By Laura Knox, inside sales team leader, DataSource Mobility
In today’s ever challenging economy it’s no surprise that we see technology customers focusing more and more on cost ... and while I am all about getting a bargain and finding the right solution at the right price for my clients, I often find myself explaining that cost does not always equal value.
Much more goes into the concept of value than the upfront purchase price of any solution. You have to think about potential downtime if the equipment breaks, repair costs, replacement if your workers refuse to use the machine because of poor performance, replacement cost if a device fails, upgraded warranty fees (most low cost solutions come with little or no warranty coverage) and the time any IT staff must spend to keep the devices working properly. So, if we are looking at overall value rather than upfront value the emphasis moves from simply finding something cheap to finding something that is high quality.
Now, most people with a healthy knowledge of IT matters already understand that inferior parts and inferior quality plus lack of service are what equal the attractively low price point of generic industry devices – and they are very anxious not to get stuck trying to support devices that will need constant attention and repair - but try explaining this to a person without IT experience who is tasked with finding a top quality solution at a “bargain bin” price and things get tricky.
So, for those of us who are not IT aficionados but need to make smart decisions for the companies we own or are employed by, the question becomes; how do I tell a high quality device from all the other options? Below is a list of questions that I strongly encourage these folks to ask before purchasing any equipment from a potential vendor.
$ vs. ROI vs. TCO
1) What is it made out of?
2) What type of service and support is included in the cost being quoted (and what will you have to pay extra for)?
3) What is the typical lifespan of the device?
4) Are parts and labor outsourced or does the manufacturer actually make the product?
5) Has it passed any level of rugged certification?
6) What is the typical failure rate for the device?
What do you think?
Showing posts with label archive. Show all posts
Showing posts with label archive. Show all posts
Wednesday, May 25, 2011
Friday, May 13, 2011
Make information safekeeping part of your hurricane preparations
Posted by Mark Brousseau
Forecasters at Colorado State University recently announced that the 2011 Atlantic hurricane season will be very active. Before the season starts, it's time for businesses to get ready, while remembering their most valuable asset: information.
"No matter the size of a company, without access to information, clients could be lost and the owner may be at risk for losing the business altogether," said Marshall Stevens, co-owner of Stevens & Stevens Business Records Management, Inc, a Florida-based records management center. "To ensure business continuity, owners should develop a disaster recovery plan to assess how they're storing and managing information. These plans can help keep a business up and running so all business functions could be handled, even without access to your facility or network."
Get prepared by considering the following:
... Location and security of your storage facility – Store information off-site in a location that's been designed to withstand high sustained winds, is located in a non-flood zone, has a secure vault and is also secured with alarms, security cameras and pass codes.
... Accessibility – Be sure you can access your information no matter the time of day or day of week.
... Document back-ups – Whether you make copies or have external hard drives, back-up files of key documents is crucial. Keep back-ups in multiple locations, so if a disaster affects your office, another copy of your information is still available.
... Alternative records storage options – Consider utilizing technology that allows files to be converted to electronic images, which are then hosted on a secure, password-protected website. So, if files are destroyed or you couldn't access your facility, information wouldn't be gone for good.
"Hurricane season can be an uneasy time, but by planning how you'll protect information now, if disaster does strike, you can focus on running your business rather than trying to pick up the pieces after the fact," said Stevens.
How does your company safeguard its information during a hurricane?
Forecasters at Colorado State University recently announced that the 2011 Atlantic hurricane season will be very active. Before the season starts, it's time for businesses to get ready, while remembering their most valuable asset: information.
"No matter the size of a company, without access to information, clients could be lost and the owner may be at risk for losing the business altogether," said Marshall Stevens, co-owner of Stevens & Stevens Business Records Management, Inc, a Florida-based records management center. "To ensure business continuity, owners should develop a disaster recovery plan to assess how they're storing and managing information. These plans can help keep a business up and running so all business functions could be handled, even without access to your facility or network."
Get prepared by considering the following:
... Location and security of your storage facility – Store information off-site in a location that's been designed to withstand high sustained winds, is located in a non-flood zone, has a secure vault and is also secured with alarms, security cameras and pass codes.
... Accessibility – Be sure you can access your information no matter the time of day or day of week.
... Document back-ups – Whether you make copies or have external hard drives, back-up files of key documents is crucial. Keep back-ups in multiple locations, so if a disaster affects your office, another copy of your information is still available.
... Alternative records storage options – Consider utilizing technology that allows files to be converted to electronic images, which are then hosted on a secure, password-protected website. So, if files are destroyed or you couldn't access your facility, information wouldn't be gone for good.
"Hurricane season can be an uneasy time, but by planning how you'll protect information now, if disaster does strike, you can focus on running your business rather than trying to pick up the pieces after the fact," said Stevens.
How does your company safeguard its information during a hurricane?
Tuesday, April 12, 2011
Selling top execs on records management
By Mark Brousseau
Every organization, regardless of industry, needs to have a records management policy, and they must have a records manager. Nonetheless, it can be an uphill climb convincing top managers to embrace records management, Kevin Joerling, senior project manager, records management, Perceptive Software, said yesterday at the company’s Inspire 2011 user conference at the Wynn in Las Vegas.
Records and information management is defined as the systematic control of records and information throughout their lifecycle, encompassing creation, use, storage, retention, and disposition. “Retention is where we find many companies are not doing a very good job – knowing how long to keep documents,” Joerling said
And this is an area where companies can waste a lot of money, Joerling said: For every $1 spent on disk storage, $3 to $8 per megabyte is spent on managing that storage, he explained. “In some cases, companies don’t even realize this,” he said.
Joerling said records and information is more important than ever because it: reduces storage costs; organizations information for quick retrieval; facilitates litigation risk avoidance; helps protect information assets; and ensures compliance with recordkeeping laws and regulations. To this last point, Joerling said records management is a key part of an organization’s commitment to risk mitigation.
“Liability lawsuits are often decided on the basis of old records,” Joerling explained. What’s more, the loss of records can have more devastating consequences than the loss of a plant, Joerling said, noting that some companies based in the World Trade Center during 9/11 went out of business because they didn’t have backup records.
So why don’t more top execs embrace records management?
For starters, most top execs don’t understand records management. “Records management is not mainstream yet,” he said. “It’s not taught in too many colleges or universities, so business managers coming out of school don’t understand it.” Many organizations also don’t have a records management professional. “Who’s going to be that champion in your company to go to senior management and say ‘We need to look into this because we could get in trouble by not doing it?’” Joerling asked.
Additionally, records and information management benefits can be difficult to quantify. With tight budgets as a result of the recession, this makes it more difficult to persuade senior management about records and information management.
Joerling offered tips for selling top execs on the need for records management:
1. Describe how records management will solve issues facing your organization.
2. Propose a recommended solution, whether it’s hiring a records manager or records management consultant.
3. Detail what will happen if a records management program is not undertaken.
4. Explain when the records management program will be deployed, and how much money, how much time and how many people will be needed for the program.
5. Keep the discussions at a high level and targeted to c-level core concerns, such as how the program ties into the company’s strategic plan.
“It’s an uphill battle because you’re dealing with something that a lot of executives don’t understand and don’t recognize why it needs to be done,” Joerling admitted. But with the growing importance of records and information management, it’s critical that document professionals convince top execs on the need for a program.
What do you think?
Every organization, regardless of industry, needs to have a records management policy, and they must have a records manager. Nonetheless, it can be an uphill climb convincing top managers to embrace records management, Kevin Joerling, senior project manager, records management, Perceptive Software, said yesterday at the company’s Inspire 2011 user conference at the Wynn in Las Vegas.
Records and information management is defined as the systematic control of records and information throughout their lifecycle, encompassing creation, use, storage, retention, and disposition. “Retention is where we find many companies are not doing a very good job – knowing how long to keep documents,” Joerling said
And this is an area where companies can waste a lot of money, Joerling said: For every $1 spent on disk storage, $3 to $8 per megabyte is spent on managing that storage, he explained. “In some cases, companies don’t even realize this,” he said.
Joerling said records and information is more important than ever because it: reduces storage costs; organizations information for quick retrieval; facilitates litigation risk avoidance; helps protect information assets; and ensures compliance with recordkeeping laws and regulations. To this last point, Joerling said records management is a key part of an organization’s commitment to risk mitigation.
“Liability lawsuits are often decided on the basis of old records,” Joerling explained. What’s more, the loss of records can have more devastating consequences than the loss of a plant, Joerling said, noting that some companies based in the World Trade Center during 9/11 went out of business because they didn’t have backup records.
So why don’t more top execs embrace records management?
For starters, most top execs don’t understand records management. “Records management is not mainstream yet,” he said. “It’s not taught in too many colleges or universities, so business managers coming out of school don’t understand it.” Many organizations also don’t have a records management professional. “Who’s going to be that champion in your company to go to senior management and say ‘We need to look into this because we could get in trouble by not doing it?’” Joerling asked.
Additionally, records and information management benefits can be difficult to quantify. With tight budgets as a result of the recession, this makes it more difficult to persuade senior management about records and information management.
Joerling offered tips for selling top execs on the need for records management:
1. Describe how records management will solve issues facing your organization.
2. Propose a recommended solution, whether it’s hiring a records manager or records management consultant.
3. Detail what will happen if a records management program is not undertaken.
4. Explain when the records management program will be deployed, and how much money, how much time and how many people will be needed for the program.
5. Keep the discussions at a high level and targeted to c-level core concerns, such as how the program ties into the company’s strategic plan.
“It’s an uphill battle because you’re dealing with something that a lot of executives don’t understand and don’t recognize why it needs to be done,” Joerling admitted. But with the growing importance of records and information management, it’s critical that document professionals convince top execs on the need for a program.
What do you think?
Inspire 2011 kicks off in Las Vegas

By Mark Brousseau
More than 900 document automation professionals have descended upon Las Vegas this week for Perceptive Software’s Inspire 2011 user conference at the Wynn.
This is the fifth year that Perceptive Software has held its Inspire event.
The attendance at this year’s Inspire user conference is a record, Jeremy McNeive, Perceptive Software’s public relations manager told me yesterday, topping the crowd of about 700 that attended Inspire 2010 in Kansas City. McNeive attributes the growth to the improving economy, the continuing pressure within organizations to improve efficiency, and the value that end-users perceive from the content. For instance, yesterday’s keynote address on the state of the company by Perceptive Software President and CEO Scott Coons was “very well received,” McNeive said.
Inspire 2011 includes more than 60 educational sessions (more than ever before at an Inspire event), with learning tracks dedicated to higher education, healthcare, financial services, the back-office, and product and platform information. There also is a large resource center where end-users can try out Perceptive Software products and get answers to technical and product questions from the company’s experts.
Eight of Perceptive Software’s partners also are exhibiting at the event: Lexmark (Perceptive Software’s parent company), Fujitsu, Napersoft, Scanning America, CSP Group, Docucon, Global Information Distribution, and HyBridge Solutions. Many of these partners provide various components for Perceptive Software’s solutions.
One of the hot topics among attendees is the anticipated release next year of ImageNow 6.7, which will offer “a little bit of everything” for end-users, McNeive said, including records information management and foldering capabilities. It will help end-users move towards collaboration in an even bigger way, McNeive added.
“There is lots of energy here and lots of excitement,” McNeive concluded.
Monday, March 28, 2011
The intelligent archive — going beyond intelligent capture
By Wendi Klein, director, marketing & communications, North America, for A2iA
Regardless of your industry of focus, you are sure to have heard the word archive. But what does archive really mean? And does it mean the same thing to you as it does to the person in the next office? Is an archive just a repository where documents are stored, never to be found again? Or is an archive something that can actually provide a benefit, or even better, a measurable ROI?
Because of the high demand for timely record retrieval, organizations both large and small need to look to a content management system that will enable them to securely and accurately store their records with as much information as possible so that the documents can be recalled quickly, creating an intelligent archive. This involves utilizing technology that can locate and recognize varying writing styles or mixed document-types and layouts so that once digital, the information can be searched, with keywords or phrases identified for fast retrieval.
Considering that documents are being imaged, how do you then make the documents intelligent —meaning searchable and reportable — and the archive a beneficial tool for the organization? Data capture and routing is critical, although not an easy feat for most recognition technologies and something that requires advanced capabilities — beyond simple rules-based classification or common OCR or ICR.
Great strides have been made in the ability to automatically locate, extract, search, and index data from electronic documents including those of an unstructured format. Technology now allows digitized documents to be analyzed and indexed on a holistic or transaction level in relation to one another, as well as by their geometric layout and content characteristics. The documents can then be searched for pre-defined elements or keywords and, in addition to being archived, the results may be incorporated into pre-existing discovery, redaction, declassification, or document management systems thus providing unparalleled access to the information.
Users maintain privacy and adhere to compliance regulations, as complex and handwritten documents are no longer a bottleneck requiring manual processing. Advanced technologies make a significant difference in the efficiency of the tasks that were previously performed by hand, by allowing the processes to become automated from initial capture through to archive.
Many still believe that unstructured or complex documents can only be keyed and, given the demands of today’s market, any automated solution must be at least as error-free as the manual processes it replaces. However, accuracy is equally as important as successful discovery, due diligence, compliance, and declassification — features found in today’s more advanced recognition and classification engines.
Additionally, those looking to implement such an archiving solution must also examine the definition of and metrics around success. The question should not only be, “What is the read rate?” but also, “How much can be automated, how much time can be saved, how much manual labor can be eliminated, and how robust and comprehensive of a database can be built for search?” The ROI produced for organizations adopting this technology is not only seen in terms of a savings on their bottom line, but also in terms of the time saved through newly realized efficiencies. And once scanned, complex data that was automatically located and extracted can be entered into the IT system and more quickly distributed to those that need it, as well as indexed for archive and retrieval based on complex queries within the newly built database. This increase in accessible and searchable information from a central repository not only speeds knowledge distribution, but it elevates the organization’s global intelligence.
With new regulations and the continued movement towards the paperless office, organizations must consider more than just how to get their documents into electronic format, but what they will do once these documents are scanned. By utilizing the right tools for capturing all data and indexing all documents, an archive can easily make the transition to intelligent archive.
What do you think?
Regardless of your industry of focus, you are sure to have heard the word archive. But what does archive really mean? And does it mean the same thing to you as it does to the person in the next office? Is an archive just a repository where documents are stored, never to be found again? Or is an archive something that can actually provide a benefit, or even better, a measurable ROI?
Because of the high demand for timely record retrieval, organizations both large and small need to look to a content management system that will enable them to securely and accurately store their records with as much information as possible so that the documents can be recalled quickly, creating an intelligent archive. This involves utilizing technology that can locate and recognize varying writing styles or mixed document-types and layouts so that once digital, the information can be searched, with keywords or phrases identified for fast retrieval.
Considering that documents are being imaged, how do you then make the documents intelligent —meaning searchable and reportable — and the archive a beneficial tool for the organization? Data capture and routing is critical, although not an easy feat for most recognition technologies and something that requires advanced capabilities — beyond simple rules-based classification or common OCR or ICR.
Great strides have been made in the ability to automatically locate, extract, search, and index data from electronic documents including those of an unstructured format. Technology now allows digitized documents to be analyzed and indexed on a holistic or transaction level in relation to one another, as well as by their geometric layout and content characteristics. The documents can then be searched for pre-defined elements or keywords and, in addition to being archived, the results may be incorporated into pre-existing discovery, redaction, declassification, or document management systems thus providing unparalleled access to the information.
Users maintain privacy and adhere to compliance regulations, as complex and handwritten documents are no longer a bottleneck requiring manual processing. Advanced technologies make a significant difference in the efficiency of the tasks that were previously performed by hand, by allowing the processes to become automated from initial capture through to archive.
Many still believe that unstructured or complex documents can only be keyed and, given the demands of today’s market, any automated solution must be at least as error-free as the manual processes it replaces. However, accuracy is equally as important as successful discovery, due diligence, compliance, and declassification — features found in today’s more advanced recognition and classification engines.
Additionally, those looking to implement such an archiving solution must also examine the definition of and metrics around success. The question should not only be, “What is the read rate?” but also, “How much can be automated, how much time can be saved, how much manual labor can be eliminated, and how robust and comprehensive of a database can be built for search?” The ROI produced for organizations adopting this technology is not only seen in terms of a savings on their bottom line, but also in terms of the time saved through newly realized efficiencies. And once scanned, complex data that was automatically located and extracted can be entered into the IT system and more quickly distributed to those that need it, as well as indexed for archive and retrieval based on complex queries within the newly built database. This increase in accessible and searchable information from a central repository not only speeds knowledge distribution, but it elevates the organization’s global intelligence.
With new regulations and the continued movement towards the paperless office, organizations must consider more than just how to get their documents into electronic format, but what they will do once these documents are scanned. By utilizing the right tools for capturing all data and indexing all documents, an archive can easily make the transition to intelligent archive.
What do you think?
Labels:
A2iA,
archive,
Branch Capture,
data capture,
ICR,
intelligent capture,
IT,
Mark Brousseau,
OCR,
TAWPI
Thursday, March 24, 2011
Government e-discovery trends
Posted by Mark Brousseau
The chief information officer increasingly is joining the chief council in setting e-Discovery strategy within government organizations. That's according to a survey by USIS, an Altegrity company, conducted among government leaders from the federal e-Discovery community.
Among the other findings of the survey:
• Information management, data collection, and producing discoverable results in a timely manner are major concerns.
• More than one-third of respondents said the preservation and collection stage of electronic data discovery (EDD) needs the most improvement.
• Organizations that place a strong emphasis on the EDD process and strategy tend to have better e-Discovery processes.
• Among respondents whose organizations do not place an emphasis on the EDD process, not a single one reported being satisfied with their e-Discovery process.
“This survey reinforces how important it is to have good information management practices in place for the e-Discovery program and the burden it can place on a team when those practices simply aren’t there,” notes Michael Santelli, president of USIS’ Information Management Division (LABAT). “Being proactive about managing data can also save money. It is not uncommon to hear that the cost of one litigation would have paid for the technology and services to better manage the data.”
What do you think?
The chief information officer increasingly is joining the chief council in setting e-Discovery strategy within government organizations. That's according to a survey by USIS, an Altegrity company, conducted among government leaders from the federal e-Discovery community.
Among the other findings of the survey:
• Information management, data collection, and producing discoverable results in a timely manner are major concerns.
• More than one-third of respondents said the preservation and collection stage of electronic data discovery (EDD) needs the most improvement.
• Organizations that place a strong emphasis on the EDD process and strategy tend to have better e-Discovery processes.
• Among respondents whose organizations do not place an emphasis on the EDD process, not a single one reported being satisfied with their e-Discovery process.
“This survey reinforces how important it is to have good information management practices in place for the e-Discovery program and the burden it can place on a team when those practices simply aren’t there,” notes Michael Santelli, president of USIS’ Information Management Division (LABAT). “Being proactive about managing data can also save money. It is not uncommon to hear that the cost of one litigation would have paid for the technology and services to better manage the data.”
What do you think?
Labels:
AIIM,
archive,
data capture,
data management,
data storage,
document imaging,
e-discovery,
ecm,
Mark Brousseau,
page scanning,
TAWPI
Monday, January 17, 2011
Leveraging MFPs to drive process improvements
Posted by Mark Brousseau
Multi-function printers (MFPs) – devices that can print, fax, copy and scan documents – continue to experience tremendous growth, Daniel Schmidt, product marketing manager, Kofax, told attendees at Kofax Transform 2011 Americas this morning in San Diego.
Schmidt cited statistics from IDC that the MFP market grew by 18 and 22 percent last year, representing a total market of 13 million MFP devices, compared to just 800,000 document scanners.
Despite this tremendous growth, most organizations have an opportunity to further reduce their operations costs by leveraging and extending MFPs as part of their business processes, Schmidt said.
Realizing these costs savings, Schmidt said, are as easy as 1-2-3:
1. Consolidate control of MFPs.
2. Leverage MFPs for distributed scanning.
3. Integrate MFPs into a scan-to-process initiative.
Consolidate
At most organizations, MFPs are fax-enabled via individual telephone lines, Roman Swoboda, vice president, business communications, Kofax told attendees. In cases where a company has thousands of deployed MFPs – possibly across the globe – this means thousands of individual telephone lines.
Swoboda said this type of MFP deployment creates a number of issues, including the tremendous costs associated with the individual phone lines (a single line costs up to $500, Swoboda noted), the lack of document tracking and archival, and the limited security over who can send faxes and where.
“A better approach is to connect the MFPs to a centralized infrastructure where faxes are sent in a consolidated and very structured way,” Swoboda said. This offers a number of advantages, including improved tracking and compliance, lower costs (fewer “trunk lines”), and the ability to leverage a consolidated platform. One company that consolidated its MFP infrastructure was able to eliminate up to two-thirds of its analog lines, delivering payback in six to eight months, Swoboda said.
Optimize
Another opportunity for improving MFP deployments is to extend the process to create searchable PDFs, as well as documents that can be archived. Schmidt suggested companies scan documents in remote offices and send them to a central archive. This reduces the costs of transporting documents between locations, eliminates the opportunity for lost document, improves information security, and enables the end-user to leverage all of the benefits of data capture, including bar code recognition.
Integrate
To maximize their MFP deployments, organizations should integrate the devices with their business processes. Schmidt said this approach can reduce processing time from days to minutes, in turn, providing more timely information that can enhance customer service. It also lowers processing costs, including labor and shipping costs; creates an audit trail for tracking documents end-to-end and improving compliance efforts; and improves security, providing complete document control.
What do you think?
Multi-function printers (MFPs) – devices that can print, fax, copy and scan documents – continue to experience tremendous growth, Daniel Schmidt, product marketing manager, Kofax, told attendees at Kofax Transform 2011 Americas this morning in San Diego.
Schmidt cited statistics from IDC that the MFP market grew by 18 and 22 percent last year, representing a total market of 13 million MFP devices, compared to just 800,000 document scanners.
Despite this tremendous growth, most organizations have an opportunity to further reduce their operations costs by leveraging and extending MFPs as part of their business processes, Schmidt said.
Realizing these costs savings, Schmidt said, are as easy as 1-2-3:
1. Consolidate control of MFPs.
2. Leverage MFPs for distributed scanning.
3. Integrate MFPs into a scan-to-process initiative.
Consolidate
At most organizations, MFPs are fax-enabled via individual telephone lines, Roman Swoboda, vice president, business communications, Kofax told attendees. In cases where a company has thousands of deployed MFPs – possibly across the globe – this means thousands of individual telephone lines.
Swoboda said this type of MFP deployment creates a number of issues, including the tremendous costs associated with the individual phone lines (a single line costs up to $500, Swoboda noted), the lack of document tracking and archival, and the limited security over who can send faxes and where.
“A better approach is to connect the MFPs to a centralized infrastructure where faxes are sent in a consolidated and very structured way,” Swoboda said. This offers a number of advantages, including improved tracking and compliance, lower costs (fewer “trunk lines”), and the ability to leverage a consolidated platform. One company that consolidated its MFP infrastructure was able to eliminate up to two-thirds of its analog lines, delivering payback in six to eight months, Swoboda said.
Optimize
Another opportunity for improving MFP deployments is to extend the process to create searchable PDFs, as well as documents that can be archived. Schmidt suggested companies scan documents in remote offices and send them to a central archive. This reduces the costs of transporting documents between locations, eliminates the opportunity for lost document, improves information security, and enables the end-user to leverage all of the benefits of data capture, including bar code recognition.
Integrate
To maximize their MFP deployments, organizations should integrate the devices with their business processes. Schmidt said this approach can reduce processing time from days to minutes, in turn, providing more timely information that can enhance customer service. It also lowers processing costs, including labor and shipping costs; creates an audit trail for tracking documents end-to-end and improving compliance efforts; and improves security, providing complete document control.
What do you think?
Labels:
archive,
bar code,
compliance,
document automation,
document management,
document scanning,
ICR,
Kofax,
Mark Brousseau,
MFPs,
OCR,
page scanning,
TAWPI
Monday, November 22, 2010
Data: Lost or Misplaced?
By Rich Walsh
In taking a look at the Kroll Ontrack “Global Data Loss Causes” survey, I found it interesting that 90 percent of responders have lost data, and 18 percent did not know how the data went missing. Mind you, these losses could be attributed to such occurrences as data that has been corrupted by a virus or just human error – files being misfiled or accidentally deleted. But, I immediately thought, “Perhaps it wasn’t lost; it just couldn’t be found.”
Having written and spoken about data storage for years, one theme has remained constant: the amount of data that corporations must manage is growing and shows no signs of stopping. Keeping track of this mass of data is a daunting challenge for many companies.
I often hear from IT executives that they are frustrated by the multitude of archiving systems at their organizations as more and more repositories are installed to meet data growth. Misplacing data becomes very plausible, and even typical, in this type of environment.
Losing data is never a good thing and when it happens, whether in a household or at a major corporation, it can create some headaches – to put it mildly. In the current environment, losing data is simply not an option as new regulations are sure to put more demands on data recovery. The consequences for missing data can be severe; you only need to read the mortgage-foreclosure headlines to get a sense of this.
Storage professionals may be feeling pressure from IT executives to fix the problem while managing costs. Data management should not be an obstacle to a corporation’s primary business objective. Now is the ideal time to address this issue because there is no apparent end in sight for the onslaught of data.
How is your company handling the barrage?
Rich Walsh is President, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.
In taking a look at the Kroll Ontrack “Global Data Loss Causes” survey, I found it interesting that 90 percent of responders have lost data, and 18 percent did not know how the data went missing. Mind you, these losses could be attributed to such occurrences as data that has been corrupted by a virus or just human error – files being misfiled or accidentally deleted. But, I immediately thought, “Perhaps it wasn’t lost; it just couldn’t be found.”
Having written and spoken about data storage for years, one theme has remained constant: the amount of data that corporations must manage is growing and shows no signs of stopping. Keeping track of this mass of data is a daunting challenge for many companies.
I often hear from IT executives that they are frustrated by the multitude of archiving systems at their organizations as more and more repositories are installed to meet data growth. Misplacing data becomes very plausible, and even typical, in this type of environment.
Losing data is never a good thing and when it happens, whether in a household or at a major corporation, it can create some headaches – to put it mildly. In the current environment, losing data is simply not an option as new regulations are sure to put more demands on data recovery. The consequences for missing data can be severe; you only need to read the mortgage-foreclosure headlines to get a sense of this.
Storage professionals may be feeling pressure from IT executives to fix the problem while managing costs. Data management should not be an obstacle to a corporation’s primary business objective. Now is the ideal time to address this issue because there is no apparent end in sight for the onslaught of data.
How is your company handling the barrage?
Rich Walsh is President, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.
Friday, November 12, 2010
The Top 5 Compliance Issues That Smolder Beneath The Surface
By Dan Wilhelms
When firefighters arrive at a burning building, their first priority (of course) is to knock down the visible flames. Yet experienced firefighters know that when those flames are extinguished, the job isn’t done yet. That’s the time they go in and start looking for the hidden flames – the smoldering materials in a ceiling or behind a wall that could suddenly erupt and engulf them when they’re not expecting it. They know those hidden fires can be the most dangerous of all simply because they can’t be seen until it’s too late.
For the past few years, IT and compliance managers have been like those firefighters first arriving on the scene. You’ve been putting out the compliance fires – the big issues that have been burning brightly since SOX legislation was passed in the early part of the millennium. You’ve done a good job too, creating a new compliance structure where roles are defined, segregation of duties (SOD) is the standard and transactions are well-documented.
Yet just like those firefighters, the job isn’t finished yet. There are still all kinds of compliance issues that, while not as visible as the first ones you tackled, can still create a back-draft that will burn your organization if you’re not careful. Following are five of the most pressing (and potentially dangerous).
Excessive access – With the complexity of the security architecture that is part of modern ERP systems, it’s easier than you might think to accidentally give some users access to potentially sensitive transactions that might be far outside their job descriptions. Access is usually assigned by the help desk, and in the heat of battle, with many pressing issues, they may not be as careful about assigning or double-checking authorizations as they should be. When that occurs, it can lead to all types of dangers.
Imagine a parts picker in the warehouse being given access to every SAP transaction in the organization (which has happened, by the way). In that instance, the warehouse worker started running and looking at transactions (including financial transactions) just out of curiosity. But what if he’d had a different agenda? He could have changed the data, either accidentally or maliciously, or executed a fraudulent transaction, creating a serious compliance breech.
Even if he didn’t change anything, there’s still a productivity issue. After all, if he’s busy running a myriad of SAP transactions, he’s not busy picking orders.
Excessive access is not the type of issue that will show up in a SOD report. The best way to address it is by installing governance, risk and compliance (GRC) software that makes managing security and authorization easier. The software should also provide you with tools that help you measure and monitor actual system usage so you can see whether the things users are doing and the places they’re going within the system are appropriate to their job requirements. Having automated systems in place is particularly important in smaller enterprises that usually do not have the resources for a lot of manual inspection.
Access to sensitive data – Users don’t necessarily need access to a broad variety of data to pose a risk; they just need access to particular data. For example who can open and close posting periods. Who can view HR salary and benefits information? Again, this is nothing that is likely to show up on a SOD report, yet it’s a very real risk.
We’ve all heard the stories about how a certain soft drink manufacturer’s formula is better-guarded than the launch codes for nuclear weapons. Imagine if the formula was sitting on the ERP system and the wrong person was given access to it – or given access to payroll, HIPAA or other sensitive information.
One key to controlling access to sensitive data, of course, is to exercise more care when assigning authorizations. This is called preventative controls. It’s also important to use reverse business engineering tools to see who does have access to sensitive transactions, whether that access is appropriate, and what they did with the information once they had it. This is called detective controls. It’s like following the smoke to discover where the hidden fire is.
Poor segregation of duties – Although SOD has already been mentioned, some organizations are not familiar with what it is and its purpose. Let’s look at the nuclear missiles analogy again. In order to launch, there are two keys controlled by two different people. Two keys are used to assure that no one person has control of the missiles in case someone decides to “go rogue.”
It’s the same with financial transactions in an enterprise. You don’t want one person to be able to create a vendor in your SAP system and then initiate payment of that same vendor; you’re just asking people to steal from you.
That’s why it’s important to have value-added tools that analyze user access against the enterprise’s SOD rulebook and flag any conflicting functions. An ongoing analysis will point out any areas of risk so they can be remediated, and keep you informed should the situation change.
Of course, in a smaller organization, conflicting duties may not be avoidable. Everyone is expected to wear multiple hats, and sometimes those hats do not allow for proper segregation. In those instances, you need to have tools that can monitor actual transactions and report against them so you can see if a compliance violation is occurring. In other words, if someone has to carry both keys, you know when they’ve inserted them both into the control panel through mitigating controls.
Even with the proper tools, it’s unlikely you’ll ever bring SOD conflicts down to zero. But you can get awfully darned close, and keep an eye on what happens from there.
Introduction of malicious programs into production systems – The modern reality is that ERP systems are rarely steady state. Often enterprises have multiple initiatives going on that introduce new data, configuration and programs into the production systems.
With lean staffing and urgent deadlines, often changes are not properly tested or audited. In other words, they don’t use proper change management. A developer who has the means to do it, the motive to do it and knows whether he/she can get away with it can wreak all kinds of havoc by including malicious code along with legitimate code when new applications are moved into production. Malicious code can download sensitive data, create fraudulent transactions, delete data or crash the systems.
It is critical to have a second person reviewing any changes at every step of the way. What that means is the person who requests the change can’t be the person who develops it; the developer can’t be the person who tests it; the person who tests it can’t be the same person who migrates it into production. In other words, transport development and approvals cannot be given by a single person – instead, an independent approver or even a committee must be controlling the entire process.
Change management duties need to be segregated and managed throughout the entire process. Even if not malicious, poorly coded, untested programs can result in a catastrophic outage. Given that in a large enterprise an hour of downtime can cost $1 million, it’s easy to see why proper change management is worth the investment.
Emergency access – In large ERP environments, there’s always the chance that emergency maintenance of production systems will need to be performed. When it does, and the enterprise is dialing 9-1-1, someone needs to be given emergency “super user” access to everything in the system. Such emergency maintenance is often by outside parties (e.g. the software vender or 3rd party consultants).
The problem is these emergency all-access passes aren’t always tracked very well. Everyone is so fixed on putting out the fire – for example unlocking a sales order that has frozen the entire system – that they never think about documenting what transactions were performed or what data was changed. The risk is increased by the widespread use of generic “firefighter” user IDs whereby the individual performing the actions isn’t definitively known.
You’d like to think that the person you give super user access to can be trusted. But blind trust is what has gotten other enterprises into trouble in the past. The person with full access may make other changes while he/she is in there – either accidentally or on purpose. You need to be able to monitor who has all-access and what they do while they have it.
It is critical to have tools that allow you to track what these super-users do while they’re in the system. Not just for the day-to-day operation of the business, but for the auditors as well. When auditors see someone has been given this additional emergency access, their job is to immediately assume the person did something nefarious. It will be your job to prove they didn’t. You’ll need to show why access was granted, what was done while the person was in there, when/how long the person was in the system, what changes were made and when the person exited.
While it’s important to put out the big compliance blazes, keep in mind those are the ones that are also easy to see. Once they’re under control, take a tip from the professional firefighters and be sure to check for the smaller, smoldering flashpoints. It’s your best insurance against getting burned.
Dan Wilhelms is President and CEO of SymSoft Corporation (www.controlpanelGRC.com, the makers of ControlPanelGRC, professional solutions for compliance automation. He can be reached at dwilhelms@sym-corp.com.
When firefighters arrive at a burning building, their first priority (of course) is to knock down the visible flames. Yet experienced firefighters know that when those flames are extinguished, the job isn’t done yet. That’s the time they go in and start looking for the hidden flames – the smoldering materials in a ceiling or behind a wall that could suddenly erupt and engulf them when they’re not expecting it. They know those hidden fires can be the most dangerous of all simply because they can’t be seen until it’s too late.
For the past few years, IT and compliance managers have been like those firefighters first arriving on the scene. You’ve been putting out the compliance fires – the big issues that have been burning brightly since SOX legislation was passed in the early part of the millennium. You’ve done a good job too, creating a new compliance structure where roles are defined, segregation of duties (SOD) is the standard and transactions are well-documented.
Yet just like those firefighters, the job isn’t finished yet. There are still all kinds of compliance issues that, while not as visible as the first ones you tackled, can still create a back-draft that will burn your organization if you’re not careful. Following are five of the most pressing (and potentially dangerous).
Excessive access – With the complexity of the security architecture that is part of modern ERP systems, it’s easier than you might think to accidentally give some users access to potentially sensitive transactions that might be far outside their job descriptions. Access is usually assigned by the help desk, and in the heat of battle, with many pressing issues, they may not be as careful about assigning or double-checking authorizations as they should be. When that occurs, it can lead to all types of dangers.
Imagine a parts picker in the warehouse being given access to every SAP transaction in the organization (which has happened, by the way). In that instance, the warehouse worker started running and looking at transactions (including financial transactions) just out of curiosity. But what if he’d had a different agenda? He could have changed the data, either accidentally or maliciously, or executed a fraudulent transaction, creating a serious compliance breech.
Even if he didn’t change anything, there’s still a productivity issue. After all, if he’s busy running a myriad of SAP transactions, he’s not busy picking orders.
Excessive access is not the type of issue that will show up in a SOD report. The best way to address it is by installing governance, risk and compliance (GRC) software that makes managing security and authorization easier. The software should also provide you with tools that help you measure and monitor actual system usage so you can see whether the things users are doing and the places they’re going within the system are appropriate to their job requirements. Having automated systems in place is particularly important in smaller enterprises that usually do not have the resources for a lot of manual inspection.
Access to sensitive data – Users don’t necessarily need access to a broad variety of data to pose a risk; they just need access to particular data. For example who can open and close posting periods. Who can view HR salary and benefits information? Again, this is nothing that is likely to show up on a SOD report, yet it’s a very real risk.
We’ve all heard the stories about how a certain soft drink manufacturer’s formula is better-guarded than the launch codes for nuclear weapons. Imagine if the formula was sitting on the ERP system and the wrong person was given access to it – or given access to payroll, HIPAA or other sensitive information.
One key to controlling access to sensitive data, of course, is to exercise more care when assigning authorizations. This is called preventative controls. It’s also important to use reverse business engineering tools to see who does have access to sensitive transactions, whether that access is appropriate, and what they did with the information once they had it. This is called detective controls. It’s like following the smoke to discover where the hidden fire is.
Poor segregation of duties – Although SOD has already been mentioned, some organizations are not familiar with what it is and its purpose. Let’s look at the nuclear missiles analogy again. In order to launch, there are two keys controlled by two different people. Two keys are used to assure that no one person has control of the missiles in case someone decides to “go rogue.”
It’s the same with financial transactions in an enterprise. You don’t want one person to be able to create a vendor in your SAP system and then initiate payment of that same vendor; you’re just asking people to steal from you.
That’s why it’s important to have value-added tools that analyze user access against the enterprise’s SOD rulebook and flag any conflicting functions. An ongoing analysis will point out any areas of risk so they can be remediated, and keep you informed should the situation change.
Of course, in a smaller organization, conflicting duties may not be avoidable. Everyone is expected to wear multiple hats, and sometimes those hats do not allow for proper segregation. In those instances, you need to have tools that can monitor actual transactions and report against them so you can see if a compliance violation is occurring. In other words, if someone has to carry both keys, you know when they’ve inserted them both into the control panel through mitigating controls.
Even with the proper tools, it’s unlikely you’ll ever bring SOD conflicts down to zero. But you can get awfully darned close, and keep an eye on what happens from there.
Introduction of malicious programs into production systems – The modern reality is that ERP systems are rarely steady state. Often enterprises have multiple initiatives going on that introduce new data, configuration and programs into the production systems.
With lean staffing and urgent deadlines, often changes are not properly tested or audited. In other words, they don’t use proper change management. A developer who has the means to do it, the motive to do it and knows whether he/she can get away with it can wreak all kinds of havoc by including malicious code along with legitimate code when new applications are moved into production. Malicious code can download sensitive data, create fraudulent transactions, delete data or crash the systems.
It is critical to have a second person reviewing any changes at every step of the way. What that means is the person who requests the change can’t be the person who develops it; the developer can’t be the person who tests it; the person who tests it can’t be the same person who migrates it into production. In other words, transport development and approvals cannot be given by a single person – instead, an independent approver or even a committee must be controlling the entire process.
Change management duties need to be segregated and managed throughout the entire process. Even if not malicious, poorly coded, untested programs can result in a catastrophic outage. Given that in a large enterprise an hour of downtime can cost $1 million, it’s easy to see why proper change management is worth the investment.
Emergency access – In large ERP environments, there’s always the chance that emergency maintenance of production systems will need to be performed. When it does, and the enterprise is dialing 9-1-1, someone needs to be given emergency “super user” access to everything in the system. Such emergency maintenance is often by outside parties (e.g. the software vender or 3rd party consultants).
The problem is these emergency all-access passes aren’t always tracked very well. Everyone is so fixed on putting out the fire – for example unlocking a sales order that has frozen the entire system – that they never think about documenting what transactions were performed or what data was changed. The risk is increased by the widespread use of generic “firefighter” user IDs whereby the individual performing the actions isn’t definitively known.
You’d like to think that the person you give super user access to can be trusted. But blind trust is what has gotten other enterprises into trouble in the past. The person with full access may make other changes while he/she is in there – either accidentally or on purpose. You need to be able to monitor who has all-access and what they do while they have it.
It is critical to have tools that allow you to track what these super-users do while they’re in the system. Not just for the day-to-day operation of the business, but for the auditors as well. When auditors see someone has been given this additional emergency access, their job is to immediately assume the person did something nefarious. It will be your job to prove they didn’t. You’ll need to show why access was granted, what was done while the person was in there, when/how long the person was in the system, what changes were made and when the person exited.
While it’s important to put out the big compliance blazes, keep in mind those are the ones that are also easy to see. Once they’re under control, take a tip from the professional firefighters and be sure to check for the smaller, smoldering flashpoints. It’s your best insurance against getting burned.
Dan Wilhelms is President and CEO of SymSoft Corporation (www.controlpanelGRC.com, the makers of ControlPanelGRC, professional solutions for compliance automation. He can be reached at dwilhelms@sym-corp.com.
Tuesday, November 9, 2010
What’s keeping CEOs up at night?
By Rich Walsh
Storage professionals who want to bring new ideas to their organizations on how better to manage corporate data might want to take note of Gartner, Inc.’s “seven major CEO concerns that CIOs should address.”
Gartner’s guide for CIOs provides some excellent insight into what management (CEOs in particular) expects from any new project that involves additional spending or technology upgrades. For example, what Gartner outlines in “investing in new cost efficiencies” is consistent with offsite e-storage management plans that I have been discussing with companies of late.
Not surprisingly, anything that saves money will be viewed favorably. As Gartner’s analysts put it, “CIOs proposing larger structural cost-saving ideas, such as major end-to-end process changes or automations, will likely receive CEO approval.”
Additionally, Gartner points out that CEOs are increasingly expecting that solutions be long-term and sustainable. Ideally, anything proposed should not simply be a quick fix.
Offsite data storage projects can meet those requirements and, done right, can produce long-term cost savings and sustainable solutions. Your management team might be interested to know that many businesses have been gradually moving to offsite data management, successfully trimming costs while being able to continue to access, control and monitor their records.
What steps are you taking to improve operations, your role in IT and data management overall?
Rich Walsh is president, Document Archive & Repository Services at Viewpointe. Rich has more than 25 years of operational information technology experience.
Storage professionals who want to bring new ideas to their organizations on how better to manage corporate data might want to take note of Gartner, Inc.’s “seven major CEO concerns that CIOs should address.”
Gartner’s guide for CIOs provides some excellent insight into what management (CEOs in particular) expects from any new project that involves additional spending or technology upgrades. For example, what Gartner outlines in “investing in new cost efficiencies” is consistent with offsite e-storage management plans that I have been discussing with companies of late.
Not surprisingly, anything that saves money will be viewed favorably. As Gartner’s analysts put it, “CIOs proposing larger structural cost-saving ideas, such as major end-to-end process changes or automations, will likely receive CEO approval.”
Additionally, Gartner points out that CEOs are increasingly expecting that solutions be long-term and sustainable. Ideally, anything proposed should not simply be a quick fix.
Offsite data storage projects can meet those requirements and, done right, can produce long-term cost savings and sustainable solutions. Your management team might be interested to know that many businesses have been gradually moving to offsite data management, successfully trimming costs while being able to continue to access, control and monitor their records.
What steps are you taking to improve operations, your role in IT and data management overall?
Rich Walsh is president, Document Archive & Repository Services at Viewpointe. Rich has more than 25 years of operational information technology experience.
Tuesday, November 2, 2010
Privacy Laws Must Change with the Times
By Todd Thibodeaux and David Valdez
A brave new world of technological innovation is emerging - some would say it has already emerged. Although we cannot predict the next killer app or revolutionary invention, we can be fairly sure that it will involve the use of personally identifiable information. Consumers have enthusiastically adopted personalized applications of all varieties, yet the way things stand now they must be prepared to sacrifice something at least as valuable: their privacy.
Congress is just beginning the complex process of developing legislation to protect consumer privacy while nurturing innovation in products and services. An important way to achieve the delicate balance between encouraging technology and preserving privacy is for Congress to expand the capabilities of the Federal Trade Commission (FTC) to ensure that it can keep up with the rapidly evolving marketplace.
In the mid to late 1990s, the FTC began reviewing how websites collected and managed consumers’ personally identifiable information. This led to the creation of a set of self-regulatory rules known as the Fair Information Practice Principles, which created four basic obligations: (1) consumers must be notified as to whether their online information is being collected, (2) consumers must provide consent as to whether or not they want their online information collected, (3) consumers must be able to view information a company has collected about them and verify its accuracy, and (4) businesses must undertake measures to ensure that information is accurate and stored securely.
The framework of the Fair Information Practice Principles is a good place to start when considering future privacy legislation. Over the past two decades it has demonstrated a suitable balance between responsible privacy standards and room for innovation. However, as technology evolves, the FTC should be able to keep up. The FTC should be provided with the discretion and flexibility to adapt, update and strengthen the Fair Information Practice Principles as well as its own role in safeguarding consumer privacy in response to changing technologies and consumer needs.
The FTC, in partnership with the private sector, should create privacy notices that are easy to read and understand in conjunction with an education campaign to inform consumers about their rights. Many privacy notices are dense and contain so much legalize that the notices become ineffective because consumers don’t read them.
Congress should provide the FTC with the resources to create an Online Consumer Protection bureau that focuses exclusively on online crimes such as identify theft, e-mail scams, and privacy enforcement. This would expand the FTC’s capabilities to investigate, prosecute and enforce consequences against breaches of privacy.
Any attempt to impose new privacy standards should distinguish between good actors that slip-up inadvertently versus bad actors that aim to cause trouble. A safe harbor program will accomplish this task by reducing liability if actions are preformed in good faith. Safe harbor programs provide a combination of carrot and stick which allow the FTC to execute different programs for different actors.
As policymakers continue to deliberate the best path for balancing the various stakeholder interests around the issue of online privacy, they must remember that any proposed legislation should not be absolute. The current set of privacy principles adopted by the FTC has worked well for over a decade and should serve as a framework for any new legislation. Technology is a moving target and privacy laws should be sufficiently flexible to adapt.
Todd Thibodeaux is CEO and president of CompTIA, a non-profit trade association advancing the global interests of information technology (IT) professionals and businesses (www.comptia.org). Todd can be reached at tthibodeaux@comptia.org. David Valdez is the organization’s senior director of public advocacy. David can be reached at dvaldez@comptia.org.
A brave new world of technological innovation is emerging - some would say it has already emerged. Although we cannot predict the next killer app or revolutionary invention, we can be fairly sure that it will involve the use of personally identifiable information. Consumers have enthusiastically adopted personalized applications of all varieties, yet the way things stand now they must be prepared to sacrifice something at least as valuable: their privacy.
Congress is just beginning the complex process of developing legislation to protect consumer privacy while nurturing innovation in products and services. An important way to achieve the delicate balance between encouraging technology and preserving privacy is for Congress to expand the capabilities of the Federal Trade Commission (FTC) to ensure that it can keep up with the rapidly evolving marketplace.
In the mid to late 1990s, the FTC began reviewing how websites collected and managed consumers’ personally identifiable information. This led to the creation of a set of self-regulatory rules known as the Fair Information Practice Principles, which created four basic obligations: (1) consumers must be notified as to whether their online information is being collected, (2) consumers must provide consent as to whether or not they want their online information collected, (3) consumers must be able to view information a company has collected about them and verify its accuracy, and (4) businesses must undertake measures to ensure that information is accurate and stored securely.
The framework of the Fair Information Practice Principles is a good place to start when considering future privacy legislation. Over the past two decades it has demonstrated a suitable balance between responsible privacy standards and room for innovation. However, as technology evolves, the FTC should be able to keep up. The FTC should be provided with the discretion and flexibility to adapt, update and strengthen the Fair Information Practice Principles as well as its own role in safeguarding consumer privacy in response to changing technologies and consumer needs.
The FTC, in partnership with the private sector, should create privacy notices that are easy to read and understand in conjunction with an education campaign to inform consumers about their rights. Many privacy notices are dense and contain so much legalize that the notices become ineffective because consumers don’t read them.
Congress should provide the FTC with the resources to create an Online Consumer Protection bureau that focuses exclusively on online crimes such as identify theft, e-mail scams, and privacy enforcement. This would expand the FTC’s capabilities to investigate, prosecute and enforce consequences against breaches of privacy.
Any attempt to impose new privacy standards should distinguish between good actors that slip-up inadvertently versus bad actors that aim to cause trouble. A safe harbor program will accomplish this task by reducing liability if actions are preformed in good faith. Safe harbor programs provide a combination of carrot and stick which allow the FTC to execute different programs for different actors.
As policymakers continue to deliberate the best path for balancing the various stakeholder interests around the issue of online privacy, they must remember that any proposed legislation should not be absolute. The current set of privacy principles adopted by the FTC has worked well for over a decade and should serve as a framework for any new legislation. Technology is a moving target and privacy laws should be sufficiently flexible to adapt.
Todd Thibodeaux is CEO and president of CompTIA, a non-profit trade association advancing the global interests of information technology (IT) professionals and businesses (www.comptia.org). Todd can be reached at tthibodeaux@comptia.org. David Valdez is the organization’s senior director of public advocacy. David can be reached at dvaldez@comptia.org.
Tuesday, October 26, 2010
E-Discovery: Addressing the Risks
By Rich Walsh of Viewpointe
At the heart of many risks facing companies today lurks e-discovery – the locating and accessing of electronically stored information (ESI) for purposes of litigation. ESI can be any electronically stored information – documents, emails, databases, etc. – potentially for use as evidence by lawyers in legal cases.
Compounding the risk to companies is the volume of data subject to e-discovery. In fact, the Association of Certified E-Discovery Specialists, a group dedicated to dealing with this problem, calls the deluge of electronically stored material used as evidence in civil actions the single biggest storyline in the legal world today.
In a recent cross-industry report commissioned by the Deloitte Forensic Center, “E-Discovery: Mitigating Risk Through Better Communication,” just 43 percent of the respondents felt that their companies were somewhat up for the e-discovery challenge. The report notes that in the e-discovery process legal, IT and other departments – those that don’t normally work together – are often thrown together “in a room” to do a difficult job under quite a bit of pressure. And with a lack of common language and systems among these groups, it only further muddies the process.
Where is all of this leading? The Deloitte report found that 49 percent of respondents expect their company’s IT department to have to work more on e-discovery efforts in the near future. So, on top of IT’s workload and limited budgets, adding new e-discovery work will further challenge their priorities. In preparation, companies will need to figure out, sooner than later, where (and even if) they have stored and can easily retrieve everything they might need to produce.
I’d love to hear from TAWPI members as how your companies may be preparing for this challenge. Any tips for colleagues? Share with us.
Rich Walsh is president, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.
At the heart of many risks facing companies today lurks e-discovery – the locating and accessing of electronically stored information (ESI) for purposes of litigation. ESI can be any electronically stored information – documents, emails, databases, etc. – potentially for use as evidence by lawyers in legal cases.
Compounding the risk to companies is the volume of data subject to e-discovery. In fact, the Association of Certified E-Discovery Specialists, a group dedicated to dealing with this problem, calls the deluge of electronically stored material used as evidence in civil actions the single biggest storyline in the legal world today.
In a recent cross-industry report commissioned by the Deloitte Forensic Center, “E-Discovery: Mitigating Risk Through Better Communication,” just 43 percent of the respondents felt that their companies were somewhat up for the e-discovery challenge. The report notes that in the e-discovery process legal, IT and other departments – those that don’t normally work together – are often thrown together “in a room” to do a difficult job under quite a bit of pressure. And with a lack of common language and systems among these groups, it only further muddies the process.
Where is all of this leading? The Deloitte report found that 49 percent of respondents expect their company’s IT department to have to work more on e-discovery efforts in the near future. So, on top of IT’s workload and limited budgets, adding new e-discovery work will further challenge their priorities. In preparation, companies will need to figure out, sooner than later, where (and even if) they have stored and can easily retrieve everything they might need to produce.
I’d love to hear from TAWPI members as how your companies may be preparing for this challenge. Any tips for colleagues? Share with us.
Rich Walsh is president, Document Archive & Repository Services at Viewpointe. He has more than 25 years of operational information technology experience.
Thursday, October 7, 2010
How Technology Came to Rule the Legal World
By James D. Shook, Esq.
Director of E-Discovery and Compliance
EMC Corporation
Ten years ago, few people, even lawyers, knew much about electronic discovery (e-discovery)—the process of finding, preserving, processing, and producing electronic information that is relevant to a legal dispute. Today, it’s difficult to find anyone who is not at least conversant with the concept, thanks to many high-profile cases and countless articles in both IT and legal journals. And yet even with all of the changes that we have already seen, the next ten years are likely to produce even more.
An extra “e” transforms “discovery”
The U.S. legal system requires that each party in a civil dispute provide the other party with all information, both good and bad, that is relevant to the case. This part of the litigation process is called discovery.
In the “old days”—which in technology terms means before 2000—the discovery process focused primarily on paper documents such as contracts, notes, files, and correspondence, including letters and memoranda. As businesses began using more technology, especially e-mail, the majority of that information shifted from paper to electronic format, and e-discovery was born.
The rules of discovery never specifically included—or excluded—electronic data, creating inconsistencies and confusion. To address this issue, the Federal Rules of Civil Procedure were amended in December 2006 to specifically include electronic data, defined as electronically stored information or ESI. Although the FRCP only governs disputes in federal courts, it strongly influences state courts, and the rules spread quickly.
Almost overnight, IT systems such as e-mail servers became concerns for lawyers, many of whom are notoriously techno-phobic. Organizations that failed to meet their e-discovery obligations faced the risk of embarrassing and costly sanctions from the courts. Simply collecting and preserving everything was cost-prohibitive. A frequently cited study found that it costs almost $20,000 to have lawyers review a single gigabyte of data (which may seem reasonable since 1 GB represents about 75,000 pages). Extrapolating those costs across hundreds of gigabytes, or even a terabyte or more of data, scared most organizations—and they started looking for a better way to manage both the e-discovery process and their electronic information.
E-discovery strategies at work, today
Organizations that lead the way in e-discovery best practices are attacking the problem in two ways. First, by managing data more centrally and efficiently, they can responsibly delete data that has no value, or which they are under no obligation to retain. Not only does this practice improve the e-discovery process, but it also creates significant savings for storage, backup, and personnel costs.
The second part of this strategy is to bring some—or all—of the e-discovery process in-house. To do this, organizations are creating cross-functional teams that include both IT and Legal, and then deploying technologies that enable fast and efficient in-place search and collection of their ESI.
Yet even today there are many organizations that have done little to address these requirements. Because e-discovery is not a voluntary process, many unprepared organizations perform “faux e-discovery”—they attempt to meet their obligations, but in reality miss significant amounts of relevant data. In doing so, they are taking on significant risk, without understanding or acknowledging it. Other organizations that fail to prepare are forced to turn to expert (and expensive) third-party vendors, frequently spending several hundred thousand to well over a million dollars to respond to a single case—without any ongoing benefit.
More data, more technologies, more challenges, more solutions
The continuing explosion in the amount and varying types of data will continue to significantly impact the e-discovery landscape. With studies noting that we will have 35 zetabytes of data created by 2020, even good processes may be totally overwhelmed by the sheer volume.
In addition, technologies that enhance the speed and efficiency of communication and businesses processes continue to be developed—and they are usually not e-discovery-friendly. Social media technologies such as Facebook and Twitter are further blurring the line between personal and business data, which can be difficult for organizations to locate and preserve. Cloud computing can put a company’s data in the hands of a third party, sometimes in a different country or jurisdiction, which also makes e-discovery more difficult.
But technology is also likely to provide solutions, such as intelligent filtering and review of data. There are tools today that can classify and determine whether documents are relevant to a case based on their similarity to other relevant documents or other criteria. But those technologies are new and complex, and their acceptance in actual court proceedings is not assured.
With all of these issues on the horizon—and certainly more that we cannot yet predict—the next 10 years in e-discovery will be every bit as interesting as the last.
As director of e-discovery and compliance at EMC Corporation, James D. Shook, Esq. works with customers to help them solve challenges related to e-discovery, compliance and privacy. James is a long-time member of The Sedona Conference, a well-known legal think tank, and is an active contributor on several of its committees.
Director of E-Discovery and Compliance
EMC Corporation
Ten years ago, few people, even lawyers, knew much about electronic discovery (e-discovery)—the process of finding, preserving, processing, and producing electronic information that is relevant to a legal dispute. Today, it’s difficult to find anyone who is not at least conversant with the concept, thanks to many high-profile cases and countless articles in both IT and legal journals. And yet even with all of the changes that we have already seen, the next ten years are likely to produce even more.
An extra “e” transforms “discovery”
The U.S. legal system requires that each party in a civil dispute provide the other party with all information, both good and bad, that is relevant to the case. This part of the litigation process is called discovery.
In the “old days”—which in technology terms means before 2000—the discovery process focused primarily on paper documents such as contracts, notes, files, and correspondence, including letters and memoranda. As businesses began using more technology, especially e-mail, the majority of that information shifted from paper to electronic format, and e-discovery was born.
The rules of discovery never specifically included—or excluded—electronic data, creating inconsistencies and confusion. To address this issue, the Federal Rules of Civil Procedure were amended in December 2006 to specifically include electronic data, defined as electronically stored information or ESI. Although the FRCP only governs disputes in federal courts, it strongly influences state courts, and the rules spread quickly.
Almost overnight, IT systems such as e-mail servers became concerns for lawyers, many of whom are notoriously techno-phobic. Organizations that failed to meet their e-discovery obligations faced the risk of embarrassing and costly sanctions from the courts. Simply collecting and preserving everything was cost-prohibitive. A frequently cited study found that it costs almost $20,000 to have lawyers review a single gigabyte of data (which may seem reasonable since 1 GB represents about 75,000 pages). Extrapolating those costs across hundreds of gigabytes, or even a terabyte or more of data, scared most organizations—and they started looking for a better way to manage both the e-discovery process and their electronic information.
E-discovery strategies at work, today
Organizations that lead the way in e-discovery best practices are attacking the problem in two ways. First, by managing data more centrally and efficiently, they can responsibly delete data that has no value, or which they are under no obligation to retain. Not only does this practice improve the e-discovery process, but it also creates significant savings for storage, backup, and personnel costs.
The second part of this strategy is to bring some—or all—of the e-discovery process in-house. To do this, organizations are creating cross-functional teams that include both IT and Legal, and then deploying technologies that enable fast and efficient in-place search and collection of their ESI.
Yet even today there are many organizations that have done little to address these requirements. Because e-discovery is not a voluntary process, many unprepared organizations perform “faux e-discovery”—they attempt to meet their obligations, but in reality miss significant amounts of relevant data. In doing so, they are taking on significant risk, without understanding or acknowledging it. Other organizations that fail to prepare are forced to turn to expert (and expensive) third-party vendors, frequently spending several hundred thousand to well over a million dollars to respond to a single case—without any ongoing benefit.
More data, more technologies, more challenges, more solutions
The continuing explosion in the amount and varying types of data will continue to significantly impact the e-discovery landscape. With studies noting that we will have 35 zetabytes of data created by 2020, even good processes may be totally overwhelmed by the sheer volume.
In addition, technologies that enhance the speed and efficiency of communication and businesses processes continue to be developed—and they are usually not e-discovery-friendly. Social media technologies such as Facebook and Twitter are further blurring the line between personal and business data, which can be difficult for organizations to locate and preserve. Cloud computing can put a company’s data in the hands of a third party, sometimes in a different country or jurisdiction, which also makes e-discovery more difficult.
But technology is also likely to provide solutions, such as intelligent filtering and review of data. There are tools today that can classify and determine whether documents are relevant to a case based on their similarity to other relevant documents or other criteria. But those technologies are new and complex, and their acceptance in actual court proceedings is not assured.
With all of these issues on the horizon—and certainly more that we cannot yet predict—the next 10 years in e-discovery will be every bit as interesting as the last.
As director of e-discovery and compliance at EMC Corporation, James D. Shook, Esq. works with customers to help them solve challenges related to e-discovery, compliance and privacy. James is a long-time member of The Sedona Conference, a well-known legal think tank, and is an active contributor on several of its committees.
Labels:
archive,
check imaging,
document automation,
document imaging,
e-discovery,
EMC,
Mark Brousseau,
TAWPI,
workflow
Friday, September 24, 2010
The Hunt for "Orphan Storage"
By Rich Walsh, Viewpointe (www.viewpointe.com)
Storage professionals are now under pressure to find and use “orphan storage,” rather than buying or building more capacity. Orphan storage is a form of unused or unallocated data in everything from a database to disk drives and storage area networks. The problem seems so universal, that I hear this almost everywhere I go. I recently heard one executive say: “When we buy storage, we know where it is, but now our mandate has become finding unused storage, wherever it happens to be.”
Symantec’s CEO has even gone so far as to tell the market to "stop buying storage." I couldn’t agree more with this sentiment. Not being able to use your existing space or, worse, access the storage you already have – those seem to be the larger problems. Certainly IT executives are probably both gratified and mortified that this issue, which is hardly new to them, is finally getting some attention.
Recently, we asked IDC to take a deeper dive into this issue; and in a whitepaper, IDC noted outsourced storage as a good solution to the growing capacity problem. Generally they concluded that for easy access, as well as appropriate amounts of storage, outsourced systems work very well. Moving data to a hosted repository allows companies to pay only for the actual capacity they currently need, as opposed to an in-house infrastructure that is generally built for future consumption. And, this approach may be better suited for accessing the needed data at a later date.
Right now, IT executives want to make good use of all the equipment and devices that they have already purchased, and that is sound business judgment. Still, at some point, organizations are going to deplete the space they have and simply purging existing files may not be enough to keep up with the increased demand.
However, the question remains: What should companies do once they have determined just how much existing storage they have? Will they continue to buy ad-hoc, only to be faced with the exact same orphan storage problem in a few more months? Or, is it time for a fresh approach to this ever-growing problem?
Storage professionals are now under pressure to find and use “orphan storage,” rather than buying or building more capacity. Orphan storage is a form of unused or unallocated data in everything from a database to disk drives and storage area networks. The problem seems so universal, that I hear this almost everywhere I go. I recently heard one executive say: “When we buy storage, we know where it is, but now our mandate has become finding unused storage, wherever it happens to be.”
Symantec’s CEO has even gone so far as to tell the market to "stop buying storage." I couldn’t agree more with this sentiment. Not being able to use your existing space or, worse, access the storage you already have – those seem to be the larger problems. Certainly IT executives are probably both gratified and mortified that this issue, which is hardly new to them, is finally getting some attention.
Recently, we asked IDC to take a deeper dive into this issue; and in a whitepaper, IDC noted outsourced storage as a good solution to the growing capacity problem. Generally they concluded that for easy access, as well as appropriate amounts of storage, outsourced systems work very well. Moving data to a hosted repository allows companies to pay only for the actual capacity they currently need, as opposed to an in-house infrastructure that is generally built for future consumption. And, this approach may be better suited for accessing the needed data at a later date.
Right now, IT executives want to make good use of all the equipment and devices that they have already purchased, and that is sound business judgment. Still, at some point, organizations are going to deplete the space they have and simply purging existing files may not be enough to keep up with the increased demand.
However, the question remains: What should companies do once they have determined just how much existing storage they have? Will they continue to buy ad-hoc, only to be faced with the exact same orphan storage problem in a few more months? Or, is it time for a fresh approach to this ever-growing problem?
Thursday, September 23, 2010
Online Storage and Privacy Laws
Posted by Mark Brousseau
If you store sensitive files on your personal computer which law enforcement authorities wish to examine, they generally cannot do so without first obtaining a search warrant based upon probable cause. But what if you store personal information online—say, in your Gmail account, or on Dropbox? What if you’re a business owner who uses Salesforce CRM or Windows Azure? How secure is your data from unwarranted governmental access?
Both the U.S. Senate and the House of Representatives are investigating these crucial questions in two separate hearings this week. Congress hasn’t overhauled the privacy laws governing law enforcement access to information stored with remote service providers since 1986. The Electronic Communications Privacy Act (ECPA), the key federal law governing electronic privacy, has grown increasingly out of touch with reality as technology has evolved and Americans have grown increasingly reliant on cloud services like webmail and social networking. As a result, government can currently compel service providers to disclose the contents of certain types of information stored in the cloud without first obtaining a search warrant or any other court order requiring the scrutiny of a judge.
Against this backdrop, the Competitive Enterprise Institute has joined with The Progress & Freedom Foundation, Americans for Tax Reform, Citizens Against Government Waste, and the Center for Financial Privacy and Human Rights in submitting a written statement to the U.S. Senate and House Judiciary Committees urging Congress to reform U.S. electronic privacy laws to better reflect users’ privacy expectations in the information age. The groups also belong to the Digital Due Process coalition, a broad array of public interest organizations, businesses, advocacy groups, and scholars who are working to strengthen U.S. privacy laws while also preserving the building blocks of law enforcement investigations.
“The success of cloud computing—and its benefits for the U.S. economy—depends largely on updating the outdated federal statutory regime that currently governs electronic communications privacy,” the statement argues. “If Congress wants to ensure Americans enjoy the full benefits of the cloud computing revolution, it should simply reform ECPA in accordance with the principles proposed by the Digital Due Process coalition.”
What do you think?
If you store sensitive files on your personal computer which law enforcement authorities wish to examine, they generally cannot do so without first obtaining a search warrant based upon probable cause. But what if you store personal information online—say, in your Gmail account, or on Dropbox? What if you’re a business owner who uses Salesforce CRM or Windows Azure? How secure is your data from unwarranted governmental access?
Both the U.S. Senate and the House of Representatives are investigating these crucial questions in two separate hearings this week. Congress hasn’t overhauled the privacy laws governing law enforcement access to information stored with remote service providers since 1986. The Electronic Communications Privacy Act (ECPA), the key federal law governing electronic privacy, has grown increasingly out of touch with reality as technology has evolved and Americans have grown increasingly reliant on cloud services like webmail and social networking. As a result, government can currently compel service providers to disclose the contents of certain types of information stored in the cloud without first obtaining a search warrant or any other court order requiring the scrutiny of a judge.
Against this backdrop, the Competitive Enterprise Institute has joined with The Progress & Freedom Foundation, Americans for Tax Reform, Citizens Against Government Waste, and the Center for Financial Privacy and Human Rights in submitting a written statement to the U.S. Senate and House Judiciary Committees urging Congress to reform U.S. electronic privacy laws to better reflect users’ privacy expectations in the information age. The groups also belong to the Digital Due Process coalition, a broad array of public interest organizations, businesses, advocacy groups, and scholars who are working to strengthen U.S. privacy laws while also preserving the building blocks of law enforcement investigations.
“The success of cloud computing—and its benefits for the U.S. economy—depends largely on updating the outdated federal statutory regime that currently governs electronic communications privacy,” the statement argues. “If Congress wants to ensure Americans enjoy the full benefits of the cloud computing revolution, it should simply reform ECPA in accordance with the principles proposed by the Digital Due Process coalition.”
What do you think?
Monday, July 12, 2010
Economic risks of data overload
By Ed Pearce (epearce@egisticsinc.com) of eGistics (www.eGisticsinc.com)
When data pours in by the millisecond and the mountain of information builds continuously, professionals inevitably cut corners and go with their 'gut' when making decisions that can impact financial markets, medical treatments or any number of time sensitive matters, according to a new study from Thomson Reuters. The study indicates that when faced with unsorted, unverified "raw" data, 60 percent of decision-makers will make "intuitive" decisions that can lead to poor outcomes.
Many government regulators have flagged increased financial risk-taking, which can be traced in some degree to imperfectly managed data, as a contributor to the recent financial crisis. Moreover, the world is awash with data -- roughly 800 exabytes -- and the velocity of information is increasing, Thomson Reuters says.
The challenge is that the staffing and investment needed to ensure that information and information channels are trusted, reliable and useful is not keeping pace. In fact, it is estimated that the information universe will increase by a factor of 44; the number of managed files by a factor of 67; storage by a factor of 30 but staffing and investment in careful management by a factor of 1.4.
"The solution to data overload is to provide decision makers with what Thomson Reuters calls Intelligent Information: better organized and structured information, rapidly conveyed to the users preferred device," says David Craig, executive vice president and chief strategy officer.
Fortunately, as the Thomson Reuters study notes, the same technological revolution that has resulted in the explosion of information also opens the way to new and improved tools for providing intelligent information: better organized and structured information, rapidly conveyed to the user's preferred device.
"We must use the benefits of the information technology revolution to minimize its risks. This is a joint task that the private sector and governments must closely focus on if we are to avoid systemic crises, in the future, whether we speak of finance, healthcare delivery, international security and a myriad of other areas," comments Craig.
How is your organization managing information overload?
When data pours in by the millisecond and the mountain of information builds continuously, professionals inevitably cut corners and go with their 'gut' when making decisions that can impact financial markets, medical treatments or any number of time sensitive matters, according to a new study from Thomson Reuters. The study indicates that when faced with unsorted, unverified "raw" data, 60 percent of decision-makers will make "intuitive" decisions that can lead to poor outcomes.
Many government regulators have flagged increased financial risk-taking, which can be traced in some degree to imperfectly managed data, as a contributor to the recent financial crisis. Moreover, the world is awash with data -- roughly 800 exabytes -- and the velocity of information is increasing, Thomson Reuters says.
The challenge is that the staffing and investment needed to ensure that information and information channels are trusted, reliable and useful is not keeping pace. In fact, it is estimated that the information universe will increase by a factor of 44; the number of managed files by a factor of 67; storage by a factor of 30 but staffing and investment in careful management by a factor of 1.4.
"The solution to data overload is to provide decision makers with what Thomson Reuters calls Intelligent Information: better organized and structured information, rapidly conveyed to the users preferred device," says David Craig, executive vice president and chief strategy officer.
Fortunately, as the Thomson Reuters study notes, the same technological revolution that has resulted in the explosion of information also opens the way to new and improved tools for providing intelligent information: better organized and structured information, rapidly conveyed to the user's preferred device.
"We must use the benefits of the information technology revolution to minimize its risks. This is a joint task that the private sector and governments must closely focus on if we are to avoid systemic crises, in the future, whether we speak of finance, healthcare delivery, international security and a myriad of other areas," comments Craig.
How is your organization managing information overload?
Saturday, July 10, 2010
Capture 2011: From Imaging to Archive
Coming in Early 2011 -- Actionable ideas for improving document-driven business applications!
TAWPI, IAPP and IARP have joined forces to create Capture 2011 – the premier event on complex data capture and transactional content management. This one-of-a-kind event focuses on emerging technologies and best practices for the automation of critical document-driven applications such as: invoice processing, order entry, application processing, loan processing, tax processing, healthcare payments processing, mailroom automation, payments and more!
Through end-user case study presentations, interactive panel discussions, and visionary keynote presentations, attendees will gain actionable strategies for improving business outcomes in document-driven applications. The event also will feature valuable networking opportunities, and an expo hall in which attendees can see data capture and transactional content management technologies and services firsthand.
Topics covered will include:
• Complex data capture
• Content management
• Workflow/decisioning
• Enterprise data capture
• Information archive/storage/delivery
• Data security/privacy/compliance
• SharePoint optimization
Vertical markets covered:
• Banking/financial services
• Insurance
• Government
• Healthcare
• Service bureaus
• Utilities/telcos
• Retail/mail order
• And more!
Capture 2011 will be an unparalleled event for professionals responsible for managing document-driven business applications. Don’t miss it!
For more details, visit www.tawpi.org or www.iappnet.org.
TAWPI, IAPP and IARP have joined forces to create Capture 2011 – the premier event on complex data capture and transactional content management. This one-of-a-kind event focuses on emerging technologies and best practices for the automation of critical document-driven applications such as: invoice processing, order entry, application processing, loan processing, tax processing, healthcare payments processing, mailroom automation, payments and more!
Through end-user case study presentations, interactive panel discussions, and visionary keynote presentations, attendees will gain actionable strategies for improving business outcomes in document-driven applications. The event also will feature valuable networking opportunities, and an expo hall in which attendees can see data capture and transactional content management technologies and services firsthand.
Topics covered will include:
• Complex data capture
• Content management
• Workflow/decisioning
• Enterprise data capture
• Information archive/storage/delivery
• Data security/privacy/compliance
• SharePoint optimization
Vertical markets covered:
• Banking/financial services
• Insurance
• Government
• Healthcare
• Service bureaus
• Utilities/telcos
• Retail/mail order
• And more!
Capture 2011 will be an unparalleled event for professionals responsible for managing document-driven business applications. Don’t miss it!
For more details, visit www.tawpi.org or www.iappnet.org.
Wednesday, July 7, 2010
Putting the kibosh on the soaring software maintenance and upgrade costs
By Randy Davis (rdavis@egisticsinc.com)
Finextra reports that in a recent speech to the Committee for Economic Development in Australia (CEDA), CBA Chief Information Officer Michael Harte lambasted legacy technology vendors for their slow embrace of cloud-based computing and their apparent preference for solutions that lock-in users to a "never-ending spiral" of costly maintenance and upgrades.
"We're saying that we will never buy another data center. We will never buy another rack or server or storage device or network device again," Harte said. "I will never let any organization that I work for get locked into proprietary hardware or software again. I'll never tell my teams in the business that it will be weeks to get them hardware provision. I'll never pay upfront for any infrastructure and certainly would never pay for any, or rent any, infrastructure that I would never use."
Harte concluded: "I will never implement an internal solution for a common problem that I could procure on subscription across the Web."
With increasing demand for cloud-based solutions, combined with a general reluctance to pay hefty upfront capital costs, Harte's comments would seem to reflect growing dissatisfaction with the traditional licensed software model -- and its “never-ending spiral” of ongoing expenses.
Are you as fed-up as Harte?
Finextra reports that in a recent speech to the Committee for Economic Development in Australia (CEDA), CBA Chief Information Officer Michael Harte lambasted legacy technology vendors for their slow embrace of cloud-based computing and their apparent preference for solutions that lock-in users to a "never-ending spiral" of costly maintenance and upgrades.
"We're saying that we will never buy another data center. We will never buy another rack or server or storage device or network device again," Harte said. "I will never let any organization that I work for get locked into proprietary hardware or software again. I'll never tell my teams in the business that it will be weeks to get them hardware provision. I'll never pay upfront for any infrastructure and certainly would never pay for any, or rent any, infrastructure that I would never use."
Harte concluded: "I will never implement an internal solution for a common problem that I could procure on subscription across the Web."
With increasing demand for cloud-based solutions, combined with a general reluctance to pay hefty upfront capital costs, Harte's comments would seem to reflect growing dissatisfaction with the traditional licensed software model -- and its “never-ending spiral” of ongoing expenses.
Are you as fed-up as Harte?
The state of storage
Randy Davis (rdavis@egisticsinc.com) of eGistics, Inc. (www.egisticsinc.com) finds several interesting trends in The 2010 State of Storage Report from Networking Computing.
1. The top planned storage project for 2010 is improved allocation
2. Forty-seven percent of respondents say insufficient storage resources for mission-critical applications is their No. 1 concern
3. Storage area network (SAN) vendors are responding to demands for lower-cost storage
4. Storage virtualization is growing
5. Thin provisioning is catching on
6. There is a significant increase in interest in cloud-based storage
How do these trends reflect your storage strategy?
1. The top planned storage project for 2010 is improved allocation
2. Forty-seven percent of respondents say insufficient storage resources for mission-critical applications is their No. 1 concern
3. Storage area network (SAN) vendors are responding to demands for lower-cost storage
4. Storage virtualization is growing
5. Thin provisioning is catching on
6. There is a significant increase in interest in cloud-based storage
How do these trends reflect your storage strategy?
Subscribe to:
Posts (Atom)