Lighthouse M365 User manual

TOP 5 M365 COMPLIANCE FEATURES
LEGAL SHOULD KNOW ABOUT
www.lighthouseglobal.com
2Proprietary/Confidential
Microsoft + Lighthouse
Alliance
Working relationship began 20 years ago
Lighthouse is the leading Microsoft Compliance Partner
for Microsoft 365
Lighthouse is Microsoft’s eDiscovery service provider
Engaged in all major U.S. regions, the UK and EU;
working with 200+ corporations globally
Key advisory positions include Partner Advisory Council
(PAC); GDPR partner program; Financial Services Consortium
Relationships within the Security and Compliance
Product Group, O365 PAC, and CELA
Strategic alignment between Microsoft and Lighthouse
Proprietary/Confidential 3
James Hart
Governance Risk Compliance Consultant, Global Advisory Services
Microsoft 365 Certified: Security Administrator Associate
Certified Information Privacy Professional – Europe (CIPP/E)
Over 10 years of in-house and consultancy experience in the legal
technology services.
Strong track record in supporting global corporations on high profile projects in the areas of Information Governance, Incident Response and E­Discovery.
Former roles with Barclays PLC, developing their eDiscovery technology
and operations capabilities before moving onto Advisory Services.
© 2018 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Introduction
A quick introduction of M365
Top 5 Features for Legal
The accessibility of data
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
5
Adoption of cloud-based data is one of the most disruptive and significant trends to hit the information governance profession in the past 20 years
Having data in the cloud (e.g. in M365) means you have the data in, effectively, one place and in, effectively, one searchable format
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
6
Insider
Risk Management
Identify and remediate
critical insider risks
Protect and govern data
anywhere it lives
Information
Protection &
Governance
Quickly investigate and
respond with relevant data
Discover
& Respond
The availability of tools
Compliance Management Simplify and automate risk assessments
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
7
Insider Risk Management
Communications Compliance
Information Barriers
Customer Lockbox
Privileged Access Management
Retention & Disposition
Cloud DLP
Communications DLP
Rules-based auto classification
Machine Learning auto
classification
Records Management
Customer Key
Advance Message Encryption
Advanced Audit
Core eDiscovery
Advanced eDiscovery
Data Subject Access
Requests
Microsoft’s Investment in Compliance (Including GDPR)
Compliance Management
Compliance Manager
Compliance Score
GDPR Dashboard
eDiscovery Reference Model
Center
of
Excellence
Typical Use cases
Litigation
DSAR
Compliance / HR investigation
Regulatory requests
Law Enforcement requests
Key Factors
M365 License Model (E3 vs. E5)
Processing, Analysis & Review capabilities or workflows
Manual vs Automated processes
Task ownership
8
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Introduction
A quick introduction of M365
Top 5 Features for Legal
1. In-Place Legal hold
When a reasonable expectation of litigation exists, organizations are required to preserve electronically stored information (ESI), including email that's relevant to the case. Also known as, in-place hold, or legal hold.
Proprietary/Confidential 11
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Traditional eDiscovery and M365
Preservation
Compliance Tools
Proprietary/Confidential 12
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Traditional eDiscovery and M365
Identification
Preservation
Collection
Core eDiscovery
Identification
Preservation
Collection
Processing
Analysis
Advanced eDiscovery
Review
13
© 2018 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
M365 In-Place Legal Hold
Create a
eDiscovery Case
Use Conditions/Filters
Select User Locations
(SharePoint/OneDrive/Exchange)
Create a
Legal Hold
Legal Holds – Litigation vs In-Place Holds
14
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Exchange Online
Mailbox
Message 6
Message 1
Message 2
Message 3
Message 4
Message 5
Litigation Hold
Applied in Exchange Admin Center
Applied on a Resource
Covers the entire resource
Holistic Approach
Legal Holds – Litigation vs In-Place Holds
15
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Exchange Online
Mailbox
Message 6
Message 1
Message 2
Message 3
Message 4
Message 5
In-Place Hold
Applied in Compliance
Center
Applied using Conditions
Covers a specific resource
Targeted Approach
Triggers litigation hold (500+
keywords)
Litigation Hold
Applied in Exchange Admin Center
Applied on a Resource
Covers the entire resource
Holistic Approach
2. In-Place Search
If your organization adheres to legal discovery
requirements (related to organizational policy, compliance, or lawsuits), In-Place eDiscovery in Microsoft Exchange Server and Exchange Online can help you perform discovery searches for relevant content within mailboxes.
17
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Content Search
Fast & Powerful
Multi-threaded makes content searches built for scalability and speed.
Includes key storage locations (Exchange, SharePoint &
OneDrive)
Using powerful Keyword Query Language (KQL)
Preview
Ability to sample the data found during the search
Export
Ability to export the results for downstream analysis
Provide a report of the results
No. of mailboxes
Speed
Average (Sec.)
100
30 seconds
0.3
1,000
45 seconds
0.045
10,000
4 minutes
0.024
25,000
10 minutes
0.024
50,000
20 minutes
0.024 100,000
25 minutes
0.015
18
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Content Search - Example
109,394
items
John NEAR(5) Collins
99,209
items
John NEAR(5) Collins
Message kind: Email
43,334
items
John NEAR(5) Collins
Message kind: Email
Date: 2020-07-25..2020-08-25
4,521 items
John NEAR(5) Collins
Message kind: Email
Date: 2020-07-25..2020-08-25
participants NOT john@ledlabs.org
528 items
John NEAR(5) Collins
Message kind: Email
Date: 2020-07-25..2020-08-25
participants NOT john@ledlabs.org
Has Attachment: True
3. Advanced eDiscovery
With Advanced eDiscovery, you can better understand your data and reduce your eDiscovery costs. Advanced eDiscovery helps you analyze unstructured data, perform
more efficient document review, and make decisions to
reduce data for eDiscovery.
Proprietary/Confidential 20
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Advanced eDiscovery
Information
Governance
Identification
(Search)
Preservation
and Collection
Processing
Review
Analysis
Production
Presentation
Core eDiscovery
Advanced eDiscovery
Identification, Preservation, Collection, Processing, Analysis, Review & Production
“Deep Indexing”
Boolean, Proximity, Wildcard,
date range, metadata
1. Create case
2. Assign
permissions
4. In-place hold on
entire source
or scoped
5. Conduct searches
7. Analytics
8. Review
and
production
Near duplicate detection
Themes
Email
threading
Redactions
Review
and
tagging
Production
Predictive
Coding
6. Processing
Export load
file
Natives
Analytic
values for
review
HTMLs
3. Add
custodians
and data
sources
Ingest external Data
Legal
hold
notice
21
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Automatic data source mapping
Simplified collection workflow
Ability to sample/test keywords or collection scope prior to collection
Filter by keywords, metadata, document types and dates
Teams message thread reconstruction
No movement or duplication of data (data remains in O365)
Search can be run by HR/Legal/Privacy depending on Operating Model
Identification
Collection
Processing
Review
Analysis
Production
HR/Legal/Privacy
IT/Security
Request
Identification
of Data sources
M365 Data?
Acquire from
other location
M365
Content
Search
Add to
Review Set
Data
Processing
Analysis &
Review
Review, Tag,
Redact
Production
Disclosure
Non-Office 365
Data Import
Assessment /
Scoping
Advanced eDiscovery
Can import non-Office 365 data sources to consolidate review
Deduplication, Near duplication and Threading simplify and speed up the
review
Optical Character Recognition (OCR) and Advanced indexing enables further filtering with search
Web based review simplifies and speeds up the review.
Document tagging enables granular document tracking and multi level
reviews.
In-place redaction removes the need to manually export and redact documents
Teams message threading improves the review by consolidating the full conversation into a single reviewable thread
Full audit history of events.
Automatic Attorney-Client Privilege detection
Workflow can include QC prior to production
Defensible production of documents in PDF or Native file formats.
DSAR Op Model
Inefficient basic workflow
Linear review (one document at a
time)
Manual document tracking
Slow document to document speeds
Inconsistent approach
Limited document management can
lead to duplication or spoliation of data within the organisation
Reliance on 3rdParty tools (Adobe)
for redactions
High risk of inaccurate productions
Manual QC
Time take to combine production
Typical DSAR
Advanced eDiscovery
Requires up to date data mapping
Can take time to contact SME’s
Inconsistent approach
22
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Undocumented / inconsistent approach
No ECA or scoping leads to over collection
Inconsistent approach
Manual copy/paste processes
Advanced eDiscovery
23
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Proprietary/Confidential
Analytics Tools
Tagging Panel
Document Viewer
File Metadata
Document List
Filters / Searches
Review Set Options
Proprietary/Confidential 24
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Microsoft 365 Advanced eDiscovery
Preserve
2.5 TB data
36 People
70-200 sources
Scope
900 GB data
13 People
50 sources
Minimize
27 GB data
97%
reduction in volume
Analyse
De-duplication: -
30%
Threading: -25%
Total further
reduction: -45%
Review
Organized
Prioritized
Consistent
Average Microsoft Cases for 2016 - 2019
Proprietary/Confidential 25
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
4. Advanced Audit
The unified auditing functionality in Microsoft 365
provides organizations with visibility into many types of
audited activities across many different services in Microsoft 365. Advanced Audit helps organizations to conduct forensic and compliance investigations by increasing audit log retention required to conduct an investigation.
M365 Audit Events
Proprietary/Confidential 27
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
M365 Audit Events
Proprietary/Confidential 28
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
Review Event Details
Review Event Details
Event List
Export Results
5. Data Insights
Pull deep insights such as:
Stale data
Ungoverned and unprotected sensitive
information
Fraudulent and suspicious activity
to identify the greatest risks in your organization.
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
30
Use eDiscovery to Identify Stale or Outdated Data
VISUALISE DATA GROWTH OVER TIME
FIND OUTDATED INFORMATION
REMEDIATE EXISTING ISSUES
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
31
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
32
Use eDiscovery to Identify Sensitive Data in SharePoint/OneDrive
IDENTIFY SENSITIVE DATA TYPES
FIND SENSITIVE INFORMATION
REMEDIATE EXISTING ISSUES
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
33
Data Loss Prevention
Use DLP to Identify Sensitive Data In-Transit (Exchange Online)
MONITOR EVENTS
INVESTIGATE ISSUES
IDENTIFY PATTERNS
Proprietary/Confidential
© 2020 Lighthouse. All rights reserved. Lighthouse is a registered trademark of Lighthouse Document Technologies.
34
Alerts
IDENTIFY PATTERNS
MONITOR ALERTS
INVESTIGATE ISSUES
Use Audit to Identify Unusual or Suspicious Activity
Thank You.
James Hart, Director of Advisory Services Compliance Consultant jhart@lighthouseglobal.com
Loading...