FIT3168 - IT forensics - 2017

6 points, SCA Band 2, 0.125 EFTSL

Undergraduate - Unit

Refer to the specific census and withdrawal dates for the semester(s) in which this unit is offered.


Information Technology

Not offered in 2017


This unit provides a broad coverage of digital ICT forensics. Students will examine definitions of evidence as they apply to investigations involving the seizure and examination of information technology devices. The unit will introduce students to various tools, techniques and algorithms that may be employed by investigators for acquisition, preservation and analysis of evidence. Disk-based (local) and network (remote) forensic environments will be explored. Students will also learn of the impediments and complicating factors that can threaten forensic investigations.


At the completion of this unit, students should be able to:

  1. explain the motivations and landscape of forensic investigations in an IT context;
  2. explain the relevant legal definitions and frameworks that apply to digital forensic investigations;
  3. select appropriate tools and algorithms to perform forensic investigations and acquire relevant evidence;
  4. apply and evaluate forensic techniques in local media-based an network-based environments;
  5. report on forensic findings in a clear and concise manner.


Examination (2 hours): 40%; In-semester assessment: 60%

Workload requirements

Minimum total expected workload equals 12 hours per week comprising:

  1. Contact hours for on-campus students:
    • Two hours lectures
    • Two hours laboratories
  2. Additional requirements (all students):
    • A minimum of 2-3 hours of personal study per one hour of lecture time in order to satisfy the reading, tute, prac and assignment expectations.

See also Unit timetable information

This unit applies to the following area(s) of study