Functional entities · Information packages · Migration strategies · PDI metadata
| # | Responsibility | Standard ref. | Status |
|---|---|---|---|
| 1 | Negotiate and accept appropriate information from Producers | ISO 14721 §3.1.1 | Partial |
| 2 | Obtain sufficient control to ensure Long-Term Preservation | ISO 14721 §3.1.2 | Compliant |
| 3 | Determine and define the Designated Community and its Knowledge Base | ISO 14721 §3.1.3 | Non-compliant |
| 4 | Ensure that the information is Independently Understandable | ISO 14721 §3.1.4 | Partial |
| 5 | Follow documented policies and procedures — no ad-hoc deletions | ISO 14721 §3.1.5 | Partial |
| 6 | Make information available to the Designated Community with Authenticity evidence | ISO 14721 §3.1.6 | Compliant |
| Algorithm | Length | Recommended use |
|---|---|---|
| SHA-256 | 256 bits | Current standard for digital preservation. Recommended by PREMIS, OAIS, and Library of Congress. |
| SHA-512 | 512 bits | Higher security for critical collections. Used in ISO 16363-certified repositories worldwide. |
| MD5 | 128 bits | Legacy — acceptable for error detection only. Not suitable for security. Known collision vulnerabilities. |
| CRC-32 | 32 bits | Transmission error detection only. Insufficient for long-term preservation assurance. |
| Risk | OAIS entity affected | Likelihood | Impact | Level | Mitigation |
|---|---|---|---|---|---|
| Format obsolescence Proprietary formats with no renderer |
Preservation Planning · Archival Storage | HIGH | CRITICAL | HIGH | Migrate to PDF/A, TIFF, XML. Continuous technology watch programme. |
| Bit rot Silent degradation on storage media |
Archival Storage | MEDIUM | CRITICAL | HIGH | Periodic SHA-256 checksum verification. 3-2-1 backup rule strictly applied. |
| Missing PDI metadata Objects without context or provenance |
Data Management · Ingest | HIGH | CRITICAL | HIGH | Implement PREMIS + ISO 23081 metadata schema at ingest. Mandatory fields enforced. |
| Hardware failure / disaster Fire, flood, disk failure, power loss |
Archival Storage · Administration | MEDIUM | CRITICAL | HIGH | Documented and tested BCP/DRP. Geographically distributed copies. Regular DR tests. |
| No preservation policy Ad-hoc decisions, no governance |
Administration | HIGH | MAJOR | HIGH | Approve institutional preservation policy. Appoint formal preservation officer with defined role. |
| Cyberattack / ransomware Encryption or malicious destruction |
Archival Storage · Administration | MEDIUM | CRITICAL | HIGH | ISO 27001 controls. Immutable offline backups. Network segmentation. Air-gap copies. |
| Undefined Designated Community No documented Knowledge Base |
Access · Preservation Planning | HIGH | MAJOR | MEDIUM | Define user profiles. Document Knowledge Base. Review periodically as community evolves. |
| Loss of archival context Images without relationship to process |
Ingest · Data Management | MEDIUM | MAJOR | MEDIUM | Integrate digitisation with ERMS/EDMS. Mandatory context metadata at ingest. |
| Single vendor dependency Vendor lock-in (software or cloud) |
Administration · Preservation Planning | MEDIUM | MAJOR | MEDIUM | Open formats mandatory. Exit clauses in contracts. Interoperability with E-ARK, BagIt, OAIS standards. |