ACC 693 Module 3 Milestone One Example

Reviewed by Portia Lambrick, MBA

This ACC 693 Module 3 Milestone One sample plans how an investigation will identify and preserve digital evidence before the person under suspicion knows it exists. SNHU ACC 693 (ACC-693) makes this plan the first stage of the final project for MS Accounting students in Module Three. At a composite Colorado roofing contractor, payables tests have pointed to a project manager and a flashing subcontractor that may exist only on paper. The paper inventories nine sources of digital evidence, sets out the order in which they will be preserved over five days, assigns each task, explains the legal basis for collecting each source, describes chain of custody and addresses the risk that evidence is destroyed once he suspects an inquiry.

CourseACC 693 Investigating with Computers
ModuleModule 3
Paper typegraduate milestone planning the identification and preservation of digital evidence
LengthAbout 1,050 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Accounting
UpdatedOctober 2026

Free sample paper for ACC 693 Module 3

1

Digital Evidence Identification and Preservation Plan

[Student Name]

Southern New Hampshire University

ACC 693: Investigating with Computers

Milestone One

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title states the two jobs the plan must do.
2

Digital Evidence Identification and Preservation Plan

Introduction

Payables analytics have identified a flashing subcontractor, paid about $1.1 million through seventy-four invoices, whose phone number matches the emergency contact of a senior project manager who approved every invoice. Before anyone speaks to him, the company must find and preserve the digital evidence that will confirm or dispel that lead. This plan, prepared for the company's general counsel, who is directing the investigation, identifies the sources, sets the order of preservation, assigns tasks, states the legal basis for each source, describes chain of custody and addresses the risks.

What this page is doingThe plan's purpose is stated.
3

Evidence Inventory

Digital evidence sources

SourceCustodianWhat it may showBasis for collection
Vendor master and change logFinance systems administratorWho created and edited the subcontractor's recordCompany system
Invoice approval historyFinance systems administratorWho approved each invoice and whenCompany system
Mailbox and OneDriveIT, Microsoft 365Communications about the subcontractor; invoice filesCompany account; acceptable use policy
Company laptopProject managerInvoice templates, documents, browser history, deleted filesCompany property; policy
Project job foldersIT, SharePointDaily logs, photos and change orders for the fourteen projectsCompany system
Badge and VPN logsIT and facilitiesWhere and when he worked when invoices were createdCompany system
Outgoing payment filesTreasuryBank account receiving each paymentCompany records
State business registrationPublic recordsThe LLC's organizer and registered agentPublic
Subcontractor's bank account and his personal phoneThird parties and the project managerWho received the money; texts with the relativeSubpoena, law enforcement or consent only

The inventory follows the approach recommended by Kent et al. (2006), which begins by listing possible data sources, then prioritizes them by likely value, volatility and the effort needed to acquire them.

What this page is doingNine sources are identified.
4

Preservation Sequence

The order is driven by one concern: preserving everything possible before the project manager suspects an inquiry. Harris (2006) describes anti-forensic techniques, from deleting files to running wiping tools, and the plan assumes he could use them if alerted.

Five-day preservation schedule

DayActionWho
1Confidential legal hold on his mailbox, OneDrive and SharePoint job folders; suspend deletion of badge and VPN logsGeneral counsel, IT director only
1Export vendor master, change log and approval history with hash valuesFinance systems administrator with examiner present
2Export outgoing payment files for the subcontractorTreasury manager
2Obtain the LLC's public registration and annual reportsExaminer
3Collect mailbox and OneDrive through the eDiscovery tool, preserving metadataIT director with outside forensic firm
4Collect SharePoint folders for the fourteen projectsOutside forensic firm
5Image the company laptop while he attends a scheduled job-site meetingOutside forensic firm

The laptop is last because collecting it is the one step he may notice. The timing of day five was chosen from his calendar, which shows a pre-construction meeting at a hospital job site sixty miles away, so the laptop will be in the office and he will be out for at least four hours. If his plans change, the imaging will move to the next scheduled site visit rather than proceed while he is present. The forensic firm will image it in a conference room using a hardware write blocker, return it within two hours and document the procedure, as Module Five will describe.

What this page is doingQuiet steps come first.
5

Sources Outside the Company's Control

Two sources cannot be collected by the company on its own. The subcontractor's bank records require a subpoena in a civil action or a request by law enforcement after a referral. The project manager's personal phone, which he used to text field crews and, the company suspects, his relative, belongs to him. The company's mobile device policy allows it to manage a work container on personal phones but not to read personal messages. The plan therefore preserves what the company does control, the work container's data through the device management system, and defers the personal phone to a request for consent at his interview or to legal process. The company's carrier records for the stipend it pays toward his phone bill do not include message content and are not needed.

Two further sources were considered and left out. His home internet records and personal bank statements would be relevant only if law enforcement became involved, and seeking them now would require legal process the company does not yet have grounds to start. The relative who organized the LLC is not a company employee, so nothing of hers is within reach except public filings. Recording these decisions protects the investigation from a later claim that it overreached, and it reminds the team that the evidence they do not collect now may still be obtained later through a referral. Module Four's discussion examines these limits further.

What this page is doingLegal process or consent is needed.
6

Chain of Custody

Each exported file and image will receive a SHA-256 hash value at the moment of collection, recorded on a custody form with the date, time, collector, source and method. Copies used for analysis will be verified against the original hash. Originals will be stored on encrypted drives in the general counsel's locked evidence cabinet, with every access logged. Casey (2011) emphasizes that digital evidence is easily altered without visible signs, so documentation, rather than appearance, is what shows it is unchanged.

What this page is doingEvery item is documented.
7

Risks and Mitigations

The gravest danger is that the project manager learns of the investigation from a colleague in IT or finance and destroys evidence. Only four people will know of the plan, each having signed a confidentiality acknowledgment. A second risk is automatic deletion: the company's email retention deletes items in the deleted folder after thirty days, which the legal hold suspends. A third risk is that the relative closes the LLC's bank account; this cannot be prevented by the company but can be documented through the payment files already exported. Finally, there is a risk of overcollection, gathering personal information without need, which the plan reduces by collecting only the work container on his phone and only the fourteen projects' folders. Collecting less, but collecting it properly, makes the eventual findings easier to defend.

What this page is doingThreats to the evidence are named with their fixes.
8

Conclusion

The plan identifies nine evidence sources, preserves the seven the company controls over five quiet days before any visible step, and reserves the two it does not control for legal process or consent. Hash values and custody forms make every item defensible. Milestone Two will analyze what the preserved email and documents show.

What this page is doingThe plan closes by restating its order.
9

References

Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.

Harris, R. (2006). Arriving at an anti-forensics consensus: Examining how to define and control the anti-forensics problem. Digital Investigation, 3, 44-49. https://doi.org/10.1016/j.diin.2006.06.005

Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to integrating forensic techniques into incident response (NIST Special Publication 800-86). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86

What the ACC 693 Module 3 instructions ask for

Milestone One in ACC 693 asks for a plan to identify, preserve and collect the digital evidence in your case before analysis begins. Guidelines typically require an inventory of evidence sources, the steps and order for preserving each, the people and tools involved, the legal authority for collection, chain of custody procedures and the risks to the evidence. Many versions stress that preservation must come before any contact with the suspect. Strong plans treat each source separately, since a mailbox, a laptop and a phone have different custodians, retention rules and legal issues, and they explain the reason for the order chosen. The plan becomes the foundation for Milestone Two's analysis.

How this ACC 693 Module 3 milestone one example is built

The paper lists nine sources: the payables system's vendor master change log and approval history, the project manager's Microsoft 365 mailbox and OneDrive, his company laptop, the project job folders, badge and VPN logs, the company's outgoing payment files, the state's business registration records for the LLC, the subcontractor's bank account and his personally owned phone. It schedules preservation over five days, beginning with a confidential legal hold on server-side data and ending with the laptop image taken while he is at a job site. Each source has a legal basis, from company ownership to the need for consent or a subpoena. Chain of custody and the risk of wiping are addressed directly.

Where the ACC 693 Module 3 rubric puts the points

The Milestone One rubric usually scores the completeness of the evidence inventory, the preservation strategy and sequence, roles and tools, legal and policy considerations, chain of custody and the identification of risks. Top papers distinguish sources the company controls from those it does not, explain why server-side data are preserved first and devices later, name the method for each acquisition and state who will do it. They also show how privacy limits affect personal devices and accounts. Papers lose credit for treating all evidence as equally accessible, for proposing to search personal accounts without authority, for leaving out custody documentation and for plans that would alert the suspect early.

ACC 693 Module 3 help: the mistakes that cost points

The usual problem with evidence plans is a single list of devices and data with no sequence. Order matters: anything stored on company servers can be preserved silently, while seizing a laptop is visible, so do the quiet steps first. Another frequent gap is legal authority; for each source, state why the company may collect it, whether through ownership, policy, consent or legal process. Students also forget that cloud data, logs and backups have retention periods that may delete evidence on their own. Close with the risks, especially deliberate destruction, and how the plan reduces them, because Milestone Seven's discussion of a wiped drive builds on this.

Get ACC 693 Module 3 written to your instructions

Send the ACC 693 Milestone One guidelines and your case. The plan will list every digital source, its custodian and legal basis, the preservation order and who does each step, and the risks to manage. Delivery runs about two days, and we charge nothing for the first one. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More ACC 693 papers and related MS Accounting samples

ACC 693 Module 3 questions, answered

Where can I find a free ACC 693 Module 3 Milestone One sample?

This page provides the complete ACC 693 Milestone One plan for preserving digital evidence in a roofing contractor's sham subcontractor case.

What is a legal hold in a digital investigation?

An instruction that suspends the normal deletion of data relevant to an investigation or lawsuit, applied to mailboxes, files, logs and backups so that evidence is not lost.

Why preserve server data before taking a suspect's laptop?

Because server data can be preserved without the suspect's knowledge, while taking a device is visible and may lead the person to delete what is still within reach.

Can an employer collect an employee's personal phone?

Not without consent, a legal order or, in some cases, a clear policy covering business data on the device; the employer's ownership of company systems does not extend to personal property.

What does chain of custody mean for digital evidence?

A written record of who collected each item, when and how, every transfer of possession and the hash values that show the data have not changed.