September 15, 2014 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES AND INDEPENDENT AGENCIES



Similar documents
August 24, 2012 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES AND INDEPENDENT AGENCIES

INFORMATION MANAGEMENT

GRS 6.1 Managed Under a Capstone Approach

Audit Report. The Social Security Administration s Management of Electronic Message Records

Transmittal Memo. SUBJECT: AGENCY POLICY 801 Capstone Records Management Policy

Records Management Policy. EPA Classification No.: CIO CIO Approval Date: 02/10/2015. CIO Transmittal No.: Review Date: 02/10/2018

Section 28.1 Purpose. Section 28.2 Background. DOT Order Records Management. CIOP Chapter RECORDS MANAGEMENT

EPA Classification No.: CIO 2155-P-3.0 CIO Approval Date: 04/04/2014 CIO Transmittal No.: Review Date: 04/04/2017

Office of the Secretary: Evaluation of Records Management and Cybersecurity Requirements

PROCEDURES FOR ELECTRONIC MANAGEMENT OF RULEMAKING AND OTHER DOCKETED RECORDS IN THE FEDERAL DOCKET MANAGEMENT SYSTEM

CHAPTER 9 RECORDS MANAGEMENT (Revised April 18, 2006)

State of Michigan Records Management Services. Frequently Asked Questions About E mail Retention

Archiving: What to Keep, What to Purge, and How To Tell

UNCLASSIFIED//FOR OFFICIAL USE ONLY

Basic Records Management Practices for Saskatchewan Government*

CMS IT - Requirements For Electronic Storage

Office of IT Planning, Architecture, and E-Government Office of the Chief Information Officer

E-Discovery. Counsel for Procurement and Employment Law Office of General Counsel National Archives and Records Administration

Record Retention and Digital Asset Management Tim Shinkle Perpetual Logic, LLC

Frequently Asked Questions (FAQs) about GRS 3.1, General Technology Management Records

Preservation of Separated Personnel s Electronically Stored Information Subject to Litigation Holds

Electronic Records Management Guidelines

Allison Stanton Director of E-Discovery U.S. Department of Justice, Civil Division

5 FAM 440 ELECTRONIC RECORDS, FACSIMILE RECORDS, AND ELECTRONIC MAIL RECORDS

Chapter WAC PRESERVATION OF ELECTRONIC PUBLIC RECORDS

Records Management. Training 101

ELECTRONIC SIGNATURES AND MANAGEMENT OF ELECTRONICALLY SIGNED RECORDS

Office of Financial Research Constituent Relationship Management Tool Privacy Impact Assessment ( PIA ) April, 2015

BPA Policy Information Governance & Lifecycle Management

Department of Homeland Security Management Directives System MD Number: Issue Date: 03/01/2003 DHS USAGE

Request for Records Disposition Authority

How To Preserve Records In Mississippi

SUTLEJ TEXTILES AND INDUSTRIES LIMITED DOCUMENT PRESERVATION AND RETENTION POLICY

Department of the Interior Privacy Impact Assessment

United States Department of the Interior

FARMINGTON PUBLIC SCHOOLS 2410

DEPARTMENT OF THE NAVY RECORDS MANAGEMENT PROGRAM

DOCUMENT RETENTION STRATEGIES FOR HEALTHCARE ORGANIZATIONS

Privacy Act of 1974; Department of Homeland Security <Component Name> - <SORN. AGENCY: Department of Homeland Security, Privacy Office.

Presented by Vickie Swam, Director of University Compliance. Records Management is one of the functions supported by the University Compliance Office.

U.S. Department of Energy Washington, D.C.

Review of Document Imaging Railroad Unemployment Insurance Act Programs Report No , November 17, 2000

Request for Records,...D-is_p_o_s-it-io_n_A_u_t_h_o-ri_ty... ~ Le_a_v_e-B-Ia_n_k-(N_A_RA--Us_e_O_nl-y)--1

Developing a Records Retention Program

Summary. 1 percent chance of flooding in any given year, as designated by FEMA.

PBGC-19: Office of General Counsel Case Management System

Privacy Impact Assessment

Classifying Correspondence. General, Administrative, Project/Case, and Transitory

5 FAM 400 RECORDS MANAGEMENT

DIRECTIVE TRANSMITTAL

RECORDS AND INFORMATION MANAGEMENT AND RETENTION

39C-1 Records Management Program 39C-3

Market Research in the Field v.1

Cloud Service Contracts: An Issue of Trust

PRIVACY IMPACT ASSESSMENT TEMPLATE

SUMMARY: The Defense Health Agency proposes to alter an. existing system of records, EDTMA 02, entitled "Medical/Dental

Allison Stanton, Director of E-Discovery U.S. Department of Justice, Civil Division. U.S. Department of Agriculture

RETENTION BEST PRACTICE. Issue Date: April 20, Intent and Purpose:

Social Media Guidance. Who s here? 7/29/2015

Rackspace Archiving Compliance Overview

UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT MANUAL TRANSMITTAL SHEET MS 1221 DIRECTIVES MANUAL

RECORDS MANAGEMENT OVERSIGHT INSPECTION REPORT 2014

General Records Management Training

3. Ensure the management of information is compliant with legislative requirements to maximise the benefits and minimise risks;

Privacy Impact Assessment

Department of Veterans Affairs VA Directive 6311 VA E-DISCOVERY

LITIGATION SUPPORT SYSTEM (SYSTEM NAME)

Senior Agency Official for Records Management FY 2015 Annual Report

PRIVACY IMPACT ASSESSMENT

Management: A Guide For Harvard Administrators

Department of Defense INSTRUCTION

DIA Records Management Program

Interagency Science Working Group. National Archives and Records Administration

NATIONAL ARCHIVES AND RECORDS ADMINISTRATION. Records Schedules; Availability and Request for Comments

Congressionally Requested Inquiry Into the EPA s Use of Private and Alias Accounts

RUTGERS POLICY. Approval Authority: Executive Vice President for Academic Affairs and Senior Vice President for Administration

Massachusetts Statewide Records Retention Schedule August 2014 Supplement

UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT MANUAL TRANSMITTAL SHEET Data Administration and Management (Public)

Jason R. Baron Director of Litigation Office of General Counsel National Archives and Records Administration

BPA Policy Systems User Policies

January 9, 2009 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND ESTABLISHMENTS, CHIEF FINANCIAL OFFICERS, AND INSPECTORS GENERAL

Privacy Impact Assessment Of the. Office of Inspector General Information Technology Infrastructure Systems

Management & Retention

Dartmouth College Records Management and Archives Access Policy

EFFECTIVE DATE: JULY 1, 2010

~'ID. Request for Records Disposition Authority

Handbook AS-353, Guide to Privacy, the Freedom of Information Act, and Records Management

University of Louisiana System

Name ofsystem/application: CRM-Correspondence Management Program Office: Office ofthe Executive Secretariat

Records Retention Timeframes for Property, Plant, & Equipment Research Report

NATO UNCLASSIFIED. 27 February 2012 DOCUMENT C-M(2012)0014 Silence Procedure ends: 16 Mar :00

RECORDS MANAGEMENT POLICY

State of Florida ELECTRONIC RECORDKEEPING STRATEGIC PLAN. January 2010 December 2012 DECEMBER 31, 2009

Electronic Recordkeeping

1 FROM (Agency or establishment) NOTIFI OFFICE OF THE U.S. TRADE REPRESENTATIVE In accordance With the provrsions of 44

Federal Trade Commission Privacy Impact Assessment. Conference Room Scheduling PIA

CITY OF ELK GROVE CITY COUNCIL STAFF REPORT

Administrative Procedures Memorandum A2005

Savings Bond Replacement System (SaBRe) Privacy Impact Assessment (PIA) May 31, 2012

Transcription:

, 0.. EXECUTIVE OFFICE OF THE PRESIDENT \ OFFICE OF MANAGEMENT AND BUDGET :t WASHINGTON, D.C. 20503 IIIIIII NATIONAL ARCHIVES AND RECORDS ADM INISTRATION WASHINGTON, D.C. 20408 September 15, 2014 '.~ ~...,,. ; ' M-14-16 MEMORANDUM FOR THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES AND INDEPENDENT AGENCIES FROM: SUBJECT: Beth F. Cobert Deputy Director for Management Office of Management and Budget David S. Ferriero ~ A1\~.. Archivist of the United States National Archives and Records Administration Guidance on Managing Email ~ Reforming records management policies and practices and developing a 21 51 -century framework for the management of go':'ernment records is a priority for this Administration. Recognizing the importance of managing email records, the Administration has specifically focused on the proper management of these records. The attached guidance reaffirms the importance of recordkeeping and is a reminder that agencies, and employees, are responsible for properly managing and retaining email records. In accordance with the President' s November 28, 2011 Memorandum, Managing Government Records, the Office of Management and Budget (OMB) and the National Archives and Records Administration (NARA) issued a joint Managing Government Records Directive in 2012, which mandated that agencies eliminate paper and use electronic recordkeeping. To ensure openness and accountability, and reduce costs, the Directive requires that: by December 31, 2016, Federal agencies will manage both permanent and temporary email records in an electronically accessible format; and by December 31, 2019, Federal agencies will manage all permanent electronic records in an electronic format. The enclosed email guidance will assist agencies in meeting these goals and the Federal records management requirements under the Federal Records Act and associated regulations. This guidance

should be used in conjunction with NARA' s August, 2013 "Capstone" guidance. NARA will begin to track agency implementation of the 2016 email records management requirement and regularly provide reports to OMB on agency progress. Please have all employees review the enclosed guidance to ensure they are aware of their responsibilities for managing email records. Agencies are also reminded of other goals from the Directive that are due at the end of this year. To ensure that agencies, and their employees, are aware of their accountability, and this responsibility is institutionalized within the organization, the Directive requires that by December 31,2014: Agency Records Officers for each agency must obtain a NARA Certificate of Federal Records Management Training; and all agencies must establish and develop suitable records management training. Agencies are also encouraged to establish annual records management training requirements and explore options for online, user-friendly training. Additionally, within the next six weeks, NARA and OMB will convene a group of Senior Agency Officials for Records Management, CIOs, General Counsels, and Records Officers to develop best practices documents for identifying and retaining Federal records that would be used as part of this training. If you have any questions regarding this guidance, please contact Paul Wester, Chief Records Officer for the U.S. Government, at paul.wester@nara.gov. Attachment 2

NationalArchives and RecordsAdministration W..Shlngton, DC 20408 l NARA BULLETIN NO. 2014-06 TO: Heads offederal Agencies SUBJECT: Guidance on Managing Email EXPIRATION DATE: Expires when revoked or superseded 1. What is the purpose of this Bulletin? This Bulletin reminds Federal agencies about their records management responsibilities regarding email. This is especially important in light of the requirement in the Managing Government Records Directive COMB M-12-18) for all email to be managed electronically by December 31, 2016. In addition, recent disclosures by agencies have put this issue into more prominent focus. NARA will continue to issue guidance that assists agencies in meeting the goals of the Directive and Federal records management requirements under the Federal Records Act and associated regulations. 2. Are emails Federal records? NARA has issued many bulletins, FAQs,regulations, and agency records management training sessions that provide guidance on Federal email management (see list in Question 9). Each has stated emails that are Federal records must be managed for their entire records life cycle. The statutory definition of Federal records is found at 44 U.S.C. 3301 and is further explained in the Code offederal Regulations at 36 CFR 1222.10. All agency-administered email accounts are likely to contain Federal records. This includes email accounts with multiple users (such as public correspondence email addresses) or email accounts for an individual on multiple systems (such as classified and unclassified email accounts). In addition, agency officials may create Federal records if they conduct agency business on their personal email accounts. Email sent on personal email accounts pertaining to agency business and meeting the definition of Federal records must be filed in an agency recordkeeping system. 3. What are agency responsibilities for email management? Agencies must have policies in place to identify emails that are Federal records. These policies must ensure that emails identified as Federal records are filed in agency

recordkeeping systems. Failure to identify and manage email as Federal records can result in their loss. In addition, agencies' policies and practices for email management must comply with other statutes and obligations, such as the Freedom of Information Act and discovery in litigation. Furthermore, the Managing Government Records Directive requires that Federal agencies manage all their email electronically by December 31, 2016. 4. What is the role of Federal employees in email management? Currently, in many agencies, employees manage their own email accounts and apply their own understanding of Federal records management. This means that all employees are required to review each message, identify its value, and either delete it or move it to a recordkeeping system. Some email, such as spam or all-staff announcements, may be deleted immediately. On the other hand, substantive policy discussions conducted in email may be appropriate for preservation for several years or ultimate transfer to NARA. NARA recognizes that placing the responsibility on employees to make decisions on an email-by-email basis can create a tremendous burden. As a result, NARA recommends that agencies immediately begin to adopt automated or rules-based records management policies for email management, such as the Capstone approach. 5. What is Capstone? Capstone is an approach to managing email. It is not a type of technology. (See NARA Bulletin 2013-02: Guidance on a New Approach to Managing Email Records.) When adopting the Capstone approach, agencies must identify those email accounts most likely to contain records that should be preserved as permanent. Agencies will determine Capstone accounts based on their business needs. They should identify the accounts of individuals who, by virtue oftheir work, office, or position, are likely to create or receive permanently valuable Federal records. Capstone officials will generally be the top-level senior officials of an agency, but may also be other key decision makers at lower levels ofthe agency. Following this approach, an agency can schedule all ofthe email in Capstone accounts as permanent records. The agency could then schedule the remaining (non-capstone) email as temporary and retain all of them for a set period of time based on the agency's needs. The Capstone Bulletin addresses additional options and best practices. Establishing the appropriate retention periods for email will help an agency determine the best approach to implement for recordkeeping and backup systems to ensure that the agency can access their email for business needs, including in response to congressional, FOIA, or discovery requests. 2

6. How long should emails be kept? As Federal records, emails must be kept for specific periods of time as mandated in records disposition schedules. Some schedules allow for transitory emails to be deleted immediately or when no longer needed. Some schedules require emails to be kept in agencies for decades and then transferred to NARA for permanent preservation. Some schedules allow agencies to delete emails after having been moved to a recordkeeping system. In addition, NARA recommends agencies determine the minimum time frame all their email must be kept electronically-in a searchable and retrievable manner-in order to meet immediate business and access needs. For example, an agency may decide to use journaling tools to keep all email for one year to meet audit and access requirements. 7. How can agencies mitigate against loss of email records? Continued use ofthe "print and file" method of managing email puts agencies at risk of losing records, not having them available for business needs, and allegations of unauthorized destruction. Converting to automated email management will reduce the risks involved in human management of email. The decision to manage email electronically needs to involve Senior Agency Officials for Records Management, Records Officers, General Counsels, Chief Information Officers, and others. Until such conversion, agencies must ensure email management policies are in place and that staff are following them. Oversight can be done through training, audits, and supervisory controls. Agencies should also ensure that electronic records backup policies and practices are adequate, including what backups are needed and how long to maintain the backup. Backups are not recordkeeping systems, but they can help restore records in the case of a technology or other type of failure. If computers or mobile devices are not backed up, then emails and other Federal records should not be stored on them. 8. How do agencies report email loss? In accordance with the Federal Records Act (44 U.S.C. 2905(a) and 3106) and its implementing regulations (36 CFR Part 1230), when an agency becomes aware of an incident of unauthorized destruction, they must report the incident to the Office of the Chief Records Officer for the U.S. Government. The report should describe the records, the circumstances in which the unauthorized destruction took place, and the corrective steps being taken to properly manage the records in the future. IfNARA learns ofthe incident before the agency has reported it, NARA will notify the agency and request similar information. The goal of 3

this process is to ensure that the circumstances that may have led to the loss of Federal records are corrected and that similar losses do not occur in the future. 9. What other related guidance does NARA provide? NARA has issued many bulletins, F AQs, regulations, and training on Federal email management and related technologies. Regulations on electronic records and email are found in 36 CFR 1236. NARA training and guidance on email is available online here. NARA guidance on email and related technologies include: NARA Bulletin 2014-04: Revised Format Guidance for the Transfer of Permanent Electronic Records specifies which file formats are acceptable when transferring permanent electronic records to NARA. NARA Bulletin 2013-03: Guidance for Agency Employees on the Management of Federal Records, Including Email Accounts, and the Protection of Federal Records from Unauthorized Removal reaffirms that agencies and agency employees must manage Federal records appropriately and protect them from unauthorized removal from agency custody. Also, this Bulletin clarifies records management responsibilities regarding the use of personal email accounts for official business and the use of more than one Federal email account. NARA Bulletin 2013-02: Guidance on a New Approach to Managing Email Records provides agencies with a new records management approach, known as "Capstone," for managing Federal record emails electronically. This Bulletin discusses the considerations that agencies should review ifthey choose to implement the Capstone approach to manage their email records. NARA Bulletin 2011-03: Guidance Concerning the Use ofemail Archiving Applications to Store Email provides guidance to Federal agencies on using email archiving applications and similar technologies. NARA Bulletin 2010-05: Guidance on Managing Records in Cloud Computing Environments addresses records management considerations in cloud computing environments and is a formal articulation ofnara's view of agencies' records management responsibilities. NARA F AQ on instant messaging answers questions about the management of instant messaging in Federal agencies. 4

10. Whom should I contact for more information? If additional information is needed or if you have any questions, please contact your agency Records Officer or the NARA Appraisal Archivist or records management contact with whom you regularly work. Please refer to the List ofnara Contacts for Your Agency. DAVID S. FERRIERO Archivist ofthe United States 5