Low Friction Information Governance with Microsoft

Information is at the core of every informed business action or decision. To provide value and avoid unnecessary risk, such as a lawsuit, to an organization, information must be captured, shared, accessed, stored and disposed of following a governed lifecycle to avoid misinformation, inefficiencies and breach of legal or regulatory requirements.

The following challenges are common among organizations attempting to ensure compliance within classic frameworks and tools:

  • Inefficient systems, originally put in place to manage physical records, as opposed to digital systems
  • Lack of employee adherence to tagging and organizing documents as required across the organization (e.g., managing documents, their versions, in the appropriate places, from draft initiation to publishing)
  • Inconsistent oversight and application of compliance needs, including the retention of data in different information and document file repositories
  • Staff expectations on how to conduct information management tasks, and leaders’ expectations on how to best ensure their team’s adherence
  • System resources required to procure, build, manage and maintain repositories, including a records center and archiving systems.

Electronic content management systems such as Microsoft SharePoint have transformed the capability and capacity of organizations to meet these requirements without relying on manual processes which are both time consuming and prone to information mismanagement.

SharePoint Online provides organizations the benefit of leveraging an in-place records management system. Rather than relying on human decisions or limited automation of when and where to retain content, SharePoint Online provides out-of-the-box features for seamless retention, without requiring user intervention or restriction.

Documents and items in SharePoint Online can be applied to a policy which will ensure retention regardless of deletion or being overwritten, allowing for content to be discoverable by authorized individuals (e.g., approved eDiscovery investigators) for the defined period (e.g., seven years). Retention policies also allow for automatic deletion of documents after a specific duration, which is critical when handling sensitive information such as personal information (PI) or personal health information (PHI).

Automation Reduces Friction

Retention automation reduces risk by ensuring policies are adhered to, but also providing the ability to delete information once it should no longer be stored, for example, once a document no longer has business value.

For more advanced needs, Microsoft 365 provides more advanced capabilities without additional third-party systems or forcing staff to interact with different tools and interfaces. These features include but are not limited to:

  • Application of compliance capabilities to multiple applications, including:
    • Automated retention of all emails, documents, and chat messages within the M365 tenant
    • In-application tagging for sensitivity to automate applications of permissions (e.g., allow only internal sharing) and document standards (e.g., watermark stating a document is confidential)
    • Monitoring and alerting of sensitive information types (e.g., passport numbers included in an email) in email and chat communications as well as documents
    • Tracking user and administrator actions and activities in Microsoft 365 for up to 10 years using the Advanced Audit Log
  • Providing a minimum or maximum retention at the document level with a few user clicks
  • Automatically setting the retention based on the storage location (e.g., Board of Directors collaboration area) or type of information within the document (e.g., monitor for financial data)
  • Ensuring documents identified as confidential do not leave the organization’s cloud environment by restricting the ability to download and copy to unmanaged devices and external accounts (e.g., cannot email outside of the company)
  • Providing eDiscovery specialists the ability to search across the organization, directly, without the need to request IT resources (and introduce potential conflicts of interest) to search and export results from multiple data sources.

Microsoft 365 provides a series of compliance tools for the core productivity and communication applications used by enterprise organizations as their day-to-day tools.

Most importantly, they optimize these capabilities by enabling automated methods for application, execution, and oversight (using reports, dashboards, and alerts). By reducing friction with staff for compliance, in terms of end user effort as well as education and training, organizations can reduce their compliance risk while improving employee productivity.

Ensuring Compliance

Managing compliance is an ongoing process which is benefitted by continuous improvement due to an ever-changing environment, both from within the organization, and from outside regulatory and legal authorities.

  • Review all legal and policy-based compliance needs
  • Identify existing information repositories and how they interact with business information through its lifecycle
  • Ensure available software is configured and capturing organizational requirements
  • Identify opportunities to optimize adherence and minimize outstanding risk (e.g., build a roadmap)
  • Implement a governance strategy to manage and maintain the organization’s compliance needs and capabilities as they evolve over time.

To learn more about our Microsoft capabilities, contact us.


Sev Derghazarian

Software Services

Subscribe to Topics

Protiviti is happy to announce that Wendy Luebbe has joined as a Managing Director for the Technology Consulting Solution. Based in Orlando and with over 20 years of experience, Wendy will focus on the Enterprise Data & Analytics segment, specializing in financial services.

Join Protiviti's Scott Laliberte and Andrew Struthers-Kennedy for thoughts on how organizations should discuss and evaluate risks and include emerging technologies as part of risk and audit reviews. http://ow.ly/oJ0a50Fx7Hx

#ITaudit #ProtivitiTech #emergingtechrisks #prowebinars

Consumer #privacy is key. Protiviti recommends focusing on three buckets and eleven requirements that cover what an organization must consider when developing personal #data privacy protections and have a relationship with #digital #identitymanagement. http://ow.ly/8BuC50FA5Hj

Protiviti’s Scott Laliberte hosted a panel with three Chief Information Security Officers on July 11th. While all faced their own distinct pandemic-related issues, many common themes emerged during the discussion. Learn more: http://ow.ly/Er9e50FA3Q3

#CISO #ProtivitiTech

Reporting and #analytics are critical for #CIOs because they structure #data to guide businesses in strategic decision making. Learn why companies must harness and use information that propels business goals. http://ow.ly/eGoR50FA2ub

#TechTransformation #enterprisetransformation

Load More...