CCSP Domain 6 : Legal Hold and eDiscovery Flashcards
What does e-discovery typically involve?
identification, collection and production of data related to a case and legal holds
What is the recommended action for a business when it faces a need for eDiscovery activity?
hiring an expert consultant who is licensed for this purpose
What is eDiscovery (electronic Discovery)?
process of identifying and obtaining electronic evidence for either prosecutorial or litigation purposes
What are the tools that aid with the process of eDiscovery?
- some cloud providers offer SaaS eDiscovery solutions in the form of cloud-based applications that can perform searches and collection of pertinent data (provider’s own cloud data center for its own customers)
- host-based tools that can be used to locate applicable information on specific machines (both HW and virtualized)
What is the most significant barrier to eDiscovery efforts in organizations that make heavy use of many different cloud services?
coordinating multiple providers that might have relevant records
I Preserve Collected Policies Rendered Absolutely Pointless
What are the seven main steps for eDiscovery?
- ESI identification
- preservation
- collection
- processing
- review
- analysis
- production
The Cloud Security Alliance points to a number of key areas to consider during e-discovery. What is most likely to drive higher costs in a cloud environment when the organization is operating under a litigation hold?
storage duration; cloud storage is typically billed by quantity and time
What is the first concern for discovery and legal hold scenarios?
identify the data that the hold request or discovery requires
What do legal holds require organizations to do with relevant data?
identify and preserve data that meets the hold’s scope
Organization preserved data due to a legal hold, but the data has hit the end of its retention timeframe due to statutory requirements. What should be done to the data?
continue to preserve the data to meet the legal hold requirements - legal holds normally take precedence over other deletion requirements
Why is a legal hold drive for retention process?
because it may require deviation from the organizational’s normal process for data retention and destruction
When does a legal hold typically occur?
organization is notified that either (a) law enforcement or regulatory entity is commencing an investigation or (b) private entity is commencing litigation against the organization
What organizational policy often accounts for legal holds?
retention policies often include language that addresses legal holds because holds can impact retention practices and requirements
eDiscovery is specifically intended to ensure compliance with what?
ensure compliance with litigation hold obligations
What is the initial phase of eDiscovery process?
legal hold