Low Friction Information Governance with Microsoft

Information is at the core of every informed business action or decision. To provide value and avoid unnecessary risk, such as a lawsuit, to an organization, information must be captured, shared, accessed, stored and disposed of following a governed lifecycle to avoid misinformation, inefficiencies and breach of legal or regulatory requirements.

The following challenges are common among organizations attempting to ensure compliance within classic frameworks and tools:

  • Inefficient systems, originally put in place to manage physical records, as opposed to digital systems
  • Lack of employee adherence to tagging and organizing documents as required across the organization (e.g., managing documents, their versions, in the appropriate places, from draft initiation to publishing)
  • Inconsistent oversight and application of compliance needs, including the retention of data in different information and document file repositories
  • Staff expectations on how to conduct information management tasks, and leaders’ expectations on how to best ensure their team’s adherence
  • System resources required to procure, build, manage and maintain repositories, including a records center and archiving systems.

Electronic content management systems such as Microsoft SharePoint have transformed the capability and capacity of organizations to meet these requirements without relying on manual processes which are both time consuming and prone to information mismanagement.

SharePoint Online provides organizations the benefit of leveraging an in-place records management system. Rather than relying on human decisions or limited automation of when and where to retain content, SharePoint Online provides out-of-the-box features for seamless retention, without requiring user intervention or restriction.

Documents and items in SharePoint Online can be applied to a policy which will ensure retention regardless of deletion or being overwritten, allowing for content to be discoverable by authorized individuals (e.g., approved eDiscovery investigators) for the defined period (e.g., seven years). Retention policies also allow for automatic deletion of documents after a specific duration, which is critical when handling sensitive information such as personal information (PI) or personal health information (PHI).

Automation Reduces Friction

Retention automation reduces risk by ensuring policies are adhered to, but also providing the ability to delete information once it should no longer be stored, for example, once a document no longer has business value.

For more advanced needs, Microsoft 365 provides more advanced capabilities without additional third-party systems or forcing staff to interact with different tools and interfaces. These features include but are not limited to:

  • Application of compliance capabilities to multiple applications, including:
    • Automated retention of all emails, documents, and chat messages within the M365 tenant
    • In-application tagging for sensitivity to automate applications of permissions (e.g., allow only internal sharing) and document standards (e.g., watermark stating a document is confidential)
    • Monitoring and alerting of sensitive information types (e.g., passport numbers included in an email) in email and chat communications as well as documents
    • Tracking user and administrator actions and activities in Microsoft 365 for up to 10 years using the Advanced Audit Log
  • Providing a minimum or maximum retention at the document level with a few user clicks
  • Automatically setting the retention based on the storage location (e.g., Board of Directors collaboration area) or type of information within the document (e.g., monitor for financial data)
  • Ensuring documents identified as confidential do not leave the organization’s cloud environment by restricting the ability to download and copy to unmanaged devices and external accounts (e.g., cannot email outside of the company)
  • Providing eDiscovery specialists the ability to search across the organization, directly, without the need to request IT resources (and introduce potential conflicts of interest) to search and export results from multiple data sources.

Microsoft 365 provides a series of compliance tools for the core productivity and communication applications used by enterprise organizations as their day-to-day tools.

Most importantly, they optimize these capabilities by enabling automated methods for application, execution, and oversight (using reports, dashboards, and alerts). By reducing friction with staff for compliance, in terms of end user effort as well as education and training, organizations can reduce their compliance risk while improving employee productivity.

Ensuring Compliance

Managing compliance is an ongoing process which is benefitted by continuous improvement due to an ever-changing environment, both from within the organization, and from outside regulatory and legal authorities.

  • Review all legal and policy-based compliance needs
  • Identify existing information repositories and how they interact with business information through its lifecycle
  • Ensure available software is configured and capturing organizational requirements
  • Identify opportunities to optimize adherence and minimize outstanding risk (e.g., build a roadmap)
  • Implement a governance strategy to manage and maintain the organization’s compliance needs and capabilities as they evolve over time.

To learn more about our Microsoft capabilities, contact us.


Sev Derghazarian

Software Services

Subscribe to Topics

Technology alone won't transform your business. At Protiviti, we believe when the right people team up, everything is possible. Let's transform together. http://ow.ly/9gVI50Kljvf

#ProtivitiTech #technology #transformation #consulting

Increased spending doesn’t translate into a stronger, more resilient cybersecurity posture. Spend four minutes with Protiviti’s Natalie Fedyuk to learn why integration has never been more critical. http://ow.ly/n6XJ50KknER

#ProtivitiTech #TechnologyInsights #Microsoft #Security

Join Protiviti’s Kelsey Dario for a speaker session discussing how to set the right expectations when looking to achieve business objectives with technology. Sign-up now: http://ow.ly/h7cR50Kb9ol

#ProtivitiTech #DigitalTransformation #BusinessObjectives #IIA

Can using trapped ions as qubits yield the most powerful quantum computers on the planet? Join host @KonstantHacker for a chat about trapped ions and the creation of @IonQ_Inc with industry pioneer Chris Monroe: http://ow.ly/Ezfm50KhZJt

#ProtivitiTech #QuantumComputing #PQW #Atom

A recent Gallup poll showed majorities of Americans across party lines now think the government should increase its regulation of big tech companies. Read how tech companies can prepare for regulatory changes: http://ow.ly/P0U250KgTaC

#ProtivitiTech #WhitePaper #Equilibrium

Load More