RECMGMT-L Archives

Records Management

RECMGMT-L@LISTSERV.IGGURU.US

Options: Use Forum View

Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Sam McCollum <[log in to unmask]>
Reply To:
Records Management Program <[log in to unmask]>
Date:
Thu, 17 May 2012 10:02:17 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (82 lines)
Wayne,

   I agree with your comment on the need for, or not, of DoD certification
for many small to medium size companies. I also recognize that even some
medium size organizations do need such stringent rules.
  However, as RIM professionals we need to be cognizant of the huge number
of companies that need some rules but find the ISO/DoD way too expensive.
That is way I don't buy the need to compare the importance of DoD versus
GARP. We all need to understand the value of the GARP principles and
Maturity Model as the best fit in many cases. We also need to recognize
that for many organizations trying to sell DoD or ISO would be a
non-starter; both from the cost perspective, and more importantly, from the
perspective that senior mgt might not want to take the time to fully
understand and justify DoD/ISO. I have found that the plain language of
GARP appeals to senior mgt who have to make the decisions on RIM projects
that they don't have the time to fully understand. The V/P of Finance
usually has the last word on project approvals and the similarity of GARP
to their GAAP world makes it easier for them to understand and support our
RIM projects.
   The bottom line for me; GARP has made my world, and my clients world, a
lot easier.

Sam McCollum, CRM, MBA

On Thu, May 17, 2012 at 8:53 AM, Wayne Hoff <[log in to unmask]> wrote:

> Larry said, "...if DOD 5015.2 v3 compliance is important to you for
> deploying
> use of this product."
>
> This question is fundamental to all deployments of RIM software, but it's
> one
> that is ignored too often.  Just because the DoD certification is the most
> stringent one doesn't mean that we have to use it in our organizations by
> default, or DoD-certification means that it is the best software you can
> get.
> Adding more security and controls to information handling necessarily
> reduces
> the freedom and functionality of information use for day-to-day
> operations.  I
> would conjecture that, unless your organzation handles extremely sensitive
> documents (such as the Department of Defense does) then DoD-certified
> software is a bad choice.  (I may be wrong, but the basic design of
> software
> aspiring to the certification will be much different than the basic design
> of
> software not holding itself to that standard.)
>
> That's not to say that RIM software is best without security and controls;
> I'm
> saying that it needs to be commensurate with the requirements of the
> organization.  I don't know Wendy's information requirements - perhaps DoD-
> certified software is the best choice in that case - but it is most
> definitely
> worth investigating.
>
> My two cents.
>
> Wayne Hoff, CRM
> Calgary, AB
>
> List archives at http://lists.ufl.edu/archives/recmgmt-l.html
> Contact [log in to unmask] for assistance
> To unsubscribe from this list, click the below link. If not already
> present, place UNSUBSCRIBE RECMGMT-L or UNSUB RECMGMT-L in the body of the
> message.
> mailto:[log in to unmask]
>



-- 
Sam McCollum, MBA, CRM, ERMm
President and CEO
SIMC Coaching Corporation
[log in to unmask]

List archives at http://lists.ufl.edu/archives/recmgmt-l.html
Contact [log in to unmask] for assistance
To unsubscribe from this list, click the below link. If not already present, place UNSUBSCRIBE RECMGMT-L or UNSUB RECMGMT-L in the body of the message.
mailto:[log in to unmask]

ATOM RSS1 RSS2