E-mail Archiving
   HOME

TheInfoList



OR:

Email archiving is the act of preserving and making searchable all email to/from an individual. Email archiving solutions capture email content either directly from the email application itself or during transport. The messages are typically then stored on magnetic disk storage and indexed to simplify future searches. In addition to simply accumulating email messages, these applications index and provide quick, searchable access to archived messages independent of the users of the system using a couple of different technical methods of implementation. The reasons a company may opt to implement an email archiving solution include protection of mission critical data, to meet retention and supervision requirements of applicable regulations, and for e-discovery purposes. It is predicted that the
email Electronic mail (email or e-mail) is a method of exchanging messages ("mail") between people using electronic devices. Email was thus conceived as the electronic ( digital) version of, or counterpart to, mail, at a time when "mail" meant ...
archiving market will grow from nearly $2.1 billion in 2009 to over $5.1 billion in 2013.


Definition

Email archiving is an automated process for preserving and protecting all inbound and outbound email messages (as well as attachments and metadata) so they can be accessed at a later date should the need arise. The benefits of email archiving include the recovery of lost or accidentally deleted emails, accelerated audit response, preservation of the intellectual property contained in business email and its attachments and "eDiscovery" in the case of litigation or internal investigations (what happened when, who said what).


Overview

Email Archiving is the process of capturing, preserving, and making easily searchable all email traffic to and from a given individual, organization, or service. Email archiving solutions capture email content either directly from the email server itself (journaling) or during message transit. The email archive can then be stored on magnetic tape, disk arrays, or now more often than not, in the cloud. Regardless of the location of the email archive, it gets indexed in order to speed future searches, and most archive vendors provide a search UI to simplify query construction. In addition to email, attachments and associated
metadata Metadata is "data that provides information about other data", but not the content of the data, such as the text of a message or the image itself. There are many distinct types of metadata, including: * Descriptive metadata – the descriptive ...
, some email archiving applications can also archive additional aspects of a mailbox including public folders,
.pst In computing, a Personal Storage Table (.pst) is an open proprietary file format used to store copies of messages, calendar events, and other items within Microsoft software such as Microsoft Exchange Client, Windows Messaging, and Microsoft Outlo ...
files, calendars, contacts, notes, instant messages and context.


Objectives

There are many motivations for enterprises or end-users to invest in an Email Archiving solution, including: * Data Preservation * Protection of Intellectual Property * Regulatory compliance * Litigation and Legal Discovery * Email Backup and Disaster Recovery * Messaging System & Storage Optimization * Monitoring of Internal & External Email Content * Records Management (Email Retention Policies) * Business & Email Continuity


Regulatory compliance

As enterprises of all sizes grow more reliant on email, the business value of that content is also growing. To protect this increasingly valuable information (''intellectual property''), numerous standards and regulations have been enacted to require records protection and retention as well as timely response to legal (discovery) and information (FOIA) requests. Modern email archiving solutions allow companies to meet regulatory requirements or corporate policies by securing and preserving data and providing flexible data management policies to enable authorized users to enact 'legal holds', set retention and purge policies, or conduct searches across multiple mailboxes to complete various inquiries. Some of the primary compliance requirements driving the need for secure email archiving are (''alphabetically''): Canada * Investment Industry Regulatory Organization of Canada (IIROC) 29.7 * Mutual Fund Dealers Association (MFDA) *
PIPEDA The ''Personal Information Protection and Electronic Documents Act'' (PIPEDA; french: Loi sur la protection des renseignements personnels et les documents électroniques) is a Canadian law relating to data privacy. It governs how private sector ...
Germany * GoBD Switzerland * Schweizerisches Obligationenrecht, article 962 United Kingdom *
British Standards Institution The British Standards Institution (BSI) is the national standards body of the United Kingdom. BSI produces technical standards on a wide range of products and services and also supplies certification and standards-related services to business ...
- BS 4783, BS 7799/ISO 17799, BS ISO 15489-1, BSI DISC PD 0008, BSI DISC PD0010, BSI DISC PD0012 *
Data Protection Act 1998 The Data Protection Act 1998 (DPA, c. 29) was an Act of Parliament of the United Kingdom designed to protect personal data stored on Computer, computers or in an organised paper filing system. It enacted provisions from the European Union (EU) Da ...
*
Freedom of Information Act 2000 The Freedom of Information Act 2000 (c. 36) is an Act of the Parliament of the United Kingdom that creates a public "right of access" to information held by public authorities. It is the implementation of freedom of information legislation ...
United States * FDA
Title 21 CFR Part 11 Title 21 CFR Part 11 is the part of Title 21 of the Code of Federal Regulations that establishes the United States Food and Drug Administration (FDA) regulations on electronic records and electronic signatures (ERES). Part 11, as it is commonly cal ...
*
Federal Rules of Civil Procedure The Federal Rules of Civil Procedure (officially abbreviated Fed. R. Civ. P.; colloquially FRCP) govern civil procedure in United States district courts. The FRCP are promulgated by the United States Supreme Court pursuant to the Rules Enabling ...
(FRCP) *
Freedom of Information Act Freedom of Information Act may refer to the following legislations in different jurisdictions which mandate the national government to disclose certain data to the general public upon request: * Freedom of Information Act 1982, the Australian act * ...
* Gramm-Leach-Bliley Act * FTA(Hedge Fund Transparency Act) *
HIPAA The Health Insurance Portability and Accountability Act of 1996 (HIPAA or the Kennedy– Kassebaum Act) is a United States Act of Congress enacted by the 104th United States Congress and signed into law by President Bill Clinton on August 21, 1 ...
* Investment Advisors Act *
FINRA The Financial Industry Regulatory Authority (FINRA) is a private American corporation that acts as a self-regulatory organization (SRO) that regulates member brokerage firms and exchange markets. FINRA is the successor to the National Associati ...
Rule 3110 and
NYSE The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District, Manhattan, Financial District of Lower Manhattan in New York City. It is by far the List of stock exchanges, world's largest s ...
Rule 440 * Sarbanes-Oxley *
California Senate Bill 1386 (2002) California S.B. 1386 was a bill passed by the California legislature that amended the California law regulating the privacy of personal information: civil codes 1798.29, 1798.82 and 1798.84. This was an early example of many future U.S. and intern ...
(Only in California) * Securities and Exchange Commission Rule 17a-4 an
SEC Rule 17a-3
*
Patriot Act The USA PATRIOT Act (commonly known as the Patriot Act) was a landmark Act of the United States Congress, signed into law by President George W. Bush. The formal name of the statute is the Uniting and Strengthening America by Providing Appropr ...
Note, that many of the compliance regulations require the preservation of "electronic business communications" which consist of not only email, but may include instant messaging, file attachments, Bloomberg Messaging, Reuters Messaging, PIN-to-PIN and SMS text messages, VoIP and other electronic messaging communications used in business.


Litigation and legal discovery

For
legal discovery Discovery, in the law of common law jurisdictions, is a pre-trial procedure in a lawsuit in which each party, through the law of civil procedure, can obtain evidence from the other party or parties by means of discovery devices such as interro ...
, email archiving solutions will lower the overall risk of
spoliation Spoliation may refer to: * Looting * Spoliation of evidence in a criminal investigation See also * Spoliation Advisory Panel *Nazi plunder Nazi plunder (german: Raubkunst) was the stealing of art and other items which occurred as a result ...
and greatly speed up electronic discovery. This is because messages are indexed, audit trails are provided, messages are deduplicated, and legal hold/preservation can be applied. For litigation support, email can be retrieved quickly and a history of the email exists to prove its authenticity for chain of custody. For compliance support, email records are stored in the archive according to administrator defined retention policies. When retention periods expire, email is automatically deleted by the archiving application. In order to be compliant, an organization can intentionally destroy email messages, so long as (1) the destruction is done pursuant to a stated company policy and (2) the destruction stops immediately if an incident occurs which could give rise to a lawsuit. If an organization has multiple separate applications, for example for e-discovery, records information management, and email archiving, each application may have a separate database and it becomes difficult to de-duplicate messages and ensure that a single retention policy is being applied. From a legal point of view, this is important because once retention periods have expired the message should be purged from the archive. Messages that are not purged are still discoverable, should litigation arise at a later date. As such, without a unified archive it is difficult to ensure one single retention policy. This problem is magnified for large organizations that manage tens of millions of emails per day. Without email archiving, email likely exists on some combination of backup tapes and on
end users In product development, an end user (sometimes end-user) is a person who ultimately uses or is intended to ultimately use a product. The end user stands in contrast to users who support or maintain the product, such as sysops, system administrato ...
’ local workstations. If a specific email needs to be found for an internal investigation or in response to litigation, it can take weeks to find and costs a great deal. With today’s legal discovery rules (see FRCP: https://web.archive.org/web/20141021110256/http://www.uscourts.gov/uscourts/RulesAndPolicies/rules/EDiscovery_w_Notes.pdf) and compliance legislations, it has become necessary for IT departments to centrally manage and archive their organization’s email, so email can be searched and found in minutes; not days or weeks.


Email backup and disaster recovery

Email is the lifeblood of many modern businesses, and enterprises today depend more on reliable email service. Virtually all enterprises implement a messaging infrastructure to connect workers and enable business processes. In the
e-commerce E-commerce (electronic commerce) is the activity of electronically buying or selling of products on online services or over the Internet. E-commerce draws on technologies such as mobile commerce, electronic funds transfer, supply chain manageme ...
arena, employees may require access to email to close sales and manage accounts. These employees, plus many others, may choose to keep their emails indefinitely, but some organizations may mandate that emails more than 90 days old be deleted. Setting these kinds of retention policies deserves careful consideration as a single email could help a company win a lawsuit or avoid litigation altogether. Email archiving can also be used for business continuity at the individual employee level. When one employee quits, his/her replacement can be given access to the departed employee's archived messages in order to preserve correspondence records, and enable accelerated on-boarding. As part of a comprehensive
disaster recovery plan Given organizations' increasing dependency on information technology to run their operations, Business continuity planning covers the entire organization, and Disaster recovery focuses on ''IT''. Auditing of documents covering an organization's ' ...
, an email archive can be instrumental in an organization's effort to "get back to business". An offsite, online archive means that secondary facilities can spin up messaging servers and quickly get access to the last mails sent/received as well as all historical messaging data. Offsite archives can take the form of disk farms (SANs) in distant DR facilities or email archives stored in public/private cloud environments. Although email archiving products do capture and copy all messages, they are not mirrored copies of the messaging server itself, and therefore cannot help recreate user accounts/groups in the event of a disaster.


Messaging system & storage optimization

Every email message takes up space on an email system's hard drive or some other permanent storage device (e.g.
Network Attached Storage Network-attached storage (NAS) is a file-level (as opposed to block-level storage) computer data storage server connected to a computer network providing data access to a heterogeneous group of clients. The term "NAS" can refer to both the techn ...
,
Storage Area Network A storage area network (SAN) or storage network is a computer network which provides access to consolidated, block-level data storage. SANs are primarily used to access data storage devices, such as disk arrays and tape libraries from serve ...
, etc.). As the number of these messages increase, simple operations such as retrieving, searching, indexing, backup, etc. utilize more information system resources. At some point older data must be removed from the production email system so that they can maintain a level of performance for their primary use, exchange of email messages. Email archiving solutions improve email server performance and storage efficiency by removing email and attachments from the messaging server based on administrator defined policies. Archived email and attachments remain accessible to end users via the existing email client applications.


See also

*
Electronic message journaling Electronic message journaling is the process of retaining information relating to electronic messages. In this context, electronic messages are defined as any type of electronic communication data structure. Historically this was an electronic mai ...
*
Electronic discovery Electronic discovery (also ediscovery or e-discovery) refers to discovery in legal proceedings such as litigation, government investigations, or Freedom of Information Act requests, where the information sought is in electronic format (often refe ...
*
File archive In computing, an archive file is a computer file that is composed of one or more files along with metadata. Archive files are used to collect multiple data files together into a single file for easier portability and storage, or simply to compress ...
*
List of email archive software This article provides a list of software products and cloud-based services used for email archiving. Email archiving has several objectives: long-term preservation of knowledge, regulatory compliance, legal protection, etc. Those different goal ...


References


Further reading

* * * *


External links


Best Practices: Email Archiving
by Forrester Research {{DEFAULTSORT:Email Archiving Email Computer archives Records management