The recent news that the US Central Intelligence Agency destroyed videotapes of interrogations of two terrorist suspects may offer a timely reminder for CIOs at private companies in the US, tasked with electronic evidence preservation rules since last December.
The e-discovery rules, amendments to US courts' Federal Rules of Civil Procedure, don't apply to the CIA, but the agency's decision to destroy videotapes showing harsh interrogation techniques may show private companies how not to handle evidence, some e-discovery experts said.
The e-discovery rules require US companies to keep electronic records when they're faced with a civil lawsuit or the likelihood of a lawsuit. In effect, what this means is that companies should archive e-mail and other electronic records, said Ralph Harvey, CEO of Forensic & Compliance Systems, an e-mail archiving vendor based in Dublin, Ireland. "The lesson learned is you keep everything for a finite period," he said.
In the CIA case, several lawmakers have called for an investigation into the destruction of the videotapes. The tapes, recorded in 2002, were destroyed in November 2005, when there was a heated debate about the use of harsh interrogation techniques on terrorism suspects. Some former staff members at the government-created 9/11 Commission have also questioned whether the tapes were evidence that the CIA withheld from the group, which was investigating the September 11 terrorist attacks on the US.
In the e-discovery rules, companies can be subject to significant fines for not producing electronic evidence they're required to keep. In May 2006, even before the new e-discovery rules went into effect, Morgan Stanley agreed to pay a US$15 million fine for failing to produce e-mail linked to several legal investigations.
"Ultimately, the issue is you don't know how important that e-mail is to someone else," Harvey said.
One of the most tricky issues with e-discovery is the security of the evidence a company is supposed to preserve, Harvey added. Companies need to be able to find the electronic records, and in some cases, they may need to be able to prove that they didn't receive a certain e-mail message, he said. In nearly every case, they'll need to assure the court that their record is accurate.
"You can't say you're in compliance when Bob from administration, with a slight slipup, can delete all e-mails," he said.
Another issue the CIA case brings up is that electronic evidence can come in many forms, said Chris O'Brien, vice president of operations for Xerox Litigation Services. Right now, e-mail is the focus of e-discovery rules, but instant messages, electronic voice mail, and Web-based video conferencing could fall under e-discovery preservation rules, he said. "Anything that's electronically preserved could theoretically be subject to discovery," he said.
O'Brien said he'd be surprised, however, if many companies are archiving their video conferences in order to meet e-discovery rules.
Perhaps the biggest lesson is not to destroy evidence when it's part of an ongoing investigation -- in the CIA's case, the 9/11 Commission inquiry, said Patrick Egan, a white-collar criminal defense lawyer based in the Philadelphia office of the Fox Rothschild law firm. "Always tell the truth," he said.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Fortinet November Threatscape Report Shows Calm Before Holiday Storm 2008-12-05 16:00:00+11
Epicor® Cited as an Order Management Solutions Leader by Independent Research Firm 2008-12-05 15:52:00+11
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 2008-12-05 13:00:00+11
International researchers gather in Sydney to preview the clever web 2008-12-05 09:48:00+11
Borderless corporate networks to shift focus to secure content management in Australia in 2009 2008-12-04 16:06:00+11
Strategies for Eliminating .PST Files
Join industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.












