Complying with data storage and retention laws - it makes good business sense

June 2011 Security Services & Risk Management, Information Security, Financial (Industry)

As the world becomes increasingly digitalised, organisations are storing more and more data electronically, much of which is mission critical and essential to running their business. The integral nature of this data to the business world, as well as events such as the Enron debacle, led governments around the world to begin passing various pieces of legislation around the protection of electronically stored information.

Compliance with legislation in this regard has forced organisations around the world to examine their data policies and adopt new guidelines for the retention, processing and destruction of electronic records and communication. One of the most notable regulations not only for the United States where this law was passed but for organisations around the world, particularly those is the financial sector, was Sarbanes-Oxley, or SOX.

Since the introduction of this regulation there have been many others from various countries, all of which affect multinational corporations or any business which has dealings with these countries. South Africa is no exception, and the most notable piece of law in this regard is the Electronic Communications and Transactions (ECT) Act which came into effect in August 2002 and is aimed at creating a legal framework for governing electronic documentation and transactions. The South African Revenue Service (SARS) also requires that companies keep documentation for a minimum of five years for tax purposes, and the Johannesburg Stock Exchange (JSE) has its own regulations around data retention that listed companies need to comply with.

With all of these regulations that must be adhered to at the risk of strict financial and business penalties, compliance has become not so much a matter of sticking to the letter of the law, but more about business continuity, which after all was the reason behind these laws being imposed worldwide in the first place. However these laws have also meant that requirements for data storage have increased dramatically, as in many cases, for instance the legal profession, they require all electronic documentation and communications to be kept, even junk e-mails and spam. The financial sector also has very strict guidelines as to what information must be kept and for how long, and these regulations mean that the required amount of storage continues to increase along with the volumes of electronic data.

One of the major issues that impacts data storage is having the incorrect software for backups, which results in duplicate copies of the same documents and communications being stored, wasting space and as a result costing money that need not be spent on excessive storage capacity. By introducing software with de-duplication technology, organisations can ensure that only one copy of electronic data will be stored, reducing space requirements dramatically.

The reality is that more laws governing electronic data are in the pipeline, and businesses need to be able to keep their information securely in order to comply. However this does not mean that data retention needs to cost the earth, as a smart strategy around backup and retention can not only aid in compliance but can safeguard the continuity of the business by ensuring that mission critical data is always available for recovery should a crisis occur.

Storage is however not a ‘one size fits all’ technology, and there are various solutions available, including disk storage, tape storage and even cloud storage technology, with both on-site and off-site options available.

Which solution is best for any particular organisation depends on the size and needs of the business, so it is advisable to deal with a backup and security expert who can help to ensure that the solutions that are put into place will meet the needs of today and into the future.

Storage, backup and recovery should form part of strategic business planning to ensure that current and future needs can be met, that businesses comply with all of the regulations related to their industry and business dealings, and that the correct software is in place to optimise the effectiveness of storage solutions and minimise the impact to the bottom line while still remaining effective and ensuring business continuity. It just makes good business sense.

Fred Mitchell, Symantec Division manager at Drive Control Corporation
Fred Mitchell, Symantec Division manager at Drive Control Corporation

For more information contact Fred Mitchell, Drive Control Corporation, +27 (0)11 201 8927, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Keeping safety central to enterprise risk management
Zulu Consulting Security Services & Risk Management
[Sponsored] As employee safety becomes an ever-more critical aspect of corporate risk management, Risk-IO assists risk managers in ensuring a safe working environment, whether in an industrial setting, an office, or anywhere.

Read more...
Empower individuals to control their biometric data
Information Security Access Control & Identity Management Security Services & Risk Management
What if your biometrics, now embedded in devices, workplaces, and airports, promising seamless access and enhanced security, was your greatest vulnerability in a cyberattack? Cybercriminals are focusing on knowing where biometric data is stored.

Read more...
Strategies for combating insider threats
Information Security Security Services & Risk Management
In Africa, insider threats pose an increasingly significant risk to businesses, driven by economic uncertainty, labour disputes, and rapid digital transformation. These threats can arise from various sources, including disgruntled employees and compromised third-party service providers

Read more...
World-first safe K9 training for drug detection
Technews Publishing SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Government and Parastatal (Industry)
The Braveheart Bio-Dog Academy recently announced the results of its scientific research into training dogs to accurately detect drugs and explosives without harming either the dogs or their handlers.

Read more...
New firearms training modules from ITA
News & Events Security Services & Risk Management
The International Firearm Training Academy has launched two new firearms training modules to support career development in the firearms industry: the Maintenance Fitter and the Firearms Custodian modules.

Read more...
Empower individuals to control their biometric data
Information Security Access Control & Identity Management Security Services & Risk Management
What if your biometrics, now embedded in devices, workplaces, and airports, promising seamless access and enhanced security, was your greatest vulnerability in a cyberattack? Cybercriminals are focusing on knowing where biometric data is stored.

Read more...
Background checks: risk levels and compliance
iFacts Access Control & Identity Management Security Services & Risk Management
Conducting background checks is a vital step in the hiring process for employers or when engaging service providers; however, it is crucial to understand the legal framework and regulations governing these checks.

Read more...
Identity is a cyber issue
Access Control & Identity Management Information Security
Identity and access management telemetry has emerged as the most common source of early threat detection, responsible for seven of the top 10 indicators of compromise leading to security investigations.

Read more...
On the ball or unaware
Technews Publishing Information Security Security Services & Risk Management
Whether an organisation is operating at a high level of information security maturity or has dangerous vulnerabilities that could put an entire business at risk, advanced, strategic penetration testing can uncover its true state of IT security.

Read more...
The bane of burnout
Editor's Choice Security Services & Risk Management
The World Economic Forum has recently formally acknowledged burnout as an occupational syndrome, giving it a status that is even more worthy of being taken seriously and resolved as quickly as possible.

Read more...