Download presentation
Presentation is loading. Please wait.
Published byUgo Paolini Modified over 6 years ago
1
IT Preservation Holds and Public Information Requests
eDiscovery Willis Marti CISO Zachary Cox Senior IT Policy Analyst
2
Agenda Introduction IT Preservation Holds (OGC)
Public Information Requests (Open Records)
3
Why is CISO involved? Bridge communication gap between OGC and university IT staff Validate and authorize ESI preservation and collection in accordance to university rules, SAPs, and information security controls Texas A&M Information Security Control AC-5 Separation of Duties
4
Definition “Electronic discovery (also E-discovery or ediscovery) refers to discovery in legal proceedings such as litigation, government investigations, or Freedom of Information Act requests, where the information sought is in electronic format (often referred to as electronically stored information or ESI).” - Various (2009). Eoghan Casey, ed. Handbook of Digital Forensics and Investigation. Academic Press. p. 567. ISBN
5
The eDiscovery Lifecycle
Identification Preservation Collection Processing Review
6
Public Information Requests
Two Similar Processes IT Preservation Holds Public Information Requests Legal proceeding Litigation Texas Public Information Act (TPIA) requests Process Owner Office of General Council TAMU Open Records ESI Coordinator TAMU CISO TAMU unit liaison Time to Resolution Months to Years 10 Days eDiscovery Solution AccessData eDiscovery Exchange eDiscovery, manual searches
7
IT Preservation Holds - Overview
TAMUS IT Preservation Standard Roles eDiscovery Lifecycle AccessData eDiscovery
8
IT Preservation Holds - Roles
ESI Preservation Coordinator Chief Information Security Officer Preservation Personnel Texas A&M IT staff Unit IT staff TAMU Human Resources Provost Named Person Custodians identified as having ESI to be preserved
9
IT Preservation Holds - eDiscovery
Variables OGC instructions to CISO for ESI preservation and collection vary by: Case Attorney and paralegal assistant Usage of AccessData Not all TAMU custodians have mailboxes on Exchange Shared Service
10
IT Preservation Holds - eDiscovery
Phase 1: Identification Notifications OGC to CISO: Notice to Identify IT Staff OGC to IT Staff: Notice to IT Personnel OGC to Custodian: Notice to Preserve Data Data Sources University and unit IT Staff knowledge Exchange mailbox, network shares, etc Custodian e-discovery questionnaire answers In-depth knowledge of the data, personal devices and cloud services, etc
11
IT Preservation Holds - eDiscovery
Phase 2: Preservation Texas A&M IT Enable “In-Place Hold” on Exchange Shared Service mailbox (as applicable) Enable NetID hold through Identity Management Office Enable holds on all identified Texas A&M IT services Unit IT Custodian
12
IT Preservation Holds - eDiscovery
Phase 3: Collection Texas A&M IT Prepare ESI for collection CISO delivers all ESI to OGC per their instructions Unit IT and Custodian CISO and Unit IT will make arrangements for transfer Chain of Custody form required
13
AccessData eDiscovery
Fully-featured eDiscovery tool Adopted early-mid CY 2016 for some new litigation matters Instance owned by OGC Hosted on Texas A&M IT infrastructure User accounts limited to OGC discretion Requires significant training to utilize effectively Not for Public Information Requests
14
IT Preservation Holds - Notice to IT Personnel
15
IT Preservation Holds - Active Holds
16
IT Preservation Holds - Active Holds
17
IT Sample Custodian Notice
18
Public Information Requests - Overview
Short timeframe with hard deadlines (10 Days) Roles and Responsibilities Challenges for eDiscovery Streamlining eDiscovery Defining Search Criteria for Exchange Reviewing, correcting, and submitting Exchange search results
19
Public Information Requests - Timeframe
By law, Texas A&M University has 10 days to provide requested information after initial request Includes time for coordination between Open Records, unit liaisons, unit IT staff, and TAMU IT. Must also factor time to review and remove extraneous search results
20
Public Information Requests - Roles
Open Records Receives request Coordinates with unit liaisons Reviews results and finalizes PIR Unit Liaison Coordinates with unit IT staff and TAMU IT Reviews results before submitting to Open Records May only coordinate and receive data for own unit TAMU IT Performs extraction of data per unit liaison criteria on relevant TAMU IT services (e.g. Exchange) Offers SME expertise (where applicable)
21
Challenges for eDiscovery
PIRs can be vague or overly-specific Unit liaisons are responsible for identifying search criteria. The better the search criteria, the better the search results Not all potential data sources may be known Specifically file shares, relevant data locations, shared mailboxes is “easy”
22
Challenges for eDiscovery (cont.)
eDiscovery tools and techniques are fragmented Exchange: In-Place eDiscovery search Hodgepodge of solutions for searching other data sources Implementing AccessData or similar solution might be too cumbersome in a tight time frame PIRs sometimes evolve into litigation, minimal verbosity is preferred
23
Streamlining eDiscovery
Ensure operational inefficiencies are minimized Communicate efficient search criteria for Exchange search Be proactive in understanding customer data and the surrounding IT environment
24
Defining Search Criteria for Exchange
Texas A&M IT CANNOT define search criteria for you. Suggestions may be offered, but must be confirmed by unit liaison. Fields Mailbox to search Keywords Can be layered using order of operations AND, OR, NOT, NEAR Start and end dates Senders and Recipients
25
Example Request: “I want all s between the provost and president regarding the expected number of graduates in Fall 2016.” Mailbox Keywords (“graduates” OR “students”) AND (“number” OR “expected” OR “count” OR “total”) AND (“fall” AND “2016”) Date Range None is specified. Search for all. From To Leave blank. Using just the “From” will limit extraneous .
26
Public Information Requests - Review
After Exchange is extracted, PST files will be sent back to units immediately. Unit liaisons should open returned PST files and validate the search results If severely erroneous search results (thousands of hits), work with TAMU IT to refine search criteria. Remove extraneous s Once validated, send to Open Records
27
Questions?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.