inset
SharePoint Records Management Certified
Jun. 4, 2007

Combined with a free add-on, the SharePoint Server 2007 corporate portal and enterprise content management platform has been certified to comply with an important U.S. Department of Defense standard for records-management applications. This certification closes a gap in SharePoint's records-management features and could attract the many U.S. government agencies and other organizations that adhere to the standard. The add-on was developed by Microsoft and partner Applied Information Sciences (AIS) and will be available to customers later in 2007. However, the company has not yet provided documentation or a precise ship date for the add-on.

Records Management in SharePoint 2007

With the release of SharePoint Server 2007 in Nov. 2006, Microsoft's corporate portal platform gained features for records management, which focuses on the storage, retention, and destruction of corporate records for legal, regulatory, or strategic reasons. A special SharePoint site, called the Records Center, provides tools and services to help organizations set up and customize record repositories and configure and automate many aspects of records-management processes. For example, records managers can use the Records Center to specify the types and properties of documents that will be managed as records, create the repositories that will store those records, and configure the policies (such as retention periods) by which records are managed.

Initial Release Lacked Compliance

SharePoint's records-management capabilities are intended to create new opportunities for Microsoft and its partners, particularly as agencies such as the U.S. Securities and Exchange Commission (SEC) and the Food and Drug Administration (FDA) continue to tighten regulations governing the handling and retention of sensitive and confidential data. Even in industries that are not heavily regulated, recent high-profile legal cases (including Microsoft's run-ins with the U.S. Department of Justice and the European Commission) highlight the need to manage electronic documents and records carefully.

Despite these goals, SharePoint Server 2007's initial release lacked a number of capabilities required to meet the U.S. Department of Defense's 5015.2 (DOD 5015) standard, which prevented it from being a serious contender in the records-management market. DOD 5015 specifies a basic set of requirements for records-management applications: although originally required only by the Department of Defense, compliance with the standard is now mandated by a variety of U.S. government agencies, including the Department of Education and the Environmental Protection Agency, and other nongovernmental organizations view compliance as a necessity.

Add-on to Meet DOD Standard

Working with AIS, Microsoft has enhanced SharePoint Server 2007 with new features designed to meet the DOD 5015 standard. The new features will be packaged as a free add-on to SharePoint Server 2007.

Among other enhancements, the add-on will provide the following:

Prebuilt content types conform to the DOD 5015 metadata specifications for electronic and nonelectronic records. Content types are a new SharePoint Server 2007 mechanism for specifying the properties and settings (or metadata) of documents and other content of like type. Among other properties, the DOD 5015 content types will allow administrators to include relationship information about records (to indicate that one record is based on another record, for instance).

A prebuilt workflow, called Vital Record Review, will help organizations ensure that important records, such as disaster recovery plans, are periodically reviewed and do not become dated or obsolete. The workflow, which is built on the Windows Workflow Foundation component of the .NET Framework 3.0, will automatically notify appropriate reviewers when a record is due for review.

Librarywide record hold lets administrators or records managers hold or temporarily suspend expiration policies for entire libraries in the Records Center, preventing those records from being deleted if their retention periods have expired. Without the add-on, SharePoint Server 2007 holds can be applied only to individual records.

Closing of record folders prevents the addition of new records to a folder, while still allowing existing records to be viewed. Policies defined for the records in a closed folder, such as retention and expiration, will continue to be applied.

A May 2007 compliance test carried out by the Joint Interoperability Test Command (JITC), a testing organization that certifies software for use by the Department of Defense, certified that SharePoint Server 2007 with the add-on met the requirements spelled out in DOD 5015. SharePoint Server 2007 joins a list of JITC-approved records-management products from other vendors, such as Computer Associates, EMC, FileNet, IBM, Interwoven, Meridio, Oracle, and SAP.

Details, Ship Date TBD

Microsoft has indicated that the add-on for DOD 5015 compliance will be available in 2007, but it has not given a more specific timeframe. Furthermore, as of early June 2007, the company has not provided any in-depth information (such as feature lists and implementation details) about the add-on nor has it made an early version of it available for interested customers to investigate. This lack of detail suggests that the company has more work to do to make the add-on ready for production deployments.

Ultimately, the features in the DOD 5015 add-on will probably be built directly into a future version (or service pack) of the product. However, moving features from an add-on into the core of the product could create upgrade and migration issues for customers.

Finally, although SharePoint Server 2007 has met the base requirements of DOD 5015, it has not met the more stringent Chapter 4 requirements of the standard, which specifies requirements and methods for handling classified records. (As of June 2007, only about a dozen products have gained Chapter 4 compliance, while about 50 have met the standard DOD 5015 requirements.) Lack of Chapter 4 support will undoubtedly give an edge in certain opportunities to competitors' products, such as Oracle's Stellent and Vignette's Records and Documents, which have attained both certifications.

Resources

The SharePoint Server home page is www.microsoft.com/sharePoint/default.mspx.

The JITC test report for SharePoint Server 2007 is at jitc.fhu.disa.mil/recmgt/mcmosps/index.html.

Records-management features in SharePoint Server 2007 are described in "SharePoint 2007 Automates Records Management" on page 12 of the Mar. 2007 Update.