SlideShare a Scribd company logo
1 of 15
In order to have a successful IG program, one of the eight (8)
Information Risk Planning and Management step is to develop
metrics and measure results. From your required readings,
discuss the value that metrics brings to the organization, and
identify critical measures of success that should be tracked
CHAPTER GOALS AND OBJECTIVES
iderations?
2
A Review of the 8 Generally Accepted
Recording Keeping Principles®
1. Accountability
2. Transparency
3. Integrity
4. Protection
5. Compliance
6. Availability
7. Retention
8. Disposition
So…what is the significance of these principles?
3
IG REFERENCE MODEL
➢ Who?
➢ ARMA International & CGOC
➢ When?
➢ 2012
➢ Where?
➢ As part of the EDRM Project Version 3.0
➢ Why?
➢ To foster the adoption by facilitating
communication and collaboration between
IG stakeholder functions, legal, records
management, risk management, and business
unit stakeholders.
4
HOW TO INTERPRET THE IGRM DIAGRAM
Outer Ring: Complex set of interoperable processes
and implementing he procedures and structural
element to put them into practice
➢ Requirements:
➢ Understanding of business imperatives
➢ Knowledge of appropriate tools and infrastructure
➢ Sensitivity to legal and regulatory obligations
Inner Ring: Depicts a work-flow (life-cycle) diagram.
Shows that information management is important at
all stages of the lifecycle
5
How the IGRM Diagram related to the
Generally Accepted Recordkeeping Principles®
➢ Support the ARMA Principle by identifying the cross-
functional groups of IG
stakeholders
➢ Depicts the intersecting objectives of the organization
➢ Depicts the relationship duty, value and information assets
➢ Used by proactive organizations as an introspective lens to
facilitate visualization,
understanding and discussion concerning how to apple the
“Principles” to the
organization.
➢ Puts focus on the “Principles”
➢ Provides essential context for the maturity model
6
Considerations in IG Policy Formation
➢ Best Practices?
➢ YES!
➢ Understand that Best
Practices will vary per
organization
➢ Review 25 generic Best
Practices, Pages 75 and 76
of text book
7
➢ Standards?
➢ YES!
➢ Two types to consider
➢ De Jure Standards - Legal standards published by
standards setting bodies such as IOS, ANSI, NIST, BTS and
others
➢ De Facto Standards – Informal standards regarded by
many as actual standards – arising through popular use
(Example: Windows in the business world in 2001-2010).
May be published by formal standards setting bodies
without having “Formal” status
Benefits and Risks of Standards
Benefits
➢ Quality Assurance Support
➢ Interoperability Support
➢ Implementation Framework and
Certification Checklists
➢ Cost Reduction
➢ International Consensus
8
Risks
➢ Possible Decreased Flexibility
➢ Standards Confusion
➢ Real-World Shortcomings to due Theoretical
Basis
➢ Cost and Maintenance Involving in Updating
Standard
KEY STANDARDS RELEVANT TO IG
Risk Management
➢ ISO 31000-2009 – States principles and generic guidelines of
risk management
applicable to IG
➢ Provides a structured framework for development and
implementation of risk
management strategies and programs
➢ “Risk Management Framework”: Set of two basic components
(foundations
and organizational arrangements) that support and sustain risk
management
throughout the organization.
9
KEY STANDARDS RELEVANT TO IG
Information Security Management
➢ ISO/IEC 27001:2005- Information Security Management
System Standard that provides
guidance in development of security controls for protection of
information assets
➢ Flexible –can be applied to different activities and processes
➢ Includes use of standards by auditors and stakeholders
➢ ISO/IEC 27002:2005-Information Technology-Security
Techniques-Code of Practice for
Information Security
➢ Establishes guidelines and general principle for initiating,
implementing, maintaining and improving
information security mgt.
➢ Includes Best Practices of Control Objectives in 11 key areas
of information security management
➢ ISO/IE 38500:2008 –International Standard for high-level
principle and guidance for senior
executives and directors, and advisors for effective and efficient
use of IT
➢ Three major sections
➢ Scope, Application and Objectives
➢ Framework for Good Corporate Governance of IT
➢ Guidance for Corporate Governance of IT
10
KEY STANDARDS RELEVANT TO IG
RECORDS AND E-RECORDS MANAGEMENT
➢ ISO 15489-1:2001 and ISO 15489-2:2001– International
Standard for Records
Management
➢ Part 1:Provides a framework and high-level overview of RM
core principles
➢ Part 1:Defines RM as “Field of management responsibility
for the efficient and
systematic control of creation receipt, maintenance, use and
disposition of
records, including processes for capturing and maintaining
evidence of and
information about business activities and transactions in the
form of records”1
➢ Part 2: Technical Specifications and Methodology for
implementing standard
➢ ISO 30300;2011 – Information and Documentation-
Management Systems for Records-
Fundamentals and Vocabulary
➢ ISO 30301:2011 – Information and Documentation-
Management Systems for Records –
Requirements
1ISO 15489-1:2001 Information and Documentation-Records
Management, Part 1:General Geneva: ISO, 2001), section 3.16.
11
NATIONAL, INTERNATIONAL AND REGIONAL ERM
STANDARDS
United States E-Records Standard
➢ U.S. DOD 5015.2 Design Criteria Standard For
Electronic Records Management Software
Applications
➢ Developed in 1997
➢ Updated in 2002 and 2007
Canadian Standards
➢ Electronic Records as Documentary Evidence
CAN/CGSB-72.34-2005
➢ Microfilm and Electronic Images as
Documentary Evidence CAN/DGSB-72.11-93
➢ Canadian Legal Considerations
➢ Relies on prime directive-that an
organization shall always be prepared to
produce its records as evidence- and its
national standards, for the admissibility of
electronic records in court proceedings
➢ The admissibility of records as evidence is
determined under the business records
provisions of the Evidence Act
12
NATIONAL, INTERNATIONAL AND REGIONAL ERM
STANDARDS…CONTINUED
United Kingdom
➢ The National Archives
➢ To sets of functions requirements to
promote the development of the
electronic records management
software market (one in 1999 and
one in 2002)
➢ Model Requirements of Electronic
Records
➢ MoReq2
➢ MoReq2010
Australian ERM and Records Management
Standards
➢ Has consistently been world leader in
this area
➢ Adopted all three parts of ISO 16175
as its e-records standard
➢ Australian Government Recordkeeping
Metadata Standard Version 2.0
➢ Australian Government Locator
Service
➢ AS 5090:2003 – Work Process Analysis
for Recordkeeping
13
LONG-TERM DIGITAL PRESERVATION
➢ Referred to as “LTDP”
➢ LTDP is a key area for IG policy
development
➢ Frequently not addressed in an IG plan
➢ Should be applied in preserving
historical and “vital records” and in
order to maintain its corporate or
organizational memory
➢ Key Standards for LTDP:
➢ PDF/A-2 –official standard format
for preserving electronic
documents, developed by Adobe.
➢ ISO 19005-1:2005 Document
Management is the published
specification requiring PDF format
➢ ISO 14721:2012 – Space Data and
Information Transfer Systems –Open
Archival Information Systems
➢ ISO TR 18492(2005) – Long Term
Preservation of Electronic
Document Based Information
➢ ISO 16363:2012 – Space Data and
Information Transfer Systems-Audit
and Certification of Trustworthy
Digital Repositories
14
BUSINESS CONTINUITY MANAGEMENT
➢ ISO 22301:2012 – Societal Security –
Business Continuity Management Systems
Requirements
➢ Specifies requirements for creating and
implementing a standardized approach to
business continuity management ----- this is
also known as Disaster Recovery
Benefits of ISO 22301
➢ Threat Identification and Assessment
➢ Threat and Recovery Planning
➢ Mission-critical process protection
➢ Stakeholder Confidence
15
THINGS TO REMEMBER IN DEVELOPING THE IG
POLICY
goals
sponsor who can garner executive
support for the IG program and
policies
communications and training
component
new policies and practices
relevant and useful and can actually
be measured
upon metrics, tests and audit results
for policy violations and communicate
that to employees
culture
16
The End
17
Topic:
This week's reading centered around how Big Data analytics can
be used with Smart Cities. This is exciting and can provide
many benefits to individuals as well as organizations. For this
week's research assignment, you are to search the Internet for
other uses of Big Data in RADICAL platforms. Please pick an
organization or two and discuss the usage of big data in
RADICAL platforms including how big data analytics is used in
those situations as well as with Smart Cities.
Your paper should meet these requirements:
Be approximately four to six pages in length, not including the
required cover page and reference page.
Follow APA 7 guidelines. Your paper should include an
introduction, a body with fully developed content, and a
conclusion.
Support your answers with the readings from the course and at
least two scholarly journal articles to support your positions,
claims, and observation

More Related Content

Similar to In order to have a successful IG program, one of the eight (8) I

71 Information Governance Policy Development .docx
71 Information Governance Policy Development      .docx71 Information Governance Policy Development      .docx
71 Information Governance Policy Development .docx
sleeperharwell
 
Agile Enterprise architecture.pptx
Agile Enterprise architecture.pptxAgile Enterprise architecture.pptx
Agile Enterprise architecture.pptx
htdvul
 
COBIT® Presentation Package.ppt
COBIT® Presentation Package.pptCOBIT® Presentation Package.ppt
COBIT® Presentation Package.ppt
Emmacuet
 
Digital Records Management & Preservation
Digital Records Management & PreservationDigital Records Management & Preservation
Digital Records Management & Preservation
victor Nduna
 
Compliance Framework
Compliance FrameworkCompliance Framework
Compliance Framework
barnetdh
 

Similar to In order to have a successful IG program, one of the eight (8) I (20)

Introduction to International Standardization
Introduction to International StandardizationIntroduction to International Standardization
Introduction to International Standardization
 
GRC in Australia slides
GRC in Australia slidesGRC in Australia slides
GRC in Australia slides
 
Lecture 06 - CoBit - Control Objectives for Information and Related Technolog...
Lecture 06 - CoBit - Control Objectives for Information and Related Technolog...Lecture 06 - CoBit - Control Objectives for Information and Related Technolog...
Lecture 06 - CoBit - Control Objectives for Information and Related Technolog...
 
Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001
 
71 Information Governance Policy Development .docx
71 Information Governance Policy Development      .docx71 Information Governance Policy Development      .docx
71 Information Governance Policy Development .docx
 
Agile Enterprise architecture.pptx
Agile Enterprise architecture.pptxAgile Enterprise architecture.pptx
Agile Enterprise architecture.pptx
 
how-to-implement-ecm.ppt
how-to-implement-ecm.ppthow-to-implement-ecm.ppt
how-to-implement-ecm.ppt
 
IT Risk assessment and Audit Planning
IT Risk assessment and Audit PlanningIT Risk assessment and Audit Planning
IT Risk assessment and Audit Planning
 
How to implement Electronic Records Management?
How to implement Electronic Records Management?How to implement Electronic Records Management?
How to implement Electronic Records Management?
 
CV jagroop jagpal
CV jagroop jagpalCV jagroop jagpal
CV jagroop jagpal
 
KT-BIM-R08-GP-05-OIR.pptx
KT-BIM-R08-GP-05-OIR.pptxKT-BIM-R08-GP-05-OIR.pptx
KT-BIM-R08-GP-05-OIR.pptx
 
Khas bank isms 3 s
Khas bank isms 3 sKhas bank isms 3 s
Khas bank isms 3 s
 
Governance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 FrameworkGovernance and Management of Enterprise IT with COBIT 5 Framework
Governance and Management of Enterprise IT with COBIT 5 Framework
 
COBIT® Presentation Package.ppt
COBIT® Presentation Package.pptCOBIT® Presentation Package.ppt
COBIT® Presentation Package.ppt
 
Digital Records Management & Preservation
Digital Records Management & PreservationDigital Records Management & Preservation
Digital Records Management & Preservation
 
Iso 27001 isms presentation
Iso 27001 isms presentationIso 27001 isms presentation
Iso 27001 isms presentation
 
Compliance Framework
Compliance FrameworkCompliance Framework
Compliance Framework
 
IHS Regulatory Compliance services
IHS Regulatory Compliance servicesIHS Regulatory Compliance services
IHS Regulatory Compliance services
 
standards1.pdf
standards1.pdfstandards1.pdf
standards1.pdf
 
Course Tech 2013, Dan Shoemaker & Ken Sigler, Engineering a More Secure Softw...
Course Tech 2013, Dan Shoemaker & Ken Sigler, Engineering a More Secure Softw...Course Tech 2013, Dan Shoemaker & Ken Sigler, Engineering a More Secure Softw...
Course Tech 2013, Dan Shoemaker & Ken Sigler, Engineering a More Secure Softw...
 

More from MalikPinckney86

Find a real-life” example of one of the following institutions. Exa.docx
Find a real-life” example of one of the following institutions. Exa.docxFind a real-life” example of one of the following institutions. Exa.docx
Find a real-life” example of one of the following institutions. Exa.docx
MalikPinckney86
 
Final Written Art Project (500 words) carefully and creatively wri.docx
Final Written Art Project (500 words) carefully and creatively wri.docxFinal Written Art Project (500 words) carefully and creatively wri.docx
Final Written Art Project (500 words) carefully and creatively wri.docx
MalikPinckney86
 
Final ProjectThe Final Project should demonstrate an understanding.docx
Final ProjectThe Final Project should demonstrate an understanding.docxFinal ProjectThe Final Project should demonstrate an understanding.docx
Final ProjectThe Final Project should demonstrate an understanding.docx
MalikPinckney86
 
Final ProjectImagine that you work for a health department and hav.docx
Final ProjectImagine that you work for a health department and hav.docxFinal ProjectImagine that you work for a health department and hav.docx
Final ProjectImagine that you work for a health department and hav.docx
MalikPinckney86
 

More from MalikPinckney86 (20)

Find a recent merger or acquisition that has been announced in the.docx
Find a recent merger or acquisition that has been announced in the.docxFind a recent merger or acquisition that has been announced in the.docx
Find a recent merger or acquisition that has been announced in the.docx
 
Find an example of a document that misuses graphics. This can be a d.docx
Find an example of a document that misuses graphics. This can be a d.docxFind an example of a document that misuses graphics. This can be a d.docx
Find an example of a document that misuses graphics. This can be a d.docx
 
Find a scholarly research study from the Ashford University Library .docx
Find a scholarly research study from the Ashford University Library .docxFind a scholarly research study from the Ashford University Library .docx
Find a scholarly research study from the Ashford University Library .docx
 
Find a work of visual art, architecture, or literature from either A.docx
Find a work of visual art, architecture, or literature from either A.docxFind a work of visual art, architecture, or literature from either A.docx
Find a work of visual art, architecture, or literature from either A.docx
 
Find a real-life” example of one of the following institutions. Exa.docx
Find a real-life” example of one of the following institutions. Exa.docxFind a real-life” example of one of the following institutions. Exa.docx
Find a real-life” example of one of the following institutions. Exa.docx
 
Find a listing of expenses by diagnosis or by procedure. The source .docx
Find a listing of expenses by diagnosis or by procedure. The source .docxFind a listing of expenses by diagnosis or by procedure. The source .docx
Find a listing of expenses by diagnosis or by procedure. The source .docx
 
Financial Reporting Problem  and spreedsheet exercise.This is an.docx
Financial Reporting Problem  and spreedsheet exercise.This is an.docxFinancial Reporting Problem  and spreedsheet exercise.This is an.docx
Financial Reporting Problem  and spreedsheet exercise.This is an.docx
 
Find a Cybersecurity-related current event that happned THIS WEEK, a.docx
Find a Cybersecurity-related current event that happned THIS WEEK, a.docxFind a Cybersecurity-related current event that happned THIS WEEK, a.docx
Find a Cybersecurity-related current event that happned THIS WEEK, a.docx
 
Financing Health Care in a Time of Insurance Restructuring Pleas.docx
Financing Health Care in a Time of Insurance Restructuring Pleas.docxFinancing Health Care in a Time of Insurance Restructuring Pleas.docx
Financing Health Care in a Time of Insurance Restructuring Pleas.docx
 
Financing International Trade Please respond to the followingCom.docx
Financing International Trade Please respond to the followingCom.docxFinancing International Trade Please respond to the followingCom.docx
Financing International Trade Please respond to the followingCom.docx
 
Financial Statement Analysis and DisclosuresDiscuss the import.docx
Financial Statement Analysis and DisclosuresDiscuss the import.docxFinancial Statement Analysis and DisclosuresDiscuss the import.docx
Financial Statement Analysis and DisclosuresDiscuss the import.docx
 
Financial Ratios what are the limitations of financial ratios  .docx
Financial Ratios what are the limitations of financial ratios  .docxFinancial Ratios what are the limitations of financial ratios  .docx
Financial Ratios what are the limitations of financial ratios  .docx
 
Financial mangers make decisions today that will affect the firm i.docx
Financial mangers make decisions today that will affect the firm i.docxFinancial mangers make decisions today that will affect the firm i.docx
Financial mangers make decisions today that will affect the firm i.docx
 
Financial Laws and RegulationsComplete an APA formatted 2 page pap.docx
Financial Laws and RegulationsComplete an APA formatted 2 page pap.docxFinancial Laws and RegulationsComplete an APA formatted 2 page pap.docx
Financial Laws and RegulationsComplete an APA formatted 2 page pap.docx
 
Financial Management DiscussionWhen reviewing the financial st.docx
Financial Management DiscussionWhen reviewing the financial st.docxFinancial Management DiscussionWhen reviewing the financial st.docx
Financial Management DiscussionWhen reviewing the financial st.docx
 
Final Written Art Project (500 words) carefully and creatively wri.docx
Final Written Art Project (500 words) carefully and creatively wri.docxFinal Written Art Project (500 words) carefully and creatively wri.docx
Final Written Art Project (500 words) carefully and creatively wri.docx
 
Final Research Paper Research the responsibility of a critical t.docx
Final Research Paper Research the responsibility of a critical t.docxFinal Research Paper Research the responsibility of a critical t.docx
Final Research Paper Research the responsibility of a critical t.docx
 
Financial management homeworkUnit III Financial Planning, .docx
Financial management homeworkUnit III Financial Planning, .docxFinancial management homeworkUnit III Financial Planning, .docx
Financial management homeworkUnit III Financial Planning, .docx
 
Final ProjectThe Final Project should demonstrate an understanding.docx
Final ProjectThe Final Project should demonstrate an understanding.docxFinal ProjectThe Final Project should demonstrate an understanding.docx
Final ProjectThe Final Project should demonstrate an understanding.docx
 
Final ProjectImagine that you work for a health department and hav.docx
Final ProjectImagine that you work for a health department and hav.docxFinal ProjectImagine that you work for a health department and hav.docx
Final ProjectImagine that you work for a health department and hav.docx
 

Recently uploaded

Recently uploaded (20)

Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...Kodo Millet  PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
Kodo Millet PPT made by Ghanshyam bairwa college of Agriculture kumher bhara...
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
 
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptxExploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
Exploring_the_Narrative_Style_of_Amitav_Ghoshs_Gun_Island.pptx
 
Interdisciplinary_Insights_Data_Collection_Methods.pptx
Interdisciplinary_Insights_Data_Collection_Methods.pptxInterdisciplinary_Insights_Data_Collection_Methods.pptx
Interdisciplinary_Insights_Data_Collection_Methods.pptx
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
REMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptxREMIFENTANIL: An Ultra short acting opioid.pptx
REMIFENTANIL: An Ultra short acting opioid.pptx
 
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptxCOMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
COMMUNICATING NEGATIVE NEWS - APPROACHES .pptx
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
Sociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning ExhibitSociology 101 Demonstration of Learning Exhibit
Sociology 101 Demonstration of Learning Exhibit
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17How to Add New Custom Addons Path in Odoo 17
How to Add New Custom Addons Path in Odoo 17
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Fostering Friendships - Enhancing Social Bonds in the Classroom
Fostering Friendships - Enhancing Social Bonds  in the ClassroomFostering Friendships - Enhancing Social Bonds  in the Classroom
Fostering Friendships - Enhancing Social Bonds in the Classroom
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
Beyond_Borders_Understanding_Anime_and_Manga_Fandom_A_Comprehensive_Audience_...
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 

In order to have a successful IG program, one of the eight (8) I

  • 1. In order to have a successful IG program, one of the eight (8) Information Risk Planning and Management step is to develop metrics and measure results. From your required readings, discuss the value that metrics brings to the organization, and identify critical measures of success that should be tracked CHAPTER GOALS AND OBJECTIVES iderations? 2 A Review of the 8 Generally Accepted Recording Keeping Principles® 1. Accountability
  • 2. 2. Transparency 3. Integrity 4. Protection 5. Compliance 6. Availability 7. Retention 8. Disposition So…what is the significance of these principles? 3 IG REFERENCE MODEL ➢ Who? ➢ ARMA International & CGOC ➢ When? ➢ 2012 ➢ Where? ➢ As part of the EDRM Project Version 3.0 ➢ Why? ➢ To foster the adoption by facilitating
  • 3. communication and collaboration between IG stakeholder functions, legal, records management, risk management, and business unit stakeholders. 4 HOW TO INTERPRET THE IGRM DIAGRAM Outer Ring: Complex set of interoperable processes and implementing he procedures and structural element to put them into practice ➢ Requirements: ➢ Understanding of business imperatives ➢ Knowledge of appropriate tools and infrastructure ➢ Sensitivity to legal and regulatory obligations Inner Ring: Depicts a work-flow (life-cycle) diagram. Shows that information management is important at all stages of the lifecycle 5 How the IGRM Diagram related to the
  • 4. Generally Accepted Recordkeeping Principles® ➢ Support the ARMA Principle by identifying the cross- functional groups of IG stakeholders ➢ Depicts the intersecting objectives of the organization ➢ Depicts the relationship duty, value and information assets ➢ Used by proactive organizations as an introspective lens to facilitate visualization, understanding and discussion concerning how to apple the “Principles” to the organization. ➢ Puts focus on the “Principles” ➢ Provides essential context for the maturity model 6 Considerations in IG Policy Formation ➢ Best Practices? ➢ YES! ➢ Understand that Best Practices will vary per
  • 5. organization ➢ Review 25 generic Best Practices, Pages 75 and 76 of text book 7 ➢ Standards? ➢ YES! ➢ Two types to consider ➢ De Jure Standards - Legal standards published by standards setting bodies such as IOS, ANSI, NIST, BTS and others ➢ De Facto Standards – Informal standards regarded by many as actual standards – arising through popular use (Example: Windows in the business world in 2001-2010). May be published by formal standards setting bodies without having “Formal” status Benefits and Risks of Standards
  • 6. Benefits ➢ Quality Assurance Support ➢ Interoperability Support ➢ Implementation Framework and Certification Checklists ➢ Cost Reduction ➢ International Consensus 8 Risks ➢ Possible Decreased Flexibility ➢ Standards Confusion ➢ Real-World Shortcomings to due Theoretical Basis ➢ Cost and Maintenance Involving in Updating Standard KEY STANDARDS RELEVANT TO IG Risk Management
  • 7. ➢ ISO 31000-2009 – States principles and generic guidelines of risk management applicable to IG ➢ Provides a structured framework for development and implementation of risk management strategies and programs ➢ “Risk Management Framework”: Set of two basic components (foundations and organizational arrangements) that support and sustain risk management throughout the organization. 9 KEY STANDARDS RELEVANT TO IG Information Security Management ➢ ISO/IEC 27001:2005- Information Security Management System Standard that provides guidance in development of security controls for protection of information assets ➢ Flexible –can be applied to different activities and processes ➢ Includes use of standards by auditors and stakeholders ➢ ISO/IEC 27002:2005-Information Technology-Security Techniques-Code of Practice for
  • 8. Information Security ➢ Establishes guidelines and general principle for initiating, implementing, maintaining and improving information security mgt. ➢ Includes Best Practices of Control Objectives in 11 key areas of information security management ➢ ISO/IE 38500:2008 –International Standard for high-level principle and guidance for senior executives and directors, and advisors for effective and efficient use of IT ➢ Three major sections ➢ Scope, Application and Objectives ➢ Framework for Good Corporate Governance of IT ➢ Guidance for Corporate Governance of IT 10 KEY STANDARDS RELEVANT TO IG RECORDS AND E-RECORDS MANAGEMENT ➢ ISO 15489-1:2001 and ISO 15489-2:2001– International Standard for Records Management ➢ Part 1:Provides a framework and high-level overview of RM core principles
  • 9. ➢ Part 1:Defines RM as “Field of management responsibility for the efficient and systematic control of creation receipt, maintenance, use and disposition of records, including processes for capturing and maintaining evidence of and information about business activities and transactions in the form of records”1 ➢ Part 2: Technical Specifications and Methodology for implementing standard ➢ ISO 30300;2011 – Information and Documentation- Management Systems for Records- Fundamentals and Vocabulary ➢ ISO 30301:2011 – Information and Documentation- Management Systems for Records – Requirements 1ISO 15489-1:2001 Information and Documentation-Records Management, Part 1:General Geneva: ISO, 2001), section 3.16. 11 NATIONAL, INTERNATIONAL AND REGIONAL ERM STANDARDS United States E-Records Standard ➢ U.S. DOD 5015.2 Design Criteria Standard For Electronic Records Management Software Applications
  • 10. ➢ Developed in 1997 ➢ Updated in 2002 and 2007 Canadian Standards ➢ Electronic Records as Documentary Evidence CAN/CGSB-72.34-2005 ➢ Microfilm and Electronic Images as Documentary Evidence CAN/DGSB-72.11-93 ➢ Canadian Legal Considerations ➢ Relies on prime directive-that an organization shall always be prepared to produce its records as evidence- and its national standards, for the admissibility of electronic records in court proceedings ➢ The admissibility of records as evidence is determined under the business records provisions of the Evidence Act 12 NATIONAL, INTERNATIONAL AND REGIONAL ERM STANDARDS…CONTINUED United Kingdom ➢ The National Archives
  • 11. ➢ To sets of functions requirements to promote the development of the electronic records management software market (one in 1999 and one in 2002) ➢ Model Requirements of Electronic Records ➢ MoReq2 ➢ MoReq2010 Australian ERM and Records Management Standards ➢ Has consistently been world leader in this area ➢ Adopted all three parts of ISO 16175 as its e-records standard ➢ Australian Government Recordkeeping Metadata Standard Version 2.0 ➢ Australian Government Locator Service ➢ AS 5090:2003 – Work Process Analysis for Recordkeeping 13 LONG-TERM DIGITAL PRESERVATION
  • 12. ➢ Referred to as “LTDP” ➢ LTDP is a key area for IG policy development ➢ Frequently not addressed in an IG plan ➢ Should be applied in preserving historical and “vital records” and in order to maintain its corporate or organizational memory ➢ Key Standards for LTDP: ➢ PDF/A-2 –official standard format for preserving electronic documents, developed by Adobe. ➢ ISO 19005-1:2005 Document Management is the published specification requiring PDF format ➢ ISO 14721:2012 – Space Data and Information Transfer Systems –Open Archival Information Systems ➢ ISO TR 18492(2005) – Long Term Preservation of Electronic Document Based Information ➢ ISO 16363:2012 – Space Data and Information Transfer Systems-Audit
  • 13. and Certification of Trustworthy Digital Repositories 14 BUSINESS CONTINUITY MANAGEMENT ➢ ISO 22301:2012 – Societal Security – Business Continuity Management Systems Requirements ➢ Specifies requirements for creating and implementing a standardized approach to business continuity management ----- this is also known as Disaster Recovery Benefits of ISO 22301 ➢ Threat Identification and Assessment ➢ Threat and Recovery Planning ➢ Mission-critical process protection ➢ Stakeholder Confidence 15
  • 14. THINGS TO REMEMBER IN DEVELOPING THE IG POLICY goals sponsor who can garner executive support for the IG program and policies communications and training component new policies and practices relevant and useful and can actually be measured upon metrics, tests and audit results for policy violations and communicate that to employees
  • 15. culture 16 The End 17 Topic: This week's reading centered around how Big Data analytics can be used with Smart Cities. This is exciting and can provide many benefits to individuals as well as organizations. For this week's research assignment, you are to search the Internet for other uses of Big Data in RADICAL platforms. Please pick an organization or two and discuss the usage of big data in RADICAL platforms including how big data analytics is used in those situations as well as with Smart Cities. Your paper should meet these requirements: Be approximately four to six pages in length, not including the required cover page and reference page. Follow APA 7 guidelines. Your paper should include an introduction, a body with fully developed content, and a conclusion. Support your answers with the readings from the course and at least two scholarly journal articles to support your positions, claims, and observation