First, a company management with the coordination of corporate legal counsel must take an inventory of all records used in a company, classify what records are vital, and identify what vital records support the continuity of business operations, legal evidence, disaster recovery work, and audit work; knowing that not all records and documents that a company handles everyday are vital records.
Some records are on paper media while other records are on electronic media. An outcome of inventorying and classifying records is developing a list of “record retention” showing each document with its retention requirements in terms of years. Then, a systematic method is needed to preserve and store these vital records onsite and offsite with rotation procedures between the onsite and offsite locations.
Corporate legal counsel plays an important role in defining retention requirements for both business (common) records and legal records. IT management plays a similar role in backing up, archiving, and restoring the electronic records for future retrieval and use. The goal is to ensure that the current version of the vital records is available and that outdated backup copies are deleted or destroyed in a timely manner.
Examples of vital records follow:
Legal records:
General contracts; executive employment contracts; bank loan documents; business agreements with third parties, partners, and joint ventures; and regulatory compliance forms and reports.Accounting/finance records
: Payroll, accounts payable, and accounts receivable records; customer invoices; tax records; and yearly financial statements.Marketing records:
Marketing plans; sales contracts with customers and distributors; customer sales orders; and product shipment documents.Human resources records:
Employment application and test scores, and employee performance appraisal forms.33. IT resource criticality for recovery and restoration is determined through which of the following ways?
1.
Standard operating procedures2.
Events and incidents3.
Business continuity planning4.
Service-level agreementsa.
1 and 2b.
2 and 3c.
3 and 4d.
1, 2, 3, and 434. An information system’s recovery time objective (RTO) considers which of the following?
1.
Memorandum of agreement2.
Maximum allowable outage3.
Service-level agreement4.
Cost to recovera.
1 and 3b.
2 and 4c.
3 and 4d.
1, 2, 3, and 435. Contingency planning integrates the results of which of the following?
a.
Business continuity planb.
Business impact analysisc.
Core business processesd.
Infrastructural services