Welcome!

SDN Journal Authors: Pat Romanski, Patrick Hubbard, Elizabeth White, Sven Olav Lund, Liz McMillan

Related Topics: Microsoft Cloud, Industrial IoT, Microservices Expo, Silverlight, Release Management , SDN Journal

Microsoft Cloud: Article

SharePoint Gone Wild: When Governance Lacks Compliance

Part four of the SharePoint Gone Wild series

If you've missed any previous part of this blog series, you can read them here.

When people think of "compliance" from a Microsoft SharePoint perspective, it can mean a lot of things to a lot of different people. Every organization will have different considerations for compliance: Essentially, which regulations they need to comply with according to their specific industry vertical, including HIPAA/HITECH, DOD 5015, Section 508 and WCAG 1.0 and 2.0.

There are two main drivers for compliance I see in organizations for SharePoint, due to the risk of non-compliance and subsequent legal and financial penalties:

  1. Records Management
  2. Legal e-Discovery

In my post last week on governance and discoverability, I focused on the typical stories I hear around people not being able to find content they need. Compliance takes this a step further, because legal teams and records managers require that the content be available for years to come.

Being in Manhattan, I work with a lot of large financial organizations and one of the most important requirements involves tracking "Regulated Users" activity in SharePoint. These users - based on the sensitivity of their work - are required by law to be tracked for all activity within SharePoint. At any point in time, a court of law can request the organization provide evidence of what content that user has accessed, created, or modified in SharePoint. In the industry this process is called the e-discovery process, and it is essential that the business expectations are set of:

  1. How you obtain information for the courts.
  2. What information you will be able to provide.
  3. An estimated time of delivery for the promised information.

The out-of-the-box auditing features in SharePoint 2010 have some key limitations in this space, specifically regarding the storage of this data over a prolonged period of time (most acts seem to be approximately seven years) as well as the ease of producing a report of an individual user's activity and attached content. The most common format followed by customers with whom I work is Concordance, which is supported by LexisNexis. But more importantly, from a content perspective, the attached content should be exactly what the user viewed, modified, or created at that point in time so versioning here is the key. This can prove hard for wiki pages that have dynamic web parts, and therefore will always render the real-time information rather than the point-in-time information (e.g. a weather web part or stock web part). Consequently, it is important to set the expectations with all involved with this issue as soon as possible.

The legal holds capability of SharePoint 2010 is also required when providing information to the courts concerning records. Although legal holds can be applied to individual documents, there is no easy way of setting legal holds on multiple documents based on reports generated on a user as part of the e-discovery process. The common issue I see with our customers is that business users often assume that this will "just work" and have experienced this streamlined approach in other records management systems. So records managers and those involved in the e-discovery process will have to be aware of this in order to set the proper expectations.

With the business requirement to maintain content to be discoverable for the e-discovery process, a suitable archiving policy needs to be put in place to manage the growth of content within SharePoint. It is important to understand which content is required to be maintained in SharePoint for compliance perspectives, and which content can be archived out of SharePoint to reduce storage consumption. Customers I speak to often struggle with how they plan for growth, especially when maintaining versions of documents. A customer spoke to me recently who said that they had one document with 90 versions which took up 8 gigabytes (GB) of storage space, essentially because SharePoint does not store differentials of files and each version is a complete file. Any "save" command in Word for instance, would mean a new version of the document. It is essential that the planning of the information architecture takes into account the configuration of Lists and Library version settings to be consistent across the environment - and not all these scenarios - unless it is necessary. The best approach to mitigate this is to store all Major versions, but only a set amount of Minor versions and train and encourage users to create Major versions when distributing to other users.

SharePoint is not always the only content repository within an organization, as we talked about in a previous blog post which homed in on appropriateness of content in SharePoint. To reiterate from a compliance perspective, in my experience I have seen customers' concerns around particular sensitive data being stored in SharePoint when it should be stored in other repositories. It is hard to enforce out of the box that users follow the guidelines on where content should go depending on the type of content it is.

From a usability perspective, SharePoint 2010 added many improvements by stating WCAG 2.0 AA compliance. In my experience at customer sites, although organizations are required to obtain Section 508 compliance, the business is not driving this as a priority over other issues mentioned above. In my opinion, I believe it will take a few public financial penalties set out by the courts around Section 508 to drive this requirement. To reach full compliance on Section 508, however, would take significant effort and expertise by modifying how SharePoint 2010 renders.

Edward Cedeno, Product Manager here at AvePoint, has also recently written a related post on Risk-Based Approach to FRCP Rule 26(f) Compliance with DocAve.

More Stories By Jeremy Thake

Jeremy Thake is AvePoint's Chief Architect. Jeremy’s 10-plus years of experience in the software development industry, along with his expertise in Microsoft technologies, earned him the label of “expert” in the global SharePoint community. He was named a Microsoft SharePoint MVP in 2009, and continues to work directly with enterprise customers and AvePoint’s research & development team to develop solutions that will set the standard for the next generation of collaboration platforms, including Microsoft SharePoint 2013.

Jeremy was one of only eight Microsoft MVPs from Australia, where he lived for seven years, who was recognized by the SharePoint Product Team in 2010 for his extensive contributions to the global SharePoint community. He also played an instrumental role in organizing the Perth SharePoint User Group during his time living there.

@CloudExpo Stories
When it comes to cloud computing, the ability to turn massive amounts of compute cores on and off on demand sounds attractive to IT staff, who need to manage peaks and valleys in user activity. With cloud bursting, the majority of the data can stay on premises while tapping into compute from public cloud providers, reducing risk and minimizing need to move large files. In his session at 18th Cloud Expo, Scott Jeschonek, Director of Product Management at Avere Systems, discussed the IT and busine...
As businesses evolve, they need technology that is simple to help them succeed today and flexible enough to help them build for tomorrow. Chrome is fit for the workplace of the future — providing a secure, consistent user experience across a range of devices that can be used anywhere. In her session at 21st Cloud Expo, Vidya Nagarajan, a Senior Product Manager at Google, will take a look at various options as to how ChromeOS can be leveraged to interact with people on the devices, and formats th...
First generation hyperconverged solutions have taken the data center by storm, rapidly proliferating in pockets everywhere to provide further consolidation of floor space and workloads. These first generation solutions are not without challenges, however. In his session at 21st Cloud Expo, Wes Talbert, a Principal Architect and results-driven enterprise sales leader at NetApp, will discuss how the HCI solution of tomorrow will integrate with the public cloud to deliver a quality hybrid cloud e...
SYS-CON Events announced today that Yuasa System will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Yuasa System is introducing a multi-purpose endurance testing system for flexible displays, OLED devices, flexible substrates, flat cables, and films in smartphones, wearables, automobiles, and healthcare.
Is advanced scheduling in Kubernetes achievable? Yes, however, how do you properly accommodate every real-life scenario that a Kubernetes user might encounter? How do you leverage advanced scheduling techniques to shape and describe each scenario in easy-to-use rules and configurations? In his session at @DevOpsSummit at 21st Cloud Expo, Oleg Chunikhin, CTO at Kublr, will answer these questions and demonstrate techniques for implementing advanced scheduling. For example, using spot instances ...
Companies are harnessing data in ways we once associated with science fiction. Analysts have access to a plethora of visualization and reporting tools, but considering the vast amount of data businesses collect and limitations of CPUs, end users are forced to design their structures and systems with limitations. Until now. As the cloud toolkit to analyze data has evolved, GPUs have stepped in to massively parallel SQL, visualization and machine learning.
The session is centered around the tracing of systems on cloud using technologies like ebpf. The goal is to talk about what this technology is all about and what purpose it serves. In his session at 21st Cloud Expo, Shashank Jain, Development Architect at SAP, will touch upon concepts of observability in the cloud and also some of the challenges we have. Generally most cloud-based monitoring tools capture details at a very granular level. To troubleshoot problems this might not be good enough.
DevOps is under attack because developers don’t want to mess with infrastructure. They will happily own their code into production, but want to use platforms instead of raw automation. That’s changing the landscape that we understand as DevOps with both architecture concepts (CloudNative) and process redefinition (SRE). Rob Hirschfeld’s recent work in Kubernetes operations has led to the conclusion that containers and related platforms have changed the way we should be thinking about DevOps and...
SYS-CON Events announced today that Taica will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Taica manufacturers Alpha-GEL brand silicone components and materials, which maintain outstanding performance over a wide temperature range -40C to +200C. For more information, visit http://www.taica.co.jp/english/.
When it comes to cloud computing, the ability to turn massive amounts of compute cores on and off on demand sounds attractive to IT staff, who need to manage peaks and valleys in user activity. With cloud bursting, the majority of the data can stay on premises while tapping into compute from public cloud providers, reducing risk and minimizing need to move large files. In his session at 18th Cloud Expo, Scott Jeschonek, Director of Product Management at Avere Systems, discussed the IT and busine...
We all know that end users experience the Internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices – not doing so will be a path to eventual b...
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities – ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups. As a result, many firms employ new business models that place enormous impor...
SYS-CON Events announced today that SourceForge has been named “Media Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. SourceForge is the largest, most trusted destination for Open Source Software development, collaboration, discovery and download on the web serving over 32 million viewers, 150 million downloads and over 460,000 active development projects each and every month.
The next XaaS is CICDaaS. Why? Because CICD saves developers a huge amount of time. CD is an especially great option for projects that require multiple and frequent contributions to be integrated. But… securing CICD best practices is an emerging, essential, yet little understood practice for DevOps teams and their Cloud Service Providers. The only way to get CICD to work in a highly secure environment takes collaboration, patience and persistence. Building CICD in the cloud requires rigorous ar...
SYS-CON Events announced today that Dasher Technologies will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Dasher Technologies, Inc. ® is a premier IT solution provider that delivers expert technical resources along with trusted account executives to architect and deliver complete IT solutions and services to help our clients execute their goals, plans and objectives. Since 1999, we'v...
As popularity of the smart home is growing and continues to go mainstream, technological factors play a greater role. The IoT protocol houses the interoperability battery consumption, security, and configuration of a smart home device, and it can be difficult for companies to choose the right kind for their product. For both DIY and professionally installed smart homes, developers need to consider each of these elements for their product to be successful in the market and current smart homes.
In the fast-paced advances and popularity in cloud technology, one of the most critical factors revolves around concerns for security of your critical data. How to assure both your company and your customers they can confidently trust and utilize your cloud environment is most often top on the list. There is a method to evaluating and providing security that exceeds conventional modes of protecting data both within the cloud as well externally on mobile and other devices. With the public failure...
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
Transforming cloud-based data into a reportable format can be a very expensive, time-intensive and complex operation. As a SaaS platform with more than 30 million global users, Cornerstone OnDemand’s challenge was to create a scalable solution that would improve the time it took customers to access their user data. Our Real-Time Data Warehouse (RTDW) process vastly reduced data time-to-availability from 24 hours to just 10 minutes. In his session at 21st Cloud Expo, Mark Goldin, Chief Technolo...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...