The cost of mismanaging information

Opinion
May 23, 20053 mins

I’ve written a fair amount lately on the topic of “information stewardship.” In case you’ve missed it, information stewardship is the discipline of ensuring that an organization’s data is:

* As accurate and complete as possible (data-quality management).

* Appropriately secured, with access granted only to appropriate parties (information protection).

* Auditable and compliant with pertinent privacy and disclosure guidelines (indexing and records retention).

*Stored on the most appropriate and effective mechanisms (information life-cycle management).

*Reliably backed up and available in the event of a failure (business-continuity planning and disaster recovery).

So far, I’m finding that few organizations have a consistent, coherent framework covering all these points – much less the technology and processes to manage it. Moreover, most of the companies tell me that information stewardship (though they usually don’t call it that) is the single- most critical strategic challenge they’re facing.

I agree. While it’s hard to pin hard-dollar numbers on the cost of an ineffective information-stewardship policy, several recent events highlight the urgency. Recently, Time Warner announced that it lost sensitive data, including names and Social Security numbers, for 600,000 employees. Time Warner’s data was on back-up tapes maintained by storage facility provider Iron Mountain and was apparently lost in transit to the storage facility. In February, Bank of America lost back-up tapes containing credit-card records for more than 1 million government employees, and ChoicePoint was attacked by identity thieves who gained access to sensitive customer data.

That’s not all. Famed investment bank Morgan Stanley was recently ordered to pay a whopping $604 million in a legal suit, primarily because the company said it was unable to find e-mails pertaining to the case. (Effective records retention and indexing is a key component of information stewardship.) And a recent study by Financial Executives International found the average cost of Sarbanes-Oxley compliance to be $4.4 million, using a base of 217 companies with average revenues of $5 billion.

The bottom line is that companies need to move now to create and adhere to effective information-stewardship policies. Start an information stewardship task force today, and include participants from within corporate finance, legal and compliance teams, as well as IT.

But that’s not enough. Our entire legal framework needs to be revamped and rethought in the context of information stewardship. Recent court cases have reached contradictory conclusions about which information can be considered private, or what legal hurdles are required to disclose it. As noted cryptographer and security guru Bruce Schneier says in this month’s Communications of the ACM, “In the information age, virtual privacy and physical privacy don’t have the same boundaries. We should be able to control our own data, regardless of where it’s stored.”

Amen.

Step 1 is for organizations to tackle the problem within their own boundaries. Step 2 is to rethink the broader public policy on information stewardship in the context of 21st century technology.