e-Discovering the Cloud

Opinion
Jan 21, 20102 mins

Enterprises should thoroughly plan e-discovery

This month, the City of Los Angeles is transitioning from Novell GroupWise to Google Apps with a 3,000 employee pilot. Google Apps will deliver office applications and collaboration to the City’s 30,000 employees. The city hopes to save $5.5 million over five years while improving collaboration, remote access and expanded storage. For security and compliance, the City of LA has a strong partner in CSC. CSC is combining its Cloud Orchestration Services and Trusted Cloud Computing services to accomplish tasks such as identity management, federation, service orchestration and remote monitoring. And, according to the City of LA, Google encrypts and fragments data at rest. In other words, confidentiality is maintained unless keys are compromised. But, what about availability? For example, how will e-discovery work? The European Network and Information Security Agency (ENISA) ranks e-discovery as a “high risk” area of cloud computing.

Each year, the City of LA faces thousands of civil lawsuits, many with e-discovery requirements. Based on the contract with CSC/Google (available from the LA City Clerk) the extent of the e-discovery requirement is “searching on content, sender and recipient, date range and metadata.” This is basic search capability and not on par with purpose-built e-discovery systems such as EMC/Kazeon or Seagate/i365 MetaLINCS. Given the volume of litigation and the potential 750 Terabytes of user data I don’t envy the people who have to perform the task.

The bottom line is that enterprises should thoroughly plan e-discovery up front. A SaaS like Google Apps may limit you to discovery capabilities inherent in the cloud.