Unit of Competency Mapping – Information for Teachers/Assessors – Information for Learners

DEFFOR006 Mapping and Delivery Guide
Conduct electronic data search and analysis

Version 1.0
Issue Date: April 2024


Qualification -
Unit of Competency DEFFOR006 - Conduct electronic data search and analysis
Description
Employability Skills
Learning Outcomes and Application This unit covers the competency to analyse electronic forensic data that has been acquired through a range of electronic forensic methodologies. It includes analysing electronic storage devices for artefacts that may become evidence. In the context of this unit, physical evidence includes both digital and analogue recording, and communications equipment including hard drives, recording media, flash drives, tape drives, random-access memory (RAM), read-only memory (ROM), basic input/output system (BIOS) and other peripherals. In addition, artefacts are any kind of tangible electronic byproducts that are produced during user or system activity.This unit applies to those working in the gathering and analysis of electronic information.The skills and knowledge described in this unit must be applied within the legislative, regulatory and policy environment in which they are carried out. Organisational policies and procedures must be consulted and adhered to, particularly those relating to WHS and the conducting of electronic data search and analysis.Those undertaking this unit would work independently, with minimal supervision, while performing complex tasks, including making complex judgements. They would use discretion and judgement and take responsibility for the quality of their outputs.No licensing, legislative or certification requirements apply to unit at the time of publication.
Duration and Setting X weeks, nominally xx hours, delivered in a classroom/online/blended learning setting.

Competency should be assessed in an actual workplace or in a simulated environment, with access to equipment and infrastructure appropriate to the outcome. Competency should be demonstrated over time to ensure the candidate is assessed across a variety of situations, with access to electronic devices with content suitable for forensic extraction including mobile devices, computers or communications equipment.

Assessors must satisfy the NVR/AQTF mandatory competency requirements for assessors.

Prerequisites/co-requisites
Competency Field Electronic Forensics
Development and validation strategy and guide for assessors and learners Student Learning Resources Handouts
Activities
Slides
PPT
Assessment 1 Assessment 2 Assessment 3 Assessment 4
Elements of Competency Performance Criteria              
Element: Reduce and describe data
  • Identify electronic forensic data to be analysed.
  • Reduce the data, identify possible artefacts and describe these in a suitable form to support the development of interpretations.
  • Decrypt data if appropriate.
  • Review the reduction and description processes to determine their appropriateness, and make improvements where necessary.
  • Save data not used in the reduction and description processes for future reference.
       
Element: Analyse and interpret data
  • Interpret the data using appropriate thinking processes based on deduction, induction and/or problem solving techniques.
  • Analyse electronic storage devices for artefacts, i.e. any kind of tangible electronic byproduct produced during user or system activity that may become evidence.
  • Apply sound reasoning to ensure consistency of interpretations based on the data.
  • Base interpretations on the factual quantitative and qualitative data.
  • Develop a reconstruction of events using analysis techniques.
       
Element: Develop conclusions and recommendations
  • Test and review possible interpretations to ensure they are credible and consistent with relevant data.
  • Refine and consolidate interpretations to strengthen inferences drawn.
  • Clearly state assumptions in the arguments leading to inferences.
  • Formulate sound inferences, probable predictions, interpretations and/or explanations from facts and the tested interpretations.
  • Ensure transparency in the investigation process by formulating inferences through a clear chain of reasoning.
  • Review inferences to identify and address any fallacies in reasoning.
  • Assess the relationship between the data developed and the probable interpretations to ensure validity and compliance, and report orally and/or in writing, formally or informally.
  • Develop and report conclusions and recommendations, addressing both strategic and tactical issues.
       
Element: Reduce and describe data
  • Identify electronic forensic data to be analysed.
  • Reduce the data, identify possible artefacts and describe these in a suitable form to support the development of interpretations.
  • Decrypt data if appropriate.
  • Review the reduction and description processes to determine their appropriateness, and make improvements where necessary.
  • Save data not used in the reduction and description processes for future reference.
       
Element: Analyse and interpret data
  • Interpret the data using appropriate thinking processes based on deduction, induction and/or problem solving techniques.
  • Analyse electronic storage devices for artefacts, i.e. any kind of tangible electronic byproduct produced during user or system activity that may become evidence.
  • Apply sound reasoning to ensure consistency of interpretations based on the data.
  • Base interpretations on the factual quantitative and qualitative data.
  • Develop a reconstruction of events using analysis techniques.
       
Element: Develop conclusions and recommendations
  • Test and review possible interpretations to ensure they are credible and consistent with relevant data.
  • Refine and consolidate interpretations to strengthen inferences drawn.
  • Clearly state assumptions in the arguments leading to inferences.
  • Formulate sound inferences, probable predictions, interpretations and/or explanations from facts and the tested interpretations.
  • Ensure transparency in the investigation process by formulating inferences through a clear chain of reasoning.
  • Review inferences to identify and address any fallacies in reasoning.
  • Assess the relationship between the data developed and the probable interpretations to ensure validity and compliance, and report orally and/or in writing, formally or informally.
  • Develop and report conclusions and recommendations, addressing both strategic and tactical issues.
       


Evidence Required

List the assessment methods to be used and the context and resources required for assessment. Copy and paste the relevant sections from the evidence guide below and then re-write these in plain English.

ELEMENTS

PERFORMANCE CRITERIA

Elements describe the essential outcomes

Performance criteria describe the performance needed to demonstrate achievement of the element. Where bold italicised text is used, further information is detailed in the range of conditions section.

1. Reduce and describe data

1.1 Identify electronic forensic data to be analysed.

1.2 Reduce the data, identify possible artefacts and describe these in a suitable form to support the development of interpretations.

1.3 Decrypt data if appropriate.

1.4 Review the reduction and description processes to determine their appropriateness, and make improvements where necessary.

1.5 Save data not used in the reduction and description processes for future reference.

2. Analyse and interpret data

2.1 Interpret the data using appropriate thinking processes based on deduction, induction and/or problem solving techniques.

2.2 Analyse electronic storage devices for artefacts, i.e. any kind of tangible electronic byproduct produced during user or system activity that may become evidence.

2.3 Apply sound reasoning to ensure consistency of interpretations based on the data.

2.4 Base interpretations on the factual quantitative and qualitative data.

2.5 Develop a reconstruction of events using analysis techniques.

3. Develop conclusions and recommendations

3.1 Test and review possible interpretations to ensure they are credible and consistent with relevant data.

3.2 Refine and consolidate interpretations to strengthen inferences drawn.

3.3 Clearly state assumptions in the arguments leading to inferences.

3.4 Formulate sound inferences, probable predictions, interpretations and/or explanations from facts and the tested interpretations.

3.5 Ensure transparency in the investigation process by formulating inferences through a clear chain of reasoning.

3.6 Review inferences to identify and address any fallacies in reasoning.

3.7 Assess the relationship between the data developed and the probable interpretations to ensure validity and compliance, and report orally and/or in writing, formally or informally.

3.8 Develop and report conclusions and recommendations, addressing both strategic and tactical issues.

Evidence required to demonstrate competence must satisfy all of the requirements of the elements and performance criteria. If not otherwise specified the candidate must demonstrate evidence of performance of the following on at least one occasion.

conducting an electronic data search

communicating (listening, questioning, presenting) and negotiating

using and interpreting the outcomes from different types of electronic forensic tools

reducing and describing data

applying thinking processes including at least two of:

inductive (interpreting raw information, identifying and testing trends or patterns)

deductive (beginning with a hypothesis and testing it), lateral, critical or creative

problem solving techniques and decision making

preparing analysis reports

constructing sound inductive arguments

evaluating data

using computer and information systems

conducting analysis including:

quantitative and/or qualitative

explorative

descriptive

causative

predictive

development of hypotheses

timeline development

link analysis

comparative

biographical

demographic or geographic

historical

scenario generation

Delphi technique

morphological maximising the potential evidentiary value of the electronic evidence

operating safely

Evidence required to demonstrate competence must satisfy all of the requirements of the elements and performance criteria. If not otherwise specified the depth of knowledge demonstrated must be appropriate to the job context of the candidate.

computer and storage device theory, characteristics and operating mechanisms

government and policy environments within which analysis will be conducted various types of electronic forensic tools and their capabilities and limitations

applicable laws, policy and procedures

available resources required to support the intelligence analysis process

security issues and classifications

the range of analytical techniques appropriate for data analysis evaluation systems

thinking and inductive/deductive reasoning processes

the influence of human factors on data analysis

evidentiary requirements


Submission Requirements

List each assessment task's title, type (eg project, observation/demonstration, essay, assignment, checklist) and due date here

Assessment task 1: [title]      Due date:

(add new lines for each of the assessment tasks)


Assessment Tasks

Copy and paste from the following data to produce each assessment task. Write these in plain English and spell out how, when and where the task is to be carried out, under what conditions, and what resources are needed. Include guidelines about how well the candidate has to perform a task for it to be judged satisfactory.

ELEMENTS

PERFORMANCE CRITERIA

Elements describe the essential outcomes

Performance criteria describe the performance needed to demonstrate achievement of the element. Where bold italicised text is used, further information is detailed in the range of conditions section.

1. Reduce and describe data

1.1 Identify electronic forensic data to be analysed.

1.2 Reduce the data, identify possible artefacts and describe these in a suitable form to support the development of interpretations.

1.3 Decrypt data if appropriate.

1.4 Review the reduction and description processes to determine their appropriateness, and make improvements where necessary.

1.5 Save data not used in the reduction and description processes for future reference.

2. Analyse and interpret data

2.1 Interpret the data using appropriate thinking processes based on deduction, induction and/or problem solving techniques.

2.2 Analyse electronic storage devices for artefacts, i.e. any kind of tangible electronic byproduct produced during user or system activity that may become evidence.

2.3 Apply sound reasoning to ensure consistency of interpretations based on the data.

2.4 Base interpretations on the factual quantitative and qualitative data.

2.5 Develop a reconstruction of events using analysis techniques.

3. Develop conclusions and recommendations

3.1 Test and review possible interpretations to ensure they are credible and consistent with relevant data.

3.2 Refine and consolidate interpretations to strengthen inferences drawn.

3.3 Clearly state assumptions in the arguments leading to inferences.

3.4 Formulate sound inferences, probable predictions, interpretations and/or explanations from facts and the tested interpretations.

3.5 Ensure transparency in the investigation process by formulating inferences through a clear chain of reasoning.

3.6 Review inferences to identify and address any fallacies in reasoning.

3.7 Assess the relationship between the data developed and the probable interpretations to ensure validity and compliance, and report orally and/or in writing, formally or informally.

3.8 Develop and report conclusions and recommendations, addressing both strategic and tactical issues.

Copy and paste from the following performance criteria to create an observation checklist for each task. When you have finished writing your assessment tool every one of these must have been addressed, preferably several times in a variety of contexts. To ensure this occurs download the assessment matrix for the unit; enter each assessment task as a column header and place check marks against each performance criteria that task addresses.

Observation Checklist

Tasks to be observed according to workplace/college/TAFE policy and procedures, relevant legislation and Codes of Practice Yes No Comments/feedback
Identify electronic forensic data to be analysed. 
Reduce the data, identify possible artefacts and describe these in a suitable form to support the development of interpretations. 
Decrypt data if appropriate. 
Review the reduction and description processes to determine their appropriateness, and make improvements where necessary. 
Save data not used in the reduction and description processes for future reference. 
Interpret the data using appropriate thinking processes based on deduction, induction and/or problem solving techniques. 
Analyse electronic storage devices for artefacts, i.e. any kind of tangible electronic byproduct produced during user or system activity that may become evidence. 
Apply sound reasoning to ensure consistency of interpretations based on the data. 
Base interpretations on the factual quantitative and qualitative data. 
Develop a reconstruction of events using analysis techniques. 
Test and review possible interpretations to ensure they are credible and consistent with relevant data. 
Refine and consolidate interpretations to strengthen inferences drawn. 
Clearly state assumptions in the arguments leading to inferences. 
Formulate sound inferences, probable predictions, interpretations and/or explanations from facts and the tested interpretations. 
Ensure transparency in the investigation process by formulating inferences through a clear chain of reasoning. 
Review inferences to identify and address any fallacies in reasoning. 
Assess the relationship between the data developed and the probable interpretations to ensure validity and compliance, and report orally and/or in writing, formally or informally. 
Develop and report conclusions and recommendations, addressing both strategic and tactical issues. 
Identify electronic forensic data to be analysed. 
Reduce the data, identify possible artefacts and describe these in a suitable form to support the development of interpretations. 
Decrypt data if appropriate. 
Review the reduction and description processes to determine their appropriateness, and make improvements where necessary. 
Save data not used in the reduction and description processes for future reference. 
Interpret the data using appropriate thinking processes based on deduction, induction and/or problem solving techniques. 
Analyse electronic storage devices for artefacts, i.e. any kind of tangible electronic byproduct produced during user or system activity that may become evidence. 
Apply sound reasoning to ensure consistency of interpretations based on the data. 
Base interpretations on the factual quantitative and qualitative data. 
Develop a reconstruction of events using analysis techniques. 
Test and review possible interpretations to ensure they are credible and consistent with relevant data. 
Refine and consolidate interpretations to strengthen inferences drawn. 
Clearly state assumptions in the arguments leading to inferences. 
Formulate sound inferences, probable predictions, interpretations and/or explanations from facts and the tested interpretations. 
Ensure transparency in the investigation process by formulating inferences through a clear chain of reasoning. 
Review inferences to identify and address any fallacies in reasoning. 
Assess the relationship between the data developed and the probable interpretations to ensure validity and compliance, and report orally and/or in writing, formally or informally. 
Develop and report conclusions and recommendations, addressing both strategic and tactical issues. 

Forms

Assessment Cover Sheet

DEFFOR006 - Conduct electronic data search and analysis
Assessment task 1: [title]

Student name:

Student ID:

I declare that the assessment tasks submitted for this unit are my own work.

Student signature:

Result: Competent Not yet competent

Feedback to student

 

 

 

 

 

 

 

 

Assessor name:

Signature:

Date:


Assessment Record Sheet

DEFFOR006 - Conduct electronic data search and analysis

Student name:

Student ID:

Assessment task 1: [title] Result: Competent Not yet competent

(add lines for each task)

Feedback to student:

 

 

 

 

 

 

 

 

Overall assessment result: Competent Not yet competent

Assessor name:

Signature:

Date:

Student signature:

Date: