Talk With an Expert

The Value of Contemporaneous Notes and Why They Are a Requirement for Security Professionals

The Value of Contemporaneous Notes and Why They Are a Requirement for Security Professionals (PDF, 6.55MB)Published: 30 Sep, 2019
Created by
Seth Enoka

Contemporaneous notes, or notes taken as soon as practicable after an event or action takes place, are invaluable to analysts in security roles performing activities such as digital forensics and incident response. There are various situations where contemporaneous notes provide a disproportionate return on time invested. However, there is no standard which defines the minimum information to record or indicates why every analyst should create some form of contemporaneous notes, whether in the civil or criminal domain. Timestamping, write-once versus write-many modalities, and how to edit or amend contemporaneous notes are important considerations. Additionally, including enough information such that the analyst, or any analyst, can follow the notes after time has elapsed and still achieve the same results and conclusions is essential when taking contemporaneous notes. The evidentiary value of contemporaneous notes should be defined and understood by every security professional.