SlideShare a Scribd company logo
1 of 46
Today’s Agenda
• The Scenario
• SharePoint Records Management
• Office 365 Records Management
• Hybrid
• Other Content Sources
• Solutions for Records
Managementhttps://erica.news/SPFEST18
On-Premises The Cloud
Key standards
ISO 16175
IS40
21 CFR Part 11
MoReq 2010
ISO 15489
SOX
HIPAA
FIPS 140-2
ANSI
VERS
NARA
DOD 5015.2
Requirement Plain English
Compliance policies need to be followed
for all data sources
In order to ensure compliance policies are followed on data, you need to
know the data exists.
Retain some content for a specific period
of time
You need to be able to categorize content to apply the correct retention
period. Retention = how long you keep it.
Dispose of content according to policy Once the retention period is over, you need to get rid of the content. This
sometimes involves an approval process.
Prove the content was deleted according
to policy
You need a stub, certificate of destruction, or some indication that the
content existed and followed all policies, for the auditor.
And Many More…
Don’t require the end users to do
anything!
They are not records management experts, and don’t fill out metadata. If
they do, it is often incorrect.
Term Plain English
File Plan The list of categories of data that you need to keep.
Retention Schedule How long you need to keep data in each category.
Disposition or Destruction Deleting the content.
Finalize a Record Locking the document so it can’t be edited.
Factor Records Center In-place records
Managing record retention The content organizer automatically puts new records
in the correct folder in the archive's file plan, based
on metadata.
There may be different policies for records and active
documents based on the current content type or
location.
Restrict which users can view
records
Yes. The archive specifies the permissions for the
record.
No. Permissions do not change when a document
becomes a record. However, you can restrict which
users can edit and delete records.
Ease of locating records (for
records managers)
Easier. All records are in one location. Harder. Records are spread across multiple
collaboration sites.
Maintain all document
versions as records
The user must explicitly send each version of a
document to the archive.
Automatic, assuming versioning is turned on.
Ease of locating information
(for team collaborators)
Harder, although a link to the document can be
added to the collaboration site when the document
becomes a record.
Easier.
Ability to audit records Yes. Dependent on audit policy of the collaboration site.
Administrative security A records manager can manage the records archive. Collaboration site administrators have permission to
manage records and active documents.
Ease of administration Separate site or farm for records. No additional site provisioning work beyond what is
already needed for the sites that have active
documents.
Source
Requirement Yes No
Compliance policies need to be followed for all data sources X
Retain some content for a specific period of time X
Dispose of content according to policy X
Prove the content was deleted according to policy X
Requires end users to do stuff X
PROS CONS
Meets the most basic records requirements Requires a lot of set up and configuration
Relies HEAVILY on end user actions
Can only manage SharePoint content
Labeling
Classify data across
your organization for
governance, and then
enforcing retention
rules based on that
classification.
Retention
Ensures that you retain
content as long as
required but no longer
than that.
Labels Retention Policies
Apply Retention X X
Event Based Retention X
Manage SharePoint, OneDrive, Groups, Exchange Email Content X X
Manage Microsoft Teams, Skype for Business, Exchange Public
Folders Content X
Manage Content as a Record (finalize) X
Apply Based on Sensitive Information X X
Apply Based on Specific Words and Phrases X X
Labels classify documents and can apply
retention. They can do the following:
• Delete content automatically.
• Retain content for a specific time period.
• Delete content once the retention period has passed.
• Trigger a disposition review
• Do nothing.
• Start the retention period from when content was
created, last modified, when the label was applied, or
when an event occurred.
Can be deployed to specific locations or the entire organization.
Entire
Locations
Include
or
Exclude
All Locations
SharePoint OneDrive for Business Groups Exchange Email
Sites
(up to 100 sites)
Accounts
(up to 1000)
Groups
(up to 100)
Recipients
(up to 1000)
Auto-applied based on sensitive information types
Auto-applied based on a search query
Auto-applied based on a document library location
If the label is… Then the label policy can be applied to…
Exchange SharePoint OneDrive Groups
Published to end users X X X X
Auto-applied based on sensitive
information types
X X
Auto-applied based on a query X X X X
When you create
auto-apply labels for
sensitive information,
you see the same list
of policy templates as
when you create a
data loss prevention
(DLP) policy.
Query-based labels use the Content
Search feature in the Office 365
Security & Compliance Center to
identify content.
You can search for a word or phrase
and use operators such as AND, OR,
and NOT.
Can only apply a default label to a
document library
Items inside a document or folder
set do inherit the default label
If you move an item with a default
label from one library to another
library with no default label, the
old default label is removed
A label that classifies
content as a record
needs to be applied
manually; it cannot
be auto-applied
For SharePoint
content, any user in
the default
Members group (the
Contribute
permission level)
can apply a record
label to content
Only the site
collection
administrator can
remove or change
that label after it's
been applied
If a label is a record
it locks the item so it
cannot be edited
For SharePoint
content, any user in
the default Members
group (the Contribute
permission level) can
apply a label
to content
If there are multiple rules that assign an auto-applied label and
the content meets the conditions of multiple rules, the label for
the oldest rule is assigned.
PERIOD. NO OTHER OPTION.
A Retention Policy is separate from a label.
It can do the following:
• Delete content automatically.
• Retain content for a specific time period.
• Delete content once the retention period has
passed.
• Do nothing.
• Start the retention period from when content
was created or last modified.
Entire
Locations
Include
or
Exclude
Exchange Email and Public Folders, SharePoint, OneDrive, and Office 365 Groups
SharePoint
OneDrive
for
Business
Groups
Exchange
Email
Sites
(up to 100
sites)
Accounts
(up to
1000)
Groups
(up to 100)
Recipients
(up to
1000)
Skype for
Business
Teams
Channel
Messages
Exchange
Public
Folders
Teams
Chats
Retention wins over deletion
Longest retention period wins
Explicit inclusion wins over implicit inclusion
Shortest deletion period wins
1. If the content is modified or deleted during the retention period
2. If the content is not modified or deleted during the retention period
2
1
Preservation
Hold Library
Document
Library
First-Stage
Recycle Bin
Second-Stage
Recycle Bin
Cleanup
Retention Period
User Purge Cleanup
Permanent
Deletion
Permanent
Deletion
93 Days
7 Days
PROS CONS
Simple content clean-up for non-records content Keeps documents for 93 days after disposition approval
Covers Skype for Business, Microsoft Teams, Exchange,
SharePoint, OneDrive, Groups
No certification of destruction
Great for companies that aren’t highly regulated or
government
No hierarchy of labels
Use to identify and action sensitive content Generic functionality that doesn’t meet local standards
Use for high-level classifications
Need to have an E3 or above or ADG SKU license for
automatic labelling
No automatic labelling for records
Have to apply document library labels to each location
Can only manage some Office 365 content
Requirement Yes No
Compliance policies need to be followed for all data sources
Retain some content for a specific period of time X
Dispose of content according to policy
Prove the content was deleted according to policy X
Requires end users to do stuff
On Premises Online
Content Types
Metadata
Search
DLP
OneDrive
Records Center Records Center
Flow
Other Workflow Other Workflow
PROS CONS
One set of content types and managed metadata
Need two records centers: one for on-premise and one for
cloud
One search index
Depending on how records management is set up, maybe a
lot of duplicate work
If using flow to move documents, can use on-premises or in
cloud
SERVICE
HAS RECORDS MANAGEMENT
CAPABILITY?
TRADITIONAL ECM YES
FILE SHARES
NO
GOOGLE DRIVE / G-SUITE
YES
BOX
YES
DROPBOX
NO
Requirement Yes No
Compliance policies need to be followed for all data sources
Retain some content for a specific period of time X
Dispose of content according to policy
Prove the content was deleted according to policy X
Requires end users to do stuff
Requirement Yes No
Compliance policies need to be followed for all data sources X
Retain some content for a specific period of time X
Dispose of content according to policy X
Prove the content was deleted according to policy X
Does not require end users to do stuff X
Erica.Toelle@RecordPoint.com
The SharePoint Records Management Story

More Related Content

What's hot

Agile Enterprise Data Model & Data Management Solution
Agile Enterprise Data Model & Data Management SolutionAgile Enterprise Data Model & Data Management Solution
Agile Enterprise Data Model & Data Management SolutionA.I. Consultancy Ltd
 
CollabDaysBE - Microsoft Purview Information Protection demystified
CollabDaysBE - Microsoft Purview Information Protection demystifiedCollabDaysBE - Microsoft Purview Information Protection demystified
CollabDaysBE - Microsoft Purview Information Protection demystifiedAlbert Hoitingh
 
M365 edrm information management strategy
M365 edrm information management strategyM365 edrm information management strategy
M365 edrm information management strategySimon Rawson
 
The Gartner IAM Program Maturity Model
The Gartner IAM Program Maturity ModelThe Gartner IAM Program Maturity Model
The Gartner IAM Program Maturity ModelSarah Moore
 
Microsoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonMicrosoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonJoel Oleson
 
Sharepoint metadata workshop
Sharepoint metadata workshopSharepoint metadata workshop
Sharepoint metadata workshopSam Marshall
 
Microsoft Information Protection demystified Albert Hoitingh
Microsoft Information Protection demystified Albert HoitinghMicrosoft Information Protection demystified Albert Hoitingh
Microsoft Information Protection demystified Albert HoitinghAlbert Hoitingh
 
M365 Structure & Document Managment Architecture Design Overview - Innovate ...
M365 Structure  & Document Managment Architecture Design Overview - Innovate ...M365 Structure  & Document Managment Architecture Design Overview - Innovate ...
M365 Structure & Document Managment Architecture Design Overview - Innovate ...Innovate Vancouver
 
SharePoint Folders vs. Metadata Best Practices
SharePoint Folders vs. Metadata Best PracticesSharePoint Folders vs. Metadata Best Practices
SharePoint Folders vs. Metadata Best PracticesChris Woodill
 
Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...Albert Hoitingh
 
March 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know WebinarMarch 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know WebinarRobert Crane
 
Salesforce Tableau CRM - Quick Overview
Salesforce Tableau CRM - Quick OverviewSalesforce Tableau CRM - Quick Overview
Salesforce Tableau CRM - Quick OverviewHarshala Shewale ☁
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDrew Madelung
 
Office 365 data loss prevention
Office 365 data loss preventionOffice 365 data loss prevention
Office 365 data loss preventionssuser1eca7d
 
Overview of Microsoft Teams and Data Loss Prevention(DLP)
Overview of Microsoft Teams  and Data Loss Prevention(DLP)Overview of Microsoft Teams  and Data Loss Prevention(DLP)
Overview of Microsoft Teams and Data Loss Prevention(DLP)Radhakrishnan Govindan
 
Utilizing SharePoint for Project Management
Utilizing SharePoint for Project ManagementUtilizing SharePoint for Project Management
Utilizing SharePoint for Project ManagementGregory Zelfond
 
Document Management in SharePoint without folders - Introduction to Metadata
Document Management in SharePoint without folders - Introduction to MetadataDocument Management in SharePoint without folders - Introduction to Metadata
Document Management in SharePoint without folders - Introduction to MetadataGregory Zelfond
 

What's hot (20)

Agile Enterprise Data Model & Data Management Solution
Agile Enterprise Data Model & Data Management SolutionAgile Enterprise Data Model & Data Management Solution
Agile Enterprise Data Model & Data Management Solution
 
CollabDaysBE - Microsoft Purview Information Protection demystified
CollabDaysBE - Microsoft Purview Information Protection demystifiedCollabDaysBE - Microsoft Purview Information Protection demystified
CollabDaysBE - Microsoft Purview Information Protection demystified
 
M365 edrm information management strategy
M365 edrm information management strategyM365 edrm information management strategy
M365 edrm information management strategy
 
The Gartner IAM Program Maturity Model
The Gartner IAM Program Maturity ModelThe Gartner IAM Program Maturity Model
The Gartner IAM Program Maturity Model
 
Microsoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonMicrosoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel Oleson
 
Sharepoint metadata workshop
Sharepoint metadata workshopSharepoint metadata workshop
Sharepoint metadata workshop
 
Microsoft Information Protection demystified Albert Hoitingh
Microsoft Information Protection demystified Albert HoitinghMicrosoft Information Protection demystified Albert Hoitingh
Microsoft Information Protection demystified Albert Hoitingh
 
M365 Structure & Document Managment Architecture Design Overview - Innovate ...
M365 Structure  & Document Managment Architecture Design Overview - Innovate ...M365 Structure  & Document Managment Architecture Design Overview - Innovate ...
M365 Structure & Document Managment Architecture Design Overview - Innovate ...
 
SharePoint Folders vs. Metadata Best Practices
SharePoint Folders vs. Metadata Best PracticesSharePoint Folders vs. Metadata Best Practices
SharePoint Folders vs. Metadata Best Practices
 
Sharepoint Basics
Sharepoint BasicsSharepoint Basics
Sharepoint Basics
 
Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...
 
March 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know WebinarMarch 2023 CIAOPS Need to Know Webinar
March 2023 CIAOPS Need to Know Webinar
 
Salesforce Tableau CRM - Quick Overview
Salesforce Tableau CRM - Quick OverviewSalesforce Tableau CRM - Quick Overview
Salesforce Tableau CRM - Quick Overview
 
Thriving in the Crisis Situation
Thriving in the Crisis SituationThriving in the Crisis Situation
Thriving in the Crisis Situation
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
 
Office 365 data loss prevention
Office 365 data loss preventionOffice 365 data loss prevention
Office 365 data loss prevention
 
Salesforce Einstein Analytics
Salesforce Einstein AnalyticsSalesforce Einstein Analytics
Salesforce Einstein Analytics
 
Overview of Microsoft Teams and Data Loss Prevention(DLP)
Overview of Microsoft Teams  and Data Loss Prevention(DLP)Overview of Microsoft Teams  and Data Loss Prevention(DLP)
Overview of Microsoft Teams and Data Loss Prevention(DLP)
 
Utilizing SharePoint for Project Management
Utilizing SharePoint for Project ManagementUtilizing SharePoint for Project Management
Utilizing SharePoint for Project Management
 
Document Management in SharePoint without folders - Introduction to Metadata
Document Management in SharePoint without folders - Introduction to MetadataDocument Management in SharePoint without folders - Introduction to Metadata
Document Management in SharePoint without folders - Introduction to Metadata
 

Similar to The SharePoint Records Management Story

Create a Compliance Strategy for Office 365
Create a Compliance Strategy for Office 365Create a Compliance Strategy for Office 365
Create a Compliance Strategy for Office 365Erica Toelle
 
Records Management for Microsoft Teams and Groups
Records Management for Microsoft Teams and GroupsRecords Management for Microsoft Teams and Groups
Records Management for Microsoft Teams and GroupsRecordPoint
 
Understanding Compliance in Office 365
Understanding Compliance in Office 365Understanding Compliance in Office 365
Understanding Compliance in Office 365Erica Toelle
 
Success with SharePoint Records Management | RecordLion
Success with SharePoint Records Management | RecordLionSuccess with SharePoint Records Management | RecordLion
Success with SharePoint Records Management | RecordLionRecordLion
 
SharePoint Records Management - Office 365
SharePoint Records Management - Office 365SharePoint Records Management - Office 365
SharePoint Records Management - Office 365InnoTech
 
SPS Denver SharePoint Wizardry 2018
SPS Denver SharePoint Wizardry 2018SPS Denver SharePoint Wizardry 2018
SPS Denver SharePoint Wizardry 2018Nate Chamberlain
 
BCS ISG 24-05-18 - labelling your data in the cloud
BCS ISG  24-05-18 - labelling your data in the cloudBCS ISG  24-05-18 - labelling your data in the cloud
BCS ISG 24-05-18 - labelling your data in the cloudPeter Baddeley
 
SPEVO13 - IW509 - Records Management and Search
SPEVO13 - IW509 - Records Management and SearchSPEVO13 - IW509 - Records Management and Search
SPEVO13 - IW509 - Records Management and SearchJohn F. Holliday
 
Who says you can't do records management in SharePoint?
Who says you can't do records management in SharePoint?Who says you can't do records management in SharePoint?
Who says you can't do records management in SharePoint?John F. Holliday
 
10 Things You'll Need to Succeed with Information Governance and SharePoint
10 Things You'll Need to Succeed with Information Governance and SharePoint10 Things You'll Need to Succeed with Information Governance and SharePoint
10 Things You'll Need to Succeed with Information Governance and SharePointRecordLion
 
Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...
Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...
Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...Innovate Vancouver
 
Archiving and compliance for SharePoint on premise and online
Archiving and compliance for SharePoint on premise and onlineArchiving and compliance for SharePoint on premise and online
Archiving and compliance for SharePoint on premise and onlineOlga Siamashka
 
DEV212 SharePoint 2010 Records Management Development
DEV212 SharePoint 2010 Records Management DevelopmentDEV212 SharePoint 2010 Records Management Development
DEV212 SharePoint 2010 Records Management DevelopmentJohn F. Holliday
 
Document management in rto know how 22-05-14 not live
Document management in rto know how   22-05-14 not liveDocument management in rto know how   22-05-14 not live
Document management in rto know how 22-05-14 not liveEmily Hodge
 
office365- discovery and compliance
office365- discovery and complianceoffice365- discovery and compliance
office365- discovery and complianceJuntarou Doi
 
SPSTC18 Laying Down the Law - Governing Your Data in O365
SPSTC18  Laying Down the Law - Governing Your Data in O365SPSTC18  Laying Down the Law - Governing Your Data in O365
SPSTC18 Laying Down the Law - Governing Your Data in O365David Broussard
 
SharePoint Governance 101 - Austin O365 & SharePoint User Group
SharePoint Governance 101  - Austin O365 & SharePoint User GroupSharePoint Governance 101  - Austin O365 & SharePoint User Group
SharePoint Governance 101 - Austin O365 & SharePoint User GroupJim Adcock
 
SharePoint Governance 101 - OKCSUG
SharePoint Governance 101 - OKCSUGSharePoint Governance 101 - OKCSUG
SharePoint Governance 101 - OKCSUGJim Adcock
 

Similar to The SharePoint Records Management Story (20)

Create a Compliance Strategy for Office 365
Create a Compliance Strategy for Office 365Create a Compliance Strategy for Office 365
Create a Compliance Strategy for Office 365
 
Records Management for Microsoft Teams and Groups
Records Management for Microsoft Teams and GroupsRecords Management for Microsoft Teams and Groups
Records Management for Microsoft Teams and Groups
 
Understanding Compliance in Office 365
Understanding Compliance in Office 365Understanding Compliance in Office 365
Understanding Compliance in Office 365
 
Success with SharePoint Records Management | RecordLion
Success with SharePoint Records Management | RecordLionSuccess with SharePoint Records Management | RecordLion
Success with SharePoint Records Management | RecordLion
 
SharePoint Records Management - Office 365
SharePoint Records Management - Office 365SharePoint Records Management - Office 365
SharePoint Records Management - Office 365
 
SPS Denver SharePoint Wizardry 2018
SPS Denver SharePoint Wizardry 2018SPS Denver SharePoint Wizardry 2018
SPS Denver SharePoint Wizardry 2018
 
BCS ISG 24-05-18 - labelling your data in the cloud
BCS ISG  24-05-18 - labelling your data in the cloudBCS ISG  24-05-18 - labelling your data in the cloud
BCS ISG 24-05-18 - labelling your data in the cloud
 
SPEVO13 - IW509 - Records Management and Search
SPEVO13 - IW509 - Records Management and SearchSPEVO13 - IW509 - Records Management and Search
SPEVO13 - IW509 - Records Management and Search
 
Who says you can't do records management in SharePoint?
Who says you can't do records management in SharePoint?Who says you can't do records management in SharePoint?
Who says you can't do records management in SharePoint?
 
10 Things You'll Need to Succeed with Information Governance and SharePoint
10 Things You'll Need to Succeed with Information Governance and SharePoint10 Things You'll Need to Succeed with Information Governance and SharePoint
10 Things You'll Need to Succeed with Information Governance and SharePoint
 
Nick kellett share point summit 2011 presentation
Nick kellett share point summit 2011 presentationNick kellett share point summit 2011 presentation
Nick kellett share point summit 2011 presentation
 
Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...
Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...
Enterprise SharePoint Program - Architecture Models - (Innovate Vancouver) - ...
 
Archiving and compliance for SharePoint on premise and online
Archiving and compliance for SharePoint on premise and onlineArchiving and compliance for SharePoint on premise and online
Archiving and compliance for SharePoint on premise and online
 
DEV212 SharePoint 2010 Records Management Development
DEV212 SharePoint 2010 Records Management DevelopmentDEV212 SharePoint 2010 Records Management Development
DEV212 SharePoint 2010 Records Management Development
 
Document management in rto know how 22-05-14 not live
Document management in rto know how   22-05-14 not liveDocument management in rto know how   22-05-14 not live
Document management in rto know how 22-05-14 not live
 
office365- discovery and compliance
office365- discovery and complianceoffice365- discovery and compliance
office365- discovery and compliance
 
Box to OneDrive Migration
Box to OneDrive MigrationBox to OneDrive Migration
Box to OneDrive Migration
 
SPSTC18 Laying Down the Law - Governing Your Data in O365
SPSTC18  Laying Down the Law - Governing Your Data in O365SPSTC18  Laying Down the Law - Governing Your Data in O365
SPSTC18 Laying Down the Law - Governing Your Data in O365
 
SharePoint Governance 101 - Austin O365 & SharePoint User Group
SharePoint Governance 101  - Austin O365 & SharePoint User GroupSharePoint Governance 101  - Austin O365 & SharePoint User Group
SharePoint Governance 101 - Austin O365 & SharePoint User Group
 
SharePoint Governance 101 - OKCSUG
SharePoint Governance 101 - OKCSUGSharePoint Governance 101 - OKCSUG
SharePoint Governance 101 - OKCSUG
 

More from Erica Toelle

Create Your End User Adoption Strategy - Office 365 Edition
Create Your End User Adoption Strategy - Office 365 EditionCreate Your End User Adoption Strategy - Office 365 Edition
Create Your End User Adoption Strategy - Office 365 EditionErica Toelle
 
High Value Scenarios for Microsoft Teams
High Value Scenarios for Microsoft TeamsHigh Value Scenarios for Microsoft Teams
High Value Scenarios for Microsoft TeamsErica Toelle
 
Plan to Migrate to SharePoint Online
Plan to Migrate to SharePoint OnlinePlan to Migrate to SharePoint Online
Plan to Migrate to SharePoint OnlineErica Toelle
 
OneDrive for Business: Much More Than a File Share
OneDrive for Business: Much More Than a File ShareOneDrive for Business: Much More Than a File Share
OneDrive for Business: Much More Than a File ShareErica Toelle
 
SharePoint Business Governance
SharePoint Business GovernanceSharePoint Business Governance
SharePoint Business GovernanceErica Toelle
 
Design a SharePoint Program for Ongoing Operational Excellence
Design a SharePoint Program for Ongoing Operational ExcellenceDesign a SharePoint Program for Ongoing Operational Excellence
Design a SharePoint Program for Ongoing Operational ExcellenceErica Toelle
 
Create Your End User Adoption Strategy
Create Your End User Adoption StrategyCreate Your End User Adoption Strategy
Create Your End User Adoption StrategyErica Toelle
 

More from Erica Toelle (7)

Create Your End User Adoption Strategy - Office 365 Edition
Create Your End User Adoption Strategy - Office 365 EditionCreate Your End User Adoption Strategy - Office 365 Edition
Create Your End User Adoption Strategy - Office 365 Edition
 
High Value Scenarios for Microsoft Teams
High Value Scenarios for Microsoft TeamsHigh Value Scenarios for Microsoft Teams
High Value Scenarios for Microsoft Teams
 
Plan to Migrate to SharePoint Online
Plan to Migrate to SharePoint OnlinePlan to Migrate to SharePoint Online
Plan to Migrate to SharePoint Online
 
OneDrive for Business: Much More Than a File Share
OneDrive for Business: Much More Than a File ShareOneDrive for Business: Much More Than a File Share
OneDrive for Business: Much More Than a File Share
 
SharePoint Business Governance
SharePoint Business GovernanceSharePoint Business Governance
SharePoint Business Governance
 
Design a SharePoint Program for Ongoing Operational Excellence
Design a SharePoint Program for Ongoing Operational ExcellenceDesign a SharePoint Program for Ongoing Operational Excellence
Design a SharePoint Program for Ongoing Operational Excellence
 
Create Your End User Adoption Strategy
Create Your End User Adoption StrategyCreate Your End User Adoption Strategy
Create Your End User Adoption Strategy
 

Recently uploaded

The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 

The SharePoint Records Management Story

  • 1.
  • 2. Today’s Agenda • The Scenario • SharePoint Records Management • Office 365 Records Management • Hybrid • Other Content Sources • Solutions for Records Managementhttps://erica.news/SPFEST18
  • 4. Key standards ISO 16175 IS40 21 CFR Part 11 MoReq 2010 ISO 15489 SOX HIPAA FIPS 140-2 ANSI VERS NARA DOD 5015.2
  • 5. Requirement Plain English Compliance policies need to be followed for all data sources In order to ensure compliance policies are followed on data, you need to know the data exists. Retain some content for a specific period of time You need to be able to categorize content to apply the correct retention period. Retention = how long you keep it. Dispose of content according to policy Once the retention period is over, you need to get rid of the content. This sometimes involves an approval process. Prove the content was deleted according to policy You need a stub, certificate of destruction, or some indication that the content existed and followed all policies, for the auditor. And Many More… Don’t require the end users to do anything! They are not records management experts, and don’t fill out metadata. If they do, it is often incorrect.
  • 6. Term Plain English File Plan The list of categories of data that you need to keep. Retention Schedule How long you need to keep data in each category. Disposition or Destruction Deleting the content. Finalize a Record Locking the document so it can’t be edited.
  • 7.
  • 8.
  • 9. Factor Records Center In-place records Managing record retention The content organizer automatically puts new records in the correct folder in the archive's file plan, based on metadata. There may be different policies for records and active documents based on the current content type or location. Restrict which users can view records Yes. The archive specifies the permissions for the record. No. Permissions do not change when a document becomes a record. However, you can restrict which users can edit and delete records. Ease of locating records (for records managers) Easier. All records are in one location. Harder. Records are spread across multiple collaboration sites. Maintain all document versions as records The user must explicitly send each version of a document to the archive. Automatic, assuming versioning is turned on. Ease of locating information (for team collaborators) Harder, although a link to the document can be added to the collaboration site when the document becomes a record. Easier. Ability to audit records Yes. Dependent on audit policy of the collaboration site. Administrative security A records manager can manage the records archive. Collaboration site administrators have permission to manage records and active documents. Ease of administration Separate site or farm for records. No additional site provisioning work beyond what is already needed for the sites that have active documents. Source
  • 10. Requirement Yes No Compliance policies need to be followed for all data sources X Retain some content for a specific period of time X Dispose of content according to policy X Prove the content was deleted according to policy X Requires end users to do stuff X
  • 11. PROS CONS Meets the most basic records requirements Requires a lot of set up and configuration Relies HEAVILY on end user actions Can only manage SharePoint content
  • 12.
  • 13. Labeling Classify data across your organization for governance, and then enforcing retention rules based on that classification. Retention Ensures that you retain content as long as required but no longer than that.
  • 14. Labels Retention Policies Apply Retention X X Event Based Retention X Manage SharePoint, OneDrive, Groups, Exchange Email Content X X Manage Microsoft Teams, Skype for Business, Exchange Public Folders Content X Manage Content as a Record (finalize) X Apply Based on Sensitive Information X X Apply Based on Specific Words and Phrases X X
  • 15.
  • 16. Labels classify documents and can apply retention. They can do the following: • Delete content automatically. • Retain content for a specific time period. • Delete content once the retention period has passed. • Trigger a disposition review • Do nothing. • Start the retention period from when content was created, last modified, when the label was applied, or when an event occurred.
  • 17. Can be deployed to specific locations or the entire organization. Entire Locations Include or Exclude All Locations SharePoint OneDrive for Business Groups Exchange Email Sites (up to 100 sites) Accounts (up to 1000) Groups (up to 100) Recipients (up to 1000)
  • 18. Auto-applied based on sensitive information types Auto-applied based on a search query Auto-applied based on a document library location
  • 19. If the label is… Then the label policy can be applied to… Exchange SharePoint OneDrive Groups Published to end users X X X X Auto-applied based on sensitive information types X X Auto-applied based on a query X X X X
  • 20. When you create auto-apply labels for sensitive information, you see the same list of policy templates as when you create a data loss prevention (DLP) policy.
  • 21. Query-based labels use the Content Search feature in the Office 365 Security & Compliance Center to identify content. You can search for a word or phrase and use operators such as AND, OR, and NOT.
  • 22. Can only apply a default label to a document library Items inside a document or folder set do inherit the default label If you move an item with a default label from one library to another library with no default label, the old default label is removed
  • 23. A label that classifies content as a record needs to be applied manually; it cannot be auto-applied For SharePoint content, any user in the default Members group (the Contribute permission level) can apply a record label to content Only the site collection administrator can remove or change that label after it's been applied If a label is a record it locks the item so it cannot be edited
  • 24. For SharePoint content, any user in the default Members group (the Contribute permission level) can apply a label to content
  • 25. If there are multiple rules that assign an auto-applied label and the content meets the conditions of multiple rules, the label for the oldest rule is assigned. PERIOD. NO OTHER OPTION.
  • 26. A Retention Policy is separate from a label. It can do the following: • Delete content automatically. • Retain content for a specific time period. • Delete content once the retention period has passed. • Do nothing. • Start the retention period from when content was created or last modified.
  • 27. Entire Locations Include or Exclude Exchange Email and Public Folders, SharePoint, OneDrive, and Office 365 Groups SharePoint OneDrive for Business Groups Exchange Email Sites (up to 100 sites) Accounts (up to 1000) Groups (up to 100) Recipients (up to 1000) Skype for Business Teams Channel Messages Exchange Public Folders Teams Chats
  • 28. Retention wins over deletion Longest retention period wins Explicit inclusion wins over implicit inclusion Shortest deletion period wins
  • 29. 1. If the content is modified or deleted during the retention period 2. If the content is not modified or deleted during the retention period 2 1 Preservation Hold Library Document Library First-Stage Recycle Bin Second-Stage Recycle Bin Cleanup Retention Period User Purge Cleanup Permanent Deletion Permanent Deletion 93 Days 7 Days
  • 30. PROS CONS Simple content clean-up for non-records content Keeps documents for 93 days after disposition approval Covers Skype for Business, Microsoft Teams, Exchange, SharePoint, OneDrive, Groups No certification of destruction Great for companies that aren’t highly regulated or government No hierarchy of labels Use to identify and action sensitive content Generic functionality that doesn’t meet local standards Use for high-level classifications Need to have an E3 or above or ADG SKU license for automatic labelling No automatic labelling for records Have to apply document library labels to each location Can only manage some Office 365 content
  • 31. Requirement Yes No Compliance policies need to be followed for all data sources Retain some content for a specific period of time X Dispose of content according to policy Prove the content was deleted according to policy X Requires end users to do stuff
  • 32.
  • 33. On Premises Online Content Types Metadata Search DLP OneDrive Records Center Records Center Flow Other Workflow Other Workflow
  • 34. PROS CONS One set of content types and managed metadata Need two records centers: one for on-premise and one for cloud One search index Depending on how records management is set up, maybe a lot of duplicate work If using flow to move documents, can use on-premises or in cloud
  • 35.
  • 36. SERVICE HAS RECORDS MANAGEMENT CAPABILITY? TRADITIONAL ECM YES FILE SHARES NO GOOGLE DRIVE / G-SUITE YES BOX YES DROPBOX NO
  • 37.
  • 38. Requirement Yes No Compliance policies need to be followed for all data sources Retain some content for a specific period of time X Dispose of content according to policy Prove the content was deleted according to policy X Requires end users to do stuff
  • 39.
  • 40.
  • 41.
  • 42.
  • 43. Requirement Yes No Compliance policies need to be followed for all data sources X Retain some content for a specific period of time X Dispose of content according to policy X Prove the content was deleted according to policy X Does not require end users to do stuff X
  • 44.