Low Friction Information Governance with Microsoft

Information is at the core of every informed business action or decision. To provide value and avoid unnecessary risk, such as a lawsuit, to an organization, information must be captured, shared, accessed, stored and disposed of following a governed lifecycle to avoid misinformation, inefficiencies and breach of legal or regulatory requirements.

The following challenges are common among organizations attempting to ensure compliance within classic frameworks and tools:

  • Inefficient systems, originally put in place to manage physical records, as opposed to digital systems
  • Lack of employee adherence to tagging and organizing documents as required across the organization (e.g., managing documents, their versions, in the appropriate places, from draft initiation to publishing)
  • Inconsistent oversight and application of compliance needs, including the retention of data in different information and document file repositories
  • Staff expectations on how to conduct information management tasks, and leaders’ expectations on how to best ensure their team’s adherence
  • System resources required to procure, build, manage and maintain repositories, including a records center and archiving systems.

Electronic content management systems such as Microsoft SharePoint have transformed the capability and capacity of organizations to meet these requirements without relying on manual processes which are both time consuming and prone to information mismanagement.

SharePoint Online provides organizations the benefit of leveraging an in-place records management system. Rather than relying on human decisions or limited automation of when and where to retain content, SharePoint Online provides out-of-the-box features for seamless retention, without requiring user intervention or restriction.

Documents and items in SharePoint Online can be applied to a policy which will ensure retention regardless of deletion or being overwritten, allowing for content to be discoverable by authorized individuals (e.g., approved eDiscovery investigators) for the defined period (e.g., seven years). Retention policies also allow for automatic deletion of documents after a specific duration, which is critical when handling sensitive information such as personal information (PI) or personal health information (PHI).

Automation Reduces Friction

Retention automation reduces risk by ensuring policies are adhered to, but also providing the ability to delete information once it should no longer be stored, for example, once a document no longer has business value.

For more advanced needs, Microsoft 365 provides more advanced capabilities without additional third-party systems or forcing staff to interact with different tools and interfaces. These features include but are not limited to:

  • Application of compliance capabilities to multiple applications, including:
    • Automated retention of all emails, documents, and chat messages within the M365 tenant
    • In-application tagging for sensitivity to automate applications of permissions (e.g., allow only internal sharing) and document standards (e.g., watermark stating a document is confidential)
    • Monitoring and alerting of sensitive information types (e.g., passport numbers included in an email) in email and chat communications as well as documents
    • Tracking user and administrator actions and activities in Microsoft 365 for up to 10 years using the Advanced Audit Log
  • Providing a minimum or maximum retention at the document level with a few user clicks
  • Automatically setting the retention based on the storage location (e.g., Board of Directors collaboration area) or type of information within the document (e.g., monitor for financial data)
  • Ensuring documents identified as confidential do not leave the organization’s cloud environment by restricting the ability to download and copy to unmanaged devices and external accounts (e.g., cannot email outside of the company)
  • Providing eDiscovery specialists the ability to search across the organization, directly, without the need to request IT resources (and introduce potential conflicts of interest) to search and export results from multiple data sources.

Microsoft 365 provides a series of compliance tools for the core productivity and communication applications used by enterprise organizations as their day-to-day tools.

Most importantly, they optimize these capabilities by enabling automated methods for application, execution, and oversight (using reports, dashboards, and alerts). By reducing friction with staff for compliance, in terms of end user effort as well as education and training, organizations can reduce their compliance risk while improving employee productivity.

Ensuring Compliance

Managing compliance is an ongoing process which is benefitted by continuous improvement due to an ever-changing environment, both from within the organization, and from outside regulatory and legal authorities.

  • Review all legal and policy-based compliance needs
  • Identify existing information repositories and how they interact with business information through its lifecycle
  • Ensure available software is configured and capturing organizational requirements
  • Identify opportunities to optimize adherence and minimize outstanding risk (e.g., build a roadmap)
  • Implement a governance strategy to manage and maintain the organization’s compliance needs and capabilities as they evolve over time.

To learn more about our Microsoft capabilities, contact us.

 

Sev Derghazarian

Manager
Software Services

Subscribe to Topics

In the latest #Technology Insights blog post, read how Protiviti works with clients who have concerns about #IoT device #security by asking five questions about their device security ecosystem: http://ow.ly/igKy50H5pbV

In this #podcast episode, Protiviti's Jim McDonald and Jeff Steadman talk with Armin Ebrahimi, Head of Distributed Identity at Ping Identity, about the role #identityproofing plays in the #identity space. Listen now: http://ow.ly/8jCz50H5mte

We invite you to visit the @Xillio #TOPGOLF VIP Cabana for a few hours of networking, happy hour food & drinks, and golf ⛳️ to unwind yourself during the #Microsoft365 Collaboration Conference in Las Vegas. Reserve your ticket at https://hubs.li/Q0106-7R0 and have fun🥳!

The #quantumcomputing industry believed #MonteCarlo simulations would be one of the best use cases to show #quantumadvantage; @QCWare proved the feasibility. @KonstantHacker and QC Ware's Yianni Gamvros chat how to access reusable #quantum #code. http://ow.ly/cRmK50H4wQh

Protiviti's Scott Laliberte shares with Venture Beat four mistakes that can lead to a failed AI implementation and what to do to avoid or resolve these issues for a successful AI rollout. http://ow.ly/wU8C50H4pBY

#ProtivitiTech #AI #machinelearning #technology

Load More...