Signature Assignment: EDMS Business Requirements Document
Hollywood Organic Co-op. Adoption of Electronic Document Management System (EDMS)
Name of student
Institution
Instructor
Components of Document Retention Policy
Hollywood Organic Co-op aims at adopting new EDMS to manage its documents
It must consider different components of document retention policy
Document retention allows an organization to make informed decisions
One component of document retention policy is development of audit procedure which allows an organization ensure programs are implemented (Overly, n.d.).
Another component is specification of individuals to manage the program
As Hollywood Organic Co-op aims to adopt the new enterprise document management system, to secure both customers and its documents, it must understand that, there are some components of document retention policies that must be considered when adopting the EDMS. Document retention is of great importance as it allows the organization to make informed decisions. Such documents can be consulted when the need arises. Component number one has to deal with the development of the audit procedure. Having an audit procedure allows an organization to ensure the retention policy is well implemented (Overly, n.d.). Also, there is a specification of individuals charged with maintaining the program to be implemented. This aids in ensuring the program is a success.
2
Components of Document Retention Policy
Document retention policy must list the retention period for each type of document (Overly, n.d.).
This allows the prioritization of documents that demands much attention
Another component is determination of procedures used to exempt documents being added to the program
This allows an organization save much of its time and resources in providing security to different documents
Listing of each document's retention period is another most valued component of document retention policy (Overly, n.d.). This component states that an organization must specify the specific duration under which the document is to be retained and stored. Having such a policy allows an organization to prioritize the attention demanded by different documents. Another component of document retention deals with procedures used for exempting documents being added into a program. This allows the organization to be safe much of its time as it will determine documents that demand more attention.
3
Components of Document Retention Policy
Another component of document retention policy is stating of methods used in implementation of the program (Overly, n.d.).
For example, a program can be instructed to delete an email after 40 days
Recording of decisions that informed the development of the program
As a component of document retention program, recording decisions for development of the program serves as an evaluation measure (Overly, n.d.).
Also, there must be definition of all documents that the program will be applied to.
Additionally, the retention policy must state how the retention program must be implemented. For example, a network can be programmed to automatically delete some documents after a specified period, for example 40 days. Also, the retention policy must record the decisions that informed the development of a retention program in addition to the period a program will be stored (Overly, n.d.). More importantly, the retention policy must explicitly define the type of documents to which it shall apply. More specifically, electronic documents such as emails and instant messages should be specifically applied. Additionally, storage locations for different documents must be clearly defined.
4
Procedures for Security of organization's critical Business Documents
Adoption of EDMS by Hollywood Organic Co-op helps it enhance the security of its information
Staff that will work with any new program must receive adequate training (Abdulkadhim, 2016)
The adoption of EDMS program without giving employees proper training will not serve its purpose
Principle of least privileged also assists in securing an organizations information
It prevents unauthorized persons from accessing information
Therefore, for information to remain safe, not everyone within the organization will have access
As the organization aims to enhance the security of most of its critical information, the adoption of EDMS will enhance the security of its information. Therefore, the staff working for the organization must receive adequate training (Abdulkadhim, 2016). It is important to note that EDMS adoption will not serve its purpose, where all people who will utilize the program are not trained. Additionally, to ensure information safety, the organization can adopt control policies such as the least privilege principle. The principle of least privilege ensures that people accessing certain documents or resources are those given merits.
5
Procedures for Security of organization's critical Business Documents
Training staff on the use of EDMS and security measures is not enough to keep the organization’s documents
The organization must therefore adopt methods of communicating its information securely
The use of conventional Internet-based e-mail improves the safety of communication (Alaba et al., 2017).
"Tor" system enhances the security of email communications leading to the safety of documents shared
Before sending emails, messages are encrypted before being decrypted multiple times
The safety of an organization's critical information has today become the most critical concern; therefore, training staff on security measures is not enough. For this reason, for an organization to secure its sensitive documents, it must adopt measures that assist is communicating data most securely (Alaba et al., 2017). The use of conventional Internet-based email makes this possible. For example, the use of the "Tor" system enhances the security of email communications. Individual messages are encrypted and re-encrypted multiple times by different computers to transmit the message to its destination. Additionally, the organization must consider keeping its data off the internet. It must not store its critical information on computers that can be accessed over the internet.
6
Regulatory Requirements for Safeguarding Data
The adoption of EDMS aiming at maintaining the organization’s data is regulated by specific requirements
Such regulations provides guidelines on how organization secures its data
Not complying with regulations can result in severe loss of data through data breaches (Scherschligt et al., 2018).
Some regulations are generally applicable to all organizations while others affect specific organizations only
The applicability of different regulations is dependent on the type of data to be maintained
The adoption of the EDMS has to be in line with some regulations. Diverse kinds of regulations have been put in place to help organizations secure most of their information. Therefore, such regulations provide guidelines and best practices based on the company's type of data to be maintained. Not complying with such regulations can result in data loss through data breaches. This, in turn, destroys the company's reputation leading to loss of customers. Some regulations are generally applicable to all organizations and must therefore be implemented. However, some regulations do not apply to all organizations. Notably, this depends on the type of data maintained by an organization.
7
Regulatory Requirements for Safeguarding Data
National Institute of Standards and Technology (NIST) help inn securing an organization’s data (Scherschligt et al., 2018).
Helps organizations manage and reduce cyber related risks through the use of different measures
This regulation is applicable to Hollywood Organic Co-op more particularly when implementing the new EDMS
The organization aims at adopting an new EDMS which helps in managing and enhancing the security of its information
As no one is safe from data breaches, it must use the above regulation
Center for Internet Security Controls CIS controls helps in enhancing an organization’s information security
National Institute of Standards and Technology (NIST) as a regulatory standard was developed to guide how organizations manage and reduce cyber-related risks using different measures (Scherschligt et al., 2018). Notably, when implementing the new EDMS, Hollywood Organic Co-op must understand that the above regulation applies to its system because documents can severely be impacted if a data breach is waged against an organization. It can lead to the loss of organizations' valuable information. Additionally, the Center for Internet Security Controls CIS controls helps in enhancing an organization's information security. This control helps an organization protect its data from known attackers.
8
Regulatory Requirements for Safeguarding Data
International Organization for Standardization (ISO 27000 Family) enhances an organizations security (Suhaimi, Noordin & bin Ya’kub, 2020).
An organization maintains its information through the maintenance of information security management systems (ISMS)
It is applicable to many types of businesses
Also, International Organization for Standardization (ISO 31000 Family) governs implementation of different programs within an organization
It can therefore be applicable during the adoption of EDMS
Additionally, the International Organization for Standardization (ISO 27000 Family) enhances an organization's security. Under these regulations, an organization can manage its data by maintaining information security management systems (ISMS) by implementing security controls bins (Suhaimi, Noordin & bin Ya'kub, 2020). These regulations are wide and can fit any business, including Hollywood Organic Co-op. Also, the International Organization for Standardization (ISO 31000 Family) can adequately guide different organizations to manage their information. It governs the principles of implementation and risk management of different programs. For example, when adopting the new EDMS, the organization receives adequate guidance from this regulation.
9
Hollywood Organic Co-op's stakeholders and their responsibilities
A stakeholder can either be affected or affect an organization
Interaction between a stakeholder and an organization is for mutual benefit
Organization achieves its aims as individuals advance their careers and experiences (Benlian & Haffke 2016).
Stakeholders can be investors, employees, customers, and suppliers
Employees such as CIO and CEO play critical roles in the organization
A stakeholder is a party having an interest in a company and can either affect or be affected by the company. In this case, as the two parties interact, they remake each other. For example, the company develops an individual career-wise while the individuals help the company achieve its desired goals through different means. Stakeholders can be investors, employees, customers, and suppliers. Therefore, the organization in question has its stakeholders as employees, such as the Chief information officer (CIO) and Chief Executive Officer (CEO).
10
Hollywood Organic Co-op's stakeholders and their responsibilities
Different stakeholders play different roles in the introduction and implementation of EDMS
The CIO sets strategies and objectives for the Information Technology department (Benlian & Haffke 2016).
CIO therefore determines the timeframe for the implementation of EDMS
CIO also selects and implements best strategies to enhance the performance of an organization
CEO makes major decisions concerning the implementation of different programs
Different stakeholders have different roles and responsibilities in the implementation of the newly developed EDMS. The CIO's roles are highly demanded as the recent advancement in a great manner relies on IT strategies within the organization. Anything dealing with IT within an organization has to be the responsibility of the CIO. The CIO sets strategies and objectives for the Information Technology department (Benlian & Haffke 2016). Therefore, the person is responsible for determining the timeframe for the implementation of the new EDMS. The CIO also selects and implements the best technologies to enhance the performance of an organization.
Furthermore, as another important stakeholder, the CEO plays a critical role in enhancing an organization's performance. The CEO makes major corporate decisions informing the performance of an organization. Therefore, the CEO is critical instrumental in the adoption of EDMS.
11
Hollywood Organic Co-op's stakeholders and their responsibilities
Employees plays critical roles in development and implementation of a program
They are vital implementers of different programs developed
Employees must therefore be trained on implementation of the EDMS program
Customers also play critical roles in the implementation of the EDMS
Customers provide information concerning what they want to be improved in an organization
Additionally, other employees play critical roles in the development and implementation of different kinds of advancements. Most commonly, employees are seen as the implementers of different developments realized within an organization. This reason, they are involved through adequate training. Additionally, other stakeholders are suppliers and customers. Suppliers provide the organization with resources used to achieve its desired objectives and, therefore, be involved in developing the new EDMS. Customer's roles entail informing the organization on areas that demand improvement. Where customers are complaining about the management of their information, the organization adopts EDMS.
12
Framework for Document Life Cycle
The framework entails the creation of either a digital or analog document
Capturing means the conversion of analog document into digital
Management focuses on storing of the documents("Document Life Cycle," n.d.)
Access to the document allows one to search and locate the document
Administration manages the users and resources
Sharing of information ensures it is well utilized for general performance of an organization
The recommended framework for a document life cycle entails creating a document that can either be analog or digital. Capturing entails the conversion of analog documents into digital formats. Management of the document entails storing documents for rapid accessibility ("Document Life Cycle," n.d.). Furthermore, access as another life cycle of a document. It allows one to access information stored in documents through the use of diverse kinds of searches. Also, there is the administration of the users and resources. Finally, there is the sharing of the documents to ensure that they are adequately utilized for an organization's success.
13
Tools
Different EDMS tools that can be used to integrate the four stores owned by the company
Templafy system helps in integration of important office suits and solutions (Process, 2020)
Files can be created and stored in a single feed
This helps in enhancing the accessibility of information stored in different stores
It is easy to use the tool
There are diverse kinds of EDMS tools that can be used to integrate the company's four stores. One notable example is Templafy. Templafy system helps in the integration of important office suits and solutions utilized by businesses daily (Process, 2020). Many files can therefore be created and managed within a single feed. Therefore, this will be applied in all the stores, which in turn increases the accessibility of data stored there. There are advantages the come with the use of Templafy. For example, it is easy to use, meaning it does not demand technical knowledge.
14
Tools
Master Control also enhances document security (Process, 2020)
Utilized by world’s largest regulatory bodies
Addresses global regulation standards
The use of the tool comes with advantages as it is supported by regulators
Another enterprise tool that can be used to enhance document security is MasterControl. This technology is most commonly utilized by some of the world's largest regulatory bodies. It is a document control software addressing global regulations and standards. MasterControl aims to reduce compliance costs and increase internal efficiency (Process, 2020). MasterControl is very advantageous because it is supported by regulators meaning there will be no legal issues. Therefore, this application will aid in providing safety to different types of information in different stores belonging to Hollywood Organic Co-op.
15
References
Abdulkadhim, H., Bahari, M., Hashim, H., Bakri, A., & Ismail, W. (2016). Prioritizing implementation factors of electronic document management system (EDMS) using topsis method: A case study in Iraqi government organizations. Journal of Theoretical and Applied Information Technology.
Alaba, F. A., Othman, M., Hashem, I. A. T., & Alotaibi, F. (2017). Internet of Things security: A survey. Journal of Network and Computer Applications, 88, 10-28.
Benlian, A., & Haffke, I. (2016). Does mutuality matter? Examining the bilateral nature and effects of CEO–CIO mutual understanding. The Journal of Strategic Information Systems, 25(2), 104-126.
bin Suhaimi, A. I. H., Noordin, N., & bin Ya'kub, M. F. (2020, May). Assessment of Malaysian E-Passport PKI based on ISO 27000 Series International Standards. In Journal of Physics: Conference Series (Vol. 1551, No. 1, p. 012003). IOP Publishing.
References
Overly, M. R. (n.d.). Basic elements of document retention policies. Retrieved from https://www.csoonline.com/article/2136612/basic-elements-of-document-retention-policies.html
Process. (2020, March 2). What is an enterprise document management (EDM) system? How to implement full document control. Retrieved from https://www.process.st/enterprise-document-management/
Scherschligt, J., Fedchak, J. A., Ahmed, Z., Barker, D. S., Douglass, K., Eckel, S., ... & Ricker, J. (2018). Quantum-based vacuum metrology at the National Institute of Standards and Technology. Journal of Vacuum Science & Technology A: Vacuum, Surfaces, and Films, 36(4), 040801.
The Document Life Cycle. (n.d.). Retrieved from https://www.dartmouth.edu/library/recmgmt/forms/DocLifeCycle.pdf