Guide to Computer Forensics and Investigations Fourth Edition

Slides:



Advertisements
Similar presentations
Common Core Standards (What this means in computer class)
Advertisements

Module 2 Sessions 10 & 11 Report Writing.
Guide to Computer Forensics and Investigations Fourth Edition
Reading and writing reports
Chapter 10 Recovering Graphics Files
Guide to Computer Forensics and Investigations Fourth Edition
Guide to Computer Forensics and Investigations Third Edition
Guide to Computer Forensics and Investigations Third Edition
Guide to Computer Forensics and Investigations Fourth Edition Chapter 13 Cell Phone and Mobile Devices Forensics.
English & Communications for College
The Systems Analysis Toolkit
Presentation Name Elements and Standards
Chapter 12 – Strategies for Effective Written Reports
Guide to Computer Forensics and Investigations Fourth Edition
Q UINCY COLLEGE Paralegal Studies Program Paralegal Studies Program Litigation and Procedure Discovery: Overview and Interrogatories Litigation and Procedure.
Guide to Computer Forensics and Investigations, Second Edition Chapter 14 Becoming an Expert Witness and Reporting Results of Investigations.
Essays IACT 918 July 2004 Gene Awyzio SITACS University of Wollongong.
Technical Writing II Acknowledgement: –This lecture notes are based on many on-line documents. –I would like to thank these authors who make the documents.
PPA 503 – The Public Policy-Making Process Lecture 2b – Memo Writing.
COS/PSA 413 Day 22. Agenda WAGM will air a short segment on the CIAG lab on Thursday (Dec 1) during the 6PM broadcast Lab 11 Graded –3 A’s, 1 C and 1.
Basic Scientific Writing in English Lecture 3 Professor Ralph Kirby Faculty of Life Sciences Extension 7323 Room B322.
Technical Communication Fundamentals, 1 st Edition W.S. Pfeiffer and K. Adkins © 2011 Pearson Higher Education, Upper Saddle River, NJ All Rights.
COS 413 Day 23. Agenda Assignment 7 not corrected yet –Will be corrected tomorrow Second Capstone Progress reports OVER Due –Did not receive any reports.
Lecture 3: Writing the Project Documentation Part I
Report Writing Three phases of report writing Exploratory phase (MAPS)
Revising and Editing Your Research Paper. Self-Revision In the revision step, focus on the following questions and strategies:  Assignment requirements:
Revising and Editing Your Research Paper. Self-Revision In the revision step, focus on the following questions and strategies:  Assignment requirements:
PENNSYLVANIA COMMON CORE STANDARDS 1.4 Writing Students write for different purposes and audiences. Students write clear and focused text to convey a well-defined.
“Prepare for Success” Academic Year 2011/2012. What is a report? A presentation of facts and findings, often as a basis for recommendations Written for.
1 Summer 2012 Educator Effectiveness Academies English Language Arts Transitioning to the CCSS by Making Strategic and Informed Choices in the Classroom.
Scientific Writing Fred Tudiver, MD Karen Smith, MA Ivy Click, MA Amelia Nichols, MS.
What Makes an Essay an Essay. Essay is defined as a short piece of composition written from a writer’s point of view that is most commonly linked to an.
Report Writing.
Guide to Computer Forensics and Investigations Third Edition
Descriptive Essays Writing. What is a descriptive essay? It is a written assignment intended to describe the subject matter to the readers so that they.
How to write a technical report Powerpoint: H VenterSpeakers: L Kruger Editor: GF De Wet G Claassen Group 42.
Guide to Computer Forensics and Investigations Fourth Edition Chapter 14 Report Writing for High-Tech Investigations.
Technical Report Writing
Writing the “Results” & “Discussion” sections Awatif Alam Professor Community Medicine Medical College/ KSU.
Guide to Computer Forensics and Investigations Fifth Edition
Guide to Computer Forensics and Investigations Fifth Edition
How to Prepare an Annotated Bibliography
Chapter 5 Tax Research McGraw-Hill/Irwin Copyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
Scientific Communication
Department of Electrical Engineering Technical Writing Technical Reports Laboratory Reports Project Reports Murali Varanasi 03/24/2009.
The Writing Process. The writing process: Audience & Purpose  Strategy  Build interest if the audience's interest is low.  Provide historic background.
Effective Communication for Colleges, 10 th ed., by Brantley & Miller, 2005© Chapter 11 Chapter 11 – Slide 1 Reports, Proposals, and Instructions for the.
What the hell is a “Report” ? ENGL Copyright 2013 by Arthur Fricke “Informal” Reports Can be a few paragraphs to a few pages Generally provide information.
1 Business Communication Process and Product Brief Canadian Edition, Mary Ellen Guffey Kathleen Rhodes Patricia Rogin (c) 2003 Nelson, a division of Thomson.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Expert Witness and Report Writing - II November 26, 2008.
Unit 1 Activity 2B Communication Barriers Report
1.  Interpretation refers to the task of drawing inferences from the collected facts after an analytical and/or experimental study.  The task of interpretation.
Preparation of a Research Report Literature review.
Mrs. Cole  A top-notch project includes four elements: Project Logbook Abstract Project Notebook (research report and forms ) Visual Display.
Chapter 3 Critically reviewing the literature
Principals of Research Writing. What is Research Writing? Process of communicating your research  Before the fact  Research proposal  After the fact.
Format of Formal Reports
DESIGNING AN ARTICLE Effective Writing 3. Objectives Raising awareness of the format, requirements and features of scientific articles Sharing information.
  Writing a Research Paper  Creating a Technological Presentation  Creating a Display Board  Writing a Test Guidelines for the Following.
REPORT WRITING.
Report Writing Three phases of report writing Exploratory phase (MAPS)
Reports Chapter 17 © Pearson 2012.
Reading and writing reports
Editing & Polishing your Assignment
Writing Careful Long Reports
Writing reports Wrea Mohammed
Guide to Computer Forensics and Investigations Fourth Edition
Writing Careful Long Reports
Guide to Computer Forensics and Investigations Fourth Edition
TECHNICAL REPORTS WRITING
Presentation transcript:

Guide to Computer Forensics and Investigations Fourth Edition Chapter 14 Report Writing for High-Tech Investigations

Guide to Computer Forensics and Investigations Objectives Explain the importance of reports Describe guidelines for writing reports Explain how to use forensics tools to generate reports Guide to Computer Forensics and Investigations

Understanding the Importance of Reports Communicate the results of your investigation Including expert opinion Courts require expert witness to submit written reports Written report must specify fees paid for the expert’s services And list all other civil or criminal cases in which the expert has testified Deposition banks Examples of expert witness’ previous testimonies Guide to Computer Forensics and Investigations

Limiting a Report to Specifics All reports to clients should start with the job mission or goal Find information on a specific subject Recover certain significant documents Recover certain types of files Before you begin writing, identify your audience and the purpose of the report Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations Types of Reports Computer forensics examiners are required to create different types of reports Examination plan What questions to expect when testifying Attorney uses the examination plan to guide you in your testimony You can propose changes to clarify or define information Helps your attorney learn the terms and functions used in computer forensics Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations

Types of Reports (continued) Verbal report Less structured Attorneys cannot be forced to release verbal reports Preliminary report Addresses areas of investigation yet to be completed Tests that have not been concluded Interrogatories Document production Depositions Guide to Computer Forensics and Investigations

Types of Reports (continued) Written report Affidavit or declaration Limit what you write and pay attention to details Include thorough documentation and support of what you write Guide to Computer Forensics and Investigations

Guidelines for Writing Reports Hypothetical questions based on factual evidence Less favored today Guide and support your opinion Can be abused and overly complex Opinions based on knowledge and experience Exclude from hypothetical questions Facts that can change, cannot be used, or are not relevant to your opinion Guide to Computer Forensics and Investigations

Guidelines for Writing Reports (continued) As an expert witness, you may testify to an opinion, or conclusion, if four basic conditions are met: Opinion, inferences, or conclusions depend on special knowledge or skills Expert should qualify as a true expert Expert must testify to a certain degree of certainty Experts must describe facts on which their opinions are based, or they must testify to a hypothetical question Guide to Computer Forensics and Investigations

What to Include in Written Preliminary Reports Anything you write down as part of your examination for a report Subject to discovery from the opposing attorney Considered high-risk documents Spoliation Destroying the report could be considered destroying or concealing evidence Include the same information as in verbal reports Guide to Computer Forensics and Investigations

What to Include in Written Preliminary Reports (continued) Additional items to include in your report: Summarize your billing to date and estimate costs to complete the effort Identify the tentative conclusion (rather than the preliminary conclusion) Identify areas for further investigation and obtain confirmation from the attorney on the scope of your examination Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations Report Structure Structure Abstract Table of contents Body of report Conclusion References Glossary Acknowledgements Appendixes Guide to Computer Forensics and Investigations

Writing Reports Clearly Consider Communicative quality Ideas and organization Grammar and vocabulary Punctuation and spelling Lay out ideas in logical order Build arguments piece by piece Group related ideas and sentences into paragraphs Group paragraphs into sections Guide to Computer Forensics and Investigations

Writing Reports Clearly (continued) Avoid jargon, slang, and colloquial terms Define technical terms Consider your audience Consider writing style Use a natural language style Avoid repetition and vague language Be precise and specific Use active rather than passive voice Avoid presenting too many details and personal observations Guide to Computer Forensics and Investigations

Writing Reports Clearly (continued) Include signposts Draw reader’s attention to a point Guide to Computer Forensics and Investigations

Designing the Layout and Presentation of Reports Decimal numbering structure Divides material into sections Readers can scan heading Readers see how parts relate to each other Legal-sequential numbering Used in pleadings Roman numerals represent major aspects Arabic numbers are supporting information Guide to Computer Forensics and Investigations

Designing the Layout and Presentation of Reports (continued) Providing supporting material Use material such as figures, tables, data, and equations to help tell the story as it unfolds Formatting consistently How you format text is less important than being consistent in applying formatting Explaining examination and data collection methods Explain how you studied the problem, which should follow logically from the purpose of the report Guide to Computer Forensics and Investigations

Designing the Layout and Presentation of Reports (continued) Including calculations If you use any hashing algorithms, be sure to give the common name Providing for uncertainty and error analysis Protect your credibility Explaining results and conclusions Explain your findings, using subheadings to divide the discussion into logical parts Save broader generalizations and summaries for the report’s conclusion Guide to Computer Forensics and Investigations

Designing the Layout and Presentation of Reports (continued) Providing references Cite references by author’s last name and year of publication Follow a standard format Including appendixes You can include appendixes containing material such as raw data, figures not used in the body of the report, and anticipated exhibits Arrange them in the order referred to in the report Guide to Computer Forensics and Investigations

Generating Report Findings with Forensics Software Tools Forensics tools generate reports when performing analysis Report formats Plaintext Word processor HTML format Guide to Computer Forensics and Investigations

Using ProDiscover Basic to Generate Reports Create a new project Add an image file to the project Search for file extensions Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations

Using ProDiscover Basic to Generate Reports (continued) Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports Create a new case Add evidence to the case Analyze evidence with FTK Look for image files Locate encrypted files Search for specific keywords Indexed search Live search Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports (continued) Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports (continued) Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports (continued) Create bookmarks Generate a report from your bookmarks Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports (continued) Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports (continued) Guide to Computer Forensics and Investigations

Using FTK Demo to Generate Reports (continued) Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations Summary All U.S. district courts and many state courts require expert witnesses to submit written reports Attorneys use deposition banks to research expert witnesses’ previous testimony Reports should answer the questions you were retained to answer A well-defined report structure contributes to readers’ ability to understand the information you’re communicating Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations Summary (continued) Clarity of writing is critical to a report’s success Convey a tone of objectivity and be detached in your observations Guide to Computer Forensics and Investigations