Setting the Stage for Automatic Disposition

Similar documents
DIRECTIVE ON RECORDS AND INFORMATION MANAGEMENT (RIM) January 12, 2018

The Need for a Terminology Bridge. May 2009

4.2 Electronic Mail Policy

Records Management Metadata Standard

RECORDS AND INFORMATION MANAGEMENT AND RETENTION

In 2017, the Auditor General initiated an audit of the City s information technology infrastructure and assets.

Before Searching for Solutions It s All About the Data

Case Study: Using the Principles to Assess Current & Future State Presented by John Isaza, Esq., FAI ARMA Houston Chapter April 23, 2013

Emerging Trends in Records Management Technology. Jessie Weston, CRA 2018 MISA Conference October 11-12, 2018

The Principles: A Needs Assessment Case Study Presented by John Isaza, Esq., FAI ARMA Houston Chapter April 23, 2013

Common approaches to management. Presented at the annual conference of the Archives Association of British Columbia, Victoria, B.C.

ISO TC46/SC11 Archives/records management

Applying Auto-Data Classification Techniques for Large Data Sets

NARA RECORDS MANAGEMENT INITIATIVES FOR MORE EFFECTIVE ACCESS TO INFORMATION. SERI Educational Webinar Tuesday, September 9, :00 pm Eastern

Managing Born- Digital Documents.

Manage as Records in SharePoint to Reduce Risk and Cost

HPE ControlPoint. Bill Manago, CRM IG Lead Solutions Consultant HPE Software

8/28/2017. What Is a Federal Record? What is Records Management?

Architecture and Standards Development Lifecycle

Records Retention Policy

Terms in the glossary are listed alphabetically. Words highlighted in bold are defined in the Glossary.

5/6/2013. Creating and preserving records that contain adequate and proper documentation of the organization.

Records Management at MSU. Hillary Gatlin University Archives and Historical Collections January 27, 2017

State Government Digital Preservation Profiles

REVIEW OF MANAGEMENT AND OVERSIGHT OF THE INTEGRATED BUSINESS MANAGEMENT SYSTEM (IBMS) January 16, 2009

Implementing a Successful Data Governance Program

Recordkeeping Metadata Study Committee

Three Year Follow up Request to Grand Jury Updated March 2, 2018

ImageNow Retention Policy Manager

Washington State Archives Public Records Management for Conservation Districts

RECORDS MANAGEMENT RECORDS MANAGEMENT SERVICES

National Open Source Strategy

Policy Summary: This guidance outlines ACAOM s policy and procedures for managing documents. Table of Contents

RECORDS MANAGEMENT AND YOU

Public Records Retention and Going Paperless for School Districts and ESDs

IRCH Methodology for Creating Legally-Defensible Retention Schedules

Management: A Guide For Harvard Administrators

Addendum 1. APPENDIX B - Technical Information / Requirements Records Management Solution Capabilities. Questions. Number

Community Unit School District No. 1. School Board

Refreshing Your Records Management. Tracy Rebstock, Southwest Regional Archivist

Information Security Policy

PRINCIPLES AND FUNCTIONAL REQUIREMENTS

PROCEDURE POLICY DEFINITIONS AD DATA GOVERNANCE PROCEDURE. Administration (AD) APPROVED: President and CEO

THE TEXAS A&M UNIVERSITY SYSTEM RECORDS RETENTION SCHEDULE

Challenges of Implementing Retention. March 9, 2017

Policies & Regulations

Records Retention Schedule

PREPARE FOR TAKE OFF. Accelerate your organisation s journey to the Cloud.

POLICY TITLE: Record Retention and Destruction POLICY NO: 277 PAGE 1 of 6

Category: Data/Information Keywords: Records Management, Digitization, Imaging, Image capture, Scanning, Process

Records Retention 101 for Local Government Agencies. Overview

Record Retention Policies: How Long Do We Keep This Record? Pari J. Swift, CRM, Senior Records Manager

Records Management - Part 1. Records Retention Folders

Strategies for Implementing Large-Scale ERM

GDPR compliance. GDPR preparedness with OpenText InfoArchive. White paper

Information Technology Branch Organization of Cyber Security Technical Standard

By John P Collins, JD DTI, Director of Information Governance & Office 365 Consulting

[your name] [your job title]

2016 SC REGIONAL HOUSING AUTHORITY NO. 3 S EIV SECURITY POLICY

Data Governance. Mark Plessinger / Julie Evans December /7/2017

Safeguarding Unclassified Controlled Technical Information

Certified Information Systems Auditor (CISA)

Records Management and Retention

Indexing Field Descriptions Recommended Practice

The Trail of Electrons

FRMA Policy Florida Records Management Association Certification Program Florida Certified Records Management Program (FCRM) January 2018

"Charting the Course... Certified Information Systems Auditor (CISA) Course Summary

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

Record Lifecycle Modeling Tasks

LOUGHBOROUGH UNIVERSITY RESEARCH OFFICE STANDARD OPERATING PROCEDURE. Loughborough University (LU) Research Office SOP 1027 LU

General Data Protection Regulation (GDPR) The impact of doing business in Asia

User Guide 16-Mar-2018

Transferring vital e-records to a trusted digital repository in Catalan public universities (the iarxiu platform)

Farmingdale State College Records Management Training PRESENTED BY DOROTHY HUGHES INTERNAL CONTROL OFFICER AND RECORDS MANAGEMENT OFFICER

FRMA Policy Florida Records Management Association Certification Program Florida Certified Records Management Program (FCRM) January 2012

Digital Service Management (DSM)

WHEATON COLLEGE RETENTION POLICY May 16, 2013

Putting It All Together:

How Long to Keep Records & Legally Dispose of Them. Virginia Fritzsch Public Records Archivist Wisconsin Historical Society

Bringing cyber to the Board of Directors & C-level and keeping it there. Dirk Lybaert, Proximus September 9 th 2016

Management Case Study. Kapil Lohia

PCI Compliance and records management

Records Retention Training

How to Clean Up Files for Better Information Management Brian Tuemmler. Network Shared Drives: RIM FUNDAMENTALS

Policy Document. PomSec-AllSitesBinder\Policy Docs, CompanyWide\Policy

NEW MICROSOFT FEATURES THAT WILL AFFECT EDISCOVERY IN THE FUTURE

University of Sunderland Business Assurance PCI Security Policy

Application for Certification

Is SharePoint the. Andrew Chapman

Publications. ACH Audit Requirements. A new approach to payments advising SM. Sound Practices Checklists

Sparta Systems TrackWise Digital Solution

PART 5: INFORMATION TECHNOLOGY RECORDS

Managing the Intelligence Community Information Environment

Australian Standard. Records Management. Part 1: General AS ISO ISO

B. To ensure compliance with federal and state laws, rules, and regulations, including, but not limited to:

Risk: Security s New Compliance. Torsten George VP Worldwide Marketing and Products, Agiliance Professional Strategies - S23

E-DISCOVERY PRESENTATION E-DISCOVERY 101: BASICS

State Government Digital Preservation Profiles

EXIN BCS SIAM Foundation. Sample Exam. Edition

WHO-ITU National ehealth Strategy Toolkit

Transcription:

Setting the Stage for Automatic Disposition Susan Cisco Director, Gimmal Education Code: MO01-4025 1

Learning Objectives Upon completion of this session, participants will be able to: 1. Define an information lifecycle model and associated business rules 2. Simplify an existing retention schedule with the big bucket approach 3. Summarize how automatic disposition is implemented including retention management for records stored in the cloud by third parties 2

Why Not Dispose of Redundant, Obsolete, and Trivial Information (ROT)? It s best practice Generally Accepted Recordkeeping Principles Retention Disposition It s cost effective and reduces business risks The Sedona Conference Commentary on Information Governance Note: ROT includes records with expired retention periods 3

What are the Barriers for Automatic Disposition? People Process Technology 4

Barriers for Automatic Disposition: People Overcoming skepticism of early adopters Issues with legacy information Confusion about big data Accuracy is 80% good enough? Agency stakeholders distrust algorithms Business unit inaction Lack of Information Governance Steering Committee 5

Barriers for Automatic Disposition: Process Some intend to apply the typical physical record disposition process to electronic records: Destruction of official records based on the following conditions: The approved retention period has expired Written approval is received Concurrent has been received from legal council Organizations may have policy but lack procedures 6

Barriers for Automatic Disposition: Technology No built-in functionality for retention Auto-classification tools can be expensive Difficulty identifying representative files for training the tools Difficulty implementing event-based retention periods Unreliable or non-existent dates to determine retention 7

Is Automatic Disposition Just Too Difficult? 8

Success Stories from Early Adopters Global Energy and Petrochemicals Company People Process Technology Started with Executive Committee mandate, then leadership teams, then communicated through various channels Allowed one year to get the message out Training is a self-directed web-based tutorial Legal holds are applied as litigation occurs Approvals not required Notifications are not planned Popular enterprise records management system for physical and electronic records 9

Success Stories from Early Adopters City of Bellevue WA People Process Technology Raised awareness for RRS and SharePoint content types in context of a game Incorporated RM into mandatory training on email management Training on SharePoint 3 Cs = communication, collaboration, and content Streamlined RRS from 730 to 75 record series Changed when we were getting permission from end of lifecycle to point of declaration Updated legal hold/release program Gimmal Compliance Suite and SharePoint 2010 10

Setting the Stage for Your Success Story PEOPLE Information Governance Steering Committee Records Coordinator Network PROCESS Update business rules / compliance framework TECHNOLOGY Do a pilot 11

Setting the Stage for Your Success Story: People You can t knock down barriers by yourself Form an interdisciplinary team / Information Governance Steering Committee Oversee development of standards and policies Harmonize policies and practices Minimize potential policy conflicts and overlapping efforts Establish a Records Coordinator network to facilitate disposition, with dotted line authority to the Records Manager / Officer Embed change management into all program level activities 12

Setting the Stage for Your Success Story: Process Need business rules for consistent retention and monitoring for compliance Update your rules / compliance framework Define an information lifecycle model and associated business rules Simplify existing retention schedule with the big bucket approach Make sure RIM policy is up-to-date and approved Legal hold / release program needs to be in place 13

Setting the Stage for Your Success Story Define an Information Lifecycle Model & Associated Business Rules START Create/ Receive Temporary Classify Work in Progress Mark Final Final Record Dispose Dispose Disposed Dispose END 14

Lifecycle Business Rules Hold Temp Work in Progress Final Record Retention Location Retention 90 Days Location(s) Network Shares email Inbox Retention 12 Months Location(s) SharePoint Retention Retention Schedule Location(s) Records Center Metadata Security Versions Metadata Name Metadata Name Content Type Metadata Name Content Type Disposition Disposition 15

Setting the Stage for Your Success Story Simplify existing retention schedule with the big bucket approach Same or similar business processes Same or similar legal/regulatory requirements Maintained for same or similar amount of time 16

Big Bucket Approach Fewer / bigger buckets in a RSS Easier to manually and automatically classify records for retention and disposition Improves ability to consistently retain/dispose of records resulting in less selective destruction Simpler is usually better 17

50 Big Bucket Records Retention Schedule 20% These buckets are more unique and deal with the specific operations of an individual organization 80% Record Series ( buckets ) in a RRS are common across organizations and industries Every organization must control records related to Accounting, HR, Tax, and other back office function 18

Setting the Stage for Your Success Story Make sure RIM policy is up-to-date and approved Ownership and responsibility for company information Definition of requirements for information lifecycle Definition and examples of types of records The company s records retention schedule Requirements with records retention and disposal Definition and importance of preservation hold orders 19

Automated Disposition Process Automated when possible and sustainable When a piece of content satisfies its retention period, it is expected to be destroyed immediately When the destruction of electronically stored content cannot be automated, manual processes are designed 20

Automated Disposition Process Audit log of the disposition tasks and outcomes Provide evidence and verify completion of electronic record destruction Keep information to a minimum Unique identification of piece of content Significant dates of piece of content s lifecycle and system-generated information and properties Prove content was destroyed and provide evidence in the case of an investigation 21

Automated Disposition Process Third Party Destruction When third parties are contracted to destroy electronic or physical content, certificates of destruction are recommended and usually include date, time, location, method of destruction and signature of the operator who destroyed the records 22

Setting the Stage for Your Success Story Legal hold / release program must be in place 7 Steps for Legal Holds of ESI and Other Documents by John J. Isaza and John Jablonski Available at the ARMA Bookstore New online course that includes the book: 7 Steps for Implementing Legal Holds 23

Setting the Stage for Your Success Story: Technology Do a pilot Easier to implement retention and disposition on a day-forward basis When a new system being procured - get on the procurement team When the organization is migrating to new system is a good time to introduce retention and disposition controls Save email and shared drives for later after you gain experience Event-based retention periods can be automated 24

Setting the Stage for Your Success Story Start planning for disposal in cloud-based services In contracts with cloud providers, document answers to these questions about disposition: How is information destroyed? Are there secure destruction options? How do we confirm disposition takes place on a timely basis and according to our rules? Refer to Job Aid for guidance 25

Setting the Stage for Automatic Disposition Please Complete Your Session Evaluation Susan Cisco susan.cisco@gimmal.com Education Code: MO01-4025 26