- A. determine the necessity for forensic preparedness procedures and recognize the appropriate moments for instigating an investigation and involving law enforcement;
- B. recognize typical forms of computer crime and abuse and the relevant evidence;
- C. assist in determining where and how evidence may be stored in computers, and how this evidence may be extracted without contamination;
- D. participate in the selection of appropriate tools for forensic investigation; and
- E. define current terminology within computer forensics.
The materials within this course focus on the Knowledge Skills and Abilities (KSAs) identified within the Specialty Areas listed below. Click to view Specialty Area details within the interactive National Cybersecurity Workforce Framework.
If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.