Top Banner
REGULATORY COMPLIANCE AND LONG-TERM STORAGE OF DATA Dr Matthew Addis Arkivum Ltd WEBINAR
39

Regulatory Compliance and Long-Term Storage of Data

Jul 02, 2015

Download

Data & Analytics

Arkivum

How do you or your company tackle the long-term storage of data? Do you actively archive? In this topical webinar, Arkivum and S3 will look at the benefits and approaches to archiving electronic documents and records in the Life Sciences industry, including the challenges of regulatory requirements, how to comply with them, and how outsourcing long-term storage can form part of the solution.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Regulatory Compliance and Long-Term Storage of Data

REGULATORY COMPLIANCE AND LONG-TERM STORAGE OF DATA

Dr Matthew Addis

Arkivum Ltd

WEBINAR

Page 2: Regulatory Compliance and Long-Term Storage of Data

S3 INTRODUCTION

Mark Treweeke

Solid State Solutions Ltd. (S3)

Page 3: Regulatory Compliance and Long-Term Storage of Data

Trusted Advisor of Choice

►Solid State Solutions (S3)› Leading independent storage integrator

› Big data and virtualisation

› Consultative approach

› Flexible range of services

►Celebrating 25 Years› Solutions not products

› Focused and Skilled

› Support

› Enduring relationships

Page 4: Regulatory Compliance and Long-Term Storage of Data

Trusted Advisor of Choice

►Cloud Services› Archive and preservation

› Backup and DR

►Managed Services› Offload day-day management tasks

› Predictable and controlled costs

►T3 Data Centre Space› Two locations

› Very secure and very efficient

Page 5: Regulatory Compliance and Long-Term Storage of Data

Trusted Advisor of Choice

►Over

Page 6: Regulatory Compliance and Long-Term Storage of Data

Trusted Advisor of Choice

►Partners

Page 7: Regulatory Compliance and Long-Term Storage of Data
Page 8: Regulatory Compliance and Long-Term Storage of Data

Contents

• Review of requirements

• Challenges of data retention and access

• Approach and solutions

• How Arkivum can help

“Security is of key importance to our business, Arkivum’s A-Stor Pharma

service allows us to store our encrypted data for the long term in a cost

efficient way that is entirely scalable and reduces pressure on our internal

IT infrastructure.”

Dan Watkins, Oxford Fertility Clinic

Page 9: Regulatory Compliance and Long-Term Storage of Data

REVIEW OF REQUIREMENTS

Page 10: Regulatory Compliance and Long-Term Storage of Data

Why keep digital data

• Regulation and compliance

• Intellectual Property

• Reuse

• Save money

• Better use of in-house resources

Page 11: Regulatory Compliance and Long-Term Storage of Data

Regulatory Compliance

• Financial, HR, Communications, Health…

• Data Protection Act

• Freedom of Information

• Statutory legislation

• Regulatory bodies

• Recommendations and good practice

Page 12: Regulatory Compliance and Long-Term Storage of Data

Medical records

DPA, FOI, Public Records Act, BS10008

and BIP0008, IG Toolkit, Retention

Periods (Part 2), Audit Trails (Annex D3)

Page 13: Regulatory Compliance and Long-Term Storage of Data

GxP Regulations and Guidelines

• FDA 21 CFR Part 11

• EudraLex Volume 4 Annex 11

• OECD series on GLP

• MHRA GCP guide

Page 14: Regulatory Compliance and Long-Term Storage of Data

Research

Page 15: Regulatory Compliance and Long-Term Storage of Data

The IT challenge

0

1

2

3

4

5

1 2 3 4 5

data volumestorage unit costIT budget

Page 16: Regulatory Compliance and Long-Term Storage of Data

The RDM challenge

Open Access, e.g. CC0

Legacy data

Commercial research

Personal data

Third-party data

Under development

No public repository

Page 17: Regulatory Compliance and Long-Term Storage of Data

Low cost

• Way to cope with data growth

• Free up expensive resources

• Eliminate the ‘cost of loss’

High safety• Data reuse or regulatory compliance

• Data is immutable, replicated, managed

• Auditable integrity, authenticity, access

Easy access

• Quick to retrieve data when its needed

• Frequency: each year, not each second

• Speed: minutes, not milliseconds

Common requirements

Page 18: Regulatory Compliance and Long-Term Storage of Data

Common outcomes

• Integrity and authenticity

• Confidentiality

• Usability / ready access / readability

• Responsibility

• Risk management and proportionality

Page 19: Regulatory Compliance and Long-Term Storage of Data

WHAT ARE THE

CHALLENGES?

Page 20: Regulatory Compliance and Long-Term Storage of Data

20 years of keeping content alive

Page 21: Regulatory Compliance and Long-Term Storage of Data

Digital Preservation

“Digital information lasts forever -

or five years, whichever comes first."Jeff Rothenberg

Page 22: Regulatory Compliance and Long-Term Storage of Data

Perpetual change

• Change costs money

• Change takes time

• Change introduces risk

• Change requires validation

• Change needs planning

• Change needs management

Page 23: Regulatory Compliance and Long-Term Storage of Data

2,200 years

30,000 years

1,200 years

20 years

200 yearsEach new generation of technology:

1000x times denser

lasts 1/10th as long

Page 24: Regulatory Compliance and Long-Term Storage of Data

IT storage is not safe

Page 25: Regulatory Compliance and Long-Term Storage of Data

People cause data loss too

Page 26: Regulatory Compliance and Long-Term Storage of Data
Page 27: Regulatory Compliance and Long-Term Storage of Data
Page 28: Regulatory Compliance and Long-Term Storage of Data
Page 29: Regulatory Compliance and Long-Term Storage of Data

Active Archiving

• Preservation best practice (diversity, intervention)

– Multiple copies in different locations

– Different technologies and different people

– Active management: migration, integrity

Ingest Queue

Access Queue

Replication and Repair Queue

Storage System 1 Storage System 2

Scrubbing and migration

Scrubbing and migration

Page 30: Regulatory Compliance and Long-Term Storage of Data

Ingredients

• Skilled and trained people

• Validated processes and procedures

• Comprehensive risk management

• Specialist infrastructure

• Economies of scale

• Independent audit and validation

Page 31: Regulatory Compliance and Long-Term Storage of Data

HOW ARKIVUM CAN HELP

Page 32: Regulatory Compliance and Long-Term Storage of Data

Arkivum service in a nutshell

SLA with 100%

data integrity

guaranteed

World-wide

professional

indemnity

insurance

Long term

contracts for

enterprise data

archiving

Fully automated

and managed

solution

Audited and

certified to

ISO27001

Page 33: Regulatory Compliance and Long-Term Storage of Data

Arkivum’s Active Archive

A-StorDC

A-StorDC

Encrypted

VPN

A-Stor creates an encrypted

copy on the gateway and

copies to Arkivum’s

Data Centre One

A-Stor

A-StorDC creates the

second copy in Arkivum’sData Centre Two

A-StorDC creates the

escrow copy in the

Tape Vault

Once all three copies are

confirmed safe and secure

the original copy can

safely be deleted

Page 34: Regulatory Compliance and Long-Term Storage of Data

Trust but verify!

Page 35: Regulatory Compliance and Long-Term Storage of Data

Audit trails

• Essential in compliance applications

• Part of records management

• Digital preservation is an active process

• Good practice to record checks/interventions

Page 36: Regulatory Compliance and Long-Term Storage of Data

Ready made exit plan

• Metadata and data on a file system

• Open standards and formats

• 3-way agreement on ownership/access

• Drive down costs and risks

LTFS

Page 37: Regulatory Compliance and Long-Term Storage of Data

Purchasing Options

• Pre-agreed terms

• PAYG or Paid-Up for 5,10 or 25 years

• JANET connected

• Ingress or egress included

• Migrations and refreshes included

• Audits and certification included

• Escrow copy included

• DMP friendly

• Not just for research data

• Easy budgeting

Page 38: Regulatory Compliance and Long-Term Storage of Data

Example customers

Page 39: Regulatory Compliance and Long-Term Storage of Data

Trusted Advisor of Choice

1 Prisma Park, Berrington AvenueBasingstoke, Hampshire, RG24 8GT

0870 7776111

[email protected]

We are here to help