SlideShare a Scribd company logo
1 of 14
Information Management, Data Theft,
and the Kill Chain
Joe Shepley, Doculabs
2 Doculabs, Inc. 2017
Session Objectives
• Information security requires defending against what is often
the weakest link in the cyberattack kill chain at organizations:
data theft
• In this session, you'll learn how InfoSec can address the
information management risk posed by data theft and drive
value for the organization
3 Doculabs, Inc. 2017
Why Information Management is Important to InfoSec
• The question of a breach isn’t if, it’s when
• When they get in, what will they find?
• When they find 5, 10, 15+ years of sensitive data that’s past it’s
legal and operational life, InfoSec is on the hook, not (typically)
records, legal, or IT
• InfoSec needs to address information management to reduce the
organization’s risk surface and do their job effectively
4 Doculabs, Inc. 2017
The Kill Chain
Historically, data theft has been the weakest link in the Kill Chain,
and Chief Information Security Officers (CISOs) are now turning to
address it.
Research the
Organization
Introduce
Malware
Control
a Device
Find Other Devices
to Control
Stay or
Leave
Data
Theft
Find the Source
of the Data
5 Doculabs, Inc. 2017
An Information Management Framework for InfoSec
Defensible Content
Disposition Playbook
Policy
Alignment
Procedure
Alignment
Content
Cleanup
Change
Management
6 Doculabs, Inc. 2017
Policy Alignment
• You need to align your corporate policies with information
management good practices
• This alignment ensures that if you’re following the good
practices, you’re also following corporate policy
• The specifics will differ from organization to organization, but
there are some general areas that any policy alignment will
need to cover:
• Corporate records management policy must address both paper and
electronic records
• You need to address the security classification of data – e.g. public,
internal, confidential, highly confidential
• You need to address orphaned and abandoned data
7 Doculabs, Inc. 2017
Procedure Alignment
• You need to align your disposition procedures with your policies
(and therefore your playbook)
• You need to provide detailed, step-by-step guidance for how to
disposition data – guidance which, if followed, makes it
reasonable for courts or regulatory bodies to assume that the
policies (and playbook) are also being followed
• You need to be granular – not content disposition, but rather a
series of linked procedures to guide your technical resources in
content disposition:
• E.g. file analytics procedure, disposition procedure, testing procedure,
remediation procedure, application decommissioning
8 Doculabs, Inc. 2017
Defensible Content Disposition Playbook
• The primary concern in content disposition is getting it right
technically
• But the legal risks are more critical and potentially more
damaging
• You need a playbook to memorialize the requirements of the
disposition and the results
• You need to be able to defend what you did regarding content
disposition for the courts or regulators – 5, 10, or 15 years later
9 Doculabs, Inc. 2017
Content Cleanup
• For some organizations, cleanup is a standalone effort to purge;
for others, it may be part of the preparations for a content
migration
• You need tools to help in the effort; it’s not reasonable to
expect end users to manually comb through their content to
purge junk or stale data, or to identify sensitive data that needs
to be protected
10 Doculabs, Inc. 2017
Content Cleanup
• The results of your repository scan are likely to be something like the
following, which we’ve observed at dozens of clients over the last 10 years:
• Approximately 30 to 70 percent “junk” content, which can be removed
immediately
• Approximately 20 to 40 percent stale content (defined as older than 3 years, based
on date last accessed), which can be archived or purged, depending on your
approach
• An estimated 1 to 10 TB of stale sensitive content, which can be quarantined
immediately with no operational impact
• By classifying your content into these buckets and purging, archiving, etc.,
you’ll reduce your overall unstructured data footprint significantly (by
anywhere from 30 to 90 percent)
• Doing so reduces the overall risk posed by your unstructured data, because
you have less junk and stale data to distract you, as well as less sensitive
data to protect
11 Doculabs, Inc. 2017
Change Management
Stakeholder Matrix
• Who are the key stakeholders that need to be informed of the change and
managed throughout your information management initiative?
Communications and Training Matrix
• What are the key communications and training events required for managing the
changes in information management?
• When do these communications and training events need to be delivered, and to
whom?
• What are the most appropriate vehicles for delivering communications and
training to your various stakeholders and user groups?
Communications and Training Schedule
• When do we need to execute the planned training and communications events?
12 Doculabs, Inc. 2017
So Now What?
• Raise awareness in InfoSec about the importance of
information management
• Articulate the quick win efforts InfoSec can take to reduce junk
and stale data, identify sensitive data, and take preliminary
steps to protect it – which reduces their risk footprint and
shows progress to the C-level, the board, the courts, and
regulators
13 Doculabs, Inc. 2017
Thank You
• Give me your card to get two Doculabs white papers on the
intersection of information management and InfoSec.
• Connect with me to continue the conversation:
• LinkedIn: https://www.linkedin.com/in/joeshepley/
• Twitter: @joeshepley
• Email: jshepley@doculabs.com
• Phone: 773.827.2945
I'd love to help you figure out how to partner effectively
with your information management team
Thank You
www.doculabs.comD C U L A B S
Joe Shepley
jshepley@docuabs.com
773.827.2945

More Related Content

What's hot

Controlling Content Cost in and Enterprise Content Management System
Controlling Content Cost in and Enterprise Content Management SystemControlling Content Cost in and Enterprise Content Management System
Controlling Content Cost in and Enterprise Content Management SystemSimona Galdikaite, B.B.A, MBA
 
Doing Information Management Right
Doing Information Management Right Doing Information Management Right
Doing Information Management Right Lane Severson
 
ADV Slides: Trends in Streaming Analytics and Message-oriented Middleware
ADV Slides: Trends in Streaming Analytics and Message-oriented MiddlewareADV Slides: Trends in Streaming Analytics and Message-oriented Middleware
ADV Slides: Trends in Streaming Analytics and Message-oriented MiddlewareDATAVERSITY
 
Dealing with Dark Data
Dealing with Dark DataDealing with Dark Data
Dealing with Dark DataKazoup
 
Governing the Chaos
Governing the ChaosGoverning the Chaos
Governing the ChaosJohn Hansen
 
Expanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challengesExpanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challengesTom Kirby
 
Data Cleanup Presentation - RecordLion
Data Cleanup Presentation - RecordLionData Cleanup Presentation - RecordLion
Data Cleanup Presentation - RecordLionAndrew Borgschulte
 
DM Radio Webinar: Adopting a Streaming-Enabled Architecture
DM Radio Webinar: Adopting a Streaming-Enabled ArchitectureDM Radio Webinar: Adopting a Streaming-Enabled Architecture
DM Radio Webinar: Adopting a Streaming-Enabled ArchitectureDATAVERSITY
 
Information Management in a Web 2.0 World May 2009
Information Management in a Web 2.0 World May 2009Information Management in a Web 2.0 World May 2009
Information Management in a Web 2.0 World May 2009Collabor8now Ltd
 
Tackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines WebinarTackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines WebinarIndex Engines Inc.
 
Symantec Data Insight 4.0 July 2013
Symantec Data Insight 4.0 July 2013Symantec Data Insight 4.0 July 2013
Symantec Data Insight 4.0 July 2013Symantec
 
Information Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer SatisfactionInformation Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer SatisfactionCapgemini
 
Security and privacy of cloud data: what you need to know (Interop)
Security and privacy of cloud data: what you need to know (Interop)Security and privacy of cloud data: what you need to know (Interop)
Security and privacy of cloud data: what you need to know (Interop)Druva
 
Data-Ed Online Presents: Data Warehouse Strategies
Data-Ed Online Presents: Data Warehouse StrategiesData-Ed Online Presents: Data Warehouse Strategies
Data-Ed Online Presents: Data Warehouse StrategiesDATAVERSITY
 
Data Loss Prevention in O365
Data Loss Prevention in O365Data Loss Prevention in O365
Data Loss Prevention in O365Don Daubert
 
Data-Ed Online: Let's Talk Metadata: Strategies and Successes
Data-Ed Online: Let's Talk Metadata: Strategies and Successes Data-Ed Online: Let's Talk Metadata: Strategies and Successes
Data-Ed Online: Let's Talk Metadata: Strategies and Successes Data Blueprint
 
What is Information Governance
What is Information GovernanceWhat is Information Governance
What is Information GovernanceAtle Skjekkeland
 
Data-Ed Online Webinar: Metadata Strategies
Data-Ed Online Webinar: Metadata StrategiesData-Ed Online Webinar: Metadata Strategies
Data-Ed Online Webinar: Metadata StrategiesDATAVERSITY
 
Big data security challenges and recommendations!
Big data security challenges and recommendations!Big data security challenges and recommendations!
Big data security challenges and recommendations!cisoplatform
 

What's hot (19)

Controlling Content Cost in and Enterprise Content Management System
Controlling Content Cost in and Enterprise Content Management SystemControlling Content Cost in and Enterprise Content Management System
Controlling Content Cost in and Enterprise Content Management System
 
Doing Information Management Right
Doing Information Management Right Doing Information Management Right
Doing Information Management Right
 
ADV Slides: Trends in Streaming Analytics and Message-oriented Middleware
ADV Slides: Trends in Streaming Analytics and Message-oriented MiddlewareADV Slides: Trends in Streaming Analytics and Message-oriented Middleware
ADV Slides: Trends in Streaming Analytics and Message-oriented Middleware
 
Dealing with Dark Data
Dealing with Dark DataDealing with Dark Data
Dealing with Dark Data
 
Governing the Chaos
Governing the ChaosGoverning the Chaos
Governing the Chaos
 
Expanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challengesExpanded top ten_big_data_security_and_privacy_challenges
Expanded top ten_big_data_security_and_privacy_challenges
 
Data Cleanup Presentation - RecordLion
Data Cleanup Presentation - RecordLionData Cleanup Presentation - RecordLion
Data Cleanup Presentation - RecordLion
 
DM Radio Webinar: Adopting a Streaming-Enabled Architecture
DM Radio Webinar: Adopting a Streaming-Enabled ArchitectureDM Radio Webinar: Adopting a Streaming-Enabled Architecture
DM Radio Webinar: Adopting a Streaming-Enabled Architecture
 
Information Management in a Web 2.0 World May 2009
Information Management in a Web 2.0 World May 2009Information Management in a Web 2.0 World May 2009
Information Management in a Web 2.0 World May 2009
 
Tackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines WebinarTackling the GDPR Dell EMC Index Engines Webinar
Tackling the GDPR Dell EMC Index Engines Webinar
 
Symantec Data Insight 4.0 July 2013
Symantec Data Insight 4.0 July 2013Symantec Data Insight 4.0 July 2013
Symantec Data Insight 4.0 July 2013
 
Information Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer SatisfactionInformation Governance: Reducing Costs and Increasing Customer Satisfaction
Information Governance: Reducing Costs and Increasing Customer Satisfaction
 
Security and privacy of cloud data: what you need to know (Interop)
Security and privacy of cloud data: what you need to know (Interop)Security and privacy of cloud data: what you need to know (Interop)
Security and privacy of cloud data: what you need to know (Interop)
 
Data-Ed Online Presents: Data Warehouse Strategies
Data-Ed Online Presents: Data Warehouse StrategiesData-Ed Online Presents: Data Warehouse Strategies
Data-Ed Online Presents: Data Warehouse Strategies
 
Data Loss Prevention in O365
Data Loss Prevention in O365Data Loss Prevention in O365
Data Loss Prevention in O365
 
Data-Ed Online: Let's Talk Metadata: Strategies and Successes
Data-Ed Online: Let's Talk Metadata: Strategies and Successes Data-Ed Online: Let's Talk Metadata: Strategies and Successes
Data-Ed Online: Let's Talk Metadata: Strategies and Successes
 
What is Information Governance
What is Information GovernanceWhat is Information Governance
What is Information Governance
 
Data-Ed Online Webinar: Metadata Strategies
Data-Ed Online Webinar: Metadata StrategiesData-Ed Online Webinar: Metadata Strategies
Data-Ed Online Webinar: Metadata Strategies
 
Big data security challenges and recommendations!
Big data security challenges and recommendations!Big data security challenges and recommendations!
Big data security challenges and recommendations!
 

Similar to Doculabs Everteam houston breakfast 06.29.17 v0.2

SME- Developing an information governance strategy 2016
SME- Developing an information governance strategy 2016 SME- Developing an information governance strategy 2016
SME- Developing an information governance strategy 2016 Hybrid Cloud
 
Why Most Migration Projects Fail – Don’t Be a Statistic Webinar
Why Most Migration Projects Fail – Don’t Be a Statistic WebinarWhy Most Migration Projects Fail – Don’t Be a Statistic Webinar
Why Most Migration Projects Fail – Don’t Be a Statistic WebinarConcept Searching, Inc
 
Handling and Processing Big Data
Handling and Processing Big DataHandling and Processing Big Data
Handling and Processing Big DataUmair Shafique
 
Group 2 Handling and Processing of big data.pptx
Group 2 Handling and Processing of big data.pptxGroup 2 Handling and Processing of big data.pptx
Group 2 Handling and Processing of big data.pptxsalutiontechnology
 
Control the Cost of too Much Content
Control the Cost of too Much ContentControl the Cost of too Much Content
Control the Cost of too Much ContentZanda Mark
 
Information Systems(UNIT 3)
Information Systems(UNIT 3)Information Systems(UNIT 3)
Information Systems(UNIT 3)SURBHI SAROHA
 
eDiscovery at Nottinghamshire County Council
eDiscovery at Nottinghamshire County Council eDiscovery at Nottinghamshire County Council
eDiscovery at Nottinghamshire County Council Concept Searching, Inc
 
Improve ROI and Productivity with Content Cleansing and Enterprise Search
Improve ROI and Productivity with Content Cleansing and Enterprise SearchImprove ROI and Productivity with Content Cleansing and Enterprise Search
Improve ROI and Productivity with Content Cleansing and Enterprise SearchPerficient, Inc.
 
Optimising Your Content for findability
Optimising Your Content for findabilityOptimising Your Content for findability
Optimising Your Content for findabilityKristian Norling
 
The value of big data analytics
The value of big data analyticsThe value of big data analytics
The value of big data analyticsMarc Vael
 
Cff data governance best practices
Cff data governance best practicesCff data governance best practices
Cff data governance best practicesBeth Fitzpatrick
 
Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Craig Jahnke
 
Information governance presentation
Information governance   presentationInformation governance   presentation
Information governance presentationIgor Swann
 
Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?
Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?
Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?Concept Searching, Inc
 
Tips --Break Down the Barriers to Better Data Analytics
Tips --Break Down the Barriers to Better Data AnalyticsTips --Break Down the Barriers to Better Data Analytics
Tips --Break Down the Barriers to Better Data AnalyticsAbhishek Sood
 
DC Salesforce1 Tour Data Governance Lunch Best Practices deck
DC Salesforce1 Tour Data Governance Lunch Best Practices deckDC Salesforce1 Tour Data Governance Lunch Best Practices deck
DC Salesforce1 Tour Data Governance Lunch Best Practices deckBeth Fitzpatrick
 
The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?DATUM LLC
 

Similar to Doculabs Everteam houston breakfast 06.29.17 v0.2 (20)

SME- Developing an information governance strategy 2016
SME- Developing an information governance strategy 2016 SME- Developing an information governance strategy 2016
SME- Developing an information governance strategy 2016
 
Why Most Migration Projects Fail – Don’t Be a Statistic Webinar
Why Most Migration Projects Fail – Don’t Be a Statistic WebinarWhy Most Migration Projects Fail – Don’t Be a Statistic Webinar
Why Most Migration Projects Fail – Don’t Be a Statistic Webinar
 
Handling and Processing Big Data
Handling and Processing Big DataHandling and Processing Big Data
Handling and Processing Big Data
 
Group 2 Handling and Processing of big data.pptx
Group 2 Handling and Processing of big data.pptxGroup 2 Handling and Processing of big data.pptx
Group 2 Handling and Processing of big data.pptx
 
Control the Cost of too Much Content
Control the Cost of too Much ContentControl the Cost of too Much Content
Control the Cost of too Much Content
 
Data Cleaning
Data CleaningData Cleaning
Data Cleaning
 
Information Systems(UNIT 3)
Information Systems(UNIT 3)Information Systems(UNIT 3)
Information Systems(UNIT 3)
 
eDiscovery at Nottinghamshire County Council
eDiscovery at Nottinghamshire County Council eDiscovery at Nottinghamshire County Council
eDiscovery at Nottinghamshire County Council
 
Improve ROI and Productivity with Content Cleansing and Enterprise Search
Improve ROI and Productivity with Content Cleansing and Enterprise SearchImprove ROI and Productivity with Content Cleansing and Enterprise Search
Improve ROI and Productivity with Content Cleansing and Enterprise Search
 
Optimising Your Content for findability
Optimising Your Content for findabilityOptimising Your Content for findability
Optimising Your Content for findability
 
Cassie findlay
Cassie findlayCassie findlay
Cassie findlay
 
The value of big data analytics
The value of big data analyticsThe value of big data analytics
The value of big data analytics
 
David Reeve - UKAD 2016 forum
David Reeve - UKAD 2016 forumDavid Reeve - UKAD 2016 forum
David Reeve - UKAD 2016 forum
 
Cff data governance best practices
Cff data governance best practicesCff data governance best practices
Cff data governance best practices
 
Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016Intro to Data Loss Prevention in SharePoint 2016
Intro to Data Loss Prevention in SharePoint 2016
 
Information governance presentation
Information governance   presentationInformation governance   presentation
Information governance presentation
 
Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?
Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?
Compliance, Security, Migration, Systems Management – All Fixed by Microsoft?
 
Tips --Break Down the Barriers to Better Data Analytics
Tips --Break Down the Barriers to Better Data AnalyticsTips --Break Down the Barriers to Better Data Analytics
Tips --Break Down the Barriers to Better Data Analytics
 
DC Salesforce1 Tour Data Governance Lunch Best Practices deck
DC Salesforce1 Tour Data Governance Lunch Best Practices deckDC Salesforce1 Tour Data Governance Lunch Best Practices deck
DC Salesforce1 Tour Data Governance Lunch Best Practices deck
 
The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?The Merger is Happening, Now What Do We Do?
The Merger is Happening, Now What Do We Do?
 

More from Everteam

280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux
280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux
280219 Webinar Reprenez le Contrôle de Vos Disques RéseauxEverteam
 
070219 Webinar Sensibilisation Sécurité Logiciel Everteam
070219 Webinar Sensibilisation Sécurité Logiciel Everteam070219 Webinar Sensibilisation Sécurité Logiciel Everteam
070219 Webinar Sensibilisation Sécurité Logiciel EverteamEverteam
 
310119 Webinar Présentation Nouveautés 5.3
310119 Webinar Présentation Nouveautés 5.3310119 Webinar Présentation Nouveautés 5.3
310119 Webinar Présentation Nouveautés 5.3Everteam
 
170119 Webinar Policy & Record Management
170119 Webinar Policy & Record Management170119 Webinar Policy & Record Management
170119 Webinar Policy & Record ManagementEverteam
 
Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...
Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...
Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...Everteam
 
Webinar | Le RGPD en pratique et bien outillé
Webinar | Le RGPD en pratique et bien outilléWebinar | Le RGPD en pratique et bien outillé
Webinar | Le RGPD en pratique et bien outilléEverteam
 
Webinar : Reprenez le contrôle de votre capital informationnel avec Everteam
Webinar : Reprenez le contrôle de votre capital informationnel avec EverteamWebinar : Reprenez le contrôle de votre capital informationnel avec Everteam
Webinar : Reprenez le contrôle de votre capital informationnel avec EverteamEverteam
 
L’ECM, première étape de la transformation digitale des entreprises
L’ECM, première étape de la transformation digitale des entreprisesL’ECM, première étape de la transformation digitale des entreprises
L’ECM, première étape de la transformation digitale des entreprisesEverteam
 
Gouvernance & cycle de vie du document avec Everteam & EI-Technologies
Gouvernance & cycle de vie du document avec Everteam & EI-TechnologiesGouvernance & cycle de vie du document avec Everteam & EI-Technologies
Gouvernance & cycle de vie du document avec Everteam & EI-TechnologiesEverteam
 
GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !
GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !
GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !Everteam
 
Everteam.records Overview: Reduce the Cost and Risk of Managing Your Information
Everteam.records Overview: Reduce the Cost and Risk of Managing Your InformationEverteam.records Overview: Reduce the Cost and Risk of Managing Your Information
Everteam.records Overview: Reduce the Cost and Risk of Managing Your InformationEverteam
 
What Zombies and Hallow’s Eve Have in Common with Records Management
What Zombies and Hallow’s Eve Have in Common with Records ManagementWhat Zombies and Hallow’s Eve Have in Common with Records Management
What Zombies and Hallow’s Eve Have in Common with Records ManagementEverteam
 
Unblock Your Path to the Cloud
Unblock Your Path to the CloudUnblock Your Path to the Cloud
Unblock Your Path to the CloudEverteam
 
Becoming Agile With BPM
Becoming Agile With BPMBecoming Agile With BPM
Becoming Agile With BPMEverteam
 
everteam.ibpms 8.0 Adds Ad Hoc Processing
everteam.ibpms 8.0 Adds Ad Hoc Processingeverteam.ibpms 8.0 Adds Ad Hoc Processing
everteam.ibpms 8.0 Adds Ad Hoc ProcessingEverteam
 
A New BAM Dashboard for everteam.ibpms 8 0
A New BAM Dashboard for everteam.ibpms 8 0A New BAM Dashboard for everteam.ibpms 8 0
A New BAM Dashboard for everteam.ibpms 8 0Everteam
 
Records Governance, Part 3: How to Manage Governance for Any Content Type and...
Records Governance, Part 3: How to Manage Governance for Any Content Type and...Records Governance, Part 3: How to Manage Governance for Any Content Type and...
Records Governance, Part 3: How to Manage Governance for Any Content Type and...Everteam
 
Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?
Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?
Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?Everteam
 
Records Governance, Part 1: Preserve the Value of Your Information
Records Governance, Part 1: Preserve the Value of Your InformationRecords Governance, Part 1: Preserve the Value of Your Information
Records Governance, Part 1: Preserve the Value of Your InformationEverteam
 
Business and Operations Friendly BPM
Business and Operations Friendly BPMBusiness and Operations Friendly BPM
Business and Operations Friendly BPMEverteam
 

More from Everteam (20)

280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux
280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux
280219 Webinar Reprenez le Contrôle de Vos Disques Réseaux
 
070219 Webinar Sensibilisation Sécurité Logiciel Everteam
070219 Webinar Sensibilisation Sécurité Logiciel Everteam070219 Webinar Sensibilisation Sécurité Logiciel Everteam
070219 Webinar Sensibilisation Sécurité Logiciel Everteam
 
310119 Webinar Présentation Nouveautés 5.3
310119 Webinar Présentation Nouveautés 5.3310119 Webinar Présentation Nouveautés 5.3
310119 Webinar Présentation Nouveautés 5.3
 
170119 Webinar Policy & Record Management
170119 Webinar Policy & Record Management170119 Webinar Policy & Record Management
170119 Webinar Policy & Record Management
 
Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...
Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...
Comment retrouver, nettoyer, organiser et gérer l’information dans votre entr...
 
Webinar | Le RGPD en pratique et bien outillé
Webinar | Le RGPD en pratique et bien outilléWebinar | Le RGPD en pratique et bien outillé
Webinar | Le RGPD en pratique et bien outillé
 
Webinar : Reprenez le contrôle de votre capital informationnel avec Everteam
Webinar : Reprenez le contrôle de votre capital informationnel avec EverteamWebinar : Reprenez le contrôle de votre capital informationnel avec Everteam
Webinar : Reprenez le contrôle de votre capital informationnel avec Everteam
 
L’ECM, première étape de la transformation digitale des entreprises
L’ECM, première étape de la transformation digitale des entreprisesL’ECM, première étape de la transformation digitale des entreprises
L’ECM, première étape de la transformation digitale des entreprises
 
Gouvernance & cycle de vie du document avec Everteam & EI-Technologies
Gouvernance & cycle de vie du document avec Everteam & EI-TechnologiesGouvernance & cycle de vie du document avec Everteam & EI-Technologies
Gouvernance & cycle de vie du document avec Everteam & EI-Technologies
 
GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !
GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !
GED, Archivage & Dataroom dans l'immobilier : Carrefour Property témoigne !
 
Everteam.records Overview: Reduce the Cost and Risk of Managing Your Information
Everteam.records Overview: Reduce the Cost and Risk of Managing Your InformationEverteam.records Overview: Reduce the Cost and Risk of Managing Your Information
Everteam.records Overview: Reduce the Cost and Risk of Managing Your Information
 
What Zombies and Hallow’s Eve Have in Common with Records Management
What Zombies and Hallow’s Eve Have in Common with Records ManagementWhat Zombies and Hallow’s Eve Have in Common with Records Management
What Zombies and Hallow’s Eve Have in Common with Records Management
 
Unblock Your Path to the Cloud
Unblock Your Path to the CloudUnblock Your Path to the Cloud
Unblock Your Path to the Cloud
 
Becoming Agile With BPM
Becoming Agile With BPMBecoming Agile With BPM
Becoming Agile With BPM
 
everteam.ibpms 8.0 Adds Ad Hoc Processing
everteam.ibpms 8.0 Adds Ad Hoc Processingeverteam.ibpms 8.0 Adds Ad Hoc Processing
everteam.ibpms 8.0 Adds Ad Hoc Processing
 
A New BAM Dashboard for everteam.ibpms 8 0
A New BAM Dashboard for everteam.ibpms 8 0A New BAM Dashboard for everteam.ibpms 8 0
A New BAM Dashboard for everteam.ibpms 8 0
 
Records Governance, Part 3: How to Manage Governance for Any Content Type and...
Records Governance, Part 3: How to Manage Governance for Any Content Type and...Records Governance, Part 3: How to Manage Governance for Any Content Type and...
Records Governance, Part 3: How to Manage Governance for Any Content Type and...
 
Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?
Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?
Records Governance, Part 2: Can One Solution Manage All Your Archiving Needs?
 
Records Governance, Part 1: Preserve the Value of Your Information
Records Governance, Part 1: Preserve the Value of Your InformationRecords Governance, Part 1: Preserve the Value of Your Information
Records Governance, Part 1: Preserve the Value of Your Information
 
Business and Operations Friendly BPM
Business and Operations Friendly BPMBusiness and Operations Friendly BPM
Business and Operations Friendly BPM
 

Recently uploaded

Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...lizamodels9
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 

Recently uploaded (20)

Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 

Doculabs Everteam houston breakfast 06.29.17 v0.2

  • 1. Information Management, Data Theft, and the Kill Chain Joe Shepley, Doculabs
  • 2. 2 Doculabs, Inc. 2017 Session Objectives • Information security requires defending against what is often the weakest link in the cyberattack kill chain at organizations: data theft • In this session, you'll learn how InfoSec can address the information management risk posed by data theft and drive value for the organization
  • 3. 3 Doculabs, Inc. 2017 Why Information Management is Important to InfoSec • The question of a breach isn’t if, it’s when • When they get in, what will they find? • When they find 5, 10, 15+ years of sensitive data that’s past it’s legal and operational life, InfoSec is on the hook, not (typically) records, legal, or IT • InfoSec needs to address information management to reduce the organization’s risk surface and do their job effectively
  • 4. 4 Doculabs, Inc. 2017 The Kill Chain Historically, data theft has been the weakest link in the Kill Chain, and Chief Information Security Officers (CISOs) are now turning to address it. Research the Organization Introduce Malware Control a Device Find Other Devices to Control Stay or Leave Data Theft Find the Source of the Data
  • 5. 5 Doculabs, Inc. 2017 An Information Management Framework for InfoSec Defensible Content Disposition Playbook Policy Alignment Procedure Alignment Content Cleanup Change Management
  • 6. 6 Doculabs, Inc. 2017 Policy Alignment • You need to align your corporate policies with information management good practices • This alignment ensures that if you’re following the good practices, you’re also following corporate policy • The specifics will differ from organization to organization, but there are some general areas that any policy alignment will need to cover: • Corporate records management policy must address both paper and electronic records • You need to address the security classification of data – e.g. public, internal, confidential, highly confidential • You need to address orphaned and abandoned data
  • 7. 7 Doculabs, Inc. 2017 Procedure Alignment • You need to align your disposition procedures with your policies (and therefore your playbook) • You need to provide detailed, step-by-step guidance for how to disposition data – guidance which, if followed, makes it reasonable for courts or regulatory bodies to assume that the policies (and playbook) are also being followed • You need to be granular – not content disposition, but rather a series of linked procedures to guide your technical resources in content disposition: • E.g. file analytics procedure, disposition procedure, testing procedure, remediation procedure, application decommissioning
  • 8. 8 Doculabs, Inc. 2017 Defensible Content Disposition Playbook • The primary concern in content disposition is getting it right technically • But the legal risks are more critical and potentially more damaging • You need a playbook to memorialize the requirements of the disposition and the results • You need to be able to defend what you did regarding content disposition for the courts or regulators – 5, 10, or 15 years later
  • 9. 9 Doculabs, Inc. 2017 Content Cleanup • For some organizations, cleanup is a standalone effort to purge; for others, it may be part of the preparations for a content migration • You need tools to help in the effort; it’s not reasonable to expect end users to manually comb through their content to purge junk or stale data, or to identify sensitive data that needs to be protected
  • 10. 10 Doculabs, Inc. 2017 Content Cleanup • The results of your repository scan are likely to be something like the following, which we’ve observed at dozens of clients over the last 10 years: • Approximately 30 to 70 percent “junk” content, which can be removed immediately • Approximately 20 to 40 percent stale content (defined as older than 3 years, based on date last accessed), which can be archived or purged, depending on your approach • An estimated 1 to 10 TB of stale sensitive content, which can be quarantined immediately with no operational impact • By classifying your content into these buckets and purging, archiving, etc., you’ll reduce your overall unstructured data footprint significantly (by anywhere from 30 to 90 percent) • Doing so reduces the overall risk posed by your unstructured data, because you have less junk and stale data to distract you, as well as less sensitive data to protect
  • 11. 11 Doculabs, Inc. 2017 Change Management Stakeholder Matrix • Who are the key stakeholders that need to be informed of the change and managed throughout your information management initiative? Communications and Training Matrix • What are the key communications and training events required for managing the changes in information management? • When do these communications and training events need to be delivered, and to whom? • What are the most appropriate vehicles for delivering communications and training to your various stakeholders and user groups? Communications and Training Schedule • When do we need to execute the planned training and communications events?
  • 12. 12 Doculabs, Inc. 2017 So Now What? • Raise awareness in InfoSec about the importance of information management • Articulate the quick win efforts InfoSec can take to reduce junk and stale data, identify sensitive data, and take preliminary steps to protect it – which reduces their risk footprint and shows progress to the C-level, the board, the courts, and regulators
  • 13. 13 Doculabs, Inc. 2017 Thank You • Give me your card to get two Doculabs white papers on the intersection of information management and InfoSec. • Connect with me to continue the conversation: • LinkedIn: https://www.linkedin.com/in/joeshepley/ • Twitter: @joeshepley • Email: jshepley@doculabs.com • Phone: 773.827.2945 I'd love to help you figure out how to partner effectively with your information management team
  • 14. Thank You www.doculabs.comD C U L A B S Joe Shepley jshepley@docuabs.com 773.827.2945

Editor's Notes

  1. Since 2014, InfoSec has become concerned with more than simply building stronger walls The high-profile breaches at organizations such as Target, Home Depot, Premera, Anthem, Sony, and CHS have shown us that the question of a breach is not “if,” but “when” When the bad guys do get in, we need to ensure that the information they find contains as little sensitive data as possible, as little junk and stale data as possible, with access rights as clean as possible