The DRAMBORA toolkit document appears to me to be very thorough and well thought out, and the progressive steps of the audit process are straight forward. It makes sense to me to follow in sequence from identification of risks, to assessment of those risks and finally to the establishment of risk treatment strategies. I found the toolkit it to be an easy to follow and self-explanatory guide for auditing digital repositories. It seems also to be flexible enough to handle almost any repository. Further, I believe the concept of basing a repository audit on risk assessment principles to be ingenious. Why else would one audit a digital repository, if not to safeguard against any and all risks of loss of the usefulness of its information?
My praise should not be taken to suggest that all is well. At times, the process in DRAMBORA seems a bit redundant, and I suppose one could argue for a consolidation of some of the worksheets. Tasks 8, 9 and 10 come immediately to mind. Each of the final three worksheets repeats the preceding sheet’s information and then adds a new step. However, it is important to take things one step at a time in such an exercise as auditing a repository. By waiting to assess risks until all risks have been identified and logged, for instance, keeps one focused on the whole of the repository at the time of assessment. In this manner it seems much easier to keep perspective about the comparative impact of a single risk when assessment comes in an organized functional sequence. Ultimately, in my view, combining the identification, assessment and evaluation of risks into the same functional step is too much to deal with at once and may overwhelm an auditor.
There is some minor repetitiveness in some of the other worksheets as well, for example where repository objectives or mandates may include initiatives that address legal issues, such sources of information may be included in multiple worksheets. We found that the same information may be listed in worksheets 2, 3, and 4, for instance. In our group we decided to handle this repetitive entry by listing the same sources of information in multiple worksheets, as long as the focused perspective of each worksheet was the cause of listing the item.
The repetitive issues did not seem that significant to me, and certainly they were not so problematic that it interfered with or belabored our audit process.
I did not find the audit project particularly difficult, but it was rather laborious and tedious, which I suppose was to be expected for audit work. All of my working experience with audits, performing them and being the subject of them, tells me this is so. But, the step by step approach of DRAMBORA keeps everything organized and very simple to follow. In the end, I liked the toolkit document, and I think the approach is a good one.
There are some aspects of IDEALS that are somewhat inflexible because of its affiliation with a University. This is especially noteworthy in the face of severe budgetary confinements. A corporate repository may have different capabilities and freedoms to respond to audit findings, and in fact, may encompass an entirely different need for an audit in the first place. With limited abilities to respond to the audit findings, IDEALS may find itself in a position of foregoing action on certain recommendations. However, this should not preclude the repository from undertaking a thorough audit of its processes, obligations and risks. It is important to understand the risks and to take action where possible. Even if some glaring risks cannot be addressed, at least the repository management becomes aware of them and can anticipate needed future changes to eventually handle the potential risk. By bringing these risks to the attention of the University’s provost and other executive leadership, such leaders will not be caught off-guard about potentially substantial financial losses as a result of the occurrence of certain events.
In my opinion, the DRAMBORA approach works fine for IDEALS. I did not perceive any significant challenges employing the audit methods for this repository. The audit steps are not complicated nor are they restrictive in their application. This flexibility, I think, allows wide-spread applicability of DRAMBORA.
As to the DRAMBORA project being useful to me in terms of its educational value, I think of some other experiences that give me reason to say confidently that is was very supportive of excellent learning outcomes in this class. For instance, in March, I participated in the GSLIS’s alternative spring break program and spent a week at the Church History Library in Salt Lake City, Utah. I mostly did some job shadowing in five different departments at this brand new facility (opened in May 2009). My experience in the digital preservation department was very rewarding, as I observed ingest, migration, audit, and archiving of text, audio and visual digital objects, some born digital and others taken from analog documents. In class, we had just finished our grant proposals in which we constructed a workflow for a digital preservation project. As I sat with the manager of the DP department at CHL, he described the workflow that his staff follows every day, which was exactly what we had just written in the group assignment. He, as did we, used the OAIS document as the basis for the workflow.
I cite this experience for two reasons. First, it is only one, but perhaps the best, example that I have found everything we have done or discussed in this class has been right at the forefront of the digital preservation world. When I discuss the concepts and principles with DP professionals, those discussions have confirmed their pertinence to real world issues. Based on that track record, I have no doubt that DRAMBORA likewise has contributed significantly to my understanding of the digital preservation process.
Second, I mention the CHL experience because it, as well as the DRAMBORA project itself, is another example of how learning through experience is the best way to learn. My experience at CHL went a long way in transitioning my understanding of the information presented in class into to real and memorable experiences in my mind. I will remember what I learned about OAIS much better for having some hands-on experience with it in a digital preservation department.
In an article about the constructivist learning theory, Cooperstein and Kocevar-Weidinger point out that learning comes from experience, and not the other way around. So, the experience of DRAMBORA (among other things in this class) has contributed greatly to my education. If we were to simply talk and theorize about auditing repositories, some of us would show up for work one day and still not know how to perform an audit. Now that we have actually completed an audit, we will be more confident, capable, and prepared to do the next one.
For a first iteration of the risk assessment based audit method, I found DRAMBORA to be quite comprehensive, and yet, user-friendly. As an old insurance guy turned librarian, I noticed DRAMBORA’s adherence to the same risk management principles used by organizations, large and small, to manage their physical exposures to loss. With that in mind, I expect DRAMBORA will only get better as new iterations are released, revised according to experiences with the first and succeeding versions.
Works referenced:
DRAMBORA, Digital Repository Audit Method Based on Risk Assessment. Digital Curation Centre and Digital Preservation Europe. Toolkit document, Release: Version 1.0, 2007.
Cooperstein, Susan E. and Elizabeth Kocevar-Weidinger. “Beyond Active Learning: A Constructivist Approach to Learning.” Reference Services Review 32 (2004): 141-8.