To retain or not to retain? That is the question

By Kevin Doyle, Security Audit & Assessment Manager, Reclamere, Reclamere |  Storage, data, e-discovery 1 comment

Thanks to the Internet and the Information Technology Age, information is being generated exponentially faster than at any other time in history. Privacy has basically gone out the window, and it’s no wonder that headlines about data breaches have become commonplace.

In the past fifteen years, the Internet has revolutionized the way business is transacted, the way we communicate with each other, and the way we learn and research. E-commerce transactions and online banking and investments occur every micro-second, and sensitive information is exchanged for each of those activities. People sign up for free e-mail accounts and chat. Social networking sites invite us to post information about ourselves and we do so, often without even a thought as to what we are telling the world about ourselves. We go to school online. “Wiki’s” and research sites have replaced hardcover encyclopedias in many cases. Many of us choose the Internet to obtain news, sports, and weather rather than newspapers.

Over this amazing period of time, it has become more convenient to keep information than to get rid of it. This brings up an interesting change in risk exposure when it comes to records retention for organizations such as schools and businesses. Are we retaining too much information and is it exposing us to data breaches or legal problems?

Advances in technology have allowed us to accumulate more and more information. Can you imagine how much paper would be needed if we converted all of our electronic data into paper files? Would we retain as much information if it was not for the technology age?
It has become more convenient for organizations to “retain everything” than to have a sound document retention plan and policy, based on legal requirements, risk, and common sense. We accumulate all of this data, and we store it on electronic media and ship it off site. Are we keeping track of all of the data stored on site and off site? Are we classifying information into what should be protected, such as private information, sensitive trade secrets, etc? What about the risk of the document custodians losing some of that information? Another hazard is retaining too much information related to something that might become a legal issue, such as an employee termination. When the subpoena comes along, it orders all information and communications related to this employee. Got e-Discovery?

Is there is adequate tracking so we retrieve only the information that is needed? Is data being de-duplicated? Are we keeping several copies of the same information? What if media gets lost in transit? Should we be encrypting?

The risk landscape for retention of information has changed dramatically in this age of technology. Management, along with attorneys and regulators, have to decide what information should be retained and for how long. The best records retention policy is not to retain information, unencrypted forever. A policy based on legal requirements and risk is the soundest approach to records and document retention.

1 comment

    Anonymous 2 years ago
    "a sound document retention plan and policy,"the correct phrase is records retention schedule. If you want to know more about records management then check out ARMA International www.arma.org which is the professional association for records and information management professional.Also check out the Institute of Certified Records Managers www.icrm.org

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      StorageWhite Papers & Webcasts

      White Paper

      ESG ~ HP StoreOnce: the Next Wave of Data Deduplication

      Leveraging deduplication in backup environments yields significant advantages. The cost savings in reducing disk capacity requirements change the economics of disk-based backup. For some organizations, it allows disk-based backup-and, importantly, recovery-to be extended to additional workloads in the environment. For others, deduplication makes it possible to introduce disk-based backup where it may not have been feasible before.

      White Paper

      Evaluator Group: Storage Federation - IT Without Limits (Analysis of HP Peer Motion with Storage Federation)

      As the role of IT increases within organizations, the need to move data when and where it is needed is critical to support emerging business requirements. This has become increasingly difficult due to the huge growth of data volumes. This white paper sponsored by HP + Intel evaluates a solution that aims to enable the movement of data without physical limitations. Read now and see how this could enable agility and efficiency.

      White Paper

      HP Converged Storage Sets the Stage for the Next Era of Computing

      Enterprise storage has undergone many changes in recent years - with converged storage and infrastructure 2.0 paving the way for reduced IT infrastructure costs and greater performance. This report discusses the latest trends that are setting the stage for the next era of computing. Learn about the new infrastructure and storage trends that are changing the way business storage works today.

      White Paper

      AppAssure vs Acronis

      In this study of data protection for environments with virtual and physical servers running Windows, openBench Labs tested AppAssure Backup and Replication software v 4.7 and Acronis Backup & Recovery 11. Both solutions utilize block-based technology to unify data protection operations.

      White Paper

      Guaranteeing 100% Backup Recovery

      The single biggest challenge for IT personnel involved in the data protection process is making sure that their backups are recoverable every time. Management and users won't remember the ninety-nine successful recoveries but they will always remember the one failure.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question