Administration of Organizations in the Criminal Justice System CCJ 5200
November 14, 2020
Incident Response and Digital Forensics

Digital forensics typically comes into play as a subset of incident response, and it is generally reserved for incidents that have the potential to end up in a civil or criminal court. Incident response teams are typically ill-prepared to manage incidents of this nature, resulting in organizations choosing to contract with external experts when serious incidents occur. The challenge for most organizations is being able to identify these differences early on, so that those with the proper expertise do not arrive to find that important evidence has been disturbed or destroyed by untrained technicians, no matter how well-meaning they may be. Using external expertise for forensics investigations also makes sense, due to the complexity and specificity of the tools and procedures used by these experts to ensure that evidence is discovered and is collected using proper chain of custody. Networks that are not properly managed, or on which robust and effective security controls are implemented, create difficult environments for forensics experts, as they try to perform their work in a way that will be appropriate for use in a court of law.


Complete the Toolwire lab. When submitting your assignment, attach the two screen prints you were asked to capture as part of the lab to this assignment to document successful completion of the lab.


Use the study materials and engage in any additional research needed to fill in knowledge gaps. Write a 2–3-page paper that covers the following topics:

  • Analyze the differences between incident response and network forensics.
  • Analyze the impact of existing network security controls on network forensics.
  • Identify the tools that are available for effective network forensics investigations.
  • Explore common methodologies used in network forensics.

Assignment Requirements

  • Written communication: Written communication is free of errors that detract from the overall message.
  • Length of paper: 2–3 pages, excluding the references page.
  • Font and font size: Times New Roman, 12 point.


