case studies: deploying information governance in the cloud - … · 2020-01-02 · case studies...
TRANSCRIPT
CASE STUDIES: Deploying Information Governance in the Cloud
Boise ARMA Chapter
2Case Studies for Deploying Information Governance in the Cloud
John P. Frost, CRM FAISenior Information Governance Specialist for Box
25+ years of Enterprise Content Management (ECM) and Information Governance (IG) experience including informationsecurity and content analytics
Roles Served:
• Corporate Records Manager
• ECM and Governance Technical Consultant
• Governance Technical Seller
• Worldwide Services Practice Lead
• Vice President of Sales and Operations
Certified Records Manager (CRM)
Fellow of ARMA International (FAI)
Customers Served:
• Global corporations
• Foreign governments
• Fortune 500 companies
Agenda /Why Govern Cloud Content?
/Case Study 1: Large Multi-National Bank
/Case Study 2: Large Insurance Company
/Cloud Deployment Best Practices for Governance
/ Summary and Questions
Why Govern Cloud Content?
5Case Studies for Deploying Information Governance in the Cloud
Value of InformationOver its lifecycle
Maximum usage includes:AnalyticsArchivingDisposal
Source: CGOC.com
6Case Studies for Deploying Information Governance in the Cloud
What Information Governance Encompasses
Source: IGInitiative.com
7Case Studies for Deploying Information Governance in the Cloud
Cloud Usage
8Case Studies for Deploying Information Governance in the Cloud
Cloud Initiatives
9Case Studies for Deploying Information Governance in the Cloud
Information Lifecycle (or Zone) ModelComposition of information in an organization
70%
25%
5%
Transitory (Purposed Served)
Work-In-Progress
Records
Information on HOLD
1%
10Case Studies for Deploying Information Governance in the Cloud
Why is Content Moving to Cloud?
• Cost• Infrastructure (hardware, backup, storage, licensing)• Human Investment
• Security• Portability• Long-term growth and maintenance• Scalability• Transparent updates• Leverage location• Acceptance• “App” Culture
11Case Studies for Deploying Information Governance in the Cloud
Case Study 1Large Multi-National Bank
12Presentation title: Go to first Master Slide to edit
Case Study 1
Large Multi-National Bank
13Case Studies for Deploying Information Governance in the Cloud
Overview of Bank Governance
• Assessment with ARMA Principles
• Governance Policy Updates
• Paper Process
• 2.5 Petabytes of Data
• Structured / Unstructured
• Regulations – GDPR, PCI-DSS, SOX, etc
• Retention - Disposition
*Source: Integro
14Case Studies for Deploying Information Governance in the Cloud
Solution Drivers
• Structured vs Unstructured• Google mail – maintain and dispose – how?• Google sites – what needs to be retained and how?• SharePoint – 6 sites, 1 Terabyte• File shares – Limited standards, unknown amount of data• Retired systems – shut off hardware while maintaining data• Active data growth – mitigate slow response from systems
*Source: Integro
15Case Studies for Deploying Information Governance in the Cloud
Tools of the Solution
• Cloud-Based on AWS• IBM Atlas Global Retention and Policy Schedule Management• IBM FileNet• IBM Enterprise Records (IER)• IBM StoredIQ• IBM Content Collector for Files & SharePoint (ICC)• IBM Content Classification (ICM)• IBM Content Navigator (ICN)• Navigator for Microsoft Office (NMO)• IBM InfoSphere Optim (Optim)• Estuate ArchLens• On-Premise• IBM Atlas Global Retention and Policy Schedule Management (DB on-prem)
*Source: Integro
16Case Studies for Deploying Information Governance in the Cloud
Lessons Learned
• C-Level approval and support was critical
• Culture shock is inevitable; sound change management needed
• Involve the business and users in the process
• People want to do the “right” thing
• Kick off meetings for each new department streamlined the process
• Certain folder names mandatory; the Record Code has to be exact; Cost Center metadata is unchangeable
• Drop down menus keep metadata consistent as much as possible
*Source: Integro
17Case Studies for Deploying Information Governance in the Cloud
Successes
• 50TB of merger/acquisition data on hold (9 years old)
• File Analysis indexed and identified data requested for litigation
• Locate PCI in shared drives
• PCI Certification made easier by using File Analysis to identify and move data to approved storage
• GDPR – anticipated future success with File Analysis
• Google – future phase leveraging Box Governance
*Source: Integro
18Case Studies for Deploying Information Governance in the Cloud
Case Study 2Large U.S. Insurance Company
19Case Studies for Deploying Information Governance in the Cloud
Overview of Governance
• Needed to update and build an effective Information Governance framework to mitigate risks related to records retention, legal holds, privacy and other challenges with clear, digestible policies and well defined initiatives
• Needed to ensure organic, full support from the units and staff of the organization through relationship building and education
• Needed a “less is more” approach to ensure compliance and reduce “information overload” on staff• Began planning in 2015 with organizational realignment, analysis and roadmap, creation of an
Information Governance committee, and a “roadshow” to learn more about the business and educate on the benefits and necessity of governance
• Hired a new team and expertise to fulfill the vision• Updated policies and schedules, and provided training and awareness to the organization• Decided on and deployed new information governance technology
*Source: Box
20Case Studies for Deploying Information Governance in the Cloud
Solution Drivers
• Organization moving to cloud technologies
• Need to replace and de-commission a large legacy, on-premise ECM and Governance solution
• Clean, organize and migrate over 20 TB (approx. 325 million files) of content and metadata to cloud
• Develop and deploy a new, more efficient taxonomy for the organization
• Ensure internal development team well skilled on cloud solution technologies for any future
enhancement
*Source: Box
21Case Studies for Deploying Information Governance in the Cloud
Tools of the Solution
• Box• Box Governance• Virgo• Zapproved
*Source: Box
22Case Studies for Deploying Information Governance in the Cloud
Lessons Learned
• Mapping configuration and design decisions accurately against the company’s strategic initiative and goals
• Ensuring appropriate migration speeds to meet objectives• Data quality, errors and issues in the legacy system• Managing many dependencies in a large, complex project• Migrating large data volumes to the cloud
*Source: Box
23Case Studies for Deploying Information Governance in the Cloud
Successes
• Hired a strong IG strategy leader to can push through initiatives and develop strong organizational relationships• Leader hired the right talent to execute on the vision and deploy the initiatives• Built a toolset that is efficient and defensible• Built a practical roadmap with tangible, achievable milestones• Built simple, easy to follow policies that require minimal updates over time• Leveraged simple, big bucket retention• Destroy information when it meets its required obligation
*Source: Box
24Case Studies for Deploying Information Governance in the Cloud
Best Practices
• Level set on goals and objectives with ALL relevant groups and stakeholders during project kickoff
• Consider dividing your organizational applications into Systems of Engagement and Systems of Record; this will help determine how to apply retention
• Retention in cloud systems needs to accommodate record and non-record content• Help the client paint the “big picture”, then stakeholders through the steps on how to
achieve the big picture• Align on the vision for how the cloud content and governance tool will be used at
your organization (i.e. what business processes and content will be powered by cloud content management)
• Agreement from Compliance, IT, Legal, Records Management, and Security on the policies and requirements necessary for content that is, or will be, stored in cloud content solution
25Case Studies for Deploying Information Governance in the Cloud
Best Practices
• Define record retention strategy and policy before technology deployment
• Help stakeholders understand the available functionalities in each solution component and how they can be utilized to address immediate needs/pain points
• Conduct knowledge transfer and training with the users to properly enable them own their solution
• Test the solution build in a sandbox environment before production deployment. Even cloud solutions have sandbox or “Test” environments
• Have a strategy to handle the content and records should your organization cancel the contract with the cloud content provider
• Use simple, big bucket retention; use event-based calculation on critical records
• Destroy information when it meets its required obligation
26Case Studies for Deploying Information Governance in the Cloud
Working with Cloud Providers
• Accessibility
• Data Security
• Data Location
• Data Segregation
• Data Integrity
• Data Ownership
• Experience of SaaS Provider
• Qualifications of Provider’s Staff
• Financial Stability of Provider – Bankruptcy?
27Case Studies for Deploying Information Governance in the Cloud
eDiscoveryData Reduction and IT Costs Risk Reduction
Actual Risk/Burden v Target Reduction for Period
Reduction of Discoverable Data Volume
Storage Volume and Cost by Business
ROI/Payback for Information Governance
28Case Studies for Deploying Information Governance in the Cloud
• eDiscovery:• $18,000 per GB for review and productionº• Total Storage Volumen X % Estimated Reduction
• Breach Cost and Reputation Risk: • Average cost of a data breach is $3.86M*• # Documents Affected X $141*, OR • # Customers X $151*
• Storage Costs Reduction:• $2.5M/per year to store 1 PB plus cost significantly add to run rate• Storage Cost X Storage Volume X % Estimated Reduction
ROI/PaybackThe Numbers
*Source: Ponemon InstituteºSource: Rand Institute
29Case Studies for Deploying Information Governance in the Cloud
In Summary… • Organizations are moving to cloud at a rapid rate
• Clean your data before moving to cloud
• These are two of many organizations successfully governing in the cloud
• Know your cloud vendor
• You will govern MORE than just records
• Simple is the key
• ROI is out there!
John [email protected]
<TRACK NAME>Next session:
Maximizing GDPR and Global Data Protection Compliance1:45 PM RM 2004/2006
On the exhibit floor:
• Visit our demo's of Relay
• Visit IBM on the Exhibit Floor
Visit us online:
• Box.com/Apps