Top Banner
Adhering to appropriate content standards and frameworks Ark EDRM Evolution Conference October Sydney 2007
21
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Privacy ark oct 2007

Adhering to appropriate content standards and

frameworks

Ark EDRM Evolution Conference October Sydney 2007

Page 2: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Information management governance

Page 3: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y What am l covering today?

“governance is a multi-faceted discipline that not only includes the formulation and implementation of strategy, but the establishment of systems and processes that enable effective risk management as well as legal and regulatory compliance.”

ASX Corporate Governance Council (2003)

“information governance is emerging as a critical competency”

Gartner (2007)

Page 4: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y The governance framework of ECM……

“the audit identified that there is an increasing range of legislation, standards, policies and guidance that is issued by a number of Australian Government entities that has recordkeeping implications. The status of this material ranged from mandatory legislative requirements to better practice advice and guidance, the majority of which is issued by Archives. The ANAO found there was differing levels of awareness of this material in the entities audited.”

Australian National Audit Office (2006)

Page 5: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y ECM standards

•ISO 15489 Records management by IT/21 (Standards Australia)•ISO9000 Quality certification compliance•ISO 2788:1986 Guidelines for the establishment and development of monolingual thesauri

•ISO TC 46 SC11 Archives/Records Management •ISO/TC171/SC2N450 - ISO/DTR 22957 Document management - Analysis, selection, and implementation of Electronic Document Management Systems (EDMS)

•ISO/TC171/SC2N451 - ISO/CD 12029 Electronic imaging – Forms design optimization for electronic image management

•W3C Web content accessibility & Mobile Web Best Practices a Candidate Recommendation

•AS 5037-2005 Knowledge management

•AS17799 s. 9 – Information Technology Code of Practice for Information Security Management - design and use of access controls & digital signatures

•AS17799 - section 8.7.4 security risks and guidelines for items to be included in an email management policy

•Australian Government Locator Service/Dublin core metadata•Anglo American Cataloguing rules

Page 6: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y ECM regulation

• Disposal schedules

• National Archives Australia (2006). Functional requirements for Electronic Records Management Software

• International Model requirements for the management of electronic records (MorEq)

• Policy and procedures identified by Archives as delegated by the relevant Act

• Designing and Implementing Recordkeeping Systems (DIRKS)

• Codes of ethics – NSW Professional Conduct regulation• VERS toolkit• Private sector Privacy Codes• Litigation plan• US Department of Defense (DOD) Directive 5015.2

Page 7: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y ECM legislation 7 case law

Common law• Evidence Act 2004 (NT) • Commonwealth Evidence Act 1995 • Archives Act 1983• Legal Deposit• Sarbanes Oxley 2002• Tax Ruling TR 2004/D23• Electronic Transactions Act 1999 (Commonwealth)• Corporations Act • Income Tax Assessment Act 1936• Crimes (Document Destruction) Act 2006 • Information Act• Freedom of Information • Copyright• Privacy Act 1988 (Cth)

Case law

• Consistency of behaviour – policy and procedures

Page 8: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Cost of non compliance – Valuing information models

“the wealth of an organisation is based on its accumulation of useful knowledge - its knowledge capital. The value added to an organisation by information, discussed ..... under `information productivity' can be regarded as an annual return on its accumulated knowledge capital.“

Strassman (1996)

Page 9: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Information valuation models

Focus on human, customer and structural capital

Focus on market capitalization, return on

assets, and other monetary

valuations.

•Intangible asset monitor (Sveiby, 1997); •Balanced scorecard (Kaplan and Norton, 1992; 1996;75 2000); •Skandia value scheme (Edvinsson and Malone, 1997). •IC-Index Model and HVA Model (Roos and colleagues 1997) •Technology Broker Model (Brooking (1996, pp. 13-14)

•Tobin's Q, economic value added (EVA), Market-to-Book Value, Intellectual Asset Valuation, Total Value Creation, Total Value •Creation, Knowledge Capital Earnings, citation weighted patents, etc. (see for instance: Stewart (1997); Bontis (2001); Bontis et al. (1999); Lev (1999); Sullivan (2000))•Value Chain Scoreboard Lev (2002)•Net Present Value (NPV)

Page 10: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Cost of non compliance

• Tax compliance• Knowledge recreated/lost• Damages awarded• Loss of business critical records• Loss of reputation• Fines• Job loss• Lost productivity

Page 11: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Government Owned Corporation NT Power Generation Pty Ltd v Power and Water Authority [2004]

"There is no other procedure established under the PAWA Act by which the minister could control the operations of PAWA. As a matter of practice, as the communications between PAWA and the minister demonstrate, the procedure of a minute from the chief executive officer and his response by endorsement on that minute was the normal means by which the minister (where he considered it appropriate) gave directions under s 16 of the PAWA Act. There is no evidence to indicate any other means by which directions under s 16 were given."

S. 132PAWA has not demonstrated error in the reasoning of Finkelstein J. PAWA took this Court to

some oral evidence of Mr Gardner in an endeavour to counter Finkelstein J's conclusion that the Minister's desire to have PAWA act as he wished was not always conveyed by direction. That oral evidence was vague, was undermined by other evidence, and, in any event, did not falsify Finkelstein J's conclusion. The PAWA Act does not stipulate that s 16 "directions" are to take any particular form, and the Court was not taken to any other legislation which did. Even if Mr Gardner's evidence establishes that he thought he had received a s 16 direction in August 1998, that does not prove that he did. Everything depends on the terms of the briefing note: no other possible "direction" was relied on. But it is not possible to infer from the briefing note that any direction was given. The acceptance of the recommendation in the briefing note was too vague to amount to a s 16 direction. It did not refer to s 16, yet citation of the source of power could be a crucial matter in the event of later political or forensic controversy about whether any directions had been given or obeyed - for Mr Gardner had a duty to obey them. It did not speak in the language of command or mandate or instruction - it did not direct.

Page 12: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Private Sector – British American Tobacco

• McCabe v British American Tobacco Services Limited (BAT)

• Review was completed by Professor Peter A Sallmann in May 2004 for the Victorian Attorney-General on Document Destruction and Civil Litigation in Victoria

• Resulted in the Document Destruction Act 2006

• Fines of $314,430 for companies and $62,886 or 5 years imprisonment for individuals

Page 13: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Health provider

H v Health Service Provider  [2007] PrivCmrA 10

• Inappropriate disclosure of information

• National Privacy Principles 2 and 4 in Schedule 3 of the Privacy Act 1988 (Cth) breached

• Extensive Privacy Commissioner audit of processes and policy

• Medical centre offered complainant compensation without admitting liability

Page 14: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Law firm

KATRINA NUGENT 9.39am: Yesterday I put my lunch in the fridge on Level 19 which included a packet of ham, some cheese slices and two slices of bread which was going to be for my lunch today. Over night it has gone missing and as I have no spare money to buy another lunch today, I would appreciate being reimbursed for it.

MELINDA BIRD 9.55: Katrina, There are items fitting your exact description in the level 20 fridge. Are you sure you didn't place your lunch in the wrong fridge yesterday?

KATRINA NUGENT 10.06: Melinda, probably best you don't reply to all next time, would be annoyed to the lawyers. The kitchen was not doing dinner last night, so obviously someone has helped themselves to my lunch. Really sweet of you to investigate for me!

MELINDA BIRD 10.14: Katrina, since I used to be a float and am still on the level 19 email list I couldn't help but receive your ridiculous email - lucky me! You use our kitchen all the time for some unknown reason and I saw the items you mentioned in the fridge so naturally thought you may have placed them in the wrong fridge. Thanks I know I'm sweet and I only had your best interests at heart. Now as you would say, "BYE"!

KATRINA NUGENT 10.15: I'm not blonde!!

!MELINDA BIRD 10.16: Being a brunette doesn't mean you're smart though!

KATRINA NUGENT 10.17: I definitely wouldn't trade places with you for "the world"!

MELINDA BIRD 10.19: I wouldn't trade places with you for the world... I don't want your figure!

KATRINA NUGENT 10.21: Let's not get person (sic) "Miss Can't Keep A Boyfriend". I am in a happy relationship, have a beautiful apartment, brand new car, high pay job...say no more!!

MELINDA BIRD 10.23: Oh my God I'm laughing! happy relationship (you have been with so many guys), beautiful apartment (so what), brand new car (me too), high pay job (I earn more)....say plenty more... I have 5 guys at the moment! haha.

Page 15: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Health departmentFunction Application

Web content management My Source Matrix

Email Lotus Notes

MS Office TRIM

Physical Mail TRIM

Linked spreadsheets Corporate drive

Logon script Accept by clicking ok

Disposal schedules TRIM

Hospital Patient files Carsys

Community Health centre patient files CCIS

Remote health patient files PKIS

e-perscription Health Connect

Federated search engine TRIM/My Source Matrix

Digital repository Dspace

Library database Virtua

Data wharehouse Shilo

Hearing Hearsoft

Well Womens Cancer Screening Breastscreen

Payroll PIPS mainframe

Finance GAS mainframe

Staff leave MyHR/PIPS

Physical files AAA Keyword Thesaurus

Physical forms Registry files 

Page 16: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Health department

Page 17: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y Case study – Web 2.0

“twenty years from now, email could be defunct. A combination of social networking and text messaging will replace electronic mails”

Accenture’s Chief Technology Architect (2007)

“corporate blogging has doubled to 8 per cent in the past year”

Accenture’s Chief Technology Architect (2007)

“wikis will also become mainstream collaboration tools in 50 per cent of enterprises by 2009”

Gartner Group (2007)

Page 18: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y How to achieve buy in

• Fear & Failure• Change management strategy• Communication• Staff involvement• IT audits• Project reviews• Duty statements• Valuations

Page 19: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

YC

HA

RLE

S D

AR

WIN

UN

IVER

SIT

Y References

http://www.anao.gov.au/uploads/documents/2006-07_Audit_Report_61.pdf

Chua and Van Toorn (2005). Documents, risk and the fate of your organisation:Document management in the age of corporate accountability

Priest, M. (2006). Document destruction could be costly. Australian Financial Review, 8/9/2006, p. 58

Moneycontrol.com (2007). Blogging will be the future management tool: Accenture

Standards Australia

www.austlii.edu.au

Page 20: Privacy ark oct 2007

CH

AR

LES

DA

RW

IN U

NIV

ER

SIT

Y

Anastasia Govan BA(IM)GradDip(Mgt)PCP AIMM MACS AALIA MRMAA

Senior Lecturer Charles Darwin University Information & Knowledge Management Director & Consultant Whitehorse Strategic GroupChair ACS & RMAA NT Executive Council

PO Box 2096, Darwin, NT, Australia, 0801Phone [email protected]

Contact details

Page 21: Privacy ark oct 2007

www.cdu.edu.au