The FJC Reference Manual and computer science
- PRODUCED BY
- National Academies with the FJC
- AUDIENCE
- Federal judges
- READ TIME
- 9 min
The Reference Manual on Scientific Evidence is the reference work federal judges consult when expert evidence turns on a field they do not practise in. Its chapters are reference guides, one per discipline. Until the fourth edition there was no guide on computer science, so a court weighing a dispute about how a filesystem records a timestamp had no neutral description of the field to read.
What is the Reference Manual on Scientific Evidence?
A reference work on scientific and technical expert evidence written for federal judges, produced by the National Academies in cooperation with the Federal Judicial Center, and organised as a set of per-discipline reference guides.
Its existence is a direct consequence of the gatekeeping role. Daubert put the reliability of expert testimony in the hands of a generalist judge, and Kumho Tire extended that duty to technical and other specialised knowledge — including, expressly, fields that are not sciences in any laboratory sense. A judge who must decide whether a method is reliable, without being able to practise it, needs something to read that was not written by either party.
The structure follows from the purpose. Each reference guide takes one field and explains how its methods work, what they are capable of establishing, where they are contested, and what a court should ask about an opinion offered from within it. The earlier editions covered ground including statistics, epidemiology, toxicology, DNA identification, engineering and mental health — the fields that generated the expert disputes of the era in which they were written.
Two properties give the Manual its weight, and both are worth keeping in view because they are also its limits. It is written for judges rather than for practitioners, which is why its chapters read as orientation rather than as procedure. And it is produced under a process with no party interest in any outcome, which is what distinguishes it from a treatise a litigant commissioned.
Why does a reference guide change the argument?
Because it moves the general capability of a field out of dispute. In a digital-evidence hearing an unreasonable amount of time goes on propositions no honest examiner on either side contests: that filesystem timestamps exist in more than one place, that deletion is ordinarily a bookkeeping change rather than an erasure, that a hash match establishes identical content and nothing about how the content arrived. Both sides brief those points from scratch, each with its own expert, and the hearing is half over before anyone reaches the actual disagreement.
A reference guide is the document that lets a court take those propositions as read. It does not decide anything. It clears the floor so that the contested question — this examination, this artifact, this inference — is what gets argued.
It does not decide anything. It clears the floor so that the contested question is what gets argued.
The asymmetry it removes
There is a second effect, less often noticed. Where no neutral description of a field exists, the side with the more confident witness has an advantage on the general questions, because there is nothing to check the confidence against. Digital forensics has been in that position for the whole of its litigated history: the available written sources are vendor documentation, practitioner guidance written for practitioners, and the occasional academic paper. None of them is addressed to the person deciding the motion.
What does the fourth edition mean for digital evidence?
The fourth edition of the Manual adds a reference guide on computer science. That is the significant fact for this discipline, and it is significant regardless of what any particular passage in the chapter says: for the first time, a judge facing a contested digital forensic opinion has a chapter in the book on the bench that is about the field the opinion comes from.
What can be said without reading it is what a computer-science reference guide has to cover in order to be useful to a court, because the list is dictated by the disputes that actually arise. Any such chapter is going to have to reach the following, and a litigator can usefully go looking for each of them:
- What a timestamp is a record of. The master file table on an NTFS volume carries timestamps in two separate attributes written by different code paths, and a discrepancy between them is the classic signature of timestamp manipulation. A court being asked to treat a displayed date as the time an act occurred needs to know that.
- What a hash comparison establishes. That two files have identical content — not the transfer path, not the arrival date, not who put the file there. This is the proposition most often stretched in both directions, and it has its own page here on whether MD5 is still defensible.
- What deletion and overwriting are. The difference between unlinking a file and destroying its content is the whole basis of recovery, and also of the limits on recovery — a solid-state drive with active garbage collection can discard deleted content with no user action at all.
- Why absence of a record is not absence of an event. Artifacts roll over, are capped by size, and are switched off by configuration. The NTFS transaction log may cover hours on an active workstation. A court that does not know this will read a negative finding as a positive one.
- Why an account is not a person. Logs record sessions and credentials. Attributing a session to a human being requires evidence from outside the machine, and the report should say which evidence it relied on.
Those five propositions are the load-bearing ones in almost every digital-evidence dispute, and each of them is currently established or contested by testimony. A chapter that states them neutrally changes what has to be proved.
How is a reference guide actually used in a Rule 702 motion?
- Separate the general from the particular before you draft. Take each proposition the motion depends on and label it: is this a claim about what the field can do, or a claim about what this examiner did? A reference guide supports the first category only.
- Cite it for the field, not for the finding. “Recovery from unallocated space commonly yields content without its filesystem metadata” is the kind of statement a reference guide supports. “The carved document therefore came from the defendant’s USB drive” is not, and a citation attached to it will be read as padding.
- Put the pin cite in, or leave the citation out. A reference to a several-hundred-page manual with no page is an invitation to be told it does not say that. This is the failure mode of every commentary written about a document its author has not read.
- Expect it to be used against the overstatement, not the method. The propositions a neutral guide states clearly are mostly limits — what a record does not contain, what an inference does not follow from. That makes it a better instrument for narrowing an opinion than for excluding one, which is also the more commonly granted relief.
- Have your own expert address it either way. An examiner whose report is consistent with the neutral description of the field is in a strong position and should say so. An examiner who departs from it has a burden to explain the departure, and explaining it in the report is better than explaining it on cross.
What will a reference guide not do?
| THE QUESTION | DOES A REFERENCE GUIDE REACH IT? | WHAT REACHES IT |
|---|---|---|
| Is disk imaging a reliable technique? | Yes — this is exactly what a neutral description of the field is for. | The guide, plus a function-level test record for the version run. |
| Was this image verified? | No. | The acquisition log and both hash values, at acquisition and at verification. |
| Can a shellbag identify a physical device? | Yes, for the general proposition. The answer is no, because the structure carries no volume serial number — and that is a fact about the artifact rather than about the case. | The guide for the general point; the artifact entry and a corroborating record for the finding. |
| Did this examiner apply the method reliably here? | No. This is Rule 702(d) and it is answered from the record of the examination. | Contemporaneous notes, named tools and versions, and a finding a second examiner can reproduce. |
| Is this examiner qualified? | No. | Training, documented casework and the scope of the tender — the ground fought over in Galaxy Computer Services v. Baker, where the court observed that computer forensics does not require a background in programming. |
The row that decides motions is the fourth one, and no reference guide has ever been able to answer it. That is not a criticism of the Manual; it is the division of labour the amended rule sets up. Rule 702(c) asks about principles and methods, which a neutral description can address. Rule 702(d) asks whether the opinion reflects a reliable application of them to the facts of this case, which only the examination record can.
What already does this job, and what each one is good for
Until a computer-science reference guide is in general circulation, and after it is, the same four sources carry most of the weight in digital-evidence briefing. They are not interchangeable.
- Rule text with the advisory committee notes. The notes to the December 2023 amendment to Rule 702 are unusually direct about expert overstatement, and they are the citation for the proposition that a forensic expert should avoid assertions of absolute certainty where the methodology is subjective. Nothing else states it as plainly.
- SWGDE best-practice publications. What the discipline expects of acquisition, examination, reporting and quality practice. Guidance rather than binding rules — so a documented departure is arguable and an undocumented one is a line of cross-examination.
- NIST process guidance and tool testing. Both the process publications and the CFTT tool test reports. These are the documents that make the error-rate factor citable rather than argumentative.
- The case law on the specific artifact. The most underused source of the four, because it is the hardest to assemble. A ruling about the reliability of testimony on wiping software is worth more in a wiping dispute than any general statement about digital forensics, and the Daubert Docket exists to make that search possible.
The reason a reference guide on computer science matters more than adding a fifth item to that list is that it is the only one of them written for the reader who decides the motion. The other four are addressed to examiners, to advocates, or to nobody in particular.
Frequently asked questions
What is the Reference Manual on Scientific Evidence?
It is a reference work written for federal judges on how to handle scientific and technical expert evidence, produced by the National Academies in cooperation with the Federal Judicial Center. It is organised as a set of reference guides, each covering one field — how the discipline works, what its methods can and cannot establish, and the questions a court should be asking.
Is the Reference Manual binding authority?
No. It is not a rule, a statute or a decision, and citing it does not settle anything. Its weight is persuasive and institutional: it is written for judges, distributed to them, and authored by subject-matter specialists under a process with no party interest in the outcome. That is a different kind of weight from a treatise commissioned by a litigant.
Did earlier editions of the Manual cover digital evidence?
Not as a field of its own. The reference guides in earlier editions addressed areas such as statistics, epidemiology, toxicology, DNA identification, engineering and mental health. A court facing a dispute about how a filesystem timestamp is written had no chapter to turn to, which is the gap the fourth edition's computer-science guide addresses.
How would a reference guide be used in a Daubert motion?
As the neutral description of the field that frames the reliability question, not as the answer to it. It supports statements about what a method is capable of and what its recognised limits are. The remaining work — whether this examination followed the method and whether this artifact supports this conclusion — is Rule 702(d) territory and has to come from the record.
Does a reference guide replace expert testimony?
No, and offering it that way invites the objection. A reference guide describes a discipline in general terms; the court still needs a witness who examined this evidence, can say what was done to it, and can be cross-examined on the inference. Where a guide helps is in preventing an argument about the general capability of a method from consuming the hearing.
Where does the Manual sit relative to SWGDE and NIST publications?
They serve different functions. SWGDE states what the discipline expects of practitioners and NIST publishes tool test results and process guidance; both are written for examiners. The Reference Manual is written for the judge who has to decide whether an examiner's opinion goes to the jury, which is why it is the only one of the three drafted with the gatekeeping question as its subject.
Law & Forensics writes reports that state what each artifact records, what it does not establish, and the confidence the record supports — the propositions a neutral description of the field will be checked against. If digital evidence is contested in your matter — start a conflicts check or reach us directly below.
ENGAGE AN EXPERT→Or write to info@lawandforensics.com or call 855-529-2466.
Related reading
- Daubert challenges to digital evidence
The gatekeeping framework a reference guide is read inside — amended Rule 702, the four factors, and how forensic opinions get excluded.
- The Daubert factors applied to forensic method
The factor-by-factor translation, and the boundary between a claim about the field and a claim about this examination.
- The Daubert Docket
Fifty-five rulings on digital forensic expert testimony — the ground attacked, the outcome, and the opinion each holding was read from.
- The artifact index
Thirty-six artifacts, each with what it proves, what it cannot prove, how it is attacked, and how long it survives.
- Glossary of digital forensic terms
Every term on this page defined by its evidentiary consequence, including the standards bodies and the reliability vocabulary.
Attorney advertising / expert services. General information about evidence law and forensic practice, not legal advice, and not a substitute for checking the rules and case law of your own forum.