Abstract
Enterprise social software (ESS) is an emerging technology that places social media type functionality into business organizations to enable enhanced levels of knowledge sharing and collaboration. However, ESS presents a significant information governance challenge for organizations that are facing ever increasing legal, regulatory and contractual obligations. Obtaining risk approval for an ESS platform in a large organization requires appropriate governance and a simple approach to ensure the right risks are identified, so that effective controls can be developed. Whilst it is unlikely that many high risk, high impact risks will exist, care should be taken to ensure the implementation of effective and proportionate controls that do not hold back the capability of the ESS to generate business value. Ultimately, it is worth spending time to build the foundations of information governance throughout an ESS programme – doing so can pay dividends for all technology implementations long into the future.
Introduction
For the chief knowledge officer, a key priority is to select, implement and achieve high levels of use and adoption from leading-edge technologies. Enterprise social software (ESS) is one of today’s leading-edge technologies, and whilst it cannot anymore be considered as novel, the ESS market is still evolving with vendors continually developing products, the market continuing to consolidate and organizations grappling with how to maximize adoption and squeeze value out of their investments. Whilst organizations are incorporating brands such as Twitter, Facebook and YouTube in ever more sophisticated ways to build and sustain stronger market presence and external relationships, ESS systems such as JIVE, Yammer or Tibbr are different. Taking capabilities found in social media (blogging, communities and activity streams), and putting them inside the enterprise, enables employees to exchange insights and collaborate far beyond simple traditional document management tools or email, unlocking new ways of working. ESS is about people connecting and working together through the creation and exchange of user-generated content in real time. Interaction is Web based with immediate accessibility and ease of use as core elements of ESS design. Content can be added and continually built on through layers of rich conversations between colleagues with established working relationships and others who may not know one another using a variety of media.
As with any major technology implementation, deploying ESS requires a robust support programme and a significant commitment from business sponsors representing the user community to assure success. Securing financial and business buy-in for ESS are substantial activities in their own right, but should not detract from another major consideration, for example, information governance. Addressing risk in technology implementations can be a time-consuming and frustrating process and this is no different for the ESS programme implementer – new risks may be frequently identified late in the day, roadblocks can occur out of nowhere and new approvers may be added to the approval chain at the eleventh hour. ESS programme teams focused on implementing new technology and satisfying user needs can find themselves in conflict when plans to realize the potential ESS capability do not satisfy risk management requirements. The business and information risk parties can consider each other to be speaking a different language and in the ensuing tussle, the inevitable loser is the business user, as timelines fall victim to wrangling between internal teams, all of whom are trying to do the best thing for the organization.
This article focuses on information governance for an ESS programme. It will first look at the forces that make information governance such an important topic for ESS, examining the key risk characteristics of an ESS. It will then turn to the topic of how to consider information governance for ESS by looking at an approach used by a large professional services organization implementing ESS across a wide international network. Finally, it will look at how information risks were considered and provide insight into the approach used and what can now – with hindsight – be learned from it.
Why information governance is such an important topic for ESS
Implementing most new technology should involve a conversation on information governance. When implementing ESS, this is particularly important as the combination of competing forces create a ‘perfect storm’ of complex implementation and use considerations. There are four main forces in this storm: 1. Organizations are under pressure to succeed and share and collaborate faster and wider than before. This can be enabled by an ESS.
The business case for purchasing an ESS is often founded on the fact that organizations (and especially those reliant on knowledge workers) need their people to share and collaborate using the capabilities inherent in these platforms. Breaking down departmental silos and connecting a distributed workforce increases response time and win rates by taking advantage of operating efficiency and cost optimization which can help deliver a better service to customers and promote employee motivation and engagement. A successful ESS implementation can become a strategic differentiator for the organization and as such there is a significant business drive behind adopting and maximizing the value from an ESS. 2. ESS makes the sharing of information easy.
For many, ESS is a key instrument in meeting the business needs stated above. However, the type of functionality that an ESS has brings risks. Concerns about knowledge sharing (e.g. protecting confidential information, handling of personal data, unauthorized storage of data outside the country of origin etc.) are not contextually unique to this type of platform, but there is an important consideration to address, that is, most knowledge sharing and collaboration that takes place within an ESS relates to user-generated content. This means: Unlike the definitive, official or sanctioned content that may sit on the organization’s portal or intranet, there may be limited editorial controls placed on content that is available on the ESS. Content is mostly un-reviewed before it is distributed to a wide audience. More conventional intranets and other knowledge repositories will usually include a formal review and publishing process. This may involve anonymizing, sanitizing or redacting content. This does not usually happen on an ESS, and moreover, such attempts to formalize content publishing in an ESS can impair use and impact. There is potential for content to have a wide reach across the organization resulting from the real-time publishing that is usually associated with ESS. These platforms are ‘open’ by nature – anyone in an organization can see and connect with anyone else, and unless content is published into designated private areas, posting content could effectively have the same impact as emailing every individual in the organization. There is potential for sharing a range of different types of content using an ESS. Posts may include text, images (including photographs), videos and all other standard file types. Whilst an organization may have processes and tools to support moderation of content contained on Web pages or in documents posted to knowledge repositories, those processes may be redundant and not scalable when considering the challenge of moderating large volumes of images, audio and video files that are posted into an ESS. 3. Regulation, laws and contractual obligations are making knowledge sharing harder.
Highly regulated environments constrain information handling, especially, as clients demand watertight confidentiality controls when handling their information. Exacerbated by recent newsworthy events relating to national governments’ accessing information held by large cloud providers and the architectural complexities of organizations operating internationally where national and jurisdictional law must be observed, it becomes extremely difficult for workers to share and collaborate, regardless of the business need they face and the ability for ESS to deliver that. The challenge is made even harder by the inherently open nature of an ESS as described in point 2 above, making it difficult to control the type of information that is shared. For example, even though the organization’s rules for sharing customer/client confidential information are technology agnostic, it may be more difficult to control the application of these in an ESS because of the open nature of user-generated content authoring and publishing and the removal of the traditional editorial and publishing controls that may be embedded into other knowledge sharing practices/platforms. This increases the need for clear and unambiguous policy guidance and rules specifically addressing these issues and for heightened awareness of each employee’s obligation to comply. 4. New technologies such as cloud computing and ESS as ‘software as a service’ make it harder to control access and use of information.
The immediacy of access to most ESS platforms means that, in practice, any employee can sign up the entire organization to an online ESS hosted on the cloud from their desktop within 10 minutes, in complete absence of any due diligence. The first the organization may find out about this is the phone call from the vendor informing them they have a few hundred employees on the system and asking whether they would like to get some control over the handling of potentially confidential information by purchasing a costly, premium subscription! The complexities of extricating unofficial ‘freemium’ products from organizations are increasingly well documented. 1 However even ‘official’ ESS implementations, sanctioned by an organization, result in many suppliers insisting that their ESS tools are hosted in the cloud outside of the organization’s firewall. Either way, the laws and associated perceptions of risk relating to cloud computing and the information stored within the cloud are still emerging, resulting in a number of unknowns and uncertainty. An organization may not want to store information in a particular jurisdiction or, contractually, may not be allowed to store a client’s information with a third party. Even if storing data with a third party is permitted, an organization has to ensure that the robustness of the security deployed by that third party meets the required standard and that any questions they have about the direct and indirect access that third parties have to confidential organizational data are satisfied.
There is obvious tension therefore between the business need to share and collaborate, which can be easily satisfied by this new technology and the increasingly restrictive rules and obligations that limit the sharing of information in order to comply with various legal and regulatory frameworks. In laying out some of the competing pressures that make information governance such an important topic for ESS, it is easier to understand the characteristic risks associated with an ESS. Risk approvals and risk management are central to most ESS implementations, so we can now turn our attention to this.
An approach to managing information risks in an ESS implementation
In the early days of planning and managing an ESS implementation it is likely that time and effort will be spent in the following two main areas: securing financial and business sponsorship and securing what many refer to as risk ‘approval’.
Given the risk management challenges that are known for ESS platforms, it is not easy to reach a solution where risk management can happily coexist with the degrees of information sharing and collaboration that an ESS can enable. One of the often-underestimated challenges for the ESS implementation team will be the facilitation of productive and constructive discussions between a group looking to deliver the benefits of an ESS and risk management specialists focused on ensuring the organization does not fall foul of its legal and regulatory obligations. Ensuring that discussion between these two important stakeholder groups begins early in the project is critical to avoid frustrations and delays as unchallenged assumptions will face hurdles arising from the wide range of risk-related challenges that will undoubtedly exist. During the large-scale ESS implementation used as a reference point here, a framework was put in place to enable effective working together for the knowledge management team leading the ESS implementation and risk management and other supporting groups selected in order to best address the legitimate risk concerns that arose. The rest of this article focuses on the nature of this governance framework.
Establishing the governance for information governance
The importance of involving the risk management function as early as possible in the planning of the ESS project cannot be overstated. However, it is also important that you are able to answer a fundamental question at this point – why are they being involved? This question may sound simple, but everyone should be clear on the answer and what it means. A couple of considerations: The term ‘risk approval’ should not be confused with ‘approval from risk management’. A risk management group will rarely be the people who accept the risks of doing business. Business stakeholders themselves will accept and approve the risks following advice from risk management groups and other supporting functions. It is important that decision-making in the ESS programme reflects this and that where accountability sits is clear. The range of topics classified as ‘risk related’ arising from ESS implementation are typically broader than those considered by a conventional risk management discussion. Thinking of these considerations as information governance, rather than risk management, from the outset will be helpful to encompass the variety of inputs and specialisms needed, including information technology (IT) security, legal and regulatory compliance, data privacy, preservation, procurement and knowledge management. External counsel may also be needed. Expertise on cloud computing, cross-border data transfer, the latest regulatory matters, data privacy – all these are fast-evolving areas, so additional support may be required to ensure that assumptions are tested and the capability for enhanced collaboration and knowledge sharing does not expose the organization to new risk. Getting the information governance of the ESS programme right is not something a risk management group alone can resolve. Establishing an ESS information governance group as part of the overall programme planning and governance will ensure that discussions are comprehensive and inclusive and decisions are more likely to be implementable as the appropriate voices have been engaged from the start. The ESS information governance group should sit within a wider governance structure for the ESS programme, which should include an overall programme steering group, led by a senior business sponsor whose responsibility is recognized and understood and who will make decisions, help challenge and overcome barriers and obstacles during the planning and implementation of the programme. The sponsor will ultimately accept any risks.
For some organizations, this programme rigour may be very natural and may already exist. For others, however, these are cultural and organizational considerations that need to be factored into the planning of the ESS programme as systematically as discussions about whether there is appetite to invest in the platform, which technology platform will be chosen or about the benefits it is anticipated will be delivered.
Be clear on what is to be achieved
With the right people involved and the right programme governance in place, bringing together disparate groups to work through the information governance considerations should be much easier. However, for any conversation to go well, it is vital to be upfront and honest from the start. Ensure that the newly formed ESS information governance group understands why they have been brought together and what is expected of them. Establish clear terms of reference to set this out. Make sure that the group members understand the aspirations and business goals for the ESS programme, even though these may initially cause tension with their vested interests. They need to understand the anticipated return on investment and business benefits to be realized in order to help them provide the greatest value in the forthcoming discussions. This will include early identification of the types of information intended for sharing and accessing via the ESS, even when it is known that these activities may be a challenge for those charged with managing risk or security in the organization. By flushing out these challenging considerations and ensuring that the difficult, but necessary, conversations start as early as possible, there is more likelihood that there is time to work through and address the associated issues and to review how to enable and deliver the desired changes. Playing down, or underestimating, the most difficult aspects of the ESS programme will surely cause delays ultimately and engender a sense of mistrust within the group that is critical to ensuring the success of the ESS programme. To ensure that the information governance group is familiar with all aspects of the ESS platform and its technology capabilities as early as possible, arrange demonstrations and pilots from the outset and talk openly about how all potential features and functionality can be used.
Identify the risks
From the outset of planning for the ESS programme, the information governance group will need to be fully aware of, and to understand the full extent of the risk issues to be addressed, so that they can work through these issues. This is essential to demonstrate to sponsors and stakeholders – especially, those who may have a residual scepticism that social software has a place in the enterprise – that risk is being addressed and managed by a solutions-focused group with the appropriate people engaged to advise and steer. Managing information risk is the responsibility of everyone in an organization and it is recommended that the ESS programme team takes a lead in identifying the risks even before engaging with the information governance group. You don’t need to be a legal, an IT security or a risk expert to identify the bigger risks involved, and by taking this first step you will: (a) be prepared to answer the more basic challenges on how risk has been considered and will be controlled; (b) demonstrate to your information governance group that you are taking risk seriously and want to find solutions; (c) have started to bridge any gap of understanding with the risk experts. Those concerned with information governance will be able to understand better and more quickly what is involved in an ESS by the programme team describing ESS in the context of risks; and (d) demonstrate business ownership of the risks and set the tone for what you want the information governance working group to do, namely, advise and steer.
Identifying risk does not need to be a complicated process. There are many different ways to perform an information risk assessment but choosing a simple approach avoids overcomplication and makes the conversation easier. The commonly used IT security principle: confidentiality, integrity (of data) and availability (of systems/data) (CIA), simplifies things. Using CIA helps to restrict and focus on the important conversations. For example, the information governance group will not be interested in project risks (such as failure of the ESS to deliver against the business objective), nor operational risks of the ESS (such as failure to provide adequate community management support for users of the ESS). Under CIA it can be argued that nine broad knowledge sharing and collaboration risks exist: Unauthorized storage, processing and/or disclosure of personal data (related to confidentiality); Unauthorized disclosure of confidential (internal or client/third party) information (related to confidentiality); Unauthorized storage of client/third party information outside of the country of origin (related to confidentiality); Upon legal or regulatory request client data/information cannot be preserved and/or recalled in a timely manner (related to integrity); Unauthorized use of intellectual property (IP; both internal organization and third party IP) (related to integrity); Data/information become out of date (and therefore no longer complete and/or accurate) (related to integrity); Unauthorized modification or deletion of data (related to integrity); ‘Facts’ are recorded and presented that mislead, or misrepresent, the firm or clients (related to integrity); and System resources are not accessible and usable (as according to performance specifications for the system) upon demand by an authorized person (related to availability).
The information governance group should consider each of these nine risk categories to identify the specific risks within the enterprise, contextualized by the particular nature of the business, the industry sector, the specific ESS platform being considered and the types of information to be governed. As before, simplicity is key. Capturing and describing these risks in plain English is important to avoid ambiguity and misinterpretation. For example: A risk that falls under “Unauthorized disclosure of confidential information” could be: “There is a risk that client information is stored outside of the country of origin which breaches local laws, regulations or contractual agreements.” A risk that falls under “Unauthorized storage, processing and/or disclosure of personal data” could be: “There is a risk that inbuilt analytics/reporting functionality within the ESS allows the unauthorized tracking of individual users.” A risk that falls under “Unauthorized modification or deletion of data” could be: “There is a risk that our organization’s intellectual capital is unintentionally lost when content is deleted or archived.”
Once risks have been identified and clarified, the expertise of the members of the information governance group can be called on to ensure that the initial list of risks considered is comprehensive and sufficiently extensive. The group can then develop specific advice on the areas requiring greater focus, for example, the legal and regulatory aspects of information governance in the organization, the confidentiality obligations, content life cycle features (from creation to destruction or preservation (or e-discovery)), data privacy and IT security. The group should also be responsible for providing a view on the likelihood of the risks (what is the probability of the risk being realized) as well as the impact of the risks. This will enable the prioritization of risks so that the most important risks are addressed and managed.
Unfortunately, there is no single list of risks associated with the implementation of an ESS that will be universally applicable across every organization, and although some of the basic common risks listed here will be relevant in most organizations, each will need to develop their own inventory. This will be an iterative process, but it is important to start as early in the planning of the implementation as practical, and for the ESS programme team to take a lead in this conversation, in order to give as much time as possible to address risks appropriately.
Build controls
Once risks have been identified, the focus shifts to how to manage them. There are a number of approaches to this, including, transfer risk (e.g. take out insurance), accept risk (do nothing and take the hit should the risk materialize), reduce risk (put in place controls to lower the chance of risk occurrence) or avoid risk (decrease the potential for risk by removing some or all aspects of the threat – e.g. revert to paper-based transactions).
Any risks not accepted will require controls to reduce their impact. This is the most likely outcome of an assessment for most risks associated with ESS. In this scenario, controls can be grouped into four areas, namely, consent, moderation, guidance and IT security. These groupings will help make dealing with the risks associated with them easier to manage, from a programme perspective, and also aid communication and user understanding.
Consent is a key concept within information risk management. It is founded in the question: Do you have the consent to share the information you have? Defining clearly understood parameters for information sharing within the ESS and setting policy to control this is critical. An example of a consent control is the existence of a formalized process, requiring a named individual or role holder to provide approval that an ESS community (a virtual space where a group of like-minded people work together) can be established to enable collaboration and knowledge sharing relating to a particular client or project. This is a particularly important control if an ESS platform is cloud hosted and contractual obligations to a client restrict the sharing of their confidential information with a third party. In this example, indicating that communities must seek consent before being established will ensure that consent is rejected on the basis that the community would not support contractual terms, demonstrating that the layer of control is effective in protecting the organization against risk.
Moderation is a powerful risk control within an ESS. From experience, it is critical to implement a moderation strategy to ensure that content is reviewed and speedily removed if it breaches the organization’s terms of use, guidelines or levels of appropriateness that are laid out specifically in ESS usage policy and more generally in employment terms and conditions. A moderation policy, and nomination of individual(s), given responsibility for moderation, helps to counter the concerns of those who worry about the risks associated with real-time, user-generated content creation and sharing.
Guidance on appropriate use is a fundamental element of any risk control programme as this helps ensure desired (and compliant) behaviours. Guidance should set out expected behaviours clearly and manage expectations relating to non-compliance. Policies and ‘terms of use’ are a common way of implementing a guidance control, however, equally important are high levels of awareness of those policies and guidance on how to comply with them. A possible consideration is the use of a mandatory ‘acceptance of terms’ for all users, either as a one-time activity preceding the first use of the ESS or as repeated acceptance at regular intervals. Another option to consider is mandatory training of those with a role other than ‘user’ within the ESS, for example, training for community managers. Other obvious steps to ensure levels of awareness of expected behaviour include easily accessible policy reminders and FAQs contained within the user interface of the ESS.
IT security: technology controls are important elements of risk management within an ESS and include activities such as performing penetration testing on the system, defining a model to control access rights and setting up secure single sign on for access via mobile devices. Technology controls are often more effective than ‘policy’-based controls and will form an important part of the control strategy.
As the ESS implementation progresses, it will be possible to identify how some controls will be effective in managing a number of different risks – for example, asking a user to accept a terms of use could also provide the necessary consent for their personal data to be used in a system account and provide them with usage guidance. You will also be able to identify how different controls complement each other – for example, although having clear guidance materials will reduce the chance of a user sharing confidential information this can be complemented by the presence of a moderator who will be charged with reviewing content and will pick up on non-compliant posts that are made. You should also seek out controls that are used already in your organization to manage existing similar risks in the ESS – this has the benefit of making the prospect of an ESS a less scary new technology, and it also may mean you can leverage other controls already in operation saving you time and money. Identifying controls that can manage multiple risks, controls that complement each other and controls already in place which can be leveraged, makes it likely that you can reduce a long list of individual controls to a much smaller focused list of significant strategic controls that will probably address a high proportion of the risks.
It is worth ending this section by stressing that controls should always be developed in a way that supports the usual day-to-day running of the ESS, that fits within the context of the organization and that do not impede use, so that for the end user, they feel seamlessly incorporated. Developing these controls early in the project will increase the likelihood of building them into the ESS and not superimposing them as an additional and onerous activity that detracts from the benefits of use.
Conclusion
This article has considered the topic of managing risk of ESS, the forces that are making information governance such an important topic for ESS, and why these projects are such a fertile ground for information risks. It has presented a high-level outline of the approach used by a large, professional services organization to manage risk as part of the wider ESS implementation programme. It highlights the importance of giving risk and information governance aspects of an ESS programme plenty of space, and these areas have the propensity to influence the success or failure of the programme considerably, especially if not considered early enough in the project.
In conclusion, some key takeaways summarize the lessons learned: Most ESS-related risks are not unique to the platform and are inherent in other technologies. However, it is the drivers behind an ESS and the risk characteristics of an ESS that makes them so pertinent. To manage the risk everyone involved in an ESS programme should get familiar with these risk characteristics: understanding both what makes ESS ‘risky’ and how your own organization will influence the scope and scale of the risks. This sets a foundation for your information governance approach. The ability to manage the risks in an ESS programme is just as important as getting the business case right for it. Importantly, see the programme as an information governance exercise. Input and support from groups beyond a traditional risk management function will be needed – engage groups early, establish the programme governance, be clear on the roles of everyone and be open with the goals of the ESS programme. Keep the approach to managing risks simple. Have a structured approach with a common language and consider simple things like categorizing risks and controls into predefined ‘buckets’. If you are managing the ESS programme take the lead in the process – recognize that everyone in an organization is responsible for risk management and risk should not just be thrown to risk management to deal with. Despite all the potential things that could go wrong, it is unlikely that there will be many actual risks that are both highly likely and have a potentially high impact . Identify the biggest and most probable risks and focus on implementing a focused set of strategic controls using controls already in place in the organization, controls that can address multiple risks and controls that can complement each other. Work hard to develop controls that work both for information governance and business reasons. Do not manage risks in a way that ultimately compromises the return on investment of the ESS. Solutions must be what the business wants, the ESS programme team want and also what information governance support groups want – controls that don’t do this will limit the business value of the ESS and often also be ineffective at managing risk anyway.
The good news is that developing an approach and a common working language to manage risk during an ESS implementation will enable effective and productive conversations not only during that programme but also in the future on other similar initiatives or emerging issues such as cloud computing and access to data from mobile devices. In turn, this will give the ESS information governance group an ongoing purpose and value. This ultimately is one of the most significant recommendations and lessons learnt, and it is worth nurturing the building of the foundations of information governance into an ESS programme, not simply to help ensure the success of the ESS programme but because it can also pay dividends in all future technology implementations.
