Fossilization: A Process for Establishing Truly Trustworthy Records
نویسندگان
چکیده
LIMITED DISTRIBUTION NOTICE: This report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g. , payment of royalties). Copies may be requested from IBM T. J. Executive Summary Trustworthy records are vital to an organization. These records help to improve an organization's operations and aid in reducing its liability and costs. The fundamental purpose of record keeping is to establish solid proof and details of events that have occurred. A trustworthy record management system is, therefore, one that can be relied upon to provide irrefutable evidence of all of the events that have been logged. In other words, trustworthiness has to be established on an end-to-end perspective, from the proper preservation of all of the records to the subsequent delivery of the relevant records to an agent seeking the proof. In this white paper, we show that the current limited focus on storing electronic records in Write-Once-Read-Many (WORM) storage is not adequate to ensure that such records are trustworthy. What is really needed is a process we call fossilization-a holistic approach to storing and managing records that ensures that they are trustworthy. Fossilization is composed of three parts. The first, fossilization of storage, guarantees that all records and their associated metadata are reliably stored and securely protected from any modification. The second, fossilization of discovery, ensures that all preserved records pertinent to an enquiry can be quickly discovered and retrieved. The third, fossilization of delivery, warrants that the exact pertinent records are delivered to the agent and that the records are delivered in an intact form. Because of the extremely high stakes involved in tampering with the records, fossilization must be realized very securely. The essential principles for securely implementing fossilization include 1) raising the barrier to any attack; 2) focusing on end-to-end trust; 3) limiting what has to be trusted; 4) using a simple, well-defined interface between trusted and untrusted components; and 5) verifying all operations.
منابع مشابه
Technical Forum : WORM storage is not enough
The fundamental purpose of record keeping is to preserve the details associated with certain transactions or events and, furthermore, to preserve irrefutable evidence of the occurrence of such events. Trustworthy record keeping is vital to an organization in the current regulatory and business environment. It enables the smooth operation of the organization, and it helps reduce the exposure of ...
متن کاملWORM is not enough !
Important documents like financial reports, customer communications etc are increasingly being maintained by businesses in electronic format. These represent much of the data on which key decisions in business operations are based and hence must be maintained in a trustworthy fashion safe from destruction or clandestine modification. Secure retention of such data is also increasingly being regu...
متن کاملContent Immutable Storage: Truly Trustworthy and Cost-Effective Storage for Electronic Records
LIMITED DISTRIBUTION NOTICE: This report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and sp...
متن کاملFossilization: five central issues
Second language acquisition research over the past three decades has generated a wide spectrum of different interpretations of “fossilization” – a construct introduced by Selinker (1972) for characterizing lack of grammatical development in second language learning. These conceptual differences found in the literature, it has become increasingly clear, create confusion rather than offering clar...
متن کاملThe Feasibility of Deploying Business Process Management in Hospitals in Iran
Background: Business process management systems (BPM) can automate all processes in an organization. These systems provide the possibility of identifying, modeling, deploying, implementing, function managing, integrating with other information systems, monitoring and improving an organization's business processes in a standard form. As far as the authors know, no related resear...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2004