Arma Slide Deck 17novb09


Published on

Presentation on the synergy and risks of RIM and ECM given 17nov09 to the Greater Anchorage Chapter of ARMA

Published in: Technology, Business
  • Be the first to comment

  • Be the first to like this

No Downloads
Total views
On SlideShare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide

Arma Slide Deck 17novb09

  1. 1. It Takes Two To Tango The Synergy of RIM & ECM Gordon E.J. Hoke, CRM Gordon E.J. Hoke, CRM M
  2. 2. The Presenter <ul><li>Gordon E.J. Hoke </li></ul><ul><ul><li>Content Management since 1989 </li></ul></ul><ul><ul><ul><li>Software vendor </li></ul></ul></ul><ul><ul><ul><li>Journalist </li></ul></ul></ul><ul><ul><ul><li>Consultant/Analyst </li></ul></ul></ul><ul><ul><li>Records Management since 2002 </li></ul></ul><ul><ul><ul><li>Certified Records Manager </li></ul></ul></ul><ul><ul><ul><li>Records Risk Management Consultant </li></ul></ul></ul><ul><ul><ul><li>Author/Analyst </li></ul></ul></ul><ul><ul><ul><li>Practitioner </li></ul></ul></ul>
  3. 3. We’re all in this together… <ul><li>Clarifications any time </li></ul><ul><li>Substantive questions at the end </li></ul>
  4. 4. The Challenge: Get the best of both worlds <ul><li>Records Mgrs. miss the profound advantages of ECM </li></ul><ul><ul><li>Business processes </li></ul></ul><ul><ul><li>Storage and device options </li></ul></ul><ul><ul><li>Cost effectiveness </li></ul></ul><ul><ul><li>Security, flexibility, universality </li></ul></ul><ul><li>Content Mgrs. miss the profound advantages of RIM </li></ul><ul><ul><li>Systematic, media-agnostic approach </li></ul></ul><ul><ul><li>Risk reduction </li></ul></ul><ul><ul><li>Governance </li></ul></ul><ul><ul><li>Controls </li></ul></ul><ul><ul><li>Cost avoidance </li></ul></ul>
  5. 5. Seeking Progress <ul><li>“ Those who cannot remember the past are doomed to repeat it.” </li></ul><ul><li>-- George Santayana </li></ul>
  6. 6. History of Records & Information Management (RIM) <ul><li>Moses, c. 1500 BCE </li></ul><ul><li>– First Disaster Recovery </li></ul><ul><li>Callimachus, c. 380 BCE </li></ul><ul><li>– First Index </li></ul><ul><li>J. B. Dancer, 1839 CE </li></ul><ul><li>– Early micrographics </li></ul><ul><li>ISO & Sedona Principles, 2005 </li></ul><ul><li>– Digital records standards </li></ul>
  7. 7. Records and Information Management – RIM Records: “ . . . information created, received, and maintained as evidence by an organization or person, in pursuance of legal obligations or in the transaction of business” – ISO 15489-1 Information and Documentation – Records Management Records and Records Life Cycle Creation Production Storage/disposal Use/Modification Conversion
  8. 8. Individual organizations must determine the definition of what a record is and, often more importantly, what it is not. Legal Inconsistency <ul><li>Courts don’t care about official designation as “Record” or “Non-Record” </li></ul><ul><li>Case Law varies. What is admissible? </li></ul><ul><ul><li>Back up tapes? </li></ul></ul><ul><ul><li>Metadata? </li></ul></ul><ul><ul><li>Random Access Memory? </li></ul></ul>
  9. 9. Where do Records Exist? <ul><li>Records exist in many media </li></ul><ul><ul><li>Paper </li></ul></ul><ul><ul><li>email </li></ul></ul><ul><ul><li>Structured applications </li></ul></ul><ul><ul><li>Instant messages </li></ul></ul><ul><ul><li>Desktop files (Word, Excel, etc.) </li></ul></ul><ul><ul><li>Shared directories on servers </li></ul></ul><ul><ul><li>Departmental information silos </li></ul></ul><ul><ul><li>Collaboration sites </li></ul></ul><ul><ul><li>Web pages/blogs </li></ul></ul><ul><ul><li>Smartphones </li></ul></ul><ul><ul><li>Facsimile </li></ul></ul><ul><ul><li>Backup tapes </li></ul></ul><ul><ul><li>Voice mail </li></ul></ul><ul><ul><li>Microfiche and film </li></ul></ul>– USB drives – Multi-function devices – RAID drives – MP3 Players – Social networks – IP telephony – Text messages – Desktop files – Dept. information silos – Web 2.0/ Tweets The significant growth of unstructured electronic records presents significant demands on storage and production. Are these on your Data Map?
  10. 10. ARMA International <ul><li>Originally, The Association of Records Managers and Administrators </li></ul><ul><ul><li>Primary goal: Support practitioners </li></ul></ul><ul><ul><li>Just published Generally Accepted Recordkeeping Principles (GARP) </li></ul></ul><ul><li>Its affiliate, The Institute for Certified Records Managers: </li></ul><ul><ul><li>Establishes competencies </li></ul></ul><ul><ul><li>Administers a daunting set of tests </li></ul></ul><ul><ul><li>Grants the gold standard credential, CRM </li></ul></ul><ul><ul><li>Requires and regulates continuing education </li></ul></ul>
  11. 11. Records and Information Management <ul><li>Traditional RIM focused on paper and microforms. </li></ul><ul><li>Library functions: </li></ul><ul><ul><li>Acquisition </li></ul></ul><ul><ul><li>Circulation </li></ul></ul><ul><ul><li>Storage </li></ul></ul><ul><ul><li>Disposal </li></ul></ul>
  12. 12. Pushing the Barriers of Content Management <ul><li>1843 – Fax machine patented (Alexander Bain) </li></ul><ul><li>1870s – Cowboys use “Book of Brands” </li></ul><ul><li>1961 – First use of email </li></ul><ul><li>1987 – First commercial document imaging software </li></ul><ul><li>1990 – Imaging merged with COLD and workflow </li></ul><ul><li>1990s – Evolution of recognition technologies, e-forms </li></ul><ul><li>2000s – Proliferation of Internet apps and email </li></ul><ul><li>2000s – Shift of info media from atoms to electrons </li></ul><ul><li>2002 – Perception of RIM as “the new buzz word” </li></ul>
  13. 13. AIIM <ul><li>1947: formed as the National Micrographics Assn. </li></ul><ul><li>Late ’80s: became the Association for Information and Image Management </li></ul><ul><li>Late ’90s: simply AIIM International </li></ul><ul><li>Yesterday: AIIM, the Enterprise Content Management Association </li></ul><ul><li>Today: AIIM, The community that provides education, research, and best practices to help organizations find, control, and optimize their information </li></ul><ul><li>Tomorrow: AIIM, the Next Evolution Assn. </li></ul>
  14. 14. The Association Liberation Movement <ul><li>AIIM + ARMA = </li></ul>Shed no tears.
  15. 15. Lack of RIM is Risky <ul><li>Risks of: </li></ul><ul><li>Non-compliance with statutes and regulations </li></ul><ul><li>Inefficient retrievals from record-clogged systems </li></ul><ul><li>Employee / operational records misuse </li></ul><ul><li>Adverse inferences from ineffective e-Discovery </li></ul><ul><li>Inability to mount legal defense </li></ul><ul><li>Adverse publicity </li></ul><ul><li>Loss of competitive advantage </li></ul>
  16. 16. RIM Is Front Page News <ul><li>Ariz. court rules records law covers 'metadata' </li></ul><ul><li>October 29, 2009 1:41 PM EDT (AP) </li></ul><ul><li>PHOENIX - Hidden data embedded in electronic public records must be disclosed under Arizona's public records law, the state Supreme Court ruled Thursday </li></ul><ul><li>WSJ, 8 Oct. 2007, </li></ul><ul><li>Qualcomm, while suing Broadcom, finds that it failed to share 300,000 missed emails during Discovery. The jury gets the case with “adverse inference”. The GC and 17 outside attorneys resign. </li></ul>
  17. 17. RIM Is Front Page News (cont.) <ul><li>TJ Maxx loses hundreds of thousands of credit card numbers </li></ul><ul><li>The U.S. Veterans Administration loses the personal information of more than a million former military personnel </li></ul>
  18. 18. RIM Is Front Page News (cont.) <ul><li>Federal Computer Week , Jan 15, 2009 </li></ul><ul><li>Court Moves to Preserve White House e-mail Messages -- By Ben Bain </li></ul><ul><li>* Citing “emergency conditions,” a federal court today ordered the Bush administration to take further steps to preserve millions of e-mail messages sent during a crucial time in the administration and are the subject of ongoing litigation.... </li></ul><ul><li>The messages that are alleged to be missing are from the period that includes the invasion of Iraq, key developments in the Valerie Plame leak investigation and the government's response to Hurricane Katrina.... </li></ul>
  19. 19. RIM Is Front Page News (cont.) <ul><li>ABC News , Jan 29, 2009 </li></ul><ul><li>Credit Card Security Breach Could be Largest EVER </li></ul><ul><li>Experts are calling it the biggest security breach ever and millions of consumers could be at risk because their credit and debit card numbers could be compromised by hackers who've gotten access to the computers of a huge company. </li></ul><ul><li>Heartland Payment Systems investigated and realized hackers broke into their system late in 2008. The company processes payments for 175,000 retailers and restaurants and it's believed information from as many as 150,000 of those may have been compromised. </li></ul>
  20. 20. RIM Is Front Page News (cont.) <ul><li>CNN , Jan 27, 2009 </li></ul><ul><li>Thrift Store MP3 Player Contains Secret Military Files </li></ul><ul><li>Chris Ogle of New Zealand was in Oklahoma about a year ago when he bought a used MP3 player from a thrift store for $9. A few weeks ago, he plugged it into his computer to download a song, and he instead discovered confidential U.S. military files. </li></ul><ul><li>The files included the home addresses, Social Security numbers and cell phone numbers of U.S. soldiers. The player also included what appeared to be mission briefings and lists of equipment deployed to hot spots in Afghanistan and Iraq. </li></ul>
  21. 21. For failing to preserve internal e-mail communications, five major financial services firms paid $1.65 million each Wall Street & Technology, February 2003
  22. 22. Bank of America Securities paid $10 million on record-keeping & access requirements violation claims Chicago Sun-Times, March 2004
  23. 23. Morgan Stanley recently suffered an adverse $1.45 billion court judgment…MS had acted in “bad faith” in failing to turn over relevant e-mails. COMPUTERWORLD , July 2005
  24. 24. Lowering Risk <ul><li>Does comprehensive </li></ul><ul><li>storage help? </li></ul>
  25. 25. Lowering Risk <ul><li> Or does it hinder? </li></ul>
  26. 26. “ How can I keep my CEO of jail?”
  27. 27. RIM Serves Business Operations <ul><li>The goal: </li></ul><ul><li>Right information in the </li></ul><ul><li>Right place in the </li></ul><ul><li>Right format at the </li></ul><ul><li>Right time </li></ul>
  28. 28. Paper-based RIM <ul><li>Stereotype: Marion the Librarian </li></ul><ul><li>“ Did you bring your Library Card?” </li></ul>
  29. 29. RIM ascends... <ul><li>From the basement to the Boardroom </li></ul><ul><li>From Facilities Dept. to Law Dept. </li></ul><ul><li>Even a Chief Records Officer </li></ul><ul><li>...While ECM improves </li></ul>
  30. 30. Myths We Have Known <ul><li>Apollo’s Chariot </li></ul><ul><li>Unicorns </li></ul><ul><li>The Easter Bunny </li></ul><ul><li>The Paperless Office </li></ul>
  31. 31. Understand the Complementary Differences
  32. 32. The Real Differences <ul><li>1. Scope </li></ul><ul><li>2. Perspective </li></ul><ul><li>3. Goals </li></ul><ul><li>4. Language </li></ul><ul><li>5. Media orientation </li></ul><ul><li>6. Governance </li></ul><ul><li>7. Controls </li></ul><ul><li>8. GARP </li></ul>
  33. 33. The Scopes are Incomparable <ul><li>How useful are tools without an operator? </li></ul><ul><li>How effective is an operator without tools? </li></ul>
  34. 34. Differences between RIM and ECM <ul><li>Scope </li></ul><ul><ul><li>ECM is a constellation of technologies </li></ul></ul><ul><ul><li>RIM is a discipline of practices </li></ul></ul>Content Management makes the tools; Records Management makes the rules.
  35. 35. Differences between RIM and ECM (continued) 2. Perspective is based on experience
  36. 36. Differences between RIM and ECM (continued) <ul><li>2. Perspective </li></ul><ul><li>When viewing a storeroom of paper: </li></ul><ul><li>-- ECM focuses on scanner clicks </li></ul><ul><li>and terabytes of storage </li></ul><ul><li>-- RIM focuses on record series </li></ul><ul><li>and retention schedules </li></ul>
  37. 37. Differences between RIM and ECM (continued) <ul><li>3. Primary Goals </li></ul><ul><ul><li>ECM: Operational efficiency and cost-effectiveness </li></ul></ul><ul><ul><li>RIM: Reduced risk and cost avoidance </li></ul></ul>
  38. 38. Differences between RIM and ECM (continued) <ul><li>4. Language </li></ul><ul><li>Words may have different definitions in ECM and RIM: </li></ul><ul><li>Archive </li></ul><ul><li>Backup </li></ul><ul><li>Capture </li></ul><ul><li>Disposition </li></ul><ul><li>ERM </li></ul><ul><li>Fiscal value… </li></ul>
  39. 39. Differences between RIM and ECM (continued) <ul><li>“ Enough of the Tower of Babel...let’s get on the same page.” </li></ul>...Try a glossary or lexicon
  40. 40. Differences between RIM and ECM (continued) 5. Media Orientation <ul><li>What is your medium of choice? </li></ul><ul><li>How long will it last? </li></ul><ul><ul><li>If it won’t last for the lifecycle of the record, what is your media migration plan? </li></ul></ul><ul><li>RIM is media-agnostic... </li></ul><ul><li>ECM is media-gnostic. </li></ul>
  41. 41. Differences between RIM and ECM (continued) <ul><li>• Records exist in many media (reprise) </li></ul><ul><li>– Paper </li></ul><ul><li>– e-Mail </li></ul><ul><li>– Structured applications </li></ul><ul><li>– Instant messages </li></ul><ul><li>– Desktop files </li></ul><ul><li>– Shared directories on servers </li></ul><ul><li>– Departmental information silos </li></ul><ul><li>– Web pages/blogs/Twitter </li></ul><ul><li>– Smart phones </li></ul><ul><li>-- Collaboration sites </li></ul><ul><li>– Facsimile </li></ul><ul><li>– Backup tapes </li></ul><ul><li>– Voice mail </li></ul><ul><li>– Microfiche and film </li></ul><ul><li>– USB drives </li></ul><ul><li>– Multi-function devices </li></ul><ul><li>– RAID drives </li></ul><ul><li>– MP3 players </li></ul><ul><li>– IP telephones </li></ul><ul><li>– Text messages </li></ul>
  42. 42. Differences between RIM and ECM (continued): 6. Governance <ul><li>Every record has an owner/custodian at every moment </li></ul><ul><li>Every worker is a records manager </li></ul><ul><li>RIM program is functional and sustainable </li></ul>President and CEO Chief Records Officer General Counsel Vital Records VP of Compliance VP of Operations Chief Information Officer Business Continuity Disaster Recovery Mail Clerk Security Privacy Workflow
  43. 43. Differences between RIM and ECM (continued) <ul><li>7. Controls </li></ul><ul><li>Controls are a pillar of RIM </li></ul><ul><ul><li>RIM has elements of control for everyone who touches records: </li></ul></ul><ul><ul><ul><li>Education – For processes and responsibilities </li></ul></ul></ul><ul><ul><ul><li>Training – Skills for job performance </li></ul></ul></ul><ul><ul><ul><li>Verification – Of education and training </li></ul></ul></ul><ul><ul><ul><li>Testing – Annual evaluation of competence and skills </li></ul></ul></ul><ul><ul><ul><li>Audit – Field sampling to verify level of accuracy </li></ul></ul></ul><ul><ul><li>Some ECM programs only offer training and support </li></ul></ul>
  44. 44. Controls <ul><li>How do you measure success? </li></ul><ul><ul><li>Metrics </li></ul></ul><ul><ul><li>Dashboard </li></ul></ul><ul><li>How do you know what you do not know? </li></ul>
  45. 45. Importance of RIM and ECM Coordination <ul><li>RIM and ECM Both Serve Business Operations </li></ul><ul><li>The goal: </li></ul><ul><li>Right information in the </li></ul><ul><li>Right place in the </li></ul><ul><li>Right format at the </li></ul><ul><li>Right time at the </li></ul><ul><li>Right cost... </li></ul><ul><li>... While limiting risk! </li></ul>
  46. 46. Potential Implications of Independent RIM and ECM Initiatives <ul><ul><li>Business processes are not optimized </li></ul></ul><ul><ul><li>Copies proliferate </li></ul></ul><ul><ul><li>Storage requirements rise </li></ul></ul><ul><ul><li>Record retention is departmental or by business unit </li></ul></ul><ul><ul><li>There are no datamaps of electronic information </li></ul></ul><ul><ul><li>E-Discovery is expensive or impossible </li></ul></ul><ul><ul><li>Many e-mails are inaccurately indexed </li></ul></ul><ul><ul><li>Staff is under-prepared to execute legal holds </li></ul></ul>
  47. 47. GARP – Generally Accepted Recordkeeping Principles <ul><li>Accountability </li></ul><ul><li>Integrity </li></ul><ul><li>Protection </li></ul><ul><li>Compliance </li></ul><ul><li>Availability </li></ul><ul><li>Retention </li></ul><ul><li>Disposition </li></ul><ul><li>Transparency </li></ul><ul><li> </li></ul>
  48. 48. How ECM and RIM can work together: <ul><ul><li>ECM brings the tools </li></ul></ul><ul><ul><li>ECM delivers capabilities </li></ul></ul><ul><ul><li>ECM brings efficiency </li></ul></ul><ul><ul><li>ECM saves money </li></ul></ul><ul><ul><li>ECM brings technical standards </li></ul></ul><ul><ul><li>ECM captures records </li></ul></ul><ul><ul><li>RIM brings the rules </li></ul></ul><ul><ul><li>RIM delivers discipline </li></ul></ul><ul><ul><li>RIM lowers risks </li></ul></ul><ul><ul><li>RIM avoids costs </li></ul></ul><ul><ul><li>RIM brings performance standards </li></ul></ul><ul><ul><li>RIM disposes records </li></ul></ul>
  49. 49. Potential Benefits of ECM-powered RIM <ul><ul><li>Operational improvements </li></ul></ul><ul><ul><li>Avoidance of storage and retrieval costs </li></ul></ul><ul><ul><li>Compliance: capability to meet audit requests </li></ul></ul><ul><ul><li>In litigation, the ability to: </li></ul></ul><ul><ul><ul><li>Effectively employ legal holds and releases </li></ul></ul></ul><ul><ul><ul><li>Deliver a comprehensive data map with confidence </li></ul></ul></ul><ul><ul><ul><li>Meet discovery requests and produce documents </li></ul></ul></ul><ul><ul><ul><li>Justify the appropriate destruction of documents </li></ul></ul></ul><ul><ul><ul><li>Mount effective legal defense </li></ul></ul></ul><ul><ul><ul><li>Defend against charges of spoliation and bad faith </li></ul></ul></ul>
  50. 50. Pointers for ECM/RIM Success <ul><ul><li>Secure a high-level, enterprise sponsor </li></ul></ul><ul><ul><li>Bring the stakeholders together; build alliances </li></ul></ul><ul><ul><ul><li>Effective programs include IT, RIM, operations, financial, and legal </li></ul></ul></ul><ul><ul><ul><li>Collectively agree on an acceptable level of risk </li></ul></ul></ul><ul><ul><li>Develop an enterprise-wide plan for ECM/RIM </li></ul></ul><ul><ul><li>Start small, perhaps with a single office or dept. </li></ul></ul><ul><ul><li>Establish governance so the program is responsive and sustainable </li></ul></ul><ul><ul><li>Agree on a glossary to overcome language barriers </li></ul></ul><ul><ul><li>Install controls to ensure that enterprise risk levels stay within the acceptable range </li></ul></ul>
  51. 51. Pointers for ECM/RIM Success (continued) <ul><ul><li>Stay flexible and update policies as often as technologies </li></ul></ul><ul><ul><li>Be active in both AIIM and ARMA </li></ul></ul><ul><ul><li>Recognize that there are no quick fixes or easy solutions </li></ul></ul><ul><ul><li>Don’t bet the store on automation; the human factor is still essential. Learn change management, and market. </li></ul></ul><ul><ul><li>Use software as a tool, not a solution </li></ul></ul><ul><ul><li>Differentiate between software’s records mgmt. functionality and a robust records program </li></ul></ul><ul><ul><li>Don’t fixate on a single issue to the exclusion of a comprehensive plan </li></ul></ul>
  52. 52. Different but Complementary <ul><li>We really do need each other…. </li></ul>
  53. 53. Things that Go Well Together <ul><li>Fish & chips, tea & crumpets, pubs & music </li></ul><ul><li>Coffee & donuts, milk & cookies, chocolate & peanut butter </li></ul><ul><li>Moose Tooth pizza & Pipeline Stout, ulu knives & tourists </li></ul><ul><li>Content Management & Records Management </li></ul>
  54. 54. Questions?
  55. 55. Stay in touch: Gordon E.J. Hoke, CRM (507) 254-6474 [email_address]