What We ll Cover. Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs



Similar documents
Retention & Disposition in the Cloud Do you really have control?

9. GOVERNANCE. Policy 9.8 RECORDS MANAGEMENT POLICY. Version 4

Document Management & Workflow

TERRITORY RECORDS OFFICE BUSINESS SYSTEMS AND DIGITAL RECORDKEEPING FUNCTIONALITY ASSESSMENT TOOL

Fundamentals of Information Governance:

How To Manage Cloud Data Safely

UNIVERSITY OF MANITOBA PROCEDURE

Record Retention and Digital Asset Management Tim Shinkle Perpetual Logic, LLC

How to Manage Your SharePoint Cloud Based Business

Information Governance

RECORD AND INFORMATION MANAGEMENT FRAMEWORK FOR ONTARIO SCHOOL BOARDS/AUTHORITIES

POLICY AND GUIDELINES FOR THE MANAGEMENT OF ELECTRONIC RECORDS INCLUDING ELECTRONIC MAIL ( ) SYSTEMS

John Essner, CISO Office of Information Technology State of New Jersey

The Next Frontier. for Records Managers. Retention and Disposition of Structured Data:

IT Forum UW-Madison Records Management Program. UW Archives and Records Management

ELECTRONIC RECORDS MANAGEMENT

The Importance of Information Governance and Risk Management

Electronic Records Management

ERMS Solution BUILT ON SHAREPOINT 2013

AIIM & ASSUREON AN ASSUREON BRIEF

CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline)

Corporate Records Management Policy

DELAWARE PUBLIC ARCHIVES POLICY STATEMENT AND GUIDELINES MODEL GUIDELINES FOR ELECTRONIC RECORDS

1. The records have been created, sent or received in connection with the compilation.

STATE OF NEBRASKA STATE RECORDS ADMINISTRATOR DURABLE MEDIUM WRITTEN BEST PRACTICES & PROCEDURES (ELECTRONIC RECORDS GUIDELINES) OCTOBER 2009

Policy Outsourcing and Cloud Based File Sharing

One of the first steps in managing information in today s

Strategies for Developing a Document Imaging & Electronic Retention Program

RECORDS MANAGEMENT POLICY

Document Management or Records Management Systems - Which Will Best Help You Satisfy Your Enterprise Information Asset Management Requirements?

SOUTHWEST VIRGINIA COMMUNITY COLLEGE RECORDS MANAGEMENT PROGRAM. Revised January 15, 2014

Generally Accepted Recordkeeping Principles

Information Security Policy September 2009 Newman University IT Services. Information Security Policy

Planning an Imaging Conversion for Shared Electronic Documents. Cheryl Young, CIP, CTT+, CDIA+, APMD, ermm, ecmp

FINAL May Guideline on Security Systems for Safeguarding Customer Information

Records Management Policy

Considerations for Outsourcing Records Storage to the Cloud

Wheaton College Records and Information Management Policies and Procedures

Services Providers. Ivan Soto

SCHEDULE NO. 55 INFORMATION TECHNOLOGY AND COMMUNICATION SYSTEMS RECORDS

Director, Value Engineering

Approved by: Vice President, Human Resources & Corporate Resources and Vice President, Treasury & Compliance Date: October 14, 2009

Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin

How To Manage Records And Information Management In Alberta

Life Cycle of Records

Part 2: Records and Information Management: Creation and Use

How To Manage Records In A Cloud

Information Governance: Where is ARMA International Headed? David M. Fleming, CRM, IGP, CIP ARMA Utah-Salt Lake Chapter Meeting September 18, 2014

September Tsawwassen First Nation Policy for Records and Information Management

Cloud Service Contracts: An Issue of Trust

Information Governance, Risk, Compliance

A Framework for EDMS/ERMS Integration

Union County. Electronic Records and Document Imaging Policy

Records and Information Management

Implementing Enterprise Information Governance: A Practical Approach

Arizona State Library, Archives and Public Records

ARMA: Information Governance: A Revenue Source Potential

Breaking Down the Silos: A 21st Century Approach to Information Governance. May 2015

Developing a Records Retention Program

NSW Government. Cloud Services Policy and Guidelines

Big Data, Big Risk, Big Rewards. Hussein Syed

John B. Breeden, CRM VDOT Records Manager Virginia Department of Transportation

Scotland s Commissioner for Children and Young People Records Management Policy

Agenda. You are not in the business to manage records

Introduction Thanks Survey of attendees Questions at the end

Administrative Procedure

Information Security Policies. Version 6.1

HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT

Electronic Records Management: Software Evaluation Decision Guide

State of Michigan Records Management Services. Frequently Asked Questions About E mail Retention

Management: A Guide For Harvard Administrators

HIPAA/HITECH Compliance Using VMware vcloud Air

RUTGERS POLICY. Approval Authority: Executive Vice President for Academic Affairs and Senior Vice President for Administration

IT Roles in Loss Prevention. Presented by: Ann Ostrander, Director of Loss Prevention Kirkland & Ellis LLP

A COMPLETE GUIDE HOW TO CHOOSE A CLOUD-TO-CLOUD BACKUP PROVIDER FOR THE ENTERPRISE

8 REASONS TO OUTSOURCE RECORDS MANAGEMENT

Information Governance in the Cloud

Identify and Protect Your Vital Records

Discovery Technology Group

Why organizations need to archive ? The underlying reasons why corporate archiving is important

PRESENTATION TOPICS 2/27/2014. Why Update Policies? 21st Century Best Practices for Information Governance & Policies. Why update policies??

How To Write A Request For Information (Rfi)

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents

Protecting Official Records as Evidence in the Cloud Environment. Anne Thurston

Realizing the ROI of Information Governance. Gregory P. Kosinski Director, Product Marketing EMC

3 BENEFITS OF COMPLIANT ARCHIVING.

Gain Efficiency, Cost Savings and Compliance with Iron Mountain s Portfolio of Services

A 15-Minute Guide to 15-MINUTE GUIDE

Defensible Disposition Strategies for Disposing of Structured Data - etrash

INFORMATION GOVERNANCE Principles for Healthcare (IGPHC)

Document Management and Records Management in SharePoint Scott Jamison

With the large number of. How to Avoid Disaster: RIM s Crucial Role in Business Continuity Planning. Virginia A. Jones, CRM, FAI RIM FUNDAMENTALS

a Legal Project Management Consultancy Plan. Resource. Realize.

The Importance of Records Management within a Governance, Retention and Compliance Strategy

ACCESS, PRODUCTION AND RETENTION OF CITY RECORDS

How to build a compliant storage infrastructure

Reduce Cost, Time, and Risk ediscovery and Records Management in SharePoint

Information Technology: This Year s Hot Issue - Cloud Computing

Transcription:

What We ll Cover Foundations of Records and Information Management Creating a Defensible Retention Schedule Paper v. Electronic Records Organization and Retrieval of Records and Information Records Management and Risk Management Defensible Disposal of Records and Information Litigation Holds Information Governance the future of records management programs Q & A 2

Foundations of Records and Information Management Record v. Information Record Recorded information, regardless of medium or characteristics, made or received by an organization in pursuance of legal obligations or in the transaction of business. Information Data that has been given value through analysis, interpretation, or compilation in a meaningful form. ARMA International Glossary of Records and Information Management Terms 3 rd Edition 3

Foundations of Records and Information Management Record v. Information How many records? On average 7-10% of the information an organization creates is a record Of that, only 2-7% are vital records And less than 1% are permanent records Most organizations retain too much information and keep records longer than required based on business value or legal/ regulatory requirements 4

Foundations of Records and Information Management Key Characteristics of a Record Authenticity Integrity Reliability Usability For information to be considered a record, it must possess all four characteristics and It must maintain those characteristics for the life of the record International Organization for Standardization. Information and documentation Records management part 1: General (ISO 15489-1). 6

Foundations of Records and Information Management Goals of Records and Information Management Programs: Ensure records are managed, retained, and disposed of in accordance with all applicable business, legal and regulatory requirements. Manage all records consistently throughout the organization regardless of media, format or location. Ensure vital records are available when needed to recover an organization s operations in the event of a disruption. Establish standards for the routine destruction of information when no longer needed for routine purposes. Establish standards for the routine disposition of records when retention requirements have been met. Assist with the location and retrieval of records and information in response to litigation or investigation. 7

Foundations of Records and Information Management Records Management Standards and Best Practices Potentially hundreds depending on industry, jurisdiction, technology used, etc. Four to know ISO 15489 - International Organization for Standardization Records management MoReq2 - Model Requirements for the Management of Electronic Records The Sedona Principles The Generally Accepted Recordkeeping Principles 9

Creating a Defensible Records Retention Schedule Legal Requirements Employment Law Tax Law Unique Federal Requirements Unique State Laws and Regulations Statutes of Limitation Litigation Profile Review/Model State Government Retention Schedules Work with Counsel 12

Creating a Defensible Records Retention Schedule Business/Organizational Requirements Operational Value versus Legal Requirements Important to work with ALL business areas Functions with unique requirements: Human Resources Finance (including Tax) Senior Leadership/Board of Directors Contracts Licenses Legal 13

Creating a Defensible Records Retention Schedule Methods for Developing the Retention Schedule Doing it yourself Inventory method Survey method Hybrid method Paying someone else Consultants Outside Counsel Software & Subscription Services 14

Creating a Defensible Records Retention Schedule Record Formats and the Retention Schedule The format agnostic schedule Separate schedules for physical and electronic Retention schedule with record format specified Email 15

Creating a Defensible Records Retention Schedule Review, Audits, and Updates of the Retention Schedule Review of the initial schedule Legal / Outside Counsel Business Areas Records Management Audits Business function compliance Retention Schedule audits Updates Frequency Implementation Governance 16

Organization and Retrieval of Records and Information Best Practices for Physical Records Filing methods Establishing Alphabetic, Numeric, and Subject Filing Systems Official records, reference copies and WIP Storage Considerations and Standards Location and Organization Offsite Storage NFPA 232 Standard for the Protection of Records ARMA TR 01-2011 - Records Center Operations Guideline for Evaluating Offsite Records Storage Facilities 22

Organization and Retrieval of Records and Information Best Practices for Electronic Records Structured versus Unstructured Databases LANs and shared drives ECM & DM Solutions MS SharePoint Email Format Considerations Proprietary formats Open formats MS Office documents Websites Social Media 23

Organization and Retrieval of Records and Information Best Practices for Electronic Records Technology Considerations Data migrations Open Source SaaS and Outsourcing Deletion versus Logical Deletion Back-up 24

Organization and Retrieval of Records and Information Standards for Electronic Records ISO 16175 - Principles and functional requirements for records in electronic office environments Procedures and Issues for Managing Electronic Messages as Records ARMA TR 02-2007 Records Center Operations ARMA TR 01-2011 Revised Framework for Integration of EDMS and ERMS AIIM/ ARMA TR 48-2006 DoD 5015.02-STD Design Criteria Standard for Electronic Records Management Software Applications Guideline for Outsourcing Electronic Records Storage and Disposition Guideline for Outsourcing Records Storage to the Cloud 25

Records Management and Risk Management Vital Records Programs Vital Record Records that are fundamental to the functioning of an organization and necessary to continue operations without delay under abnormal conditions. ARMA International Glossary of Records and Information Management Terms 3 rd Edition Types of Vital Records Costly Operational Legal Emergency 26

Records Management and Risk Management Vital Records Programs The objectives of a vital records program are to: Identify records needed to conduct business under emergency operating conditions Identify records needed to perform or reconstruct the organization's most mission-critical functions Identify records protecting the legal and financial rights of the organization/institution, its employees, and the people it serves Develop and implement cost effective methods, including off-site storage and the application of technology, to protect and safeguard those records identified as vital from loss, misuse, and unauthorized access or modification Develop policies, procedures, and a plan of action to assess damage and to begin recovery of any records that may be affected by an emergency or disaster, regardless of the storage medium 27

Records Management and Risk Management Records Management and Business Continuity & Recovery The Vital Records Inventory Record Recovery Recovery Time Objective Recovery Point Objective Record Protection for BC&R Duplication and Back-up Offsite storage of physical records Offsite data centers for electronic records 28

Records Management and Risk Management Privacy Privacy versus access and usability Customer information Employee information Vendors and third parties International challenges Why do you track this info? The CIPO 29

Records Management and Risk Management Information Security Passwords Encryption Access versus Usability Laws and Regulations The more you have The CISO 30

Records Management and Risk Management Litigation Risk Volume Discovery Costs for electronic information Record integrity Spoliation Over production Under production 31

Information Governance The future of Records Management Programs Information Governance The specification of decision rights and an accountability framework to encourage desirable behavior in the valuation, creation, storage, use, archival and deletion of information. It includes the processed, roles, standards and metrics that ensure the effective and efficient use of information in enabling an organization to achieve its goals Gartner A holistic approach to managing and leveraging information for business benefits and encompasses information quality, information protection and information life cycle management - IBM 45

Information Governance The future of Records Management Programs Information Governance Address all phases of the information life cycle Incorporates privacy requirements, electronic discovery, storage optimization, metadata management, information security Is built upon a foundation of strong Records Management Encompasses more disciplines and perspectives than traditional Records Management 46