Why Information Must Be Destroyed
- 25 February, 2009 09:32
- Comments
The inability to discard worthless items even though they appear to have no value is known as compulsive hoarding syndrome. If the eccentric Collyer brothers had a better understanding of destruction practices, they likely would not have been killed by the very documents and newspapers they obsessively collected.
While most organizations don't hoard junk and newspapers like Homer and Langley Collyer did, they do need to keep information such as employee personnel records, financial statements, contracts and leases and more. Given the vast amount of paper and digital media that amasses over time, effective information destruction policies and practices are now a necessary part of doing business and will likely save organizations time, effort and heartache, legal costs as well as embarrassment and more.
In December 2007, the US Federal Trade Commission announced a US$50,000 settlement with American Mortgage Company, over charges the company violated the FTC's Disposal, Safeguards, and Privacy rules by failing to properly dispose of documents containing consumers' credit and personally identifiable information. In announcing the settlement, the FTC put all companies on notice that it is taking such failures seriously.
A US$50,000 settlement might seem low when measured against the potential for financial harm to individuals as a result of the company's negligence, but in addition to the negative PR for American Mortgage, the settlement includes an obligation to obtain an audit, every two years for the next 10 years, from a qualified, independent, third-party professional to ensure that its security program meets the standards of the order. Any similar failures by this company during the next decade will be met with more severe punishment. That, indeed, is a very costly lesson.
In today's litigious environment, there are a plethora of aggressive lawyers who would love to devour your organization for failure to take due care around document and media destruction.
This article will look at the key areas to ensure that your organization does not fall prey to such lawyers when it comes to the physical destruction of documents and records. The next article will go into the details around the destruction of digital documents and digital media.
Every organization has data that needs to be destroyed
Besides taxes, what unites every business is that they possess highly sensitive information that should not be seen by unauthorized persons. While some documents can be destroyed minutes after printing, regulations may require others to be archived from a few years to permanently. But between these two ends of the scale, your organization can potentially have a large volume of hard copy data occupying space as a liability, both from a legal and information security perspective.
Depending on how long you've been in business, the number of physical sites and the number of people you employ, it's possible to have hundreds of thousands, if not millions, of pages of hard copy stored throughout your company -- much of which is confidential data that can be destroyed.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- How will CIOs meet growing Security Threats?
- Aberdeen Group Analyst Insight Report: Does Your Enterprise Have a “Dropbox Problem?”
- Security Threat Report 2012
- Why Encrypt? Securing Email without compromising communications.
- HP VirtualSystem VS3 for VMware - Simple, agile, efficient enterprise virtualisation
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Social networking, ignorance, and apathy
-
China's Alibaba sees big growth with AliExpress site
-
10 Tips for Dealing with a Bully Boss
-
How to design a successful RACI project plan
-
CommVault Extends its Data Protection and Information Management Strategy with Simpana 9
This IDC Insight explores the differentiators of CommVault's Simpana data and information management software and the customer challenges the help address. The focus of this Insight is on the data management and data protection capabilities on Simpana. -
CIO Executive Council ROI
This document was created by Council CIOs as a means to illustrate ROI for membership. It outlines the services available to member CIOs and their deputies. -
IDC Whitepaper: Generating Proven Business Value with EMC Next-Generation Backup and Recovery
IDC interviewd ten companies that have deployed EMC backup and recovery solutions, including EMC Data Domain and EMC Avamar. Some of the customers also had EMC NetWorker. The purpose was to identify and quantify the resulting business value of each project, in order to calculate a cumulative return on investment. Read on.
-
Beginning Cryptography with Java
-
Macromedia Flash MX ActionScript for Dummies
-
Fedora 8 and Red Hat Enterprise Linux Bible
-
Mastering Visual C# .Net
-
Access 2010 All-In-One for Dummies®
-
Windows XP for Dummies, 2nd Edition
-
Drer Digital Classroom
-
Ubuntu Linux Bible
-
Private Mythology Poems Trade Paperback Reissue








Comments
Post new comment