Digital Continuity: An introduction Digital continuity… The ability to use your information in the way you need for as long as you need.


Similar presentations
ICT Services Suppliers Briefing Thursday, 17 September 2009.

Enabling non-technical innovation – enabling the demand side Professor Stephen Roper Warwick Business School, UK
1 of 13 Organization and Management Information Management in Your Organization IMARK Investing in Information for Development Organization and Management.
1 of 18 Information Dissemination New Digital Opportunities IMARK Investing in Information for Development Information Dissemination New Digital Opportunities.
1 of 15 Information Access Internal Information © FAO 2005 IMARK Investing in Information for Development Information Access Internal Information.
Outlook 2 Everything feels good now as prices are high. However...
Effectively applying ISO9001:2000 clauses 6 and 7.
Value for Money – new requirements and challenges
How to commence the IT Modernization Process?
Develop an Information Strategy Plan
©Ian Sommerville 2004Software Engineering, 7th edition. Chapter 27 Slide 1 Quality Management.
DRM P-CM Roadmap V5_MCS Change Control: Rolling updates for Taxonomy, Adjusting Training, Technology, DRM Process, Facilities 5. Design Change Controls.
1 Overview for DAP Business Units Digital Archives Problem Statement Records are all material "regardless of physical form, created or received in connection.
Health Records Management Practitioner
©Ian Sommerville 2006Software Engineering, 8th edition. Chapter 30 Slide 1 Security Engineering 2.
Child Safeguarding Standards
Chapter 14 Fraud Risk Assessment.
Assessment and eligibility
1 Auditing in the Public Interest Records Management in the Victorian Public Sector Audit objective Audit had two objectives : The first objective was.
An Intro to Professionalizing Procurement & Strategic Sourcing
Buying Better Outcomes Workshop 4 Equalities and Contract Management If you do not take it seriously, why should the supplier?
Risk and Resilience Delivered by Alba
ITIL: Service Transition
Knowledge and Information Management Strategy July 2012.
The Australian/New Zealand Standard on Risk Management
Integrated Process Model - v2
Welcome ISO9001:2000 Foundation Workshop.
Guidelines 4-6 Developing a file plan for government agencies Tuvalu Government Filing Manual Funafuti, Tuvalu June 2013 There are three guidelines in.
Resiliency Rules: 7 Steps for Critical Infrastructure Protection.
Facilities Management Category Management Plan Synopsis Version 1.1 (March 2015)
Self Assessment Feedback Logistics R Us GOLD Member.
1 Jon Whitfield Agency CEO Head of Government Internal Audit.
G17: Recordkeeping for Business Activities Carried out by Contractors Patrick Power, Manager Government Recordkeeping Programme Archives New Zealand.
Open Data from Reliable Records Anne Thurston. The Open Data movement, a key aspect of Open Government, is now a top development interest across the world.
Thomas Levy. Agenda 1.Aims: Reducing Cyber Risk 2.Information Risk Management 3.Secure Configuration 4.Network Security 5.Managing User Access 6.Education.
Ecords Management Records Management Paul Smallcombe Records & Information Compliance Manager.
Mark Merifield, The National Archives ISKO – 24 October 2013 Availability is everything.
Challenges Emerging Technologies present for Information Managers Allegra Huxtable Manager Government Information Strategy Unit Tasmanian Archive and Heritage. PUBLIC Kevin Holland Service Management An example ITIL-based model for effective Service Integration and Management.
Engin Ali ARTAN Industrial Engineering
1 of 27 How to invest in Information for Development An Introduction Introduction This question is the focus of our examination of the information management.
London Health Libraries 27 February Drivers for Change World Class Commissioning NHS Operating Framework Healthcare for London.
Recordkeeping for Good Governance Toolkit Workshop PARBICA 14 Evidence and Memory in the Digital Age.
Queen’s Management & Leadership Framework
Digital Preservation across the technologies, strategies, open standards & interoperability aspects including the legal issues Pratik Shrivastava Scientist.
Digital recordkeeping strategy for mobile work processes Joel Smith HPRM System Administrator.
ISO/IEC 27001:2013 Annex A.8 Asset management
@theEIFoundation | Early Intervention to prevent gang and youth violence: ‘Maturity Matrix’ Early intervention (‘EI’) is about getting extra.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
25 Years and Beyond: The Benefits of Managing over 25 Year Old Records John Roberts, Group Manager Archives Management Archives New Zealand.
Fire Prevention Education Team Organization 1A-01-P310-EP.
1 Information Governance (For Dental Practices) Norman Pottinger Information Governance Manager NHS Suffolk.
Collaborative & Interpersonal Leadership
Solihull Review of Urgent Care Programme Approach And Governance 2013
University Information Audit 2014
Office 365 Security Assessment Workshop
Configuration Management and Prince2
Originating the role of Information Governance Officer
Ulrich’s model of HR.
Project Roles and Responsibilities
Here are some top tips to help you bake responsible data into your project design:.
Moving in the digital world – breaking down the barriers Monique Nielsen National Archives of Australia February 2018.
Archives New Zealand update
On Call Training For Winter Preparedness
Portfolio, Programme and Project
Legacy system components
Data Governance & Management Skills and Experience
Investing in Data Management Capabilities
Data Security and Protection Toolkit Assurance 2018/19
eRecords Sustainability
Presentation transcript:

Digital Continuity: An introduction

Digital continuity… The ability to use your information in the way you need for as long as you need

Information is usable if you can… Find it when you need it Open it as you need it Work with it in the way that you need to Understand what it is and what its about Trust that it is what it says it is

It does make the headlines…

We havent made this up… Any electronic data degrades over time. Some of this information is more than 20 years old. I'm not even sure that the xxx still has the tools needed to retrieve data from that era. You're talking about technology that would qualify as museum pieces now. The transition to the new system has, however brought to light discrepancies in our existing records and this is resulting in a number of incorrect notices being issued. The only evidence beyond surmise that Dept X rely upon to support their assertion that the document is not held, is their failure to locate it. Transfer of records from Dept Y to Depts Z and A has resulted in two scenarios that have effectively rendered metadata captured in the EDRMS as lost.

Digital information is vulnerable… Risks are inherent in change o Organisational change o Technology change o Process and policy change in how information is managed

The impact of change… o information ownership becomes unclear - risks are missed or unmanaged o information is not disposed of appropriately o information is not migrated to new technologies effectively o information is trapped in legacy IT systems – or locked in a format that cant be opened or used o information is no longer understood by the organisation – or cannot be trusted

Why it matters… o Efficiency and effectiveness o Transparency and accountability o Managing information risk

Managing digital continuity… 10 Plan for action Define what you need Assess and manage risks Maintain digital continuity

The Digital Continuity Service… 11 Guidance Risk Assessment Self-Assessment Tool Procurement Framework DROID

Stage 1: Planning

Managing digital continuity… 13 Define what you need Assess and manage risks Maintain digital continuity Plan for action

Plan for Action… Key roles understand risk and responsibilities SRO for digital continuity Multi-disciplinary team Embed approach in business as usual

Role of the SRO… Champion digital continuity Lead action to manage risk and embed Co-ordinate across disciplines Prioritise resources Escalate issues

Introducing DoRA… You are the SRO Who do you need to be involved in managing digital continuity? What are their drivers for taking action?

Roles and responsibilities… SIRO and information risk management IAOs Information assurance Information management Information technology Change and project management

Stage 2: Define Requirements

Managing digital continuity… 19 Assess and manage risks Maintain digital continuity Plan for action Define what you need

Information Assets Technical Environment Business Needs Digital Continuity


Information Assets Technical Environment Business Needs Digital Continuity

Information Assets Technical Environment Business Needs

Information Assets Technical Environment Business Needs

Information Assets Technical Environment Business Needs

Information Assets Technical Environment Business Needs

Information Assets Technical Environment Business Needs

Understand what information you have and how its managed… What information do you have? Where is it? How is it organised and managed? Have you defined all your information assets?

An information asset is a body of information defined and managed as a single unit so that it can be understood, shared, protected and exploited effectively Understand what information you have and how its managed…

Understand how you need to use your information… Who needs to be able to find it? What do they need to be able to open it? How do they need to work with it? Can they understand what it is and what it is about? Can they trust that it is what they think it is?

Understand your technical environment… What IT systems do you have? What is their lifecycle? What hardware are they reliant on? What is their lifecycle? What file formats is your information in? What storage media are you using?

Define what you need for digital continuity… Usable = complete + available

Documenting what you know… Information Asset Register Configuration Management Database Maintenance as important as capture

Understanding DoRA… You have to build an: o Information Asset Register o Configuration Management Database What information do you need to capture? How can you maintain the relationships between the information assets and technology?

IAR Name and description Owners and users Retention period Usability requirements Technology dependencies CMDB Lifecycle Support and warranties Dependencies and relationships Owners and users Information assets

Over lunch…. Questions Confessions DROID demo

Stage 3: Risk Assessment

Managing digital continuity… 38 Maintain digital continuity Plan for action Define what you need Assess and manage risks

Information Assets Technical Environment Business Needs Digital Continuity

Identify your risks (and opportunities)… Do you know what information you have, where it is, what its for? Does the way you manage your information and IT environment keep your information usable as you need? Are there opportunities to get rid of information and technology you dont need?

Risk assessment… You can assess your whole organisation You can assess risks to particular assets – perhaps at point of change Regularly review and update risk assessments

Risk assessing DoRA… What risks to digital continuity is DoRA facing? How can you mitigate against them? Can you identify just FIVE mitigations to address all of the risks youve found? Feedback: What is your highest priority mitigation and what risks will this address?

Mitigation strategies… Change your : o technology o information o policies and procedures o Governance And test for continuity

Stage 4: Maintaining

Managing digital continuity… 45 Plan for action Define what you need Assess and manage risks Maintain digital continuity

Maintain your digital continuity… Plan for change o Build your digital continuity and usability requirements into your plans and processes o Manage your IT and information for future flexibility and agility Manage digital continuity through change o Change Projects to assess impact on information

Technology Change at DoRA… Supplier is withdrawing support for BlackHole 2.0. Three choices of what to do now: o Keep using the legacy system o Buy an off-the-shelf product o Build another bespoke system Assess the risk to digital continuity of your information from each option Identify potential mitigations in each case Feedback - Decide what option you would choose and why

Assessing the risks… Legacy technology hard to maintain – risks increase over time Bespoke technology becomes legacy eventually Bespoke technology requires specialist knowledge to maintain Off-the-shelf may not meet all business needs Off –the-shelf might still bring interoperability issues – can you migrate data in?

Organisational change at DoRA… Review of ALBs prompts reorganisation of DoRA with its agencies being closed, transferred or merged. Assess the risks to digital continuity from these changes Identify possible mitigations in each case Decide how you will tackle the operational process of managing this change Feedback – what are the key elements of your action plan?

Managing change … Think about prevention and preparation for change Manage the process Learn lessons Key things to remember: o Ownership o Usability requirements o Relationships between technology and information o Knowledge and skills needed o Mapping policies and procedures o Maintaining governance

Final Thoughts

What to take home with you… 1) Ownership is important – digital continuity needs to be a strategic objective recognised at the highest level. An SRO is needed to drive and co-ordinate action.

What to take home with you… 2) Cross-disciplinary approach – digital continuity can only be managed with collaboration across IT, IM, IA and change and project teams.

What to take home with you… 3) Prevention not restoration – preventing a loss of digital continuity is easier than restoring it – but learn from incidents to improve your risk management.

What to take home with you… 4) Focus on information usability – put how the business needs to use its information at the centre of your approach to managing digital continuity.

What to take home with you… 5) Embed in operational processes – make sure digital continuity management is part of existing IT, IM, IA, project and change management policies and processes.

And what to do now… 1) Find out more about digital continuity – understand the issues and how they affect your own organisation.

And what to do now… 2) Find out more about your organisation – understand the policies and processes in place for managing information, risk, technology and change.

And what to do now… 3) Build bridges and ask questions – identify who needs to work on digital continuity related issues and start connecting with them.

And what to do now… 4) Manage digital continuity as a key information risk – talk to the SIRO or information risk team and find out if they are aware of digital continuity and their responsibility to manage it.

And what to do now… 5) Advocate and influence upwards – influence as best you can, and push for a digital continuity SRO to be identified to drive this forwards.

62 Guidance Risk Assessment Self-Assessment Tool Procurement Framework DROID And how we can help…

Digital continuity… The ability to use your information in the way you need for as long as you need