This Page

has been moved to new address

The eDiscovery Paradigm Shift

Sorry for inconvenience...

Redirection provided by Blogger to WordPress Migration Service
----------------------------------------------------- Blogger Template Style Name: Snapshot: Madder Designer: Dave Shea URL: mezzoblue.com / brightcreative.com Date: 27 Feb 2004 ------------------------------------------------------ */ /* -- basic html elements -- */ body {padding: 0; margin: 0; font: 75% Helvetica, Arial, sans-serif; color: #474B4E; background: #fff; text-align: center;} a {color: #DD6599; font-weight: bold; text-decoration: none;} a:visited {color: #D6A0B6;} a:hover {text-decoration: underline; color: #FD0570;} h1 {margin: 0; color: #7B8186; font-size: 1.5em; text-transform: lowercase;} h1 a {color: #7B8186;} h2, #comments h4 {font-size: 1em; margin: 2em 0 0 0; color: #7B8186; background: transparent url(http://www.blogblog.com/snapshot/bg-header1.gif) bottom right no-repeat; padding-bottom: 2px;} @media all { h3 { font-size: 1em; margin: 2em 0 0 0; background: transparent url(http://www.blogblog.com/snapshot/bg-header1.gif) bottom right no-repeat; padding-bottom: 2px; } } @media handheld { h3 { background:none; } } h4, h5 {font-size: 0.9em; text-transform: lowercase; letter-spacing: 2px;} h5 {color: #7B8186;} h6 {font-size: 0.8em; text-transform: uppercase; letter-spacing: 2px;} p {margin: 0 0 1em 0;} img, form {border: 0; margin: 0;} /* -- layout -- */ @media all { #content { width: 700px; margin: 0 auto; text-align: left; background: #fff url(http://www.blogblog.com/snapshot/bg-body.gif) 0 0 repeat-y;} } #header { background: #D8DADC url(http://www.blogblog.com/snapshot/bg-headerdiv.gif) 0 0 repeat-y; } #header div { background: transparent url(http://www.blogblog.com/snapshot/header-01.gif) bottom left no-repeat; } #main { line-height: 1.4; float: left; padding: 10px 12px; border-top: solid 1px #fff; width: 428px; /* Tantek hack - http://www.tantek.com/CSS/Examples/boxmodelhack.html */ voice-family: "\"}\""; voice-family: inherit; width: 404px; } } @media handheld { #content { width: 90%; } #header { background: #D8DADC; } #header div { background: none; } #main { float: none; width: 100%; } } /* IE5 hack */ #main {} @media all { #sidebar { margin-left: 428px; border-top: solid 1px #fff; padding: 4px 0 0 7px; background: #fff url(http://www.blogblog.com/snapshot/bg-sidebar.gif) 1px 0 no-repeat; } #footer { clear: both; background: #E9EAEB url(http://www.blogblog.com/snapshot/bg-footer.gif) bottom left no-repeat; border-top: solid 1px #fff; } } @media handheld { #sidebar { margin: 0 0 0 0; background: #fff; } #footer { background: #E9EAEB; } } /* -- header style -- */ #header h1 {padding: 12px 0 92px 4px; width: 557px; line-height: 1;} /* -- content area style -- */ #main {line-height: 1.4;} h3.post-title {font-size: 1.2em; margin-bottom: 0;} h3.post-title a {color: #C4663B;} .post {clear: both; margin-bottom: 4em;} .post-footer em {color: #B4BABE; font-style: normal; float: left;} .post-footer .comment-link {float: right;} #main img {border: solid 1px #E3E4E4; padding: 2px; background: #fff;} .deleted-comment {font-style:italic;color:gray;} /* -- sidebar style -- */ @media all { #sidebar #description { border: solid 1px #F3B89D; padding: 10px 17px; color: #C4663B; background: #FFD1BC url(http://www.blogblog.com/snapshot/bg-profile.gif); font-size: 1.2em; font-weight: bold; line-height: 0.9; margin: 0 0 0 -6px; } } @media handheld { #sidebar #description { background: #FFD1BC; } } #sidebar h2 {font-size: 1.3em; margin: 1.3em 0 0.5em 0;} #sidebar dl {margin: 0 0 10px 0;} #sidebar ul {list-style: none; margin: 0; padding: 0;} #sidebar li {padding-bottom: 5px; line-height: 0.9;} #profile-container {color: #7B8186;} #profile-container img {border: solid 1px #7C78B5; padding: 4px 4px 8px 4px; margin: 0 10px 1em 0; float: left;} .archive-list {margin-bottom: 2em;} #powered-by {margin: 10px auto 20px auto;} /* -- sidebar style -- */ #footer p {margin: 0; padding: 12px 8px; font-size: 0.9em;} #footer hr {display: none;} /* Feeds ----------------------------------------------- */ #blogfeeds { } #postfeeds { }

Wednesday, January 25, 2012

The Perfect Storm: eDiscovery and Cloud Service Providers

The market for Cloud Service Providers (CSPs) is very sunny.  Forrester Research predicted in a research report published earlier this year titled, “Sizing the Cloud” that the global cloud computing market would reach $241 billion in 2020 compared to $40.7 in 2010.  And, Gartner Predicts that the eDiscovery market will reach $1.5 Billion by 2013.  However, based upon the research that I have completed over the past sixty (60) days, Cloud Service Providers (CSPs) and their clients are ignoring eDiscovery as an important component of a standard cloud service offering.

I have some theories in regards to why this is the case:

CSPs DON'T UNDERSTAND eDISCOVERY

Over the pat five (5) years Cloud Service Providers (CSPs) have been busy focusing on their core offerings of Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS), honing their value propositions and trying to figure out how to differentiate themselves from the pack.  Overwhelmed with the rudimentary issues of what to offer and how to make a profit , eDiscovery has not been a requirement that has reached the road map of any CSPs that I have interviewed.

Most of the reasons behind this is the fact that eDiscovery is actually a "
latent pain" that the CSP's clients and prospects are not asking for (I will cover this in more detail in the next section).  However, part of the reason may be just plain semantics.  I have found that when you ask a CSP business development executive if their clients are asking about eDiscovery, the answer will be no.  However, if you change the question and ask if their clients are asking about information governance, compliance, business analytics or something even simpler like universal or federated search, the answer may be yes.  This subtle difference is confusing to most in the eDiscovery market and therefore it is no wonder that it is very confusing to the CSP market.As In indicated in my Blog post on September 15, 2011,titled, "Evolving from Information Governance to eDiscovery", I believe that eDiscovery is actually part of a larger market called information governance (IG).  And, as Sunil Soares, the Director of Information Governance within the IBM Software Group indicated in a blog post on April 11, 2011 titled, Why Information Governance is a Market, Not Just a Process, “information governance is like the blind man and the elephant. Depending on which part of the elephant you touch, people define information governance to include master data management, data stewardship, data quality management, metadata management, business glossaries, information lifecycle management and security and privacy.” 

I would actually include several other components as integral parts of IG in pursuit of my premise that if Gartner predicts that the eDiscovery market is going to reach $1.5 Billion by 2013, the information governance market is going to be many times this size.  Or, in other words, more than likely the largest  software and services market on the planet in the next five (5) years (Note that HP paid $11 Billion for Autonomy to play in the IG Market).

So, maybe CSPs need to think of eDiscovery as Information Governance and concentrate on the fact that information governance is potentially the single biggest market on the planet in the coming years?


CSP CLIENTS DON'T UNDERSTAND eDISCOVERY
Another interesting fact emerged from my recent study on eDiscovery in the CSP market.  It appears that most CSP enterprise clients don't understand eDiscovery.  Come to find out, a very high percentage of the standard CSP client base are actually "renegade" business units with global 2000 enterprises that were unhappy being held hostage by their IT organizations and decided to outsource their information management to a CSP.  Unless the business unit in question is the legal department (which is highly unlikely), the stakeholders within these units have no idea what eDiscovery or information governance is or would they know to even ask their CSP if it can be supported if the need were to present itself.

After further investigation into this market dynamic, the story actually gets even more interesting.  If one of these global 2000 enterprises is sued and is presented with a request to produce information (ESI) or some governance regulatory entity asks for proof of compliance, the request is normally handled by the General Counsel (GC) and legal department.  More than likely the first place the GC will go is to the IT department asking for its help in producing the requested data (Please note that most global 2000 enterprises are now relatively adept at the process of internal eDiscovery).  However, the GC may not even know to ask about the data (ESI) from the renegade business unit and if they do, the renegade business unit is not going to know how to comply with the request and their IT department is probably not going to help since they are no at all happy that they went to a CSP for IT services in the first place.  Given all of this, the business unit executives or the GC may call the CSP and ask for help.  However, since the CSP doesn't really understand eDiscovery, they aren't going to be much help.  Basically, at this point the entire eDiscvoery process can get pretty ugly.  The GC is under a legal obligation to respond (i.e. Federal Rules of Civil Procedure) under a fairly limited time frame with financial and other sanctions are real possibilities for non-compliance with the request.


THE PERFECT STORMSo, unfortunately, what I have determined to be the current status in the Cloud Service Provider (CSP) market is the perfect storm of neither the CSP or the CSP's client base understanding the need for eDiscovery.  However, there are solutions and there is hope.

THE ROADMAP FOR SUCCESS FOR CSPs
The roadmap to success for the CSPs is actually not that complicated.  CSPs need to get serious about providing eDiscovery and/or information governance as a component or their standard offering.

In a January 8, 2012 blog post titled, "Cloud Computing Architecture and eDiscovey", I stated that "It is within the Platform-as-a-Service (PaaS) layer where eDiscovery services belong.  In fact, this may be a good time to coin the term eDiscovery-as-a-Service (eDaaS)... And, since providing eDaaS as a standard option for any PaaS offering makes so much sense and could provide a first mover and key competitive advance for Cloud Service Providers (CSPs), I predict that we will see several eDaaS offerings before the end of 2012.  And, I also predict that once the eDaaS offerings hit the market, the legacy eDiscovery platform providers will be forced to re-evaluate the value propositions of their non eDaaS offerings in the cloud."

CSPs can contact me at cskamser@ediscoverysolutionsgroup.com for additional insight on which technology vendors currently have or are about to announce eDaaS offerings.

THE ROADMAP FOR SUCCESS FOR CSP CLIENTS
The roadmap to success for the CSP clients is also actually not that complicated.  First of all, enterprise business unit stakeholders need to add eDiscovery and Information Governance to  their list of requirements for the CSPs.  And, they need to seek out and collaborate with their legal and IT departments in regards to a plan to follow when an eDiscovery and/or compliance event occurs.  It just make sense and its not complicated.

Enterprise stakeholders that are contemplating or already working with a CSP can contact me at cskamser@ediscoverysolutionsgroup.com for additional insight on what to expect from their CSP and what best practices to follow when an eDiscovery and/or compliance event occurs.

CONCLUSION
Both the cloud and the eDiscovery / Information Governance trains have left the station and therefore it is no longer an option for either Cloud Service Providers or their clients to ignore the legal requirements and business benefits.  The current practices to address the issues of eDiscovery or Information Governance are ugly at best.  However, the roadmap for success is not that complicated.  And, the rewards for both the CSP and their clients is well worth the investment.

Labels: , , , , , , ,

Tuesday, July 26, 2011

eDiscovery Decisions in 2011 Increase at Accelerating Rate

The eDiscovery Race The coveted  Gibson Dunn 2011 mid-year analysis on eDiscovery cases is out and it is not surprising that the number and sophistication of eDiscovery cases continued to grow at an accelerating rate.

Highlights from the Gibson Dunn analysis of pertinent decisions include:

 

  • The number of eDiscovery decisions continues to increase at a blistering pace. The 187 decisions we identified in the first half of 2011 represents an 82% increase over the 103 decisions we identified at mid-year 2010.
  • The number of instances in which litigants sought sanctions in the first half of 2011 was more than double the number in the same period last year (68 at mid-year 2011 versus 31 at mid-year 2010), and sanctions awards have nearly doubled in absolute terms (38 at mid-year 2011 versus 21 at mid-year 2010).
  • Notwithstanding this increase, courts awarded sanctions at essentially the same rate as in 2010 (56% of the instances in which a party sought sanctions in the first half of 2011, versus 55% for the full year in 2010).
  • Determining when litigation is "reasonably foreseeable" for purposes of triggering the duty to preserve continued to be a fact-specific analysis.
  • Courts continued to emphasize that counsel's responsibility to ensure preservation does not end with timely distribution of a legal hold notice.
  • Courts continued to demand cooperation and remained keenly aware of counsel's efforts--or lack thereof--to resolve eDiscovery disputes before seeking judicial involvement.
  • It turns out that there is such a thing as "discovery karma," at least in the 10th Circuit, and "ankle-biting" an opponent for alleged discovery glitches may not be appreciated, especially when one's own house is not in order.
  • While no reported case addressed the use of predictive coding or other advanced search technologies, there is no doubt that these tools have been noticed, as The New York Times and Forbes focused on their potential impact in featured articles.
  • eDiscovery law continued to develop rapidly, and while some areas of law are coming into focus, other areas--including basic issues such as whether a litigation hold notice must be written--continue to be heavily debated.
  • Calls for reform of the Federal Rules of Civil Procedure continued, and the Civil Rules Advisory Committee is considering various

Unless you are stuck in some Star Trek  time warp where Electronically Stored Information (ESI) and the associated eDiscovery is in some future and maybe even parallel universe, the Gibson Dunn report should come as no surprise.  The amount of ESI is going to continue to grow at an accelerated rate for the foreseeable future.  The cloud is going to accelerate the increase in the volume of  ESI acceleration even faster.  So, the fact that our judiciary is “dealing” with these facts is a good think. Let’s all hope that this continues to accelerate also.

Labels: , ,

Tuesday, May 11, 2010

eDiscovery Data Mapping Should be a Top Priority for General Counsel and CIOs within the Global 2000

A key aspect and legal requirement of eDiscovery is the creation of a data map to determine precisely what information is available within an organization and where it resides. This is a process that should begin long before a company ever finds itself in court. Surprisingly, over the past 2 years, I haven’t found more than a hand full of General Counsel and CIOs at some of the largest companies in the world that truly understand the importance of eDiscovery Data Mapping, the risks involved in not having a working eDiscovery Data Map nor the fact that they should be leading the charge to develop and manage an enterprise wide eDiscovery Data Map.

Ganesh Vednere, a manager at Capgemini, wrote an excellent overview of the key aspects of eDiscovery Data Mapping titled, “The Quest for eDiscovery: Creating a Data Map”. that appeared on the November / December 2009 Informatics site. In this overview, Ganesh indicated that, at a minimum, the enterprise should consider completing the following tasks as a general practice to start the eDiscovery Data Mapping process:

Get a list of all systems – and be prepared for a few surprises
Begin the process by creating a list of all systems that exist in the company. This is easier said than done, as in many cases, IT does not even have a full list of all systems. Sure, they usually have a list of systems, but don’t take that as the final list! Due diligence involves talking to business process owners, employees, and contractors, which often brings to light hidden systems, utilities, and home-grown applications that were unbeknownst to IT. Ensure that all types of systems are covered, e.g. physical servers, virtual servers, networks, externally hosted systems, backups (including tapes), archival systems, and desktops, etc. Pay special attention to emails, instant messaging, core business systems, collaboration software, and file shares, etc.

Document system information
After the list of all systems is known, gather as much information about each as possible. This exercise can be performed with the help of system infrastructure teams, application support teams, development teams, and business teams. Here are some types of information that can be gathered: system name, description, owner, platform type, location; is it a home grown-package, and does it store both structured and unstructured data; system dependencies (i.e., what systems are dependent on it and what systems does it depend on); business processes supported, business criticality of the system, security and access controls, format of data stored, format of data produced, reporting capabilities, how/ where the system is hosted; backup process and schedule, archival process and schedule, whether data is purged or not; if purged, how often and what data gets purged; how many users, is there external access allowed (outside of the company firewall), are retention policies applied, what are the audit-trail capabilities, what is the nature of data stored, e.g. confidential data, nonpublic personal information, or still others.

Get a list of business processes
Inventory the list of business processes and map it to the system list obtained in the step above to ensure that all the various types of ESI are documented. The list of business processes is also useful during the discovery process, when one can leverage the list to hone in on a particular type of ESI and obtain information about how it was generated, who owned the data, how the data was processed, how it was stored, and so on. A list of business processes can also be useful when assessing information flows.

Develop a list of roles, groups, and users (custodians)
Obtain the organizational chart and determine the roles and groups across the business and the business processes. Document the process custodians and map out who had privileges to do what. Understand the human actors in the information lifecycle flow.

Document the information flow across the entire organization
Determine where critical pieces of information got initiated, how the information was/is manipulated, what systems touch the information, who processes the information, what systems depend on the information, and so on. Understanding the flow of information is key to the data mapping/discovery process.

Determine how email is stored, processed, and consumed
Given the large percentage of business information and business records that reside in email, special attention needs to be placed on email ESI. Typically email is the first thing that opposing counsel go after, so determining whether email retention and disposition policies are consistently enforced will be key to proving good faith. There are a number of automated tools that will enable you to create email maps, link threads of conversation, heuristically perform relevancy search, extract underlying metadata, and so on. Before deciding to buy the best-of-breed solution, however, perform due diligence on existing email processes. Understand how employees are using email. Are they creating local archives (.PST files), are they storing emails on a network or a repository, are they disposing of them at the end of retention periods, are they using personal emails to conduct official business, and so on. Identify deficiencies and violations in email policies before the opposing counsel does.

Identify use of collaboration tools
SharePoint will have the lion’s share of the collaboration space in many organizations, but even then you must ensure that all other tools – whether they are social networking tools, Web-based tools, or home-grown tools – are included in the data-mapping process. You need to carefully document the types of information being stored on each of these tools. Sometimes company information has a nasty habit of being found in the most unlikely of places. Wherever possible work with compliance, information management, or records management groups to establish usage policies to prevent runaway viral growth of these tools. If the organization already has thousands of unmanaged SharePoint sites, work with IT and business to institute governance controls to prevent further runaway growth.

Don’t forget offsite storage
After inventorying and mapping all systems, one would think the job is done. Alas, there is more work ahead. Offsite storage is an often under-appreciated aspect of the discovery process. It is quite reasonable to assume that there might be substantial evidence stored offsite which might become incriminating at a later date. Offsite storage may contain boxes or tapes full of records whose existence was somehow never properly documented, with the result that they cannot be located unless someone opens the box or attempts to recover the tape data. These records continue to live well past their onsite cousins. This means the organization continues to have the record in backup tapes (or paper) and other formats that it purportedly claimed to have destroyed. The search for records in offsite storage is made more complicated if the offsite storage process did not create detailed indices about the contents. If there are tapes labeled “2007 Backup Y: Drive,” then it may become quite an arduous task to determine what information is really contained in those tapes. Nevertheless the journey must be started. It could involve anything from a full-scale review of all tapes, followed by reclassifying and re-filing the tapes, to perhaps a review of just the offsite storage manifests. It could also involve a search for critical information or a clean-up of the last three years’ worth of tapes, and so on.

eDiscovery Data Mapping Platform
This is an impressive beginning best practice. However, I would add the requirement of seriously considering investing in an eDiscovery Data Mapping platform to help guide you through the eDiscovery Data Mapping process and then manage all of the information that you discovery. After all, just creating your eDiscovery Data Map is just the beginning of the process. The real value of creating the eDiscovery Data Map will be seen when your enterprise uses the eDiscovery Data Map to support your first legal matter and enables you to more fully meet the legal requirements of the the Federal Rules of Civil Procedure (FRCP) and the associated state and local rules.

Genome from Exterro, is an excellent example of a new generation of data mapping solutions that are dynamic, shifting to reflect your company's information universe as it evolves.Through intelligent workflows and automated processes, Genome enables IT departments and legal teams to quickly visualize and analyze data source information to proactively scope case parameters. Over the next couple of weeks, I will be reviewing the solutions that are currently available along with some recommendations for which platforms will provide the best return on your investment (ROI).

The full text of Ganesh Vednere’s overview is as follows:

A key aspect of ediscovery is the creation of a data map to determine precisely what information is available within an organization and where it resides. This is a process that should begin long before a company ever finds itself in court.

The phone rings. It is the general counsel. The organization may be sued over patent infringement. Counsel knows that this could be “The Big One.” All sorts of data, documents, metadata, emails, and other forms of information may be required. Counsel asks IT: Do you have, or can you get together, a list of all systems and the data they contain?” There is a long, silent pause on the phone. Then the IT manager says “Well, we do have a list of systems. Let me send it your way.” Counsel gets the list. It is nothing close to the data map it needs. Instead it is a list of servers, their IP addresses, platform configuration, and their physical rack location in the data center. Good information for disaster recovery purposes, but not particularly helpful in court.

“Well, this is the best I’ve got,” comes the retort from IT. “We do not have a data map nor would we know how to create one – and, by the way, do you really think we have the bandwidth to work on this now?”

Why You? The Challenge of Data Mapping
So who gets stuck with the job? You do. You might argue that “IT manages all the infrastructure and stuff, why couldn’t they just run an inventory on their systems?” And IT will reply that “Well, we do manage the infrastructure, but we know very little about the inputs, outputs, documents, records, and other information on these applications. Go talk to the business side.” And you go to business, and business will tell you that “I just use the system and click these buttons on the screen. The system is a black box to me. I have no idea about all of the underlying data, metadata, and data structures. I suggest you talk to the operational folks.” And you talk to the operational folks, and they say, “What are you talking about? We just execute business processes. Don’t ask us about data and metadata. Go talk to the analyst who worked on the system design.” And you look for the analyst, and you eventually learn that …“Oh, she was a consultant and she left the project three years ago.”
The challenges are many but the data map must be created. And the job is yours. So where do you start? By going back to the beginning … the very beginning.

How Did We Get in Such a Mess?
Let’s take a look at a typical mid-size organization. It has several thousand employees and contractors with offices in the U.S. and E.U. The sheer volume of information that resides in just one division is mind-boggling. New information sources keep popping up, employees keep creating new SharePoint sites on their own, and there is use (or misuse) of social collaboration tools, to say nothing of several hundred IT systems in play at any point in time. Data is moved and migrated from one place to another without proper documentation or communication, more and more tape backups are being created, and some employees are making copies of data on thumb drives or worse, emailing them to their personal email addresses.

How did things ever become such a mess? There are manifold reasons: IT is traditionally kept at arm’s length on compliance and uninvolved with information management and governance during systems design and development. Records management departments, on the other hand, often institute sound policies and retention schedules but have a tough time putting these into practice and getting people to adhere to them. On the legal side, general counsels often work against themselves: becoming increasingly exasperated over the large amount of money spent on searching, processing, and producing electronically stored information (ESI), they often push hard to cut costs, thereby shortcircuiting the process.

Must an Organization Have a Data Map?

It may seem surprising that even today, many successful organizations do not have a data map, or at best, a superficial one. It is not that organizations are lacking in will, however, but that the process seems too daunting. Consider the “typical organization” above. If there are several hundred IT systems and other home-grown business applications, one must not only know what these systems are, and where they are located, but also the types of information (documents, records, other content) that are produced from these systems and additional information such as data format, data location, whether the data is updated by other systems, or transformed into other formats, etc.

To add to the complexity, a determination also needs to be made as to whether a piece of ESI can be extracted and presented using reasonable and customary means. For example, if an IT system was retired and the data backed-up on tape, it is reasonable to assume that extracting the tape, processing the information, and presenting it in a readable format may not be easy since the underlying version of the software no longer exists. Counsel, however, must be able to assess whether this is indeed the case. Having a data map eases some of these tasks and makes it easier for counsel to relate the information as needed.

Data Mapping Considerations

In the current economic environment, companies are bracing themselves for an uptick in the number of lawsuits. Whether the matter is related to regulators, customers, consumers, employees, or business partners, companies are often required to provide ESI in court. While this should be sine qua non for most organizations, many are simply too overwhelmed to be able to react fast enough and are thus placing themselves at a much greater risk. If that’s the case in your enterprise, here are some initial steps that will help you move forward.
  1. Understand the prevailing legal environment. Organizations are not created equally, and not all have the same set of applicable legal requirements. It is therefore important to analyze the type of environment that the organization operates in, the jurisdiction it is under, and the various federal and state laws, regulations, and common industry standards that apply to it, with regard to ESI. While the contents of a data map by itself do not directly correlate to a particular law or regulation, it is useful to know what checks and controls need to be established during the datamapping process and ensure that there are no “show-stopper” questions in court around how the data map was created or what the process was.
  2. Use a partnership model and obtain buy-in from senior management. It is important that each entity within an organization have a vested stake in the success of any data-mapping project. This means that management in each of these organizational fiefdoms must understand what a data map is, how it will be used, and what the process of creating one is. Getting buy-in from these senior managers is a crucial first step and must be completed prior to the start of the process. Additionally, it is important that people of the appropriate rank are selected to work on the project. Folks who are deep in the weeds will generally have a lot more information about data flows and how processes and people work together versus the senior executive who operates in more of a decision-making capacity.
  3. There is little point in pursuing a “big-bang” approach for the data map. Instead, work towards a phased approach. Prioritize which divisions or lines of business to focus on first and then address the remaining ones later. Work with line managers to determine what, if any, information has been collected on systems and processes within their particular areas. Standard industry lists may be employed as a starting point, e.g. HR, Accounting, Communications and Marketing, etc. Begin the first phase of the process here and then iteratively build upon what’s already available.
  4. Use the right technology. As more capital is allocated towards automating ediscovery, vendors will naturally gravitate towards building specialized software for this mission. Time, cost, and relevancy of results will drive the success of vendor products. While some organizations have attempted to build custom tools, more and more prefer choosing established products or service offerings to guide them through the rediscovery and data-mapping process. Already many vendors have begun mapping their offerings to the electronic discovery reference model (EDRM) and other industry standards. This market is still maturing and organizations should not go out and immediately purchase a top-rated vendor’s software without due consideration of the organization’s unique circumstances.
Creating the Data Map
Once you’ve worked your way through each of considerations above and taken action as needed, you’re ready to start the actual data-mapping process. It is lengthy but well-defined and can be broken down into each of the following steps:

The Data Mapping Process

  1. Get a list of all systems – and be prepared for a few surprises. Begin the process by creating a list of all systems that exist in the company. This is easier said than done, as in many cases, IT does not even have a full list of all systems. Sure, they usually have a list of systems, but don’t take that as the final list! Due diligence involves talking to business process owners, employees, and contractors, which often brings to light hidden systems, utilities, and home-grown applications that were unbeknownst to IT. Ensure that all types of systems are covered, e.g. physical servers, virtual servers, networks, externally hosted systems, backups (including tapes), archival systems, and desktops, etc. Pay special attention to emails, instant messaging, core business systems, collaboration software, and file shares, etc.
  2. Document system information. After the list of all systems is known, gather as much information about each as possible. This exercise can be performed with the help of system infrastructure teams, application support teams, development teams, and business teams. Here are some types of information that can be gathered: system name, description, owner, platform type, location; is it a home grown-package, and does it store both structured and unstructured data; system dependencies (i.e., what systems are dependent on it and what systems does it depend on); business processes supported, business criticality of the system, security and access controls, format of data stored, format of data produced, reporting capabilities, how/ where the system is hosted; backup process and schedule, archival process and schedule, whether data is purged or not; if purged, how often and what data gets purged; how many users, is there external access allowed (outside of the company firewall), are retention policies applied, what are the audit-trail capabilities, what is the nature of data stored, e.g. confidential data, nonpublic personal information, or still others.
  3. Get a list of business processes. Inventory the list of business processes and map it to the system list obtained in the step above to ensure that all the various types of ESI are documented. The list of business processes is also useful during the discovery process, when one can leverage the list to hone in on a particular type of ESI and obtain information about how it was generated, who owned the data, how the data was processed, how it was stored, and so on. A list of business processes can also be useful when assessing information flows.
  4. Develop a list of roles, groups, and users (custodians). Obtain the organizational chart and determine the roles and groups across the business and the business processes. Document the process custodians and map out who had privileges to do what. Understand the human actors in the information lifecycle flow.
  5. Document the information flow across the entire organization. Determine where critical pieces of information got initiated, how the information was/is manipulated, what systems touch the information, who processes the information, what systems depend on the information, and so on. Understanding the flow of information is key to the data mapping/discovery process.
  6. Determine how email is stored, processed, and consumed. Given the large percentage of business information and business records that reside in email, special attention needs to be placed on email ESI. Typically email is the first thing that opposing counsel go after, so determining whether email retention and disposition policies are consistently enforced will be key to proving good faith. There are a number of automated tools that will enable you to create email maps, link threads of conversation, heuristically perform relevancy search, extract underlying metadata, and so on. Before deciding to buy the best-of-breed solution, however, perform due diligence on existing email processes. Understand how employees are using email. Are they creating local archives (.PST files), are they storing emails on a network or a repository, are they disposing of them at the end of retention periods, are they using personal emails to conduct official business, and so on. Identify deficiencies and violations in email policies before the opposing counsel does.
  7. Identify use of collaboration tools. SharePoint will have the lion’s share of the collaboration space in many organizations, but even then you must ensure that all other tools – whether they are social networking tools, Web-based tools, or home-grown tools – are included in the data-mapping process. You need to carefully document the types of information being stored on each of these tools. Sometimes company information has a nasty habit of being found in the most unlikely of places. Wherever possible work with compliance, information management, or records management groups to establish usage policies to prevent runaway viral growth of these tools. If the organization already has thousands of unmanaged SharePoint sites, work with IT and business to institute governance controls to prevent further runaway growth.
  8. Don’t forget offsite storage. After inventorying and mapping all systems, one would think the job is done. Alas, there is more work ahead. Offsite storage is an often under-appreciated aspect of the discovery process. It is quite reasonable to assume that there might be substantial evidence stored offsite which might become incriminating at a later date. Offsite storage may contain boxes or tapes full of records whose existence was somehow never properly documented, with the result that they cannot be located unless someone opens the box or attempts to recover the tape data. These records continue to live well past their onsite cousins. This means the organization continues to have the record in backup tapes (or paper) and other formats that it purportedly claimed to have destroyed. The search for records in offsite storage is made more complicated if the offsite storage process did not create detailed indices about the contents. If there are tapes labeled “2007 Backup Y: Drive,” then it may become quite an arduous task to determine what information is really contained in those tapes. Nevertheless the journey must be started. It could involve anything from a full-scale review of all tapes, followed by reclassifying and re-filing the tapes, to perhaps a review of just the offsite storage manifests. It could also involve a search for critical information or a clean-up of the last three years’ worth of tapes, and so on.
Conclusion
In today’s highly litigious world, creating a data map is one of the primary steps in responding to litigation requests. It is vital that organizations get a solid foundation by focusing time, energy and resources in doing it right – and creating it long before it’s needed.

Labels: , , , , , , , , , , ,

Saturday, January 16, 2010

The Seven Deadly Sins of eDiscovery

The Seven Deadly Sins, also known as the Capital Vices or Cardinal Sins, is a classification of the most objectionable vices which has been used since early Catholic times to educate and instruct followers concerning (immoral) fallen man's tendency to sin. The final version of the list consists of wrath, greed, sloth, pride, lust, envy, and gluttony.

Comparing the tendencies of the players in the complex and high stakes world of eDiscovery in 2010 to The Seven Deadly Sins may be a bit over the top. However, there are some "Deadly" tendencies occurring within eDiscovery that are worth noting. Please note that this list does not necessarily correspond to the list of Seven Deadly Sins and several of the items on my list cover multiple sins and I decided to leave wrath off as it is the inevitable result from our clients when we commit any of the other sins.

eDiscovery Sin # 1: Thinking that eDiscovery is Just the Latest Fad
Whether it's pride or sloth, there are some lawyers that believe that eDiscovery is just the latest technology fade designed by the technology vendors to complicate and increase the cost of the legal process. I have heard many within the legal community express the view the principles of evidence have not changed, the process of discovery has not changed and that eDiscovery is not something that should change the basic tenants of litigation.This is not to say that intricate processes of litigation and the associated unique knowledge of how to best navigate that process that litigators have spent years learning and perfecting are no longer valid. However, litigators need to "change with the times", educate themselves regarding what effect eDiscovery will have on their practice and adjust, mature and evolve appropriately.

With the volume of Electronically Stored Information continuing to increase at an accelerating rate and the associated changes to the Federal Rules of Civil Procedure (FRCP) and now many of the State and Local Rules of Civil Procedure, eDiscovery has already changed litigation and will continue to be the driving factor behind additional dramatic changes to the way in which we litigate.

eDiscovery Sin # 2: Lusting after eDiscovery Technology
Although pride and sloth may be clouding the judgment of some within the legal community to the realities of eDiscovery, lust for eDiscovery technology to magically solve all of the issues within the eDiscovery lifecycle may be just as bad.The best example of this is the current debate that is going on within the Early Case Assessment (ECA) arena. Many are lusting after ECA technology as the "Silver Bullet" that is going to magically uncover/produce all of the requested/required document and reduce the cost of eDiscovery with the simple click of a button.Of course on the opposite side of this argument are the prideful and in some cases slothy (is that a word?) litigators that believe that technology has no place in litigation and that all Electronically Stored Information (ESI) should be TIFFed and filed in legal boxes so that lawyers can start to apply sticky notes.The best use of ECA technology is obviously some middle ground where litigators educate themselves regarding the value of ECA technology, possibly employ some ECA technology experts (maybe the ECA vendors and consultants) and utilize ECA technology as a tool.

eDiscovery Sin # 3: Hoarding Data
Gluttony, derived from the Latin gluttire meaning to gulp down or swallow, means over-indulgence and over-consumption of food, drink, or intoxicants to the point of waste. As the saying goes, "if a little bit is good, a whole lot has to be better? " In the world of eDiscovery this has translated into over collection or an overly long and intrusive data retention policy.Obviously if you hoard your data and/or over collect, then you will never be accused of either purposeful or inadvertent destruction of potential responsive data. The obvious danger with this approach is that if you keep everything than it could eventually be "discoverable". And, having watched the TV show called "Hoarders" as few times, many of the houses and people that Hoarders crew works with remind me of the enterprises and the IT and or data management executives that I work with in regards to their data retention policies. The similarities are surprising.On the opposite end of this argument , I have heard many General Counsel and several outside counsel point out that if we don't have it then we don't have to produce it in regards to a very aggressive data retention policy.

Obviously, the best approach is to develop a data retention policy for your organization that follows the standard guidelines for your industry and then let common sense rule the gray areas of when and when not keep data.

eDiscovery Sin # 4: Charging Too Much for eDiscovery Services and Technology
The world of eDiscovery for the past 5 years as been the equivalent of the wild west and has in most cases provided a license to steal for eDiscovery consultants, technology vendors and the law firms that they have been working with (I guess I won't be making many friends in the industry with that comment?). This is obviously the sin of Greed at its finest. Unfortunately, the result has been that only the very wealthy have been able to afford access to the legal system due to the extreme cost of even evaluating the merits of a case.

Don't get me wrong in regards to where I stand on the issue of open markets and capitalism as I believe very strongly that markets will always self regulate and provide the best prices for all involved.And, as I have pointed out on this Blog, I think that the cost of eDiscovery is coming down and will continue to drop as uses become more educated in regards to "what it should cost", new technology replaces older technology and renegade providers introduce dramatically different pricing models such as fixed prices for processing data.


eDiscovery Sin # 5: Unreasonable Requests to Produce Documents
I believe that "unreasonable requests for production" has been one of the most outrageous (and therefore sinful in the context of this Blog post) and unfortunately trendy legal maneuvers currently employed in litigation. Even before the advent of Electronically Stored Information (ESI), it was not uncommon for counsel on both sides to try and overwhelm the opposing party with requests to produce. And, with the exponential increase in the amount of data now available and the known issues with collecting and producing this data, unreasonable requests have become even more prevalent. With some help from the changes to the Federal Rules of Civil Procedure and subsequent case law, it is becoming increasingly difficult to pull this stunt. However, I still see parties suffer the results of this legal maneuver every week. Hopefully the courts will finally catch on in 2010 and put a stop this approach once and for all.


eDiscovery Sin # 6: Thinking that eDiscovery is Just for Lawyers and the Legal Departments
I am not sure what category the sin of myopic behavior fits into. However, it is prevalent throughout eDiscovery. As I have posted on this Blog many times, I believe that eDiscovery is actually a subset of the broader arena of Governance, Risk and Compliance (GRC). Basically, I contend that the enterprise should collect ESI "one time", store it in a central repository based on reasonable and well thought out data retention policies and provide access to "that data" to everyone within the enterprise that needs access.Unfortunately, what I see is the same data being collected multiple times by multiple different organizations within the same enterprise through multiple and redundant systems. This is not a new phenomena to the world of enterprise Information Technology. I can't even count how many times I have sold completely redundant system to different organizations within the same enterprise for political reasons or because each thought that they we so unique that their needs couldn't possibly be met by another departments systems. And, I attribute most of this to political envy and hoarding.

However, in 2010 with cloud computing, cheap storage, open systems integration and Software-as-as-Service (SaaS) based applications, enterprises no longer have an excuse for redundant systems. And, as a stock holder in the Global 2000 and a consumer, its about time to see some of the cost savings trickle down and turn into lower prices and/or higher margins.

eDiscovery Sin # 7: Not Changing Your Business Model to Encompass eDiscovery
Again, whether it's pride or sloth, or in this case, ignorance, not changing your business model to encompass eDiscovery, may be the biggest miscalculation of sin that you can commit. eDiscovery is not an "art" as some would have you believe. It should not happen behind the curtain like some Wizard of Oz magic trick. eDiscovery is nothing more than another business process and therefore can be defined, managed and tracked just like any other business process within the enterprise. And therefore, eDiscovery and it bigger brother (Governance, Risk and Compliance) should be integrated into the overall business process of the enterprise. And, in some cases the business models should be changed to take into consideration eDiscovery things like legal holds and data retention policies, etc.

Just ask one of your Lean Six Sigma buddies if you don't believe me. And, BTW - if you don't have a Lean Six Sigma buddy, contact me and I will introduce you to one because you are probably going to need one.

Summary
Comparing the tendencies of the players in the complex and high stakes world of eDiscovery in 2010 to The Seven Deadly Sins may be a bit over the top. However, there is always room for improvement in any system and in many cases just acknowledging that you have a problem many be the first step to making that improvement. Hopefully, my list will at least provide the foundation for thinking about what needs to be improved in eDiscovery. And, I would bet that every single of you has an even better list of The Seven Deadly Sins of eDiscovery.

Labels: , ,

Saturday, December 12, 2009

Obsolete Already?: Why the 2006 Amendments to the Federal Rules of Civil Procedure Need Revision

As most people in the electronic discovery field are aware, eDiscovery is expensive, time consuming and complicated. The 2006 amendments to the Federal Rules of Civil Procedure did little more than acknowledge that electronic records are part of the discovery process. While this might have been shocking to some, it should not have been. Everything held, known, used or within the control of a party is subject to discovery unless privileged. The 2006 amendments did not change that.

The problem is that the 2006 amendments do not go far enough. As the cases involving eDiscovery disputes are resolved it is becoming clear that what is needed are additional rules that the parties control the eDiscovery process. California attempted to fix this problem by enacting the Electronic Discovery Act. (The jury is still out on how those requirements will work but it will be interesting to watch). While I doubt that most state legislatures will get as involved in the eDiscovery process as California, the courts should. The courts need to take a more active role in reducing the cost of eDiscovery by pursuing a more active cost/benefit analysis for discovery requests, forcing lawyers to be more reasonable in their requests, and awarding parties who take active steps to simplify the eDiscovery process. Certainly some vendors, including our own eDiscovery Solutions Group (http://www.ediscoverysolutionsgroup.com/), are finding ways to lower the cost of eDiscovery. This includes preparation, choosing the right technology, and negotiating a fair price. However, we cannot do it alone. The courts must help.

In civil cases, the judge and the parties usually live on three different planets. Each is comfortable in its own home with its own perspective of what should happen in the case. Then, they collide into each other. There can be an enormous collision at the eDiscovery stage (and again at trial). Both parties believe that the other’s electronic records will provide them with a smoking gun, forcing the other to settle on favorable terms. The judge wants the discovery process to reach a natural resolution and often detests bickering over discovery. Judges wonder why the parties cannot be professional and find a mutually agreeable resolution. This collision drives up the cost of eDiscovery. Better rules will force all involved to be more reasonable.

I predict that within 10 years the 2006 amendments to the Rules of Civil Procedure will be obsolete. New rules will be enacted that set better rules for the eDiscovery process.

Labels: ,

Friday, October 9, 2009

Standards Need to Emerge for Collecting and Processing Electronically Stored Evidence (ESE)

Most litigators and their litigation support staff that have been practicing over the past 5-10 years could probably teach a class on the process of preservation, collection, processing, review and production of paper evidence. Or, at least they could stand at a whiteboard and draw a basic workflow diagram of the basic steps.

However, with the dramatic and accellerating increase in the amount of Electronically Stored Information (ESI) which I like to call Electronically Stored Evidence (ESE), the subsequent technical issues and the associated changes to the Federal Rules of Civil Procedures (FRCP), very few, if any of the same litigators and their staff, can now even describe the most basic workflow to to get ESE for a trial. Therefore, although many are talking of their importance (myself included), eDiscovery standards of any substance, are a long way off.

This is certainly not the fault of the lawyers as they have never been required to have much of true understanding of the technology of processing evidence in order to be successful litigators. However, the bar has now literally been raised and litigators can't even provide adequate representation without an indepth understanding of these new issues.

Maybe we should consider requiring a license or some type of ceritification to practice law when eDiscovery is involved? Or, has ESE become so intertwined in our matters that there isn't a case without eDiscovery and therfore every lawyer that want to litigate anything should have to be certified?

As a place to start this discussion / debate, we need to start identifying the basic components of ESE and how it is stored, how to preserve it, how to extract it (the new word for collection), how to process it, how to review it, and how to produce it.

Wouldn't it great if 5 years from now, litigators could stand at a whiteboard and diagram and explain the basic "standard" components of the workflow for processing Electronically Stored Evidence (ESE)?

Eric P. Blank addresses these issues in an excellent article titled,"The Need for E-Discovery Standards: A Call From the Trenches", posted on October 5, 2009 on the EDD Update Blog.

Eric P. Blank is the founder and managing attorney of Blank Law + Technology PS. His practice focuses on electronic discovery counseling, e-security response planning and implementation, investigations and computer forensics. Mr. Blank has conducted more than 300 investigations into computer and software-related torts and employee misconduct since 2001 and has frequently been a court-appointed special master or neutral in e-discovery matters.

The full text of Mr. Blank's post is as follows:

Most discussion about standards in electronic discovery focuses on the big-picture issues of scope, cost and cost shifting.

These are important questions eloquently argued in the courts. However, they overlook the mundane, pick-and-shovel e-discovery concerns that affect every case. I’m talking about the elementary technical issues of preservation, extraction, processing, review and production.

I’m talking about extracting data from electronic storage media, processing the data and its metadata into a document review software application platform, supporting the review and producing the data as discovery or evidence.

Outside the e-discovery world, the first stage of this process is known as Extract, Transform, Load (ETL). Identifying and overcoming the challenges of ETL have occupied computer scientists for decades. Principal obstacles to effective ETL include widely diverse and poorly documented storage repositories, asynchronous multimedia platforms, constantly evolving software, hardware and software anomalies, and human error, usually with respect to initial planning.

E-discovery vendors on the ground face those obstacles and more. Consider, as just a few of many examples, the following:

Mobile phones and PDAs: In some models, data can be extracted through forensic imaging. In others, such as many of those without SIM cards, data can only be pulled through live file extraction. Click here and here to read my earlier blog posts about the difference between forensic imaging and live file extraction. In any case, the question is this: Should data extraction scope be defined by current technical capabilities, or should there be a single common standard – such as live files only – for those instances when mobile phones and PDAs are subject to e-discovery?

A multitude of file types: Extraction and processing applications address dozens, sometimes hundreds, of file types. These file types are usually associated with, and identified by, a particular file extension, such as .doc or .xls. However, custom extensions are easy to apply – documents I create might have a .epb file extension, for example – and it is also simple to apply a nonstandard extension to a particular file type (e.g., a .doc extension to a PDF file). These are often missed, or improperly processed, by extraction and processing software.

Computer forensics software in the hands of an experienced technician can reveal documents by file type without relying on extension format and such, but doing so is costly and time consuming. What checks should be done for mislabeled or unusual file extensions? When are such checks required?

Metadata: Most of us think of metadata in basic terms such as the putative author, creation date, modification date, last-access date and so forth. However, metadata varies widely across data types. Microsoft Office documents, for example, have more than 100 metadata fields. It is also possible to create custom fields with many document types. Nearly all of these, such as the ubiquitous P-size and L-size, are nearly never important in civil litigation.

“Nearly never” is not, however, the same as “never.” Such data can be extracted, but it is not, as a rule, supported by processing software, which renders it unavailable at the attorney review level. Is it possible to agree on which metadata fields should be preserved and processed? When they should be processed? Which fields are important forensically? When all fields should be preserved?

Rapid technological change: Software is updated all the time. This affects how metadata is produced and the appearance of electronic documents. Processing software hasn’t kept up. It’s also inconsistent. For example, the last-access date on a Word 2007 document running in Windows Vista is affected differently than an Office XP Word document running on Vista. Both documents, however, are processed the same, as if the metadata means the same, when it does not. How should inconsistencies like this be addressed? What should the typical approach be?

Webmail: Screenshots of Web-based email services such as Hotmail are a common and inexpensive workaround to downloading actual Hotmail files. Which method is preferred? Is either method not preferred? As third-party cloud data repositories multiply, what constitutes best practices with regard to extraction methods will become a critical question.

Capture rates: What percentage capture rate is acceptable for processing software? Many files are often not processed by even the best technology, and must be laboriously hand processed. In a million-item processing job, a 1 percent miss rate equals 10,000 documents not processed and available for review. Is 99 percent acceptable? Is 98 percent? Note: If you think that the processing rate for your document review software is 100 percent, you’re kidding yourself.

Searching: Keyword searching, including keyword searches supported by “fuzzy” search techniques, are giving way to conceptual searching, which is the future of document search and review. Conceptual searching, however, involves proprietary algorithms and processes with a wide range of accuracy. What standards must conceptual searching meet to be accepted? How are these standards applied? When, if ever, is conceptual searching disallowed?

File format: In e-discovery today, most documents are produced in .Tiff format. Putting aside the larger question of whether .Tiff should be the standard for producing electronic documents, what about documents such as spreadsheets that don’t translate well into .Tiff files? In what format should presentation-type documents be produced? As slide shows? As workbook copies with notes and presenters’ comments? How are native files to be tracked and authenticated as a best practice?

Today, e-discovery consultants decide many of these questions on their own or after consulting with litigation counsel. In essence, a consultant decides when it is and isn’t practical to extract files from a system, whether to image a particular hard drive and whether to put aside as unreadable a back-up tape from a set of tapes that must be searched.

Much of the time, the consultant makes the “right” decision, as subsequently decided by the court, the client or the opposing party. It’s a rare consultant, however, who won’t admit that adopting e-discovery standards would bring enormous benefit to the practical challenges of data extraction, processing and production.

I'll be discussing these and other issues in the future. Any of the problems mentioned above could be an entire article. I look forward to working with the legal and technical community to address these “technical” standards – as opposed to the widely discussed “strategic” standards which may ultimately be addressed by changes in the Federal Rules of Civil Procedure.

Labels: , , , , , ,

Tuesday, June 30, 2009

Gunfight at the OK Corral or Forced Mediation in eDiscovery

As I am winding down my week getting ready for the July 4th holidays, I came across an interesting article posted on Compliance Week (http://www.complianceweek.com/) by Jaclyn Jaeger, titled “Cutting your eDiscovery Costs”.  The article is really more about how to use court forced mediation as a way to more efficiently resolve disputed that involve eDiscovery that it is about actually cutting the cost of eDiscovery.

According to Jaclyn, the basis for this course of action is a “pocket guide to eDiscovery”, written by Judge Lee Rosenthal—the U.S. district judge who chaired the committee that revised the rules of civil procedure in 2006.  Judge Rosenthal contends that judges have responsibilities in helping lawyers wade through the rough waters of eDiscovery cases.

The guide goes on to state that rather than wait on lawyers to identify and argue matters, judges should “require parties to provide the judge with expert briefings on the relevant technological issues.” In some instances, courts should require the parties to seek mediation, the guide advised.

There is no doubt that eDiscovery has added a whole new layer of technical complexity to litigation.  Further, there is also no doubt that there are still an unacceptable percentage of litigators that don’t understand the first thing about eDiscovery and as a result are providing inadequate representation.  However, it is also my opinion that there are still many judges that don’t understand the first thing about eDiscovery and as a result are providing inadequate support.

So, maybe Judge Rothenthal’s  “forced” mediation has a place in today’s system.   It would provide equal access/representation and possibly provide for more accurate outcomes at reduced costs.  However, in a “free”society with a system of justice that theoretically enables us “choose our own paths” and make our own decisions about how to best litigate our matter(s) within the system, does this approach set over the historic line of enabling the system to work?

Maybe eDiscovery is just too much for our current system and we do need to create what amounts to forced mediation with all the eDiscovery technical issues being driven by a central sanctioned expert.   Or, maybe we just need to let all the players mature and leave the system alone?

Being a fan of the John Wayne / Clint Eastwood type western, I have a tendency to want to leave the system alone and, even though there may be some unfair fights along the way,  let the parties work out their differences on their own.  In the long run, its better for the system.

The full text of article by Jaclyn Jaeger is as follows:

One of the biggest beefs companies have with corporate litigation has been the rise in discovery costs, especially as Corporate America has entered the electronic era and creates exponentially more information to search. But many times, it’s the lawyers themselves who make the process more expensive than it needs to be.

That was the message expressed by federal magistrate Judge Robert Collings, who spoke recently at the IQPC Corporate Litigation Exchange. He noted that misunderstandings over e-discovery arise when opposing sides attempt to guess at the scope of a dispute, rather than coming to an agreement and sticking to it. The result, he said, is that parties take their best guesses at what the other side wants—and fail, leading to time-consuming and costly pre-trial hearings and disputes.

A better approach is for lawyers to resolve the issues among themselves and then come to the court with solutions, an approach that would be “embraced by judges,” says Rick Wolf, CEO of legal consulting firm Lexakos.

As Collings pointed out, many magistrates would be more than happy to help settle the scope of a dispute. What really gets under their skin is refereeing each side’s decisions after those choices have been made.
That’s where the growing role of mediators in e-discovery disputes is coming into play, driven in part by 2006 amendments to the Federal Rules of Civil Procedure. Rule 29, in particular, gives opposing sides the leeway to set their own discovery rules, which has given rise to “a whole additional cottage industry of consultants,” says John Watkins of law firm Chorey, Taylor & Feil, and a registered mediator with the Georgia Office of Dispute Resolution.
“The mediator is not there to act as a judge or jury or to decide the case,” Watkins explains. Generally, he or she provide suggestions, offers feedback, asks probing questions, and—unlike arbitrators—tries to assist the parties in reaching their own agreement, he says.
While mediation itself is not anything new, lawyers are only just beginning to turn to neutral outsiders to help resolve issues unique to e-discovery, including “scope, identifying search terms, and the proper use of technology to call out information that may be privileged or confidential,” says Wolf, who sits on the e-discovery panel for the International Institute for Conflict Prevention & Resolution.
Using mediation in that narrow e-discovery context, he says, “could provide a very efficient means of getting to the merits of a problem.” By reaching a compromise outside the courtroom, lawyers can “come to the judge with progress reports, rather than being embroiled in suits.”
That approach does cut the costs of discovery—one of the most expensive parts of litigation, Watkins notes—but it can also save considerable time as well. Mediation can range anywhere from a few hours to a few days, and because the process is voluntary, a party can choose to walk away if he believes the process isn’t accomplishing much, he adds.

Choosing a Decider

Standards for experts and consultants in the field of e-discovery have not yet fully developed, so litigants (and courts) should carefully consider the knowledge and wisdom of a potential consultant, experts say. “Find a person who’s experienced in litigation and the court system, and also has some experience in the area of the particular dispute,” Watkins says.

Effective mediators will “not just understand how to mediate cases and be experienced in mediation, but also understand how things work in corporations,” says Wolf. “In other words, if you don’t understand the infrastructure and operation of technology systems and e-mail systems in companies and also the way corporations operate, it’s difficult to be able to navigate through and help in a mediation setting.”

Those burdens don’t just fall upon lawyers. As discussed in a paper written by Judge Lee Rosenthal—the U.S. district judge who chaired the committee that revised the rules of civil procedure in 2006—judges also have responsibilities in helping lawyers wade through the rough waters of e-discovery cases.

According to the Federal Judicial Center, which published Rosenthal’s “pocket guide,” judges “must understand the relevant technology at a level that allows effective communication with attorneys, parties, and experts,” if they are to effectively manage these issues. “Judges must also encourage parties to narrowly target requests for [electronically stored information] and to make these as early as possible in the litigation.”
The guide goes on to state that rather than wait on lawyers to identify and argue matters, judges should “require parties to provide the judge with expert briefings on the relevant technological issues.” In some instances, courts should require the parties to seek mediation, the guide advised.

Watkins, however, prefers that parties seek mediation voluntarily, “because if it’s voluntary, at least the parties have expressed some interest in resolving the dispute.”

Quicker resolution of e-discovery arguments also hinges on companies developing a more centralized approach to litigation management. “The reason that there is a struggle or a misunderstanding is because the mystery around a corporation’s technology, infrastructure, and systems continue,” Wolf says. He cites a survey conducted by Lexakos, which found that only 32 percent of law departments last year used a centralized litigation group; that number has jumped to 49 percent for 2009.

Those numbers show that law departments are getting more creative in how they cut costs and manage themselves more efficiently, Wolf says. “That’s significant, because it’s impossible to manage electronic discovery and the complex issues that are associated with it unless you have centralization and standards that are in place internally to access the information for litigation purposes.”

Centralization should give outside lawyers more streamlined access to a company’s internal information; that, in turn, should simplify disputes and lower costs, Wolf continues. “So the more centralized you are, the better your processes are. The easier it’s going to be for outside lawyers and judges to get to the heart of the matter.”

Labels: , , , , ,

Friday, June 5, 2009

Ease The Pain Of eDiscovery

20061214_pain Even though it seems like there have been more “horror” stories than success stories in eDiscovery, it is my opinion that the successes are beginning to outpace the failures. A good example of how three companies have pulled together IT, legal, and other stakeholders to reduce the complexity and cost of finding information when the lawyers come calling by recently posted by Andew-Conry-Murray in InformationWeek on May 30, 2009 12:02 AM (From the June 1, 2009 issue) in an article titled “Ease the Pain of eDiscovery”.

The article starts out with the famous horror story of the $6 million ediscovery costs associated with the Federal Housing Enterprise Oversight Office of as they attempted to respond to subpoenas for documents in litigation involving Fannie Mae and Freddie Mac.

After making his point about the “horrors” of eDiscovery, Andew-Conry-Murray goes on to provide a great overview how eDiscovery teams from Blue Cross, Webcor and Verizon eased the pain of eDiscovery by following some simple rules during each of the phases of eDiscovery.

As the article proves, eDiscovery isn’t a black art that requires a high paid Merlin type to pull off. There are plenty of very good guides and best practice models publically available that will enable even the most eDiscovery challenged among us to have a pretty good chance at success.

The full text of the article is as follows:

When the Office of Federal Housing Enterprise Oversight was subpoenaed for documents in litigation involving Fannie Mae and Freddie Mac, its IT department thought it had searched every cranny to find relevant e-mails. It turned out the agency overlooked disaster-recovery backups that were stored off-site.

That oversight triggered a legal fight and then a protracted search that resulted in a $6 million discovery bill--a whopping 9% of the office's annual budget.

When it comes to e-discovery costs, $6 million isn't an outlier, which points to the urgency of IT and legal departments working hand in hand to build policies and execute on them when litigation hits. At times, however, IT and legal work at cross-purposes--they don't communicate or, worse, argue over the best approach to collecting electronically stored information that's being called for, often on short notice.

To avoid these squabbles and the mistakes that come out of them, smart companies are creating e-discovery teams led by legal and IT principals, with other stakeholders in the organization brought in as needed. These teams set policies for data retention and preservation, oversee implementation of these policies, and handle e-discovery work related to specific legal cases. We'll look at what three companies--in insurance, telecom, and construction--are doing to make e-discovery the team sport it must be.

Team Leaders

One key component to the smooth operation of these teams is a liaison who coordinates the technical and legal requirements of discovery efforts. In some cases, this liaison may be a tech-savvy paralegal or attorney, but often it's an IT pro.
Brandon D'Agostino, of health insurer Blue Cross Blue Shield of South Carolina, had 10 years of IT experience, including four at BCBS working with application and database servers, when he left to get a law degree. He planned to become a litigator, but before taking the bar heard that Blue Cross was creating a new position--ESI counselor, charged with creating policies for the company's electronically stored information.

"We joke that I have street credibility from the IT department, because I was the guy getting called in at 2 a.m., so I understand what they're going through," D'Agostino says. They may joke, but street cred goes a long way toward smoothing over and anticipating conflicts between IT and the legal counsel's office. That's because a critical part of the liaison's role is to build relationships between the two groups.

You have to have buy-in from key people before a crisis erupts, D'Agostino says. He cultivated relationships with systems experts who work with Tier 1 repositories of information, such as e-mail and file servers, so that when an investigation hits his desk he doesn't have to spend precious time explaining to IT people what the legal department is trying to do.
Another lesson these liaisons have learned is that they need to convince IT that discovery efforts aren't a one-time exercise, and that the scope of any one investigation could easily expand. If legal needs e-mail from 10 people today, D'Agostino makes sure to ask IT what would happen if they end up needing it from 200 instead.

"If you give an IT person a horrible task to do one time, he'll complain," D'Agostino says. "Give it to him 10 times, and he'll find a way to automate it." E-discovery needs can't be attacked with "manual, fly-by-the-seat-of-your-pants processes," he says.

Verizon's director of legal discovery technology, Jaideep Singh, puts it another way: IT must understand that you'll be coming back. Singh, too, has an IT background, having initially worked in IT running billing and order fulfillment systems before moving to the legal department five years ago, where he quickly was pulled into discovery work because of his IT chops. Now he coordinates with the IT groups in charge of key sources of stored data, including e-mail, billing, and human resources systems.

Common Ground
Legal-IT liaisons like D'Agostino and Singh generally work with IT on specific phases of the discovery process, like those outlined in the Electronic Discovery Reference Model. Created by George Socha and Tom Gelbman, EDRM lays out the steps required for a discovery process, creating a map for e-discovery that both IT and legal groups have adopted (see chart, "Steps To Discovery", below).

IT's main work in this model comes in the first four steps: information management, identification, preservation, and collection.

The information management phase encourages companies to institute data management policies and technologies that address the creation, retention, and disposition of information, including unstructured content. It's a critical stage for IT and legal teams to work together to make for a smoother and less expensive discovery process.
The relationship between IT and legal faces its real test, however, in the next three phases, when a discovery effort is under way.

The Identification Phase

This phase focuses on finding all sources of electronically stored data that may be relevant to a legal action. Companies are required to keep such data and eventually may have to provide it to opposing counsel.

Legal departments generally have a rough idea which employees are associated with a legal matter, the time frame within which relevant information may have been produced, and keywords that are likely to lead to relevant data. It's up to the legal department's IT liaison to ensure that all appropriate IT systems will be included in the discovery effort.
It's also up to the IT liaison to dispel the Google myth. "Everybody has a perception that you can go to a screen and do a search, and all of the things relevant to a search are going to pop up," Singh says. Clearly, e-discovery isn't nearly that easy.

Often the key constraint is too few hands to do the work, as many IT organizations have been "cut to the bone," Singh says. In-house counsel shouldn't assume that e-discovery requests will always get priority over other projects that IT staffers are working on.
There are technology obstacles as well. When a discovery tool is used to collect information on desktops or servers at remote locations, coordination is needed with the network operations group to get access to those systems.

Another complication is that potentially relevant information may reside on mission-critical systems, and IT teams get twitchy when outsiders ask to mess with them. D'Agostino looks for workarounds, such as agreeing to read-only access or collecting data during off-peak hours.
Framing the scope of the discovery effort also is critical for IT-legal teams. If an attorney asks for all of a specific employee's e-mails on a certain subject, does IT just need to look in the in-box? What about the "Sent" or other folders? Does the request include locally stored files and ones on flash drives? If the request isn't clear, it will lead to mistakes. "You don't want technology folks interpreting legal requests," D'Agostino says.

Search terms also play a part in determining the scope of a discovery effort. Broad terms will kick back an unwieldy pile of results, as the legal department at Webcor Builders learned the hard way.

"They would say, 'Give me any e-mail about Oracle,'" says Webcor CIO and senior VP Gregg Davis, who also serves as a liaison between the construction company's IT and legal departments. The result was tens of thousands of e-mails when legal needed only a few hundred.
Experiences like this one led Webcor to form a discovery team that includes Davis, two IT administrators, two members each from the legal and HR departments, and people from the business side as needed. Since then, attorneys have been doing a better job coming to IT with refined search terms, specific date parameters, and the specific people whose data is involved, Davis says. As for IT, it has taught attorneys a thing or two about "if-and" statements and other search techniques to produce more accurate results, he says.

The Preservation Phase

Preservation, the third stage of the discovery process, is where IT has a major role in protecting potentially relevant information from being destroyed. Companies must keep information not just when litigation's begun, but also when there's a reasonable expectation of legal action. For example, if a company fires an employee and things turn acrimonious, the legal department may issue a preservation notice for that employee's e-mail, HR records, and work files in anticipation of a lawsuit.

In these cases, IT must be able to shut down the machinery of automated deletion. So if the company's document management system purges files after a certain time period, exceptions must be made for data associated with a discovery effort. The same may apply to policies for overwriting backup tapes. Attorneys also rely on IT to put safeguards in place to prevent people from deleting any data that's potentially relevant to a discovery effort from PCs, shared files, and removable media.

IT has two options for preserving data. The first is to copy and move data to a secure repository. The upside to this approach is that IT and legal can be confident that data will be there when it's needed. But it's time-consuming and expensive, and it can be wasteful since many times the data won't ever be subject to legal review or required by the court.

The second option is to preserve data in place, changing user or administrator permissions to prevent people from opening, writing to, or copying the data. Many archives and document management systems let IT place legal holds on information.

Preservation, whether through moving data or keeping it in place, requires IT and legal to work together because large volumes of information may end up on legal hold for months or even years, which will affect storage demands.

The Collection Challenge

The final phase that requires IT involvement is collection. Here, relevant data is gathered and delivered to inside or outside attorneys (sometimes both), who review and analyze it. Based on that analysis, counsel may expand the search, coming back to IT with new names of employees whose data could be relevant to the case, as well as new search terms and date ranges.
Collection must be conducted in a way that preserves the data's integrity, including metadata such as information on when a file was last opened or changed. Where possible, collected information is also expected to be available to counsel in its native file format.

At Blue Cross Blue Shield of South Carolina, D'Agostino collects data himself, operating the discovery software used at the company. Verizon's Singh helps craft requirements and track down locations where relevant data may reside, but the company's security department does the collecting. Verizon chose this approach because its security team is experienced in collecting digital evidence for forensic investigations and knows how best to protect metadata and maintain data's chain of custody.

At Webcor, Davis runs sensitive searches himself. For nonsensitive ones, two trained IT administrators use an e-discovery module that sits on top of the company's e-mail archive. They use terms and date ranges provided by the legal counsel's office to conduct searches. The system is set up so that the administrators don't get to see the results; only the company's attorneys have that access.

It Takes A Team

Companies can't appoint a legal-IT liaison and consider their work done. E-discovery needs a team that includes, at a minimum, IT and legal representatives, plus people from other areas with major information management responsibilities such as HR and records management. Thomas Smith, a partner and founding member of the e-Discovery Analysis and Technology group at law firm K&L Gates, also recommends a business unit representative who knows how information is used, what the business needs are, and where relevant information resides.
Regular meetings are key, even when there isn't pending litigation. Webcor CIO Davis meets quarterly with counterparts in legal and HR, and they sometimes bring in a business unit executive. The meetings are used to set policies and procedures, and for IT and legal to update each other on the latest trends in their fields that may be relevant to discovery. When a case hits, Davis maps out a strategy with legal counsel and HR for the collection and preservation of relevant information. E-discovery teams at companies where litigation is common tend to meet more frequently.

At Verizon, the e-discovery team takes part in finding and selecting discovery tools, so there's input on the IT, legal, and security needs when testing and choosing products, Singh says.
Some of the most important work e-discovery teams do in regular meetings is to set policies on information retention and disposal. Poor policy can be costly. IT may assume the legal department wants to save every e-mail, when in-house counsel wants IT only to save information that's potentially relevant to a legal action.

In fact, the legal department likely wants IT to delete information when allowed by the law and industry regulations. That reduces the amount of potential information that has to be collected and analyzed, saving on the cost of e-discovery.

"Follow your policies" is one of the first lessons Webcor's Davis and his IT team learned from working with legal counsel. "One of the first questions they ask you in a deposition is, 'Do you ever deviate from policy?'" Davis says. "If you say yes, you have another three hours on the stand. The minute you deviate from policy, you open the door to massive damages."

Opposing counsel is sure to raise questions about a company's ability to maintain control over its data, especially if that data strengthens a company's defense. "But when you show how on top of this you are, you take a lot of wind out of the opposing counsel's sails," Davis says.
Solid e-discovery policies won't guarantee a win in court. But they can ensure that a case isn't lost based on a misstep with data identification, collection, and preservation. Key to this is the strength of the e-discovery team, one that has established comprehensive policies and has mechanisms in place to ensure that those policies are followed.


Labels: , , , , ,

Monday, April 20, 2009

Doesn't Everyone Already Know About eDiscovery?

It's been over 2 years since the changes to the Federal Rules of Civil Procedure (FRCP) took effect, spawned a whole new industry called ediscovery and changed the face of litigation forever. So, since I have been living and breathing eDiscovery and watching this "eDiscovery Paradigm Shift" from ground zero and helping the "early adapters" wade their way through the morass of issues and technology, it appears that I may have lost some perspective in regards to the fact that no everyone in the legal market or in enterprises across the globe are worrying about eDiscovery compliance. How could that possible be?

Well, whether intended or not, that point was made clear to me by Rick Dales, Vice President of Product Management at Proofpoint, through an article that he had published on the Computer Technology Review site titled, "Is Your Company Ready for e-Discovery?: What FRCP Can Mean for Your Business and How to Prepare."

This article is well written, very informative and would be a great resource for the novice, uninformed IT director as an introduction to the requirements for managing Electronically Stored Information (ESI) in 2009. It may also qualify as required reading for any litigators or anyone associated with enterprise information management that been in a coma for the last 36 months.

In all seriousness, it is really easy for those of use who spend most of our waking hours working within the eDiscovery market to forget that eDiscovery is a fairly new discipline and that there are more professionals that don't know about it or haven't thought too extensively about how it will effect their operations and business than have.

So, maybe I am the one that has been living under the eDiscovery rock and maybe its time for me to realize that the rest of the world has not yet had the pleasure of experiencing the thrill and excitement of eDiscovery.

The full text of the article is as follows:

Electronic Discovery (or e-Discovery) refers to the producing, obtaining and reviewing of digitally stored electronic evidence in response to civil litigation. With the passing of the Federal Rules of Civil Procedure (FRCP), it’s a new era in which organizations are challenged with how to face the increasing pressure to proactively manage the retention and handling of various forms of corporate records and data for compliance and legal discovery purposes.

The first step to addressing this challenge is for enterprises to be aware of what is required under FRCP. Next, businesses should prepare themselves for compliance by ensuring the ability to retrieve and analyze terabytes of data upon request. With new advances in technology, this crosses an increasingly expansive landscape, including: email, instant messages, handhelds, laptops, enterprise networks, databases and SMS. By proactively addressing FRCP challenges, enterprise IT staffs can ensure a seamless process should the need for legal discovery ever arise.
What Is the FRCP?
The FRCP governs the conduct of all civil actions in US Federal District courts. Although the most recent amendments to the FRCP were made over a year ago, many companies are not familiar with what is required of them by law. Enterprises should be concerned about these new amendments because, unlike most data retention requirements that are industry specific (such as the NASD and SEC rules for financial institutions and broker-dealers), the FRCP applies to organizations in all industries.

Proper data retention is no longer just a best practice – it’s a legal obligation. If electronic data is not properly managed, corporations face serious consequences that include hefty fines or imprisonment, making it particularly important for business decision-makers and IT administrators to understand the new amendments. To prepare for e-discovery, organizations must adopt a complete approach to managing all types of data so that it can be easily searched and retrieved when necessary.

The Amendments and Their Implications
Recent FRCP amendments require companies to retain all their corporate correspondence, including electronically stored information (ESI), so that it can be produced in a timely and complete manner. As such, litigation readiness has become an increasingly important IT responsibility. The following is a summary of the amendments that impact e-discovery and reinforce the need for email archiving.

Rule 16: Pretrial Meetings
Requires all parties to meet and discuss a discovery plan and evaluate the preservation and production of ESI.

Rule 26(a): Duty to Disclose
Requires parties to identify all sources of ESI that may be relevant by category and location.

Rule 26(b): Discovery Scope and Limits
Every organization has “a duty to disclose all potentially relevant sources of information” to the courts as soon as they “reasonably anticipate” litigation unless these sources are “not reasonably accessible because of undue burden or cost.”

Rule 26(f): Planning for Discovery
Requires opposing parties to meet before the trial, or at least 21 days before a scheduled conference to discuss the nature and basis of their claims in an attempt to speed the possibilities of a prompt settlement.

Rule 34(a): Producing Documents
Electronically stored data – including email – is one of the types of records which can be requested for inspection by opposing parties.

Rule 34 (b): Procedure and Form of Production
As a part of the discovery process, the responding party should provide a “proposed plan for discovery” and produce all requested information, including ESI, in a form that is “reasonably useable.”

Rule 37(f): Sanctions for Failure to Make Disclosures or to Co-operate in Discovery
This rule creates a “safe harbor” protecting a party from sanctions arising from its deliberate deletion of ESI as long as it was deleted “as a result of routine, good faith operation of an electronic information system.”

Complying with the Amendments
In an effort to be proactive, businesses should develop an organization-wide approach to understanding and organizing ESI. However, many storage managers do not have the technology in place to properly produce information such as corporate and personal email records, attached files and instant messages. According to a recent survey conducted by Osterman Research, about one third of IT managers surveyed admitted that they could not produce an email over a year old.

The research showed that only a small number of organizations have a corporate retention policy in place and one fourth of these companies deleted their emails within 90 days of being stored. The lack of policies for items such as personal emails and the inability to locate each and every place where corporate or personal email data could reside can cause serious problems for companies that need to produce all relevant information during e-discovery or regulatory audits. These findings demonstrate that over a year after the amended FRCP, most organizations are not fully prepared to comply. To meet these requirements, organizations must develop a sound email policy that can be implemented and maintained with an effective email archiving solution.

Are You Prepared?
To evaluate your organization’s litigation readiness, IT managers should ask the following:

Do you have an email retention policy?
Your records management policy must address the different types of electronic documents that may be created in a corporate environment. It is critical that email policies provide adequate instructions to employees regarding their duty to preserve email and the manner, method and location of preservation.

Are you confident that your email retention policy is being enforced?
Simply having an email retention policy is not sufficient to meet the FRCP requirements. Organizations must ensure that the policy is enforced and that all copies of email are disposed of once they have reached their retention period. Implementing an effective email archiving solution within your organization will allow you to set retention policies that are automatically enforced so that regular electronic data is not kept longer than necessary and relevant data (such as emails that have been placed on litigation hold) is preserved for a longer period of time.

Do you know where all copies of corporate email are stored? Can you easily access them?
As the FRCP amendments require full disclosure of relevant ESI and their location, organizations must clearly disclose to staff the acceptable locations for storage of business records. By specifying in the email policy that all electronic records can only be stored in the corporate email server (and the accompanying corporate email archive), businesses can dramatically simplify this process.

Can you enforce a litigation hold?
The FRCP requires businesses to place a litigation hold on any information that may be relevant to a case as soon as they “reasonably anticipate” litigation. Placing a litigation hold ensures that any existing or future electronic records related to a particular lawsuit are preserved indefinitely, even if past the stated retention period. Most companies do not have the storage resources to handle this, nor do they have the ability to put data on hold within short notice. An email archiving solution that is equipped with a litigation hold capability can address this concern by allowing organizations to automatically put relevant records on hold so that they are preserved for the duration of the litigation.

Do you have the tools to search through every email sent or received for legal discovery purposes within 30 days of an order?
Electronic messages are typically stored in many different locations. For purposes of litigation, companies must be able to quickly sort through all this email data. The simplest and most effective way of achieving this is to ensure that electronic records are stored in a searchable format in a centralized location. Most email archiving systems have an advanced search capability which allows the legal department to easily search through the full text and attachments of all email in order to quickly respond to legal discovery requests.

If you answered ‘No’ to any of the above questions you need to sit down with your IT team and legal counsel as soon as possible. In order to be in compliance, appropriate solutions need to be in place before it is too late.

Labels: , , , , , , ,