Home > Ask the Storage Technology Experts > Compliance/data retention strategy Questions & Answers > Sarbanes-Oxley and how it applies to e-mail archiving
Ask The Storage Expert: Questions & Answers
EMAIL THIS

Sarbanes-Oxley and how it applies to e-mail archiving

Mike Casey EXPERT RESPONSE FROM: Mike Casey

Pose a Question
Other Storage Categories
Meet all Storage Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 March 2004
I'm a network administrator with a small community bank in the north east. We're concerned about Sarbanes-Oxley requirements for record retention and how it applies to e-mail archiving. We currently have no archiving solution in place.

Management is proposing the following policy -- tell end users that they're responsible for archiving customer and vendor-related e-mail by BCCing those e-mails to a mailbox we set up on our Exchange server.

I'm concerned about leaving this responsibility up to the end-user. Would the policy proposed cover us for Sarbanes-Oxley regulations or should we look to archive all e-mail incoming/outgoing/internal using a third party product?


BROWSE BY TAG
Data storage management,   Compliance/data retention strategy,   Archive,   Administrative Tools and Strategies,   Data Storage Management,   Data storage compliance and archiving,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Data storage management
Choosing a storage system for data archiving
Green storage best practices control costs, increase energy efficiency
Best practices for using server virtualization in your storage environment
Best practices for effective thin provisioning
Three tips for ensuring a user-friendly email archiving system
Top tips when evaluating a storage automation product
Guidelines for implementing virtualization in your storage infrastructure
The value of easy-to-use SAN storage
Pros and cons of storage capacity management tools
What are the differences between SATA II vs. SATA I?

Compliance/data retention strategy
How can I set up a cost-effective tiered storage strategy?
Where to focus your compliance efforts
CD-ROM vs. DVD for long term storage
Will compliance spell the end of optical storage?
Compliance tools you should be requesting from vendors
Who's going to be responsible for compliance -- vendors or end users?
What compliance means for peripheral storage
Compliance shouldn't limit your choice of technology
Assessing current policies and matching to appropriate HW/SW
Where to put your compliance dollars

Archive
It makes sense to build data archives on a SAN
Solving the backup dilemma

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Sarbanes-Oxley (SOX) increases the regulatory focus on proper record retention and is just one of many good reasons for taking a closer look at archiving. Other reasons include industry-specific regulations, strategies for reducing litigation risks and discovery costs and the operational benefits of an intelligent archiving policy.

Of course, your institution should consult with its legal counsel and accounting professionals for specific advice, including federal, state and local laws and regulations that may apply.

In this context, here are a few points to consider:

  • In general, companies should maintain a complete and accurate business record for internal use and external reporting -- including archived copies of electronic documents and communications such as e-mail.
  • The proposed policy -- making end users responsible for sending selected e-mail messages to an archive mailbox -- depends on the good judgment and consistent behavior of every end user, every day. To provide reasonable assurance of adherence to the policy, the firm would need to make a substantial ongoing investment in training, supervision, monitoring and enforcement.
  • The proposed policy does not guarantee that all relevant e-mail messages will be captured. So the firm could still face substantial risks and costs in the event of litigation discovery or a regulatory request -- e.g., for all messages related to a specific customer, vendor or employee during a 12-month period.
  • A more reliable strategy is to capture and archive all e-mail messages -- incoming, outgoing and internal. This approach provides the strongest assurance that all relevant e-mail messages are being captured and will help increase the confidence of internal and external auditors and regulatory authorities in the integrity of the resulting audit trail.
  • The first step is to assess your archiving needs in light of the regulatory, litigation and business drivers and to develop a records retention and archiving policy that includes e-mail as well as other documents and records. The policy should address what to save, how long to keep it and the required capabilities for protection, security and accessibility. Once you have achieved consensus on the policy, you can move confidently forward to solution architecture, design and implementation.
  • Depending on the number of e-mail users and servers involved, a variety of technical solutions might be appropriate.

  • For a small organization, it might make sense to configure the e-mail server for message journaling, i.e., force it to make a copy of every message that passes through the system and send it to a designated "archive" mailbox. This would at least eliminate the dependence on end-user selection and copying.
  • For a larger organization, a third-party archiving product can provide end-user productivity benefits and infrastructure cost reductions that will help justify the purchase -- in addition to higher levels of archive protection, functionality and accessibility for business and compliance purposes.
  • Ed note: If you would like to read additional compliance articles, opinions and expert advice, make sure to sign-up for our ALERTS on compliance. Click here to sign up. SearchStorage.com also offers alerts on low-cost storage.




    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Search for Data Management Tools and Tiered Storage Reseller Solutions
    TechTarget Storage Media
    Storage Magazine View this month\\'s issue and subscribe today.
    Storage Decisions Apply online for free conference admission.
    SearchStorage.com
    HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts