Writing a Computer Forensic Technical Report
Introduction
One of the forensic analyst’s primary functions is the dissemination of the forensic process to the intended audience. To do their jobs successfully, they must write forensic reports that are both technically accurate and easy to read. A great investigation can be rendered largely ineffective if the resulting report is poor. In fact, a report that is disorganized and poorly written may actually hinder their case. Many find forensic technical writing a difficult job, particularly in making reports readable for the intended audience. This paper will offer a methodology to ensure a repeatable standard and hopefully make the job of forensic technical writing easier.
Report Preparation
Forensic information has limited value if it is not collected and reported in a usable form and presented to those who need to apply the information. Therefore, a big goal of the process is a standard way to document why the computer system was reviewed, how the computer data was reviewed, and what conclusions were arrived at. Computer forensic technical report writing requires a documented process to ensure a repeatable standard is met by the forensic analyst or the organization he is representing. The computer forensic report should achieve the following goals (taken from Incident Response. 211° Edition —see References):
- Accurately describe the details of an incident
- Be understandable to decision-makers
- Be able to withstand a barrage of legal scrutiny
- Be unambiguous and not open to misinterpretation
- Be easily referenced
- Contain all information required to explain your conclusions
- Offer valid conclusions, opinions, or recommendations when needed
- Be created in a timely manner
We will propose a general methodology based on the five major stages of technical report preparation. Within these general stages, we will add the specific details or guidelines as they relate to the field of computer forensics.
Download Digital Forensics Report Template | Example Document Template – Forensic Report Template:
Download PDF: Click Here
Download Word: Click Here
The five major stages of technical report preparation are (From NASA’s Guide to Research and Technical Writing — see References):
- Gathering the data
- Analyzing the results