AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance?...

66
Living in a Hybrid World: Compliance and Governance Meet Cloud

Transcript of AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance?...

Page 1: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Living in a Hybrid World: Compliance and Governance Meet Cloud

Page 2: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business
Page 3: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Agenda

as a Service

Page 4: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Governance

Page 5: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Importance of Information Governance

Gartner Research: 2016 Prediction

Page 6: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

What is SharePoint Governance?

“Governance is the set of and

that directs, and controls how an organization’s business divisions and I.T. teams to achieve business goals.” Microsoft – http://bit.ly/nmNSbj

Page 7: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

IT Governance

Corporate Governance

SharePoint

IT Governance

System Governance

SAP Lotus

Notes

Page 8: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

How Much Governance is Needed?

Personal/My Sites

Governance

Vis

ibil

ity

Project/Team Sites

Community Sites

Portal

Page 9: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Striking the Balance

Business

Needs

Usage

Technical

Needs

Control

Page 10: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Requirements for IT Governance

Tech

Process

People

Policy

Governance

Page 11: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

People

Business

Owners IT

Back

Office

Finance

Legal

HR

Corp. Communications

Executive Sponsorship

Workload Owners

Departmental Owners

Functional Owners

Architects

IT Operations

Administrators

Page 12: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Customization Adoption Continuous

Improvement

Operations Information

Architecture

Information

Management

Project

Management Leadership

Infrastructure

Typical Policy Categories

Page 13: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Encouragement

Resource

intensive

Human error

PowerShell

scripts

3rd Party Products

Custom apps

3rd Party Products

Process of Policy Enforcement

Automated Semi-Automated Manual

Page 14: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

2 Weeks

8 Weeks

3 – 6 Months

SharePoint List + SharePoint Designer

InfoPath SharePoint Designer

Custom APIs .Net Coder

SharePoint Administrator

InfoPath Developer

.NET Developers

Technology: Build vs. Buy

Options Time Required Resources

Multiply for Every Service Request

Page 15: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Customization Adoption Continuous

Improvement

Operations Information

Architecture

Information

Management

Project

Management Leadership

Infrastructure

Typical Policy Categories

Page 16: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Compliance, Risk and Privacy

Page 17: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

What is Risk?

“Risk is the potential that a chosen action or activity (including the choice of inaction) will lead to a loss (an undesirable outcome). The notion implies that a choice having an influence on the outcome exists (or existed). Potential losses themselves may also be called "risks". Almost any human endeavor carries some risk, but some are much more risky than others.”

- Wikipedia

Page 18: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

What is Compliance?

Compliance means conforming with stated requirements.

Achieved through management processes

which identify the applicable requirements

Assess the state of compliance

Assess the risks and potential costs of non-

compliance

Prioritize, fund and initiate any corrective

actions deemed necessary

Page 19: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

What does Compliance mean to us?

− Making information available to the people who should have it

− Protecting information from the people who should not

At the very highest level:

Page 20: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

The Challenge-Legions of compliance obligations and risks to information

• Intellectual property and trade secrets

• Sensitive customer information and data

• Collaborations on strategy

• Personal information

• Legal and compliance issues

• Information getting in the wrong hands

The onslaught of risk and compliance issues related to

Information sharing includes:

Page 21: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Just a few compliance standards

Page 22: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Information must be accessible and available to the people who should have access to it and protected from the people who should not

Further this information may need to be stored, archived and preserved for some period of time

These laws have common elements

Page 23: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Hackers gaining access

80%

70%

60%

50%

40%

30%

20%

10%

0%

Accidental employee

breach

Accidental 3rd party

breach

Intentional Employee

breach

Intentional 3rd party

breach

Source: HCCA;, “Data Privacy: How Big a Compliance Challenge?”;

January 2011

8%

61%

41%

30%

13%

How likely do you think the following privacy breach risks are of occurring?

Page 24: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Confidentiality leaks

—Compromised privacy

Loss of data integrity

No access to or

availability of data

Some specific risks to consider…

Page 25: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Questions to Ask: Designing a Compliance Policy

Page 26: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Risk Awareness

Risk Ignorance

Risk Assessment: Don’t just focus on what you can see

“Never in all history have we harnessed such formidable technology. Every scientific advancement known to man has been incorporated into its design. The operational controls are sound and foolproof!”

E.J. Smith, Captain of the Titanic

Page 27: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Defining & Assessing Your Compliance Position

Balancing Accessibility &

Security

Classification of Documents

Confidentiality of Documents

Integrity of Information within

Documents

Understanding Different Roles

Page 28: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Building a Compliance Policy

Transparency/

Collaboration

Data

Protection/

Management

Page 29: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Balancing transparency and collaboration with data

protection and management

Creating and maintaining a compliant SharePoint environment is a continuous process

• People

• Policy and Process

• Technology

• Training

• Governance and Oversight

• Technical Enforcement

Page 30: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Compliance & Technical Enforcement

Prevent

Detect

Track

Respond & Resolve

Page 31: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Make Control part of the Process

Identify

Non-

Compliance

2 Prioritize

the

Business

Needs

3

Diagram

New Security

Boundaries

4 Architect

in GovSec

5 Undertake

Migration

6 Maintain

Control

7 Analyze the

Current

Environment

1

Page 32: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Deployment Opportunities

Page 33: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Our heads are already in the cloud…

Page 34: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

How did we get here?

Access

databases

Server

room

Centralized

data center

Cloud

Page 35: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Service layers

IaaS PaaS SaaS

Storage

Applications

Servers

Virtualization

O/S

Middleware

Runtime

Data

Applications

Storage

Applications

Servers

Virtualization

O/S

Middleware

Runtime

Data

Applications

Storage

Applications

Servers

Virtualization

O/S

Middleware

Runtime

Data

Applications

Page 36: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Why?

• Rapid onboarding • “Instant” optimization • Effortless move to new versions

• Strong SLAs • Scaling/performance • Cost, Move from CapEx to OpEx

• Cross-organization collaboration

• Ease storage burden • Hype

Page 37: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Why not?

• Integration with internal systems

• Ability to customize

• Test/staging environment

• Data sovereignty

• Offline/low bandwidth accessibility

• Security and availability concerns persist

Page 38: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

How do we control?

Page 39: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Information Architecture vs. Management

Page 40: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Information Architecture (Site Map)

http://intranet

HR Finance

Team Vacation

Tracking Financial

Performance Benefits

Marketing

Logos Expense

Reports Team Team

Page 41: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Information Architecture vs. Management

Page 42: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Management controls and scopes

Farm

Web

Application

Service

Application Zone

Content DB

Site collection

Top-level site

List/Library

[Folder]

Item / Document

Sub site Sub site

Page 43: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Logical Architecture

Site

collection

Marketing

Content DB

Site

collection

HR

Site collection

Intranet

Home

HR Marketin

g Finance

Farm

Content DB Content DB

TEAMS SOCIAL INTRANET

Page 44: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Cloud architecture

TEAMS SOCIAL INTRANET

Farm

Site

collection

Marketing

Content

DB

Site

collection

HR

Content

DB

Content

DB

Site collection

Intranet

Home

HR Mark

eting

Finan

ce

EXTRANET

O365

Page 45: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Shared Services Farm Architecture

Content

Farm

SOCIAL INTRANET TEAMS

Site collection

Marketing

Content DB

Site collection

HR

Content DB Content DB

Site collection

Intranet Home

HR Marketin

g Finance

EXTRANET

O365

Service

Farm

PROFILE SEARCH BCS METADATA

Page 46: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Business Critical Architecture

Content

Farm

SOCIAL INTRANET TEAMS

Site collection

Marketing

Content DB

Site collection

HR

Content DB Content DB

Site collection

Intranet Home

HR Marketin

g Finance

EXTRANET

O365

TEAMS*

Biz Crit

Farm

Content DB

Site collection

Finance

Service

Farm

PROFILE SEARCH BCS METADATA

Page 47: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

LOB applications architecture

Content

Farm

SOCIAL INTRANET TEAMS

Site

collection

Marketing

Content DB

Site

collection

HR

Content DB Content DB

Site collection

Intranet

Home

HR Marketin

g Finance

EXTRANET

O365

TEAMS*

Biz Crit

Farm

Content DB

Site

collection

Finance

<LOB>

LOB

Farm

Service

Farm

PROFILE SEARCH BCS METADATA

Page 48: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Applications farm architecture

On-Prem

Farm

SOCIAL INTRANET TEAMS

Site collection

Marketing

Content DB

Site collection

HR

Content DB Content DB

Site collection

Intranet Home

HR Marketin

g Finance

EXTRANET

O365

TEAMS*

Biz Crit

Farm

Content DB

Site collection

Finance

<LOB>

LOB

Farm

APPS

Apps

Farm

Service

Farm

PROFILE SEARCH BCS METADATA

Page 49: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Don’t panic – plan with end in mind…

On-Premise

Farm

SOCIAL INTRANET TEAMS

Site collection

Marketing

Content DB

Site collection

HR

Content DB Content DB

Site collection

Intranet Home

HR Marketin

g Finance

EXTRANET TEAMS*

Content DB

Site collection

Finance

<LOB> APPS

Service

Farm

PROFILE SEARCH BCS METADATA

Page 50: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Presenting SharePoint as a Service

Page 51: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Service

User Request

Approval Stages

Approval Process Start Execute Request

Page 52: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Configuration Policies

Backup RBS Archiving Auditor

1 hour Tier 1 – SAN 7 years Full

1 day Tier 2 – NAS 3 years Views +

Edits

1 week None 1 years Views

Page 53: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Secure vs. Non-Secure content

Regulated Users Non-Regulated Users

Page 54: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Service Offerings

Regulated Non-

Regulated Non-Secure

Archiver 7 years 3 years 1 year

Backup 1 hour 1 day 1 week

Auditing Full View + edits Views

RBS Tier 1 – SAN Tier 2 – NAS None

Vault Autonomy None None

Compliance WCAG 2.0 WCAG 2.0 None

SharePoint

Deployment On-premises On-premises Online

SharePoint

Designer Enabled Disabled Disabled

Content

Database Isolated DB Shared N/A

Quota 100Gb 50Gb 10Gb

Page 55: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Context-targeted Services Projects

Gold

All Mgmt.

AD Groups

Project Site

Template

3-stage

Active Directory

User

Project Purpose

PII not allowed

6 months

HR

Gold, Silver

HR Mgmt.

AD Group

Employee Site

Template

2-stage

Active Directory

User

Employee

Department

PII allowed

1.5 years

Sales

Silver, Bronze

Sales Mgmt.

AD Group

Customer Site

Template

1-stage

Active Directory

User

Account Type

PII not allowed

2 years

Policies

Security

Customizatio

ns

Approval

Process

Business

Contact

Classification

Compliance

Lease

Page 56: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Site Collection Lifecycle Management

Pre-approval Backup Archive Auditor RBS

Configure

Change Contact

Inactive Lease Lease

Change Policy

Lease Expiration

Page 57: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Year 0

Content

Year 1

Collaboration

Year 2

Development

Year3

ECM

Active Content

Storage Growth

Page 58: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Number of site collections and sites

0

1000

2000

3000

4000

5000

6000

7000

8000

9000

Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec

IT Training Engineering Sales HR

Page 59: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Site analytics

0

2000

4000

6000

8000

10000

12000

14000

Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec

IT Training Engineering Sales HR

Page 60: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Decrease of File Share / Exchange

0

1000

2000

3000

4000

5000

6000

Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec

SharePoint Exchange File Share

Page 61: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Continuous Improvement Lifecycle

Mixed Junk

IN

Filter for

Compliance

Prioritize for

Business Need

Structure

for

Governance

Organized

Gold OUT

Page 62: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Wrap Up

Page 63: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

Integrate with your technology

solutions

Integrate policy with

“enforcement”

Create a policy with enforceable

& measurable rules

Engage Executive Leadership &

keep them briefed!

Gather your stakeholders! Content contributors: Internal and External, Process

owners, Legal, PR, CPO, IT, Data Security

Key Takeaways

Page 65: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business

THANK YOU

Page 66: AvePoint: Living in a Hybrid World: Compliance and ... · What is SharePoint Governance? “Governance is the set of and that directs, and controls how an organization’s business