Module Outline
Date retreived
22/07/2026 5:27 PM AWST
22/07/2026 5:27 PM AWST
Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.
Gather and validate digital forensic data from workstations
Gather and validate digital forensic data from workstations
Module
National Code
VU23295
VU23295
State Code
AZ602
AZ602
DTWD Status
Approved
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to select tools and apply techniques to gather and validate digital forensic data from workstations by physical or virtual means or through email or web applications.
The unit applies to persons working as cyber security practitioners who, as part of a team responds to cyber security incidents in an organisation.
The unit is not intended to prepare a cyber security practitioner to gather evidence for legal purposes.
No licensing or certification requirements apply to this unit at the time of accreditation.
The unit applies to persons working as cyber security practitioners who, as part of a team responds to cyber security incidents in an organisation.
The unit is not intended to prepare a cyber security practitioner to gather evidence for legal purposes.
No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Examine privacy laws and ethical practises pertaining to digital forensics
- Difference between acquiring digital data and digital forensics for workstations is explained
- Processes of forensic science and investigation for workstations are identified
- Current Australian privacy laws and digital forensic legislation are collated and evaluated
- Current Australian ethical practises for digital forensics are collated and evaluated
- An ethical code of practise for an organisation performing digital forensics is identified and adopted
Define data to be recovered using digital forensic tools
- Forensic data to be recovered from the workstation is defined
- Triage principles for acquiring and securing data for an organisation are developed
- Tools for digital forensics are evaluated and selected
Acquire defined forensic data from storage media
- Structure and operation of the workstation’s file system structure is identified and examined
- Forensic data provided by the Windows registry structure and content is identified and evaluated
- Data from disk drives is acquired
- Universal Serial Bus (USB) and bring your own device (BYOD) connection and disconnection times are determined
- Disk file open and file closure times are determined
Acquire defined email forensic data
- Structure and operation of an email packet is reviewed
- Different types of email formats are examined
- Common forensic email tools are evaluated and selected
- Email senders geographic locations are determined
Acquire defined web forensic data
- Existing web browser structures and operation are reviewed
- Common browser forensic tools are evaluated and selected
- Tools and techniques to examine web forensic data are evaluated and selected
- Web forensic data for a particular browser is collated
Review defined recovered data
- Defined data from storage media, email and the web is collated
- Acquired data is reviewed and checked for readability and completeness
- Report on the acquired data is compiled and discussed with appropriate personnel
Identify further data forensic tools and training
- Advanced data collection forensic tools are identified and classified
- Forensic training for staff is planned and implemented
Replaces
| State Code | National Code | Title | Type |
|---|---|---|---|
| AX653 | VU22247 | Acquire digital forensic data from workstations | Unit of competency |
Associated Qual/Courses
| State Code | National Code | Title | Type |
|---|---|---|---|
| BGT52 | 22610VIC | Advanced Diploma of Cyber Security | Accredited course |