| Course | ACC 693 Investigating with Computers |
|---|---|
| Module | Module 3 |
| Paper type | graduate milestone planning the identification and preservation of digital evidence |
| Length | About 1,050 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Accounting |
| Updated | October 2026 |
Free sample paper for ACC 693 Module 3
Digital Evidence Identification and Preservation Plan
[Student Name]
Southern New Hampshire University
ACC 693: Investigating with Computers
Milestone One
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Digital Evidence Identification and Preservation Plan
Introduction
Payables analytics have identified a flashing subcontractor, paid about $1.1 million through seventy-four invoices, whose phone number matches the emergency contact of a senior project manager who approved every invoice. Before anyone speaks to him, the company must find and preserve the digital evidence that will confirm or dispel that lead. This plan, prepared for the company's general counsel, who is directing the investigation, identifies the sources, sets the order of preservation, assigns tasks, states the legal basis for each source, describes chain of custody and addresses the risks.
Evidence Inventory
Digital evidence sources
| Source | Custodian | What it may show | Basis for collection |
|---|---|---|---|
| Vendor master and change log | Finance systems administrator | Who created and edited the subcontractor's record | Company system |
| Invoice approval history | Finance systems administrator | Who approved each invoice and when | Company system |
| Mailbox and OneDrive | IT, Microsoft 365 | Communications about the subcontractor; invoice files | Company account; acceptable use policy |
| Company laptop | Project manager | Invoice templates, documents, browser history, deleted files | Company property; policy |
| Project job folders | IT, SharePoint | Daily logs, photos and change orders for the fourteen projects | Company system |
| Badge and VPN logs | IT and facilities | Where and when he worked when invoices were created | Company system |
| Outgoing payment files | Treasury | Bank account receiving each payment | Company records |
| State business registration | Public records | The LLC's organizer and registered agent | Public |
| Subcontractor's bank account and his personal phone | Third parties and the project manager | Who received the money; texts with the relative | Subpoena, law enforcement or consent only |
The inventory follows the approach recommended by Kent et al. (2006), which begins by listing possible data sources, then prioritizes them by likely value, volatility and the effort needed to acquire them.
Preservation Sequence
The order is driven by one concern: preserving everything possible before the project manager suspects an inquiry. Harris (2006) describes anti-forensic techniques, from deleting files to running wiping tools, and the plan assumes he could use them if alerted.
Five-day preservation schedule
| Day | Action | Who |
|---|---|---|
| 1 | Confidential legal hold on his mailbox, OneDrive and SharePoint job folders; suspend deletion of badge and VPN logs | General counsel, IT director only |
| 1 | Export vendor master, change log and approval history with hash values | Finance systems administrator with examiner present |
| 2 | Export outgoing payment files for the subcontractor | Treasury manager |
| 2 | Obtain the LLC's public registration and annual reports | Examiner |
| 3 | Collect mailbox and OneDrive through the eDiscovery tool, preserving metadata | IT director with outside forensic firm |
| 4 | Collect SharePoint folders for the fourteen projects | Outside forensic firm |
| 5 | Image the company laptop while he attends a scheduled job-site meeting | Outside forensic firm |
The laptop is last because collecting it is the one step he may notice. The timing of day five was chosen from his calendar, which shows a pre-construction meeting at a hospital job site sixty miles away, so the laptop will be in the office and he will be out for at least four hours. If his plans change, the imaging will move to the next scheduled site visit rather than proceed while he is present. The forensic firm will image it in a conference room using a hardware write blocker, return it within two hours and document the procedure, as Module Five will describe.
Sources Outside the Company's Control
Two sources cannot be collected by the company on its own. The subcontractor's bank records require a subpoena in a civil action or a request by law enforcement after a referral. The project manager's personal phone, which he used to text field crews and, the company suspects, his relative, belongs to him. The company's mobile device policy allows it to manage a work container on personal phones but not to read personal messages. The plan therefore preserves what the company does control, the work container's data through the device management system, and defers the personal phone to a request for consent at his interview or to legal process. The company's carrier records for the stipend it pays toward his phone bill do not include message content and are not needed.
Two further sources were considered and left out. His home internet records and personal bank statements would be relevant only if law enforcement became involved, and seeking them now would require legal process the company does not yet have grounds to start. The relative who organized the LLC is not a company employee, so nothing of hers is within reach except public filings. Recording these decisions protects the investigation from a later claim that it overreached, and it reminds the team that the evidence they do not collect now may still be obtained later through a referral. Module Four's discussion examines these limits further.
Chain of Custody
Each exported file and image will receive a SHA-256 hash value at the moment of collection, recorded on a custody form with the date, time, collector, source and method. Copies used for analysis will be verified against the original hash. Originals will be stored on encrypted drives in the general counsel's locked evidence cabinet, with every access logged. Casey (2011) emphasizes that digital evidence is easily altered without visible signs, so documentation, rather than appearance, is what shows it is unchanged.
Risks and Mitigations
The gravest danger is that the project manager learns of the investigation from a colleague in IT or finance and destroys evidence. Only four people will know of the plan, each having signed a confidentiality acknowledgment. A second risk is automatic deletion: the company's email retention deletes items in the deleted folder after thirty days, which the legal hold suspends. A third risk is that the relative closes the LLC's bank account; this cannot be prevented by the company but can be documented through the payment files already exported. Finally, there is a risk of overcollection, gathering personal information without need, which the plan reduces by collecting only the work container on his phone and only the fourteen projects' folders. Collecting less, but collecting it properly, makes the eventual findings easier to defend.
Conclusion
The plan identifies nine evidence sources, preserves the seven the company controls over five quiet days before any visible step, and reserves the two it does not control for legal process or consent. Hash values and custody forms make every item defensible. Milestone Two will analyze what the preserved email and documents show.
References
Casey, E. (2011). Digital evidence and computer crime: Forensic science, computers, and the Internet (3rd ed.). Academic Press.
Harris, R. (2006). Arriving at an anti-forensics consensus: Examining how to define and control the anti-forensics problem. Digital Investigation, 3, 44-49. https://doi.org/10.1016/j.diin.2006.06.005
Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to integrating forensic techniques into incident response (NIST Special Publication 800-86). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86
What the ACC 693 Module 3 instructions ask for
Milestone One in ACC 693 asks for a plan to identify, preserve and collect the digital evidence in your case before analysis begins. Guidelines typically require an inventory of evidence sources, the steps and order for preserving each, the people and tools involved, the legal authority for collection, chain of custody procedures and the risks to the evidence. Many versions stress that preservation must come before any contact with the suspect. Strong plans treat each source separately, since a mailbox, a laptop and a phone have different custodians, retention rules and legal issues, and they explain the reason for the order chosen. The plan becomes the foundation for Milestone Two's analysis.
How this ACC 693 Module 3 milestone one example is built
The paper lists nine sources: the payables system's vendor master change log and approval history, the project manager's Microsoft 365 mailbox and OneDrive, his company laptop, the project job folders, badge and VPN logs, the company's outgoing payment files, the state's business registration records for the LLC, the subcontractor's bank account and his personally owned phone. It schedules preservation over five days, beginning with a confidential legal hold on server-side data and ending with the laptop image taken while he is at a job site. Each source has a legal basis, from company ownership to the need for consent or a subpoena. Chain of custody and the risk of wiping are addressed directly.
Where the ACC 693 Module 3 rubric puts the points
The Milestone One rubric usually scores the completeness of the evidence inventory, the preservation strategy and sequence, roles and tools, legal and policy considerations, chain of custody and the identification of risks. Top papers distinguish sources the company controls from those it does not, explain why server-side data are preserved first and devices later, name the method for each acquisition and state who will do it. They also show how privacy limits affect personal devices and accounts. Papers lose credit for treating all evidence as equally accessible, for proposing to search personal accounts without authority, for leaving out custody documentation and for plans that would alert the suspect early.
ACC 693 Module 3 help: the mistakes that cost points
The usual problem with evidence plans is a single list of devices and data with no sequence. Order matters: anything stored on company servers can be preserved silently, while seizing a laptop is visible, so do the quiet steps first. Another frequent gap is legal authority; for each source, state why the company may collect it, whether through ownership, policy, consent or legal process. Students also forget that cloud data, logs and backups have retention periods that may delete evidence on their own. Close with the risks, especially deliberate destruction, and how the plan reduces them, because Milestone Seven's discussion of a wiped drive builds on this.
Get ACC 693 Module 3 written to your instructions
Send the ACC 693 Milestone One guidelines and your case. The plan will list every digital source, its custodian and legal basis, the preservation order and who does each step, and the risks to manage. Delivery runs about two days, and we charge nothing for the first one. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More ACC 693 papers and related MS Accounting samples
- ACC 693 Module 1 Discussion: What Computers Changed About Fraud Investigation
- ACC 693 Module 2 Data Analytics Assignment: Testing Three Years of Payables
- ACC 693 Module 4 Discussion: Personal Phones, Private Email and the Employer's Reach
- ACC 620 Module 2 Lease Accounting Assignment: A Terminal Lease and a Tractor Lease Side by Side
- ACC 645 Module 8 Internal Audit Assignment: A Risk-Based Internal Audit Plan
- ACC 640 Module 2 Client Acceptance Assignment: Taking Over After a Resignation
- ACC 692 Module 2 Interview Planning Assignment: Who to Talk To, and in What Order
ACC 693 Module 3 questions, answered
Where can I find a free ACC 693 Module 3 Milestone One sample?
This page provides the complete ACC 693 Milestone One plan for preserving digital evidence in a roofing contractor's sham subcontractor case.
What is a legal hold in a digital investigation?
An instruction that suspends the normal deletion of data relevant to an investigation or lawsuit, applied to mailboxes, files, logs and backups so that evidence is not lost.
Why preserve server data before taking a suspect's laptop?
Because server data can be preserved without the suspect's knowledge, while taking a device is visible and may lead the person to delete what is still within reach.
Can an employer collect an employee's personal phone?
Not without consent, a legal order or, in some cases, a clear policy covering business data on the device; the employer's ownership of company systems does not extend to personal property.
What does chain of custody mean for digital evidence?
A written record of who collected each item, when and how, every transfer of possession and the hash values that show the data have not changed.