Complying with data storage and retention laws - it makes good business sense

June 2011 Security Services & Risk Management, Information Security, Financial (Industry)

As the world becomes increasingly digitalised, organisations are storing more and more data electronically, much of which is mission critical and essential to running their business. The integral nature of this data to the business world, as well as events such as the Enron debacle, led governments around the world to begin passing various pieces of legislation around the protection of electronically stored information.

Compliance with legislation in this regard has forced organisations around the world to examine their data policies and adopt new guidelines for the retention, processing and destruction of electronic records and communication. One of the most notable regulations not only for the United States where this law was passed but for organisations around the world, particularly those is the financial sector, was Sarbanes-Oxley, or SOX.

Since the introduction of this regulation there have been many others from various countries, all of which affect multinational corporations or any business which has dealings with these countries. South Africa is no exception, and the most notable piece of law in this regard is the Electronic Communications and Transactions (ECT) Act which came into effect in August 2002 and is aimed at creating a legal framework for governing electronic documentation and transactions. The South African Revenue Service (SARS) also requires that companies keep documentation for a minimum of five years for tax purposes, and the Johannesburg Stock Exchange (JSE) has its own regulations around data retention that listed companies need to comply with.

With all of these regulations that must be adhered to at the risk of strict financial and business penalties, compliance has become not so much a matter of sticking to the letter of the law, but more about business continuity, which after all was the reason behind these laws being imposed worldwide in the first place. However these laws have also meant that requirements for data storage have increased dramatically, as in many cases, for instance the legal profession, they require all electronic documentation and communications to be kept, even junk e-mails and spam. The financial sector also has very strict guidelines as to what information must be kept and for how long, and these regulations mean that the required amount of storage continues to increase along with the volumes of electronic data.

One of the major issues that impacts data storage is having the incorrect software for backups, which results in duplicate copies of the same documents and communications being stored, wasting space and as a result costing money that need not be spent on excessive storage capacity. By introducing software with de-duplication technology, organisations can ensure that only one copy of electronic data will be stored, reducing space requirements dramatically.

The reality is that more laws governing electronic data are in the pipeline, and businesses need to be able to keep their information securely in order to comply. However this does not mean that data retention needs to cost the earth, as a smart strategy around backup and retention can not only aid in compliance but can safeguard the continuity of the business by ensuring that mission critical data is always available for recovery should a crisis occur.

Storage is however not a ‘one size fits all’ technology, and there are various solutions available, including disk storage, tape storage and even cloud storage technology, with both on-site and off-site options available.

Which solution is best for any particular organisation depends on the size and needs of the business, so it is advisable to deal with a backup and security expert who can help to ensure that the solutions that are put into place will meet the needs of today and into the future.

Storage, backup and recovery should form part of strategic business planning to ensure that current and future needs can be met, that businesses comply with all of the regulations related to their industry and business dealings, and that the correct software is in place to optimise the effectiveness of storage solutions and minimise the impact to the bottom line while still remaining effective and ensuring business continuity. It just makes good business sense.

Fred Mitchell, Symantec Division manager at Drive Control Corporation
Fred Mitchell, Symantec Division manager at Drive Control Corporation

For more information contact Fred Mitchell, Drive Control Corporation, +27 (0)11 201 8927, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
SABRIC appoints Andre Wentzel as interim CEO
News & Events Financial (Industry) Associations
The South African Banking Risk Information Centre (SABRIC) has announced the appointment of Andre Wentzel as interim chief executive officer, effective immediately.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
FICA in the era of deepfake and AI-driven fraud
Security Services & Risk Management
A growing fraud strategy involves leveraging AI to produce highly convincing fake images, videos, and audio, commonly referred to as deepfakes, which are used to impersonate real individuals and spread misleading or false information.

Read more...
Continuous security optimisation.
News & Events Information Security
Cymulate has announced its partnership with SentinelOne, a threat exposure validation and AI-powered cybersecurity platform. The collaboration delivers self-healing endpoint security that empowers businesses to increase protection for every endpoint on their network.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.