The Sarbanes-Oxley Act Has Forced Many Companies To Review Email Retention Policies.

Four years have passed since President Bush signedperiod for such retention should be at least five
the Sarbanes-Oxley Act and most analysts agree theyears. The emails should be classified by dates
law is working as larger companies are finally getting(months and years) to make it less complicated for
their accounting books in order.auditors to access such information. If the emails are
The act was formulated to strengthen accountingdisorganized, the auditors may have to dig deeper
oversight and corporate accountability. It did this byand they might find improprieties.
increasing accounting and auditor regulations,- The obstruction of justice segment is similar to the
enhancing disclosure requirements, creating newdocument alteration provision under the
federal laws and increasing penalties under existingSarbanes-Oxley Act, but it includes a statute that
federal laws.prohibits tampering with witnesses. The legislation
An important aspect of the act focuses on thestates that acting or attempting to alter or destroy a
details of data security, retention and protection. Sorecord or other object "with the intent to impair the
the question is, how does the Sarbanes-Oxleyobject's integrity or availability for use in an official
legislation impact email retention policies?proceeding" can be punishable with fines,
Surveys indicate that 93 percent of all businessimprisonment for up to 20 years, or both. How does
documents are created electronically and that hasthis impact email retention policies? Again, any
forced most corporations to address their retentioncompany that has a data retention policy must
policies. Businesses, small or large, can no longerenforce a security plan such that data can be
consider email retention a non-priority.accessed by only the proper personnel. An online
Companies must develop a classification of data fordata backup service with strong encryption and user
off-site storage, such as an online storage servicetracking helps eliminate the chance of human
that encrypts and protect the data.intervention with whatever email data has been
The Sarbanes-Oxley Act includes three provisionsstored. With certain managed backup services, online
that deal with electronic documents, such as thosebackups are performed automatically, so data is
communicated through emails. They include documentprotected without manual intervention. Data moves
alteration or destruction, mandatory documentthrough an existing network connection, using
retention and obstruction of justice.state-of-the-art data security including AES
- In terms of document alteration or destruction, theencryption to a secure remote data center.Clearly,
Sarbanes-Oxley law states that people whothe document-retention regulations implemented by
knowingly alter, destroy, mutilate, falsify or concealthe Sarbanes-Oxley legislation sends a signal to
any document (electronic or paper) with the intent tobusinesses that they must institute a policy regarding
impede proceedings involving federal agencies maytheir data and documents, including those transmitted
be fined or imprisoned up to 20 years, or both. Howthrough email. Businesses must realize that they can
does this impact email retention policies? If abe held liable for retained and deleted electronic
company has an email retention policy in place, itdocuments. The policies these businesses put in place
must include a security plan. Only certain individualsshould include an inventory of all the electronic
should be given clearance to access the archivedhardware and software that can store emails
emails. A report with that person's name and purpose(including cell phones and laptops), all locations and
should be produced every time a certain email isstorage formats of archived emails, and all the
accessed, and documentation of change to themethods that email documents can be transferred
existing document should be noted.into and out of the company. The next step should
- The Sarbanes-Oxley provision of mandatoryinclude classification of such emails, and then a secure
document retention forces businesses to keepoff-site online backup storage plan.
records readily for review for a period of up to fiveThe days of simply keeping emails in a folder at each
years. The penalty for knowingly and willfully violatingworkstation are part of the past thanks to
this provision imposes fines and a maximum sentencebusinesses that have put forth a solid data retention
of 10 years in prison, or both. How does this impactplan. The Sarbanes-Oxley Act has served as an
email retention policies? A business must generate aeffective means to help push the creation of such
data-retention policy with archive history periodsplans.
included. According to Sarbanes-Oxley, the time