Home > Ask the Security Experts > Platform Security Questions & Answers > How to enforce a data destruction policy
Ask The Security Expert: Questions & Answers
EMAIL THIS

How to enforce a data destruction policy

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 January 2007
Is there technology available that can help enforce document destruction policies?

>
Tracking and archiving an organization's documentation has become a very complex and difficult task. There are now so many digital forms that documents can take: spreadsheets, emails, Word/PDF documents, instant messages and so on. Several new technologies do aim to solve these problems, such as Chronicle Solutions Inc.'s netReplay and Mathon Systems Inc.'s Integral. AXS-One Inc.'s Retention Manager, an integrated component of the AXS-One Compliance Platform, also enables organizations to apply retention and disposition rules to electronic records, regardless of the originating application.

When you're talking about documents transmitted electronically, however, it becomes almost impossible for an organization to effectively enforce a document destruction policy. I have read internal reports where organizations estimate that there are at least 16 or more copies of most business documents spread throughout their network. This is mainly due to people including an original message and attachments in their replies.

Documents distributed beyond the corporate network represent a significant concern. Deleted documents can often be recovered easily, while additional versions of a document may unknowingly exist elsewhere. We are a long way from a time when a document's permissions can be embedded at the file level, traveling with the document no matter where it is sent. Ideally, someday your document destruction and retention policy will enforce itself, no matter where the documents are stored.

Another problem, though, with trying to automate document destruction policies is that no uniform standards exist for managing the lifecycle of documents and electronic data. Policies must be tailored to the unique business needs of each organization and its regulatory requirements. And because of the Sarbanes-Oxley Act, intentional document destruction is now a process that must be carefully monitored.

Despite the fact that the enforcement of document retention policies can't be handled by technology alone, the destruction process does bring real benefits: preserving the storage space on the network, on desktops and on backup media. Document retention also optimizes network and search performance and lessens the chance of having information used against an organization in lawsuits.

The period of time for storing business records should be determined by a retention schedule that takes business concerns and the requirements of federal and state regulations into consideration. Detailed logs of all destroyed documents and their exact data should be maintained. When getting rid of documents, be sure that the destruction method renders the information unusable and unrecoverable. Finally, don't just allow anyone to destroy your records. Payroll information, for example, or documents relating to labor relations or legal affairs, should not be entrusted to lower-level employees. If you use third-party contractors, make sure you understand the service level agreement and how they will ensure the security of your documents during the destruction process.

More information:

  • Take a look at some of your compliance archiving options.
  • Secure data with full-disk encryption.


  • BROWSE BY TAG
    Platform Security,   Security Audit, Compliance and Standards,   Sarbanes-Oxley Act,   Enterprise Data Protection,   Enterprise Data Governance,   Data Loss Prevention,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Platform Security
    What patch management metrics does Project Quant use?
    Should developers create libraries of common cryptographic algorithms?
    How to secure USB ports on Windows machines
    What is the best database patch management process?
    What is an encryption collision?
    What are new and commonly used public-key cryptography algorithms?
    Should management processes change based on a patch release schedule?
    Does an EULA make it truly illegal to decompile software?
    Should businesses delay Windows Vista adoption and just buy Windows 7?
    Why should we place data files on a separate partition than the OS?

    Sarbanes-Oxley Act
    SOX compliance burdens midmarket security teams
    Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
    Information security book excerpts and reviews
    Internal audits for Sarbanes Oxley and internal IT support
    Internal auditors and CISOs mitigate similar risks
    Implement security and compliance in a risk management context
    Does password sharing in international branches violate SOX?
    Consensus Controls project aims to set benchmarks for compliance
    Security visualization helps make log files work
    The Little Black Book of Computer Security, 2nd Edition
    Sarbanes-Oxley Act Research

    Enterprise Data Governance
    How to protect distributed information flows
    Interpreting 'risk' in the Massachusetts data protection law
    Creating an enterprise data protection framework
    Analyst DLP study finds maturity, ranks top DLP vendors
    Voltage, RSA spar over tokenization, data protection
    Twitter gets condemned by CISOs at Forrester forum
    PCI DSS compliance requirements: Ensuring data integrity
    Trustwave acquires data loss prevention vendor Vericept
    Data has become too distributed to secure, Forrester says
    Cloud-based security services should start private

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cut-and-paste attack  (SearchSecurity.com)
    data masking  (SearchSecurity.com)
    data splitting  (SearchSecurity.com)
    deperimeterization  (SearchSecurity.com)
    Google hacking  (SearchSecurity.com)
    masquerade  (SearchSecurity.com)
    snooping  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts