CS5291 - Cybersecurity Forensics and Incident Response | ||||||||
| ||||||||
| * The offering term is subject to change without prior notice | ||||||||
Course Aims | ||||||||
This course provides students with an integrated skill set in Digital Forensics and Incident Response (DFIR). Upon completion, students will gain a comprehensive understanding of computer forensics principles, including evidence identification, acquisition, preservation, analysis, and the incident response lifecycle, which encompasses preparation, detection, containment, eradication, recovery, and post-incident recovery. Additionally, students will acquire the ability to conduct investigations utilizing industry-standard tools, analyze case studies, identify potential threat actors or root causes, adhere to legal and ethical standards, and generate comprehensive reports that guide DFIR efforts effectively. | ||||||||
Assessment (Indicative only, please check the detailed course information) | ||||||||
Continuous Assessment: 50% | ||||||||
Examination: 50% | ||||||||
Examination Duration: 2 hours | ||||||||
Min. Examination Passing Requirement: 30% | ||||||||
For a student to pass the course, at least 30% of the maximum mark for the examination must be obtained. | ||||||||
Detailed Course Information | ||||||||
| CS5291.pdf | ||||||||