8 months ago

Arkib Negara ELECTRONIC RECORDS MANAGEMENT and archive mgmt guideline_eng

e-SPARK 5 Special Topics

e-SPARK 5 Special Topics 5.1 Electronic Records and Business Continuity 7 Loss of electronic records in a disaster can be crippling for a public office. Information is the lifeblood of modern business – communications, contracts, research data, strategic plans, policy advice, customer records, payments and receipts. Without records, business grinds to a halt, corporate memory is lost and public offices are vulnerable to a multitude of risks. Data on digital storage devices can be more susceptible to damage through disaster than other record formats, such as paper or microforms. Relatively minor damage to digital storage devices can easily render all information contained on a storage device inaccessible. Disasters that can affect electronic records include: • Natural events such as earthquakes, cyclones, bushfires, floods and vermin plagues. • Structural or building failure such as malfunctioning sprinklers, leaks in roofs, poor wiring and power surges. • Industrial accidents such as nuclear or chemical spills. • Technological disasters such as viruses and computer equipment failures. • Criminal behaviour such as theft, arson, espionage, malicious computer hacking, vandalism, riots, terrorism and war; and • Accidental loss through human error, unsuitable storage conditions (e.g. storage of magnetic media near electronic equipment generating strong magnetic fields) or by the natural decay of materials (e.g. corrosion of poor quality compact disks). All electronic records and systems for which a public office is responsible should be incorporated into a business continuity plan. Appropriate disaster management arrangements for records created, and systems used, by outsource providers on behalf of the public office should also be provided for in contractual obligations. 5.1.1 Establishing a business continuity plan The Arkib Negara encourages all public offices to develop, implement and maintain an effective business continuity plan to cover their electronic records and recordkeeping and business information systems. It is critical to plan and protect electronic records and business information systems from the risk of disaster, and to ensure the continuation of business in the event of a disaster. 7 Based on guidance provided in Digital Recordkeeping: Guidelines for Creating, Managing, and Preserving Digital Records, National Archives of Australia, consultation draft, May, 2004 Copyright Arkib Negara Malaysia Page 53 of 86

e-SPARK Typically, a business continuity plan will comprise measures to prevent or minimize the impact of a disaster, protection strategies for vital records and disaster recovery and restoration procedures to be followed if a disaster occurs. The key components of such a plan include: • A general policy statement. • Assignment of staff responsibilities, including contact details for emergency services staff and the public office disaster recovery team. • Threat analysis identifying the most likely potential disasters. • Steps for preparedness, response and recovery. • Procedures for identification and declaration of a disaster situation. • List of vital records, noting significant or vulnerable holdings, and associated location and control documentation. • Clearly identified priorities for salvage. • Details of equipment and materials available for use in disaster salvage and recovery • Building plans identifying and addressing any potential site risks. • Provisions for staff training and current awareness. • Emergency funding and insurance arrangements. Periodic monitoring and review of a public office’s business continuity plan should be undertaken to ensure its continued viability and effectiveness. 5.1.2 Counter disaster strategies Public offices should be proactive in matters of business continuity and ensure that appropriate procedures and practices are in place to minimize the risk of electronic records being lost or damaged as a result of disaster. Before establishing a business continuity plan, public offices should undertake a risk analysis to determine the types of threats being faced, the likelihood of disasters occurring and the potential impact of the resulting loss of records. All reasonable risks affecting electronic records and business information systems should be identified, prioritized and assessed as part of the risk analysis, so that steps can be taken to determine appropriate counter disaster strategies. Counter disaster strategies are measures devised and implemented to improve a public office’s capacity to prevent, prepare for and respond to disasters. Implementation of these strategies is central to any business continuity plan. The following represent the core counter disaster strategies for the protection of electronic records: • Duplication and dispersal of vital electronic records. Copyright Arkib Negara Malaysia Page 54 of 86

