Report Template
This template defines a public research report structure for findings that are broader than a single advisory. Reports may summarize a research method, a class of observations, an aggregate dataset, or a sanitized case study.
Required Sections
- Title And Status — public title, publication state, and canonical URL.
- Executive Summary — concise technical summary with no unsupported claims.
- Scope — what was reviewed, what was excluded, and what authority applied.
- Method — repeatable description of safe, non-disruptive research steps.
- Findings — evidence-backed observations with impact boundaries.
- Limitations — known uncertainty, untested conditions, and excluded systems.
- Defensive Guidance — remediation, detection, hardening, or review actions.
- Data Handling — statement on evidence reduction and redaction.
- References — standards, vendor material, advisories, and public context.
Publication Rules
Reports should demonstrate restraint. A strong report does not need to overstate severity or include every private detail. It should give defenders enough information to act while preserving coordination obligations and minimizing sensitive data exposure.
Review Checklist
- Claims are traceable to evidence.
- Evidence shown publicly is sanitized.
- The report does not imply authorization outside the stated scope.
- Defensive value outweighs disclosure risk.
- Any data tables have schema, provenance, and privacy notes.