Maintaining, Preserving & Disposing of Data on Social Media & Cloud Computing Platforms Catherine Teti Managing Director, Knowledge Services Chief Agency Privacy Officer US Government Accountability Office December 1, 2011
Presentation Overview Challenges, issues and requirements that agencies need to be mindful of/address when moving into the cloud or using social media. Value Proposition Risks and Requirements Governance – effective information management and oversight GAO’s Experience Additional References December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Value Proposition  What . . .  Problem will be solved? Service enhanced? Operational or resource efficiencies realized? Understand your audience/customer base Multiple points of information dissemination (e.g., reposting information to agency web sites) OMB “Guidance for Agency Use of Third-Party Websites and Applications”, M-10-23, June 25, 2010 Provide alternatives to 3d party websites/applications (i.e., public shouldn’t have to join a social media site to access agency information or services) December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Risks and Requirements - Records  Is a record required? See Value proposition (why are you doing this in the 1 st  place? Evidence of agency policy, decisions, mission Original or repurposed content (is it already captured elsewhere?) Caution:  Content vs. medium December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Risks and Requirements – Capture/Retain  Capture and retention Preserving data that isn’t “owned” or controlled by your agency  - Do you (or should you) care? What if – the cloud vendor goes out of business, the agency changes contractors, you decide to stop using Facebook? Disposing of or destroying data at the end of its retention period (inclusion in terms of service) Does it matter if you can’t dispose of it – i.e., potential lack of control December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Risks and Requirements – Security/Privacy  Security Potential for hacking or attacking systems and/or data  Privacy – Potential for inappropriate use of personal data What is captured (essential only) ?  Why?  How is it used?  How is it secured?  User notification – collection and use See also OMB M-10-23 requirements for  privacy impact assessments  Agency privacy notices December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Federal Agency Information Management Requirements The Paperwork Reduction Act  – information collection and responsibilities for the management of information resources The Privacy Act  - use of personal information by federal agencies FISMA, the Federal Information Security Management Act  - requirements for protecting agency information and systems from misuse FOIA  - public access to agency records The Federal Records Act  - requires agencies to manage records needed for their operations and have processes to properly dispose of or save (historically significant) records NARA Bulletin 2011-02 - Guidance on Managing Records in Web 2.0/Social Media Platforms December 1, 2011 Data Management Challenges – Social Media & Cloud Page
E-Discovery Requirements  Formalized in the amended Federal Rules of Civil Procedures in 2006.  All Electronically Stored Information (ESI) stipulated in a subpoena must be preserved as part of a legal hold.  Organizations must be able to preserve and produce all ESI relevant to a discovery order.  Organizations’ inability to search for and locate relevant information is causing significant risk. Costs for e-discovery are continuing to skyrocket for organizations without proper information management. December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Governance – The Key to Effective Information Management and Oversight  Different information – and mission - disciplines working together for an integrated approach: Records Management Information Security Information Technology Legal Privacy Business owner(s) Realigning and re-engineering stove-piped management processes to create integrated and coordinated approaches to managing information across the information life cycle Oversight – capture/custodianship Guidance – Who speaks for the agency December 1, 2011 Data Management Challenges – Social Media & Cloud Page
GAO’s Key Requirements for Effective IM Business Purpose Align management with GAO business processes to meet mission objectives Organizational Commitment Ensure executive sponsorship and stakeholder buy-in Governance Clearly define policy and requirements Recognize constraints and limitations Strive for user engagement and senior executive sponsorship Information governance alliance among IT, records, legal, information security, privacy, public affairs, business owners Oversight Performance measures and accountability December 1, 2011 Data Management Challenges – Social Media & Cloud Page
GAO’s (Adaptive) Use of Social Media Tools Information Dissemination Twitter (RSS feeds) YouTube Podcasts Facebook Flickr Information Sharing Wiki (internal)  All records are managed according to GAO IM policies December 1, 2011 Data Management Challenges – Social Media & Cloud Page
An Effective IM Program An effective IM program allows GAO to: Retrieve:  Easily retrieve relevant information in a timely fashion Access:  Provide access to information to the right people when it is needed Audit:  Able to identify anomalies and ensure compliance with all applicable rules and regulations (FRA, FISMA, etc.) Dispose:  Ability to dispose of information in the normal course of business when it is no longer needed in accordance with GAO’s retention and disposition policy December 1, 2011 Data Management Challenges – Social Media & Cloud Page
GAO’s Disposition Strategy GAO’s records disposition schedule applies to records regardless of format or media. Disposition strategy is comprehensive for all records types (paper, electronic, data sets, and other “stuff”) so it is applied uniformly across all media and formats. Ensures that GAO complies with all requirements, mitigates risk and exposure, saves storage space, is cost-effective, and allows for easier search and retrieval of remaining records.  December 1, 2011 Data Management Challenges – Social Media & Cloud Page
GAO Reports on Information Management and Social Media GAO-11-605: Social Media: Federal Agencies Need Policies and Procedures for Managing and Protecting Information They Access and Disseminate  GAO-10-838T: Information Management: The Challenges of Managing Electronic Records GAO-11-15: NARA: Oversight and Management Improvements Initiated, but More Action Needed  GAO-08-536: Privacy: Alternatives Exist for Enhancing Protection of Personally Identifiable Information  GAO-10-537T: Freedom of Information Act:  Requirements and Implementation Continue to Evolve December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Additional References OMB Memorandum M-10-23, Guidance for Agency Use of Third-Party Websites and Applications Best Practices Study of Social Media Records Policies, ACT/IAC Collaboration and Transformation (C&T) Shared Interest Group (SIG), March 2011 (  www.actgov.org/SocialMediaRecords  ) NARA Bulletin 2011-02, Guidance on Managing Records in Web 2.0/Social Media Platforms, October 20, 2010 December 1, 2011 Data Management Challenges – Social Media & Cloud Page
Questions? Catherine Teti  Managing Director, Knowledge Services, Chief Agency Privacy Officer US Government Accountability Office (GAO) [email_address] 202.512.9255 December 1, 2011 Data Management Challenges – Social Media & Cloud Page
December 1, 2011 Data Management Challenges – Social Media & Cloud Page  GAO on the Web Web site:  http://www.gao.gov/   Contact Chuck Young, Managing Director, Public Affairs,  [email_address] (202) 512-4800, U.S. Government Accountability Office 441 G Street NW, Room 7149, Washington, D.C. 20548 Copyright This is a work of the U.S. government and is not subject to copyright protection in the United States. The published product may be reproduced and distributed in its entirety without further permission from GAO. However, because this work may contain copyrighted images or other material, permission from the copyright holder may be necessary if you wish to reproduce this material separately.

More Related Content

PPT
D R M Evolution 2005 10 19
PDF
Removing Danger From Data
PDF
Privacy & Social Media
PDF
Multi-Dimensional Privacy Protection for Digital Collaborations.
PPTX
Building A Modern Security Policy For Social Media and Government
PPTX
Doculabs Everteam houston breakfast 06.29.17 v0.2
PDF
AI and Legal Tech in Context: Privacy and Security Commons
PDF
TITUS - Top Reasons For Data Classification
D R M Evolution 2005 10 19
Removing Danger From Data
Privacy & Social Media
Multi-Dimensional Privacy Protection for Digital Collaborations.
Building A Modern Security Policy For Social Media and Government
Doculabs Everteam houston breakfast 06.29.17 v0.2
AI and Legal Tech in Context: Privacy and Security Commons
TITUS - Top Reasons For Data Classification

Similar to E-discovery - social media & cloud-dec2011 (20)

PDF
Social media and records management challenges 2012 09-17-m
PDF
Case for Compliant IM
PPTX
Arma november2010
KEY
NARA and Social Media, Spring 2011
PDF
Best practices of social media records policies
PDF
Best practices of social media records policies ct sig - 03-31-11 (3)
PDF
(eBook PDF) Information Governance: Concepts, Strategies, and Best Practices
KEY
AERM Workshop
PPTX
What does the Obama Administration Records Management Directive Tell Us?
DOC
Website and Social Media Archiving: A Growing Necessity for Government Agencies
PPTX
Information governance process & technology
PPTX
How To Manage Social Media In Your Organization: Building A Successful Govern...
PPT
Effective Information Management V2 18sep2008
PDF
Prepare For Breaches Like a Pro
PDF
2 7-2013-big data and e-discovery
PDF
Information Explosion - Erik Moller
PPTX
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
PDF
Breached! The First 48
PPTX
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
PDF
Information Management in a Web 2.0 World May 2009
Social media and records management challenges 2012 09-17-m
Case for Compliant IM
Arma november2010
NARA and Social Media, Spring 2011
Best practices of social media records policies
Best practices of social media records policies ct sig - 03-31-11 (3)
(eBook PDF) Information Governance: Concepts, Strategies, and Best Practices
AERM Workshop
What does the Obama Administration Records Management Directive Tell Us?
Website and Social Media Archiving: A Growing Necessity for Government Agencies
Information governance process & technology
How To Manage Social Media In Your Organization: Building A Successful Govern...
Effective Information Management V2 18sep2008
Prepare For Breaches Like a Pro
2 7-2013-big data and e-discovery
Information Explosion - Erik Moller
Information Governance, Managing Data To Lower Risk and Costs, and E-Discover...
Breached! The First 48
3rd Party Risk: Practical Considerations for Privacy & Security Due Diligence
Information Management in a Web 2.0 World May 2009
Ad

Recently uploaded (20)

PPTX
BUSINESS CYCLE_INFLATION AND UNEMPLOYMENT.pptx
PPTX
2 - Self & Personality 587689213yiuedhwejbmansbeakjrk
PDF
Chapter 2 - AI chatbots and prompt engineering.pdf
PDF
Sustainable Digital Finance in Asia_FINAL_22.pdf
PDF
Cross-Cultural Leadership Practices in Education (www.kiu.ac.ug)
PDF
Middle East's Most Impactful Business Leaders to Follow in 2025
PPTX
IMM.pptx marketing communication givguhfh thfyu
DOCX
Center Enamel Powering Innovation and Resilience in the Italian Chemical Indu...
PDF
Susan Semmelmann: Enriching the Lives of others through her Talents and Bless...
PPTX
IMM marketing mix of four ps give fjcb jjb
PDF
Comments on Clouds that Assimilate Parts I&II.pdf
PDF
Stacey L Stevens - Canada's Most Influential Women Lawyers Revolutionizing Th...
PPTX
chapter 2 entrepreneurship full lecture ppt
PDF
HQ #118 / 'Building Resilience While Climbing the Event Mountain
PPTX
Project Management_ SMART Projects Class.pptx
PDF
Communication Tactics in Legal Contexts: Historical Case Studies (www.kiu.ac...
DOCX
Hand book of Entrepreneurship 4 Chapters.docx
PPTX
operations management : demand supply ch
PPTX
Transportation in Logistics management.pptx
PPT
Retail Management and Retail Markets and Concepts
BUSINESS CYCLE_INFLATION AND UNEMPLOYMENT.pptx
2 - Self & Personality 587689213yiuedhwejbmansbeakjrk
Chapter 2 - AI chatbots and prompt engineering.pdf
Sustainable Digital Finance in Asia_FINAL_22.pdf
Cross-Cultural Leadership Practices in Education (www.kiu.ac.ug)
Middle East's Most Impactful Business Leaders to Follow in 2025
IMM.pptx marketing communication givguhfh thfyu
Center Enamel Powering Innovation and Resilience in the Italian Chemical Indu...
Susan Semmelmann: Enriching the Lives of others through her Talents and Bless...
IMM marketing mix of four ps give fjcb jjb
Comments on Clouds that Assimilate Parts I&II.pdf
Stacey L Stevens - Canada's Most Influential Women Lawyers Revolutionizing Th...
chapter 2 entrepreneurship full lecture ppt
HQ #118 / 'Building Resilience While Climbing the Event Mountain
Project Management_ SMART Projects Class.pptx
Communication Tactics in Legal Contexts: Historical Case Studies (www.kiu.ac...
Hand book of Entrepreneurship 4 Chapters.docx
operations management : demand supply ch
Transportation in Logistics management.pptx
Retail Management and Retail Markets and Concepts
Ad

E-discovery - social media & cloud-dec2011

  • 1. Maintaining, Preserving & Disposing of Data on Social Media & Cloud Computing Platforms Catherine Teti Managing Director, Knowledge Services Chief Agency Privacy Officer US Government Accountability Office December 1, 2011
  • 2. Presentation Overview Challenges, issues and requirements that agencies need to be mindful of/address when moving into the cloud or using social media. Value Proposition Risks and Requirements Governance – effective information management and oversight GAO’s Experience Additional References December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 3. Value Proposition What . . . Problem will be solved? Service enhanced? Operational or resource efficiencies realized? Understand your audience/customer base Multiple points of information dissemination (e.g., reposting information to agency web sites) OMB “Guidance for Agency Use of Third-Party Websites and Applications”, M-10-23, June 25, 2010 Provide alternatives to 3d party websites/applications (i.e., public shouldn’t have to join a social media site to access agency information or services) December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 4. Risks and Requirements - Records Is a record required? See Value proposition (why are you doing this in the 1 st place? Evidence of agency policy, decisions, mission Original or repurposed content (is it already captured elsewhere?) Caution: Content vs. medium December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 5. Risks and Requirements – Capture/Retain Capture and retention Preserving data that isn’t “owned” or controlled by your agency - Do you (or should you) care? What if – the cloud vendor goes out of business, the agency changes contractors, you decide to stop using Facebook? Disposing of or destroying data at the end of its retention period (inclusion in terms of service) Does it matter if you can’t dispose of it – i.e., potential lack of control December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 6. Risks and Requirements – Security/Privacy Security Potential for hacking or attacking systems and/or data Privacy – Potential for inappropriate use of personal data What is captured (essential only) ? Why? How is it used? How is it secured? User notification – collection and use See also OMB M-10-23 requirements for privacy impact assessments Agency privacy notices December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 7. Federal Agency Information Management Requirements The Paperwork Reduction Act – information collection and responsibilities for the management of information resources The Privacy Act - use of personal information by federal agencies FISMA, the Federal Information Security Management Act - requirements for protecting agency information and systems from misuse FOIA - public access to agency records The Federal Records Act - requires agencies to manage records needed for their operations and have processes to properly dispose of or save (historically significant) records NARA Bulletin 2011-02 - Guidance on Managing Records in Web 2.0/Social Media Platforms December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 8. E-Discovery Requirements Formalized in the amended Federal Rules of Civil Procedures in 2006. All Electronically Stored Information (ESI) stipulated in a subpoena must be preserved as part of a legal hold. Organizations must be able to preserve and produce all ESI relevant to a discovery order. Organizations’ inability to search for and locate relevant information is causing significant risk. Costs for e-discovery are continuing to skyrocket for organizations without proper information management. December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 9. Governance – The Key to Effective Information Management and Oversight Different information – and mission - disciplines working together for an integrated approach: Records Management Information Security Information Technology Legal Privacy Business owner(s) Realigning and re-engineering stove-piped management processes to create integrated and coordinated approaches to managing information across the information life cycle Oversight – capture/custodianship Guidance – Who speaks for the agency December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 10. GAO’s Key Requirements for Effective IM Business Purpose Align management with GAO business processes to meet mission objectives Organizational Commitment Ensure executive sponsorship and stakeholder buy-in Governance Clearly define policy and requirements Recognize constraints and limitations Strive for user engagement and senior executive sponsorship Information governance alliance among IT, records, legal, information security, privacy, public affairs, business owners Oversight Performance measures and accountability December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 11. GAO’s (Adaptive) Use of Social Media Tools Information Dissemination Twitter (RSS feeds) YouTube Podcasts Facebook Flickr Information Sharing Wiki (internal) All records are managed according to GAO IM policies December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 12. An Effective IM Program An effective IM program allows GAO to: Retrieve: Easily retrieve relevant information in a timely fashion Access: Provide access to information to the right people when it is needed Audit: Able to identify anomalies and ensure compliance with all applicable rules and regulations (FRA, FISMA, etc.) Dispose: Ability to dispose of information in the normal course of business when it is no longer needed in accordance with GAO’s retention and disposition policy December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 13. GAO’s Disposition Strategy GAO’s records disposition schedule applies to records regardless of format or media. Disposition strategy is comprehensive for all records types (paper, electronic, data sets, and other “stuff”) so it is applied uniformly across all media and formats. Ensures that GAO complies with all requirements, mitigates risk and exposure, saves storage space, is cost-effective, and allows for easier search and retrieval of remaining records. December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 14. GAO Reports on Information Management and Social Media GAO-11-605: Social Media: Federal Agencies Need Policies and Procedures for Managing and Protecting Information They Access and Disseminate GAO-10-838T: Information Management: The Challenges of Managing Electronic Records GAO-11-15: NARA: Oversight and Management Improvements Initiated, but More Action Needed GAO-08-536: Privacy: Alternatives Exist for Enhancing Protection of Personally Identifiable Information GAO-10-537T: Freedom of Information Act:  Requirements and Implementation Continue to Evolve December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 15. Additional References OMB Memorandum M-10-23, Guidance for Agency Use of Third-Party Websites and Applications Best Practices Study of Social Media Records Policies, ACT/IAC Collaboration and Transformation (C&T) Shared Interest Group (SIG), March 2011 ( www.actgov.org/SocialMediaRecords ) NARA Bulletin 2011-02, Guidance on Managing Records in Web 2.0/Social Media Platforms, October 20, 2010 December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 16. Questions? Catherine Teti Managing Director, Knowledge Services, Chief Agency Privacy Officer US Government Accountability Office (GAO) [email_address] 202.512.9255 December 1, 2011 Data Management Challenges – Social Media & Cloud Page
  • 17. December 1, 2011 Data Management Challenges – Social Media & Cloud Page GAO on the Web Web site: http://www.gao.gov/   Contact Chuck Young, Managing Director, Public Affairs, [email_address] (202) 512-4800, U.S. Government Accountability Office 441 G Street NW, Room 7149, Washington, D.C. 20548 Copyright This is a work of the U.S. government and is not subject to copyright protection in the United States. The published product may be reproduced and distributed in its entirety without further permission from GAO. However, because this work may contain copyrighted images or other material, permission from the copyright holder may be necessary if you wish to reproduce this material separately.

Editor's Notes

  • #10: Guidance to staff – Who posts where, who speaks for the agency Tie to existing media policy