Module Outline

Date retreived
23/07/2026 5:23 AM AWST

Whilst all efforts are made to provide accurate and timely information from the relevant source/documentation, please be aware that the information supplied may not be the most current version. The accuracy of the detail has not been confirmed by the Department and therefore should not be relied upon without first confirming the contents.

Gather and validate digital forensic data from mobile devices

Gather and validate digital forensic data from mobile devices

Module
National Code
VU23296
State Code
AZ603
DTWD Status
Approved
State Implementation and Classification
Approved Date
08/06/2023
Field of Education
029901 - Security Science
Nominal Hours
40
Description
This unit describes the performance outcomes, skills and knowledge required to select tools and apply techniques to gather and validate digital forensic data from mobile devices.

It requires the ability to use mobile forensic data tools to acquire data from mobile devices for review and validation. The unit also covers the relevant legislation, privacy laws, and regulations to enable the practitioner to review an organisations policies and procedures to validate compliance regarding the use of mobile devices.

The unit applies to cyber security practitioners who, as part of a team respond to cyber security incidents.

The unit is not intended to prepare a cyber security practitioner to gather evidence for legal purposes.

No licensing or certification requirements apply to this unit at the time of accreditation.
No information
No information
Elements and Performance Criteria
Examine relevant privacy laws, procedures and processes pertaining to mobile digital forensics
  • Difference between acquiring digital data and digital forensics for mobile devices is clarified
  • Process of forensic science and investigation for mobile devices is identified
  • Current Australian privacy laws and mobile digital forensic legislation is collated and evaluated
  • Current Australian ethical practises for mobile forensics are collated and evaluated
  • An ethical code of practise for an organisation performing mobile forensics is adopted
  • Layered models of mobile forensic data acquisition are defined and evaluated
Determine smartphone fundamentals and select mobile digital forensic tools
  • Smartphone fundamentals for dealing with data are defined
  • Components of, and foundational operation of the digital cellular network are investigated
  • Mobile forensic data tools are identified and evaluated
  • File system structure and operation of a Android and IPhone smartphones are examined and compared
Acquire mobile forensic data
  • Tools and techniques to access the mobile device where passwords are not known are identified
  • Software drivers, cables and tools to synchronise phone data with a workstation from a phone are selected
  • Key data to be acquired from a mobile device is identified
  • Mobile forensic data tool to acquire key data for the phone is selected
  • Mobile forensic data tool selected is installed and commissioned
  • Users are familiarised with the tool selected to acquire the mobile device data
  • Data from the mobile device is acquired
Review defined recovered data
  • Acquired data from the mobile device is collated
  • Acquired data is checked for readability and completeness
  • Report on the acquired data is compiled and discussed with appropriate personnel
Investigate the function and operation of further tools and techniques for mobile devices
  • Joint Test Action Group (JTAG) methods and tools to acquire and analyse data from mobile devices are examined
  • Data encryption use in mobile devices is examined
  • Cloud based mobile forensic tools are evaluated and selected
  • Tools and techniques to examine mobile forensic data on Universal Integrated Circuit Card (UICC) devices are evaluated
  • Hardware tools used to acquire erased data files for mobile devices are researched
  • Developments in mobile data collection forensic tools are identified and classified
Replaces
State Code National Code Title Type
AX654 VU22248 Acquire digital forensic data from mobile devices Unit of competency
Associated Qual/Courses
State Code National Code Title Type
BGT52 22610VIC Advanced Diploma of Cyber Security Accredited course