Digital Forensics

A.Y. 2026/2027
6
Max ECTS
42
Overall hours
SSD
INFO-01/A
Language
Italian
Learning objectives
Within the Master's Degree in Cybersecurity, the Digital Forensics course represents a fundamental discipline for the analysis and handling of digital evidence in both criminal and civil contexts.
The course provides advanced knowledge and operational skills for the proper handling of digital evidence, adopting an interdisciplinary approach that integrates technical, methodological, and legal aspects. Particular attention is devoted to complex organizational environments, where investigative needs, compliance requirements, and potential legal implications coexist.
Digital forensics is approached as an applied scientific method aimed at reconstructing relevant events from digital evidence, according to the principles of:
· reproducibility,
· traceability,
· documentation,
· legal defensibility.
The course integrates:
· theoretical and scientific foundations,
· national and European legal frameworks (e.g., GDPR, eIDAS),
· operational procedures and international standards.
Expected learning outcomes
Knowledge and Understanding
At the end of the course, students will be able to:
· understand the scientific principles of digital forensics and the characteristics of digital evidence;
· analyze the relevant national and European legal framework;
· understand the role of international standards in the management of digital evidence.
Applying Knowledge and Understanding
Students will be able to:
· apply forensic methodologies for the identification, acquisition, preservation, and analysis of digital evidence, ensuring chain of custody;
· operate in complex organizational environments, interacting with multiple business functions;
· apply incident response procedures in line with international standards.
Making Judgements
Students will develop the ability to:
· assess the admissibility, integrity, and reliability of digital evidence;
· select appropriate methodologies based on the operational context;
· balance investigative needs with legal constraints, particularly with regard to the protection of fundamental rights.
Communication Skills
Students will be able to:
· produce clear, structured, and well-documented technical reports;
· present evidence and conclusions in a coherent and verifiable manner.
Learning Skills
Students will develop the ability to:
· independently update their knowledge in response to technological and regulatory developments;
· address new types of digital evidence by applying forensic methodologies.
Single course

This course can be attended as a single course.

Course syllabus and organization

Single session

Lesson period
Third four month period
Course syllabus
topics covered:
1. Digital forensics in criminal investigations;
2. Digital forensics in civil proceedings;
3. Electronic documents and electronic signatures in Italy and abroad;
4. Evidentiary value of electronic documents;
5. Technical assessment in corporate liability;
6. Digital forensics in the event of a data breach;
7. Information systems and employee monitoring;
8. Digital forensics and industrial property protection;
9. Digital forensics and software protection;
10. Digital forensics and software certification;
11. Elements of healthcare digital forensics;
12. ISO 27037;
13. ISO 27035;
14. ISO 19011;
15. Incident response;
16. Forensic readiness plan;
17. Incident response;
18. Cloud Forensics;
19. IoT Forensics;
20. Multimedia forensics
Prerequisites for admission
Basic knowledge is required in:
· operating systems,
· computer networks,
· information security,
· fundamentals of IT law (recommended but not mandatory).
Teaching methods
Lectures and lab simulations
Teaching Resources
Casey, E. (2011). Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet (3a ed.). Waltham (MA): Academic Press / Elsevier. ISBN 978-0-12-374268-1.
Casey, E. (a cura di) (2010). Handbook of Digital Forensics and Investigation. Burlington (MA): Academic Press / Elsevier. Con contributi di C. Altheide, C. Daywalt, A. de Donno, D. Forte, J. O. Holley, A. Johnston, R. van der Knijff, A. Kokocinski, P. H. Luehr, T. Maguire, R. D. Pittman, C. W. Rose, J. J. Schwerha IV, D. Shaver, J. R. Smith. ISBN 978-0-12-374267-4.
Farmer, D., & Venema, W. (2005). Forensic Discovery. Upper Saddle River (NJ): Addison-Wesley Professional (Pearson Education). ISBN 0-201-63497-X.
Kävrestad, J., Birath, M., & Clarke, N. (2024). Fundamentals of Digital Forensics: A Guide to Theory, Research and Applications (3a ed.). Cham: Springer Nature Switzerland, collana Texts in Computer Science. ISBN 978-3-031-53648-9 (cartaceo); 978-3-031-53649-6 (e-book). DOI: 10.1007/978-3-031-53649-6.
Oettinger, W. (2022). Learn Computer Forensics: Your One-Stop Guide to Searching, Analyzing, Acquiring, and Securing Digital Evidence (2a ed.). Birmingham: Packt Publishing. ISBN 978-1-80323-830-2.
Carofiglio, G. (2007). L'arte del dubbio. Palermo: Sellerio Editore, collana «La memoria», 734, 231 pp. ISBN 978-88-389-2249-7.
Luparia, L. (a cura di) (2009). Sistema penale e criminalita' informatica. Milano: Giuffre'.
Ziccardi, G. (2019). Manuale di informatica giuridica e diritto delle nuove tecnologie (2a ed.). Torino: UTET Giuridica.
Assessment methods and Criteria
Learning outcomes will be assessed through:
· a written exam consisting of open-ended questions aimed at evaluating theoretical understanding, analytical skills, and methodological application.
Assessment will consider:
· accuracy and completeness of knowledge,
· ability to apply concepts,
· autonomy of judgment,
· clarity of presentation and methodological rigor.
INFO-01/A - Informatics - University credits: 6
Lessons: 42 hours