NARA gives guidance on managing Web records
Connecting state and local government leaders
The records agency advises webmasters and records managers to reuse their IT system risk assessments to establish records management controls.
The National Archives and Records Administration is advising webmasters and records managers to reuse their IT system risk assessments to establish records management controls. NARA also recommends performing a risk mitigation to ensure the authenticity, integrity and usefulness of agency information on their Web sites.
The importance of risk assessments and mitigation were a major part of a new guidance NARA released late last week. The document, which was almost seven years in the making, is a high-level guidance to improve and standardize the management of agency Web sites and online records, said Howard Lowell, director of NARA's modern records program.
'Managing Web records properly is essential to effective Web site operations, especially the mitigation of the risks an agency faces by using the Web to carry out agency business,' NARA noted in the guidance.
The guidance is broken into three sections'general background, responsibilities and requirements; managing Web records; and scheduling Web records'and each part tries to answer common questions agency webmasters and records officers may have.
'Agencies have been waiting for us to come out with this guidance,' said Nancy Allard, a senior policy specialist at NARA. 'They have been waiting for us to tell them how to put their hands around the Web and then they can ask more specific questions.'
Agencies should conduct a risk assessment of their Web sites by evaluating certain factors such as records management threats, visibility, consequences of compromised records and sensitivity of the records.
Once an agency has determined its Web site vulnerabilities, NARA recommends mitigating those risks by:
- Documenting the systems used to create and maintain Web records
- Ensuring that the Web records are created and maintained in a secure environment
- Implementing standard operating procedures for the creation, use, and management of Web records and maintaining adequate written documentation of those procedures
- Creating and maintaining Web records according to these documented standard operating procedures
- Training agency staff in the standard operating procedures
- Developing a retention schedule for Web records and obtaining official NARA approval of that retention schedule.