[Webinar] SpiraTest - Setting New Standards in Quality Assurance
E discovery 2-cloud_v5
1. e-Discovery 2.0: In the Cloud
Wednesday, November 16, 2011
9:45 AM - 10:45 AM
Steven C. Markey, MSIS, PMP, CISSP, CIPP, CISM, CISA, STS-EV, CCSK
Founder/Principal, nControl, LLC;
Adjunct Professor;
President, Cloud Security Alliance – Delaware Valley Chapter
(CSA-DelVal)
2. • Presentation Overview
– Technology
• Case Study 1: IN the Cloud
• Case Study 2: FROM the Cloud
• e-Discovery Cloud Benefits
• e-Discovery Cloud Concerns
• e-Discovery Cloud Solutions
– Process
• Electronic Discovery Reference Model (EDRM)
• Information Governance Reference Model (IGRM)
4. • Case Study 1: IN the Cloud
– Background
– Drivers
– Technologies
– Limitations
– Risks
– Lessons Learned
5. • Case Study 1: IN the Cloud (Continued)
– Background
• A Fortune 1000 Financial Services Firm
– Investment Management (PA)
– Life Insurance (CT)
– Annuities (IN)
• Legacy Project: 2005/2006
• In-House, Mature IT Team
– Drivers
• Efficiency/GUI Availability
• Compliance
• Cost
6. • Case Study 1: IN the Cloud (Continued)
– Technologies
• Email: In-House Exchange/IXOS
– Recently Transitioned from GroupWise in CT
• Discovery: Zantaz (SaaS)
– Limitations
• De-Centralized Back Office (IT, Compliance, HR)
– No Formal Records & Info Mgmt (RIM) Function/Role
• Lack of Enterprise Project Mgmt Office (PMO)
• Lack of Discovery Specialists
7. • Case Study 1: IN the Cloud (Continued)
– Risks
• Data Loss
– Tape Conversion
– Large Result-Set Delivery
» CD-ROMs via Snail Mail
» Hourly Vendor Processing Fee
• Vendor Management: Contractual/SLA Omissions
• Search/Result-Set False Positives/Negatives
• BCP/DR: Datacom
• Poor Usability
• Scope Creep
8. • Case Study 1: IN the Cloud (Continued)
– Lessons Learned
• Schedule/Effort Underestimated
– Uploading Email on Tape to Zantaz
» Transitioned Legacy GroupWise Data to Exchange
• Not Enough On-Site Training
– Compliance, HR Not Technical
• Discovery Support Resource Limitations
– Budget Was Not There
• Testing Plans
– Incident Response
– BCP/DR
9. • Case Study 2: FROM the Cloud
– Background
– Drivers
– Technologies
– Limitations
– Risks
– Lessons Learned
– Next Steps
10. • Case Study 2: FROM the Cloud (Continued)
– Background
• Financial Services SMB
– Capital Management (PA)
• Recent Project: 2010
• IT: Managed Service Provider/Operations, Director
– Drivers
• Cost
• Compliance
– Technologies
• Email: Exchange Server ‘07/Online/BPOS/Office 365
• Discovery: Symantec Enterprise Vault (EV) v8.0/v9.0
11. • Case Study 2: FROM the Cloud (Continued)
– Limitations
• Budget
• Skill-Sets
• Resources
– Risks
• Software/System Interoperability
• Vendor Management: Contractual/SLA Omissions
• BCP/DR: Datacom
• Legacy Email Availability
• Scope Creep
12. • Case Study 2: FROM the Cloud (Continued)
– Lessons Learned
• Limited Cost Savings
– On-Site Exchange Box for Journaling
– Upgrade to EV v9.0 to Support Exchange 2010
• Exchange Journaling From the Cloud, Complicated
• Leverage Interim Solution for BlackBerry Services
– Shutdown BlackBerry Enterprise Server (BES)
– Leverage AstraSync (Exchange ActiveSync)
13. • Case Study 2: FROM the Cloud (Continued)
– Next Steps
• Upgrade to EV v10.0
– Incorporate Social Media
• Test BCP/DR e-Discovery Functionality
• BlackBerry Office 365/BES Express
– Looking at BES Balance (“Data Boxing”)
• Reviewing Cloud e-Discovery SaaS Solutions
– Symantec Enterprise Vault.cloud
– Microsoft EOA/EHA
14. • e-Discovery Cloud Benefits
– Generic (Across SPI Stack)
– SaaS Specific
– PaaS Specific
– IaaS Specific
15. • e-Discovery Cloud Benefits (Continued)
– Generic (Across SPI Stack)
• Cost
– More Quantifiable Return on Investment (ROI)….?
– Total Cost of Ownership (TCO) Savings
» Operating Expense versus Capital Expense
» Variable Expense versus Fixed Expense
• Core Competency Focus
– Vendor Has Skill-Set
» Configuration Management
» Tie-In 3rd Party Products
– Legal/Litigation Support
– Cross-Platform Support
29. • e-Discovery Cloud Solutions
– PaaS
• Various Platform Vendors
– Build e-Discovery Modules Leveraging Existing Platform
» Not Much of a Market/Business Model
» Re-Create the Wheel
– IaaS
• Various Cloud Vendors
– Build e-Discovery Solution on IaaS Instance
» Leverage Existing Licensing
» Analogous to Hosting