario.
A small development company, ACME, has the followin" rel="nofollow">ing computer use policy (in" rel="nofollow">in part);
1. Employees of ACME should be aware that bandwidth for in" rel="nofollow">internet connectivity is limited. As such, we enforce the followin" rel="nofollow">ing;
1. NO downloads of ISO’s or in" rel="nofollow">installs of any type unless approved by your manager in" rel="nofollow">in writin" rel="nofollow">ing.
2. NO downloads of and pictures larger than 2 MB (jpegs are strongly encouraged over bit maps as they are smaller, therefore no bitmap downloads).
3. No usin" rel="nofollow">ing company bandwidth to send personal data over 1MB
2. For security reasons all traffic is monitored on the network. There is no expectation of privacy.
3. Your system’s contents may be checked periodically to in" rel="nofollow">insure compliance to company policy. For that reason, data on hard drives must be unencrypted.
4. Failure to comply too the computer use policy may lead to a negative yearly performance review, or dependin" rel="nofollow">ing on the severity of the non-compliance, may lead to dismissal.
You have been asked by a Director of ACME to scan several hard drives, and all appear to be clear of in" rel="nofollow">infrin" rel="nofollow">ingement with the exception of one. You produce an FTK report (Your report from class) and
do the followin" rel="nofollow">ing;
Assignment
Write a short (one page maximum) executive summery that explain" rel="nofollow">ins your fin" rel="nofollow">indin" rel="nofollow">ings, referrin" rel="nofollow">ing to the FTK report, of your scan of the system in" rel="nofollow">in question.
Answer in" rel="nofollow">in your report the followin" rel="nofollow">ing questions (justify your answers)
Does it appear that the employee violated company policy?