Legal Archiving & Records management, existing technologies and solutions Marc Vandeveken - I.R.I.S.

Slides:



Advertisements
Similar presentations
The Impact of Auditing on Records Management Risk and Compliance Susan B. Whitmire, CRM, FAI Manager, Enterprise Records and Information Management BlueCross.
Advertisements

Security by Design A Prequel for COMPSCI 702. Perspective “Any fool can know. The point is to understand.” - Albert Einstein “Sometimes it's not enough.
Fedora Users’ Conference Rutgers University May 14, 2005 Researching Fedora's Ability to Serve as a Preservation System for Electronic University Records.
Records Management for UW-Madison Employees – An Introduction UW-Madison Records Management UW-Archives & Records Management 2012 Photo courtesy of University.
Archiving for legal purposes How to implement the new Belgian legislation to destroy physical invoices and use an electronic archive.
Dematerialization of Organisations’ Key Business Processes Security and e-Invoicing ATHENEE PALACE HILTON, Bucuresti September 21 st 2004 Genovel Iovu.
IMPLEMENTING AN ELECTRONIC RECORDS MANAGEMENT PROGRAM Philip C. Bantin Indiana University Archivist IU Electronic Records Program Website:
Guide to Massachusetts Data Privacy Laws & Steps you can take towards Compliance.
Records Management What to Keep and What to Toss.
PAPERLESS BUSINESS in GEORGIAN FINANCIAL SECTOR NANA ENUKIDZE - Advisor to the Governor.
M.Sc. Hrvoje Brzica Boris Herceg, MBA Financial Agency – FINA Ph.D. Hrvoje Stancic, assoc. prof. Faculty of Humanities and Social Sciences Long-term Preservation.
Coping with Electronic Records Setting Standards for Private Sector E-records Retention.
Information security An introduction to Technology and law with focus on e-signature, encryption and third party service Yue Liu Feb.2008.
DIGITAL SIGNATURE AND ELECTRONIC DOCUMENTS IN ITALY Prof. Pierluigi Ridolfi AIPA Authority for Information Technology in the Public Administration V. Solferino,
Database Administration Chapter FOSTER School of Business Acctg. 420.
1 E-Discovery Changes to Federal Rules of Civil Procedure Concerning Discovery of Electronically Stored Information (ESI) Effective Date: 12/01/2006 October,
Internet Resources Discovery (IRD) IBM DB2 Digital Library Thanks to Zvika Michnik and Avital Greenberg.
Creating a Secured and Trusted Information Sphere in Different Markets Giuseppe Contino.
Stephen S. Yau CSE465 & CSE591, Fall Information Assurance (IA) & Security Overview Concepts Security principles & strategies Techniques Guidelines,
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Beyond Paper: Records Preservation in the Digital World Nien-Ling Wacker, CEO LaserFiche Document Imaging
Long-term Archive Service Requirements draft-ietf-ltans-reqs-00.txt.
Author(s): David A. Wallace and Margaret Hedstrom, 2009 License: Unless otherwise noted, this material is made available under the terms of the Creative.
Electronic Archive Services in Lithuania Dr. Arūnas Stočkus Vilnius University Faculty of Mathematics and Informatics Lithuania EBNA,
Legal Scanning Scan your documents with IRISPowerscan™ Wim Cops – I.R.I.S.
Instructions and forms
Defining Electronic Systems
8 Nob 06 / CEN/ISSS ETSI STF 305: Procedures for Handling Advanced Electronic Signatures on Digital Accounting CEN/ISSS Workshop.
Records Management Overview. Why? It’s the Law It’s the Law It’s University Policy It’s University Policy Fiscal and Legal Compliance Fiscal and Legal.
Records Management: It’s Not Just Paper
Chinese-European Workshop on Digital Preservation, Beijing July 14 – Network of Expertise in Digital Preservation 1 Trusted Digital Repositories,
1 EDMS 101 Speaker: Monica Crocker, DHS EDMS Coordinator Overview of current project(s) Objective of this section: This session outlines EDMS fundamentals.
Legal aspects of digital archiving. Agenda Objectives of the conference Archiving vs Legal Archiving vs Compliance Legal archiving coverage and principles.
MSS Technologies and the AIIM Grand Canyon Chapter present: Electronic Document Management System Needs Analysis.
STORAGE MANAGEMENT/ EXECUTIVE: Managing a Compliant Infrastructure Processes and Procedures Mike Casey Principal Analyst Contoural Inc.
Archiving Where did I put that mail?. Business criticity Importance to manage : –Authenticity –Integrity –Perennity –Compliance High TCO of mail.
RECORDS MANAGEMENT Office of Compliance. OBJECTIVES Four main objectives of a Records Management Program: –Increase efficiency of record keeping. –Protection.
Electronic Records Management: A Checklist for Success Jesse Wilkins April 15, 2009.
P. Schirmbacher Humboldt-Universität zu Berlin The Changing Process of Scholarly Publishing or the Necessity of a New Culture of Electronic.
Evaluating trusted electronic documents Petr Švéda Security and Protection of Information ‘03 © 2003 Petr Švéda, FI MU.
Massella Ducci Teri Italian approach to long-term digital preservation Policies for Digital Preservation ERPANET Training Seminar.
ادارة الوثائق الالكترونية Naji Shukri Alzaza University of Palestine April 2010.
Developing Policy and Procedure Management System إعداد برنامج سياسات وإجراءات العمل 8 Safar February 2007 HERA GENERAL HOSPITAL.
Author(s): David A. Wallace and Margaret Hedstrom, 2009 License: Unless otherwise noted, this material is made available under the terms of the Creative.
1 Integrating digital signatures with relational database: Issues and organizational implications By Randal Reid, Gurpreet Dhillon. Journal of Database.
Lifecycle Metadata for Digital Objects October 18, 2004 Transfer / Authenticity Metadata.
Washington State Archives “Going Paperless” Presented by: Leslie Koziara, ERMP May 7, 2009 A GUIDE TO WASHINGTON STATE’S APPROVAL PROCESS FOR THE DESTRUCTION.
DIGITAL SIGNATURE.
Digital Preservation across the technologies, strategies, open standards & interoperability aspects including the legal issues Pratik Shrivastava Scientist.
Database security Diego Abella. Database security Global connection increase database security problems. Database security is the system, processes, and.
E-discovery Discussion. 2 Policies and Procedures Do you have a set of e-discovery policies and procedures? – Who is the lead for e-discovery efforts.
Digitally Signed Records – Friend or Foe? Boris Herceg Hrvoje Brzica Financial Agency – FINA Hrvoje Stančić.
1/ 4 OCTOBER 2007 Electronic Records Retention Issues Frank Nemeth NMCI Engineering.
Preserving Electronic Mailing Lists as Scholarly Resources: The H-Net Archives Lisa M. Schmidt
ISO DOCUMENT CONTROL. ISO Environmental Management Systems2 Lesson Learning Goals At the end of this lesson you should be able to: 
RECORDS MANAGEMENT Office of Business Affairs. OBJECTIVES Four main objectives of a Records Management Program: –Increase efficiency of record keeping.
E-SIGNED DocFlow SYSTEM in GEORGIAN FINANCIAL SECTOR NANA ENUKIDZE – E-Business Development Consultant.
The world leader in serving science OMNIC DS & Thermo Security Administration 21 CFR Part 11 Tools for FT-IR and Raman Spectroscopy.
Directive 123 / 2006 / CE on Services in the Internal Market Point of Single Contact Directive 123 / 2006 / CE on Services in the Internal Market Point.
Building Preservation Environments with Data Grid Technology Reagan W. Moore Presenter: Praveen Namburi.
Chang, Wen-Hsi Division Director National Archives Administration, 2011/3/18/16:15-17: TELDAP International Conference.
What ICT specialists need to know about information and records Christine Johnston.
January 26, 2010 WAPRO Electronic Records Management 101 WAPRO Electronic Records Management 101 Washington Association of Public Records Officers Kyle.
Content Introduction History What is Digital Signature Why Digital Signature Basic Requirements How the Technology Works Approaches.
Defining Electronic Systems
ELECTRONIC DOCUMENT: LITHUANIAN EXAMPLE
Retain Data Commensurate with Value
Digital Signature.
FOIA, Privacy & Records Management Conference 2009
Mohammad Alauthman Computer Security Mohammad Alauthman
Presentation transcript:

Legal Archiving & Records management, existing technologies and solutions Marc Vandeveken - I.R.I.S.

Agenda  Definition  Key drivers and objectives  The actual picture…  Impact on IDR, ECM and ICT.  Q & A

Definition « Archiving is the process of collecting, classifying and preserving information for future reference ». Legal archiving is archiving for legal and regulation purposes.

Key Drivers and Objectives  E-docs replace P-docs…  80% of the information is located in s, e-docs and web.  Most of the key-business transactions are now processed electronically.  Volume of p-docs is decreasing.  Paper archive : expensive, no added-value. …but what about the legal value of E-docs ?  Legal value of p-docs is obvious (signature), not the case for e-docs. The Key objective of Legal Archiving is to legitimate electronic information by conferring it the same legal value as paper information).

Key Drivers and Objectives  Legal and regulation pressure is growing …  Increasing requirements for documents’ traceability, retention and disposition +  Emerging requirements for private information protection implies :  Proven destruction of private information after retention period expiration.  Ability to prove the usage of private information (traceability).  Need to protect organization’s key information against :  Unauthorized access, usage and alteration by internal users.  Erroneous deletion or alteration by technical or business staff.

The actual picture  Original P-doc is considered as a proof.  E-doc can be considered as a proof when : “Its origin and author can be undoubtedly proved.” The document has been electronically signed (the author is known). A third-party certificate guaranties the undoubtable link between the signature and the content of the document. This certificate must be qualified (i.e : must rely on approved technologies, provider and must contain enough information). “No alteration has been made possible since the moment it has been created in its final form.”

The actual picture…  To be used as a legal proof, an E-doc must be:  authenticated  (electronic signature + certificate)  not altered (integrity)  Secured and auditable process in the organization :  End-to-end (from documentation creation/scanning to archiving)  Traceability (who has done what ? When ?)  “Contextual information” : Date, time, place of creation -> “time stamping” (Horodatage) would reinforce value of proof.  Secured long-term storage

Concepts and criteria  No real legal text to define what “a reliable legal archiving system” must be.  Different norms exist :  AFER – 16/2008 (E.T ) dd :  Condition and terms for storing and archiving the e-invoices and e-data based on the VAT law  Legal context on the production and the archiving of e-docs  NF – Z (AFNOR France 2001 – new version in 2008) :  Set of technical and operational measures to ensure a proper long-term storage and retrieval of electronic documents (scanned or produced by an IT application).  Recommends optical storage - physical WORM-, new version also admits logical WORM.  ISO MoReq :  Dedicated to the records management.  MoReq is the operational approach of ISO  MoReq 2 :  European Directive  New version of MoReQ

Concepts and criteria  Authenticity :  Signature  Time stamping  Non alterability :  Through the use of non-rewritable storage  Physical WORM (optical juke-boxes)  Logical WORM magnetic disk bays (IBM DR550, EMC Centera)  Based only on the signature  Normal magnetic disk (reinscriptible)  Authentication through PKI  Durability:  Technological cycle : < 10 years (minus the retention rules)  Storage durability : 5-10 years (magnetic), years (optical)  Plan periodical upgrade of the systems  Regularly verify storage media / perform duplicates through a validated procedure (use of masters).  For magnetic disks, use RAID + hot-swappable disks.  Use standard file formats (PDF/A-1A)

Concepts and criteria  Retention period  Based on document type.  When does it start :  On creation date…  After the last event date (example : account closing, death etc…)  The retention delay can be freezed :  Example : an account has been reopened. Legal archiving is a process, not a product

Impact on IDR, ECM and ICT  Impact on IDR (Legal Scanning – AFER regulation) :  Endorsing (small print on scanned document : timestamp + operator ID).  Identification of the scanning operator + scanner ID + date/time)  Electronic signature + certificate during scanning process (pay attention to certificate management as they expire).  Scanning application must be secured :  No graphical editor authorizing the alteration of the image file.  Use of non-alterable image format (TIFF group 4).  Authentication of operator through sign-on.  Use of dedicated network for scanning process.  Image file associated with all meta-data released to ECM.  The release process generates log files.  Log files must be stored and controlled on a regular basis. Legal Scanning

Impact on IDR, ECM and ICT  Impact on ECM  No alteration of the original document is allowed…only annotation on a separate layer. No image editor is available  not technically possible to alter original document.  Every operation on the original document is logged (search, read, annotate etc…).  Should a modification of the original document is authorized, this is done through the use of versioning and strictly logged.  Documents are encrypted and stored in specific legal hardware.  Documents are stored according to retention rules (date-based or event-based).

Impact on IDR, ECM and ICT  Impact on ICT (Storage)  Use of specific legal storage hardware (ex : IBM DR550; EMC Centera).  No “illegal” operations allowed (removal impossible).  Management of retention period expiration (flag for destruction).  Access data only from ECM solution (no file-system-like browsing).  Possibility of logical data segregation  Data security tools (mirroring, replication etc…)

How to face your major challenge: Do more with less, while reducing your carbon footprint Do more with less – Automate processes – Reduce workload Legal Archiving is GREEN! – Reduce paper volume Decrease square meters for archiving Printing no longer an obligation

Questions?

Thank you !!