ITOP 2140: Digital Forensics and Incident Response
Effective date
January 2027
School
Continuing Studies
Description
Students will learn how to uncover what happened during a security incident by applying core forensic and response techniques. In this course, students will collect and verify forensic data, reconstruct event timelines, and analyze artifacts across systems, logs, and identity sources. Students will also practice incident response procedures, correlate indicators from multiple platforms, and produce clear forensic reports, developing the analytical and technical skills needed to support organizational investigations and response efforts.
Year of study
2nd Year Post-secondary
Course Learning Outcomes
Upon successful completion of this course, students will be able to:
- Preserve digital evidence following chain-of-custody procedures and tamper-evident protocols, ensuring admissibility for legal or organizational requirements.
- Acquire and verify digital assets (e.g. images) of storage systems by validating cryptographic hash and evidence integrity before analysis.
- Perform forensic triage and timeline reconstruction, extracting and analysing artifacts from logs, containers, and application data to support incident investigations.
- Correlate indicators from multiple sources, such as cloud platforms, identity systems, network telemetry, to reconstruct attacker activities and identify compromise pathways.
- Execute incident response procedures following industry-recognized playbooks (e.g. contain, eradicate, recover) documenting decision points and remediation steps.
- Produce a forensic report detailing methods, findings, limitations, and evidence references in a format aligned with industry or legal standards.
Prior Learning Assessment & Recognition (PLAR)
PLAR is assessed through one or more of the following methods: challenge exam, student portfolio/products, demonstration/simulation, project-based asessment, or through another assessment method that is aligned with the course learning outcomes.
Hours
Lecture, Online, Seminar, Tutorial: 30
Clinical, Lab, Rehearsal, Shop, Kitchen, Simulation, Studio: 12
Total Hours: 42
Instructional Strategies
Instructional strategies may include:
Knowledge checks
Lectures
Hands-on lab activities
Scenario-based activities
Demonstrations
Problem-based exercises
Discussion
Reflection
Grading System
Letter Grade (A-F)
Evaluation Plan
|
Type
|
Percentage
|
Assessment activity
|
|
Project
|
45-60
|
Project involving multiple components that may involve preservation, acquisition, analysis, and/or reporting of digital evidence.
|
|
Assignments
|
40-55
|
Multiple hands-on lab exercises and/or assignments related to forensic and incident response exercises.
|
Course topics
- Digital Evidence Preservation & Chain of Custody
Forensic Acquisition & Hash Verification
Forensic Triage & Timeline Reconstruction
Cross-Platform Indicator Correlation & Analysis
Incident Response Procedures & Playbook Execution
Forensic Reporting & Legal Documentation
Notes:
- Course contents and descriptions, offerings and schedules are subject to change without notice.
- Students are required to follow all College policies including ones that govern their educational experience at VCC. Policies are available on the VCC website at:
https://www.vcc.ca/about/governance--policies/policies/.
- To find out if there are existing transfer agreements for this course, visit the BC Transfer Guide at https://www.bctransferguide.ca.