Anatomy of a Case Study: Difference between revisions
(First draft version.) |
(Updating anatomy further.) |
||
| Line 5: | Line 5: | ||
== About [Service] == | == About [Service] == | ||
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events | The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events. | ||
Include: | Include: | ||
* | * Known history of when and how the service was started. | ||
* What problems does the company or service claim to solve? | * What problems does the company or service claim to solve? | ||
* What marketing materials were used by the firm or business? | * What marketing materials were used by the firm or business? | ||
* Audits performed, and excerpts that may have been included. | * Audits performed, and excerpts that may have been included. | ||
* Business registration documents shown (fake or legitimate). | * Business registration documents shown (fake or legitimate). | ||
* How were people recruited to participate? | * How were people recruited to participate? | ||
* Public warnings and announcements prior to the event. | |||
Don't Include: | Don't Include: | ||
* Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed. | * Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed. | ||
* Anything that wasn't reasonably knowable at the time of the event. | |||
== The Reality == | == The Reality == | ||
This sections is included if a case involved deception or information that was unknown at the time. | This sections is included if a case involved deception or information that was unknown at the time. Examples include: | ||
* When the service was actually started (if different than the "official story"). | |||
* Who actually ran a service and their own personal history. | |||
* How the service was structured behind the scenes. (For example, there was no "trading bot".) | |||
* Details of what audits reported and how vulnerabilities were missed during auditing. | |||
== What Happened == | == What Happened == | ||
The specific events of the loss. | The specific events of the loss and how it came about. What actually happened to cause the loss. | ||
== Immediate Reactions == | == Immediate Reactions == | ||
How did the firm, platform, or individual deal with the events? | How did the firm, platform, or affected individual(s) deal with the events? Were services shut down? Were announcements made? Were groups formed? | ||
== Ultimate Outcome == | == Ultimate Outcome == | ||
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Were funds recovered? Was any tracing done? | What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Were funds recovered? Was any tracing done? | ||
== Ongoing Developments == | |||
What parts of this case are still remaining to be concluded? | |||
Revision as of 12:48, 12 January 2023
Case studies generally comprise of the following primary sections:
Overview
A high level overview of all the most relevant facts and information in the case.
About [Service]
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Include:
- Known history of when and how the service was started.
- What problems does the company or service claim to solve?
- What marketing materials were used by the firm or business?
- Audits performed, and excerpts that may have been included.
- Business registration documents shown (fake or legitimate).
- How were people recruited to participate?
- Public warnings and announcements prior to the event.
Don't Include:
- Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
- Anything that wasn't reasonably knowable at the time of the event.
The Reality
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss.
Immediate Reactions
How did the firm, platform, or affected individual(s) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Were funds recovered? Was any tracing done?
Ongoing Developments
What parts of this case are still remaining to be concluded?