ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Choosing a Document Management System: Security Questions to Ask

Evaluating NetDocuments, iManage or another DMS? Use this question list covering access control, encryption, audit trails, exit terms and integrations.

3 min readBy Counsel Cyber Team

A document management system, or DMS, sits at the center of a law firm's work. It holds drafts, correspondence, discovery and the final work product that clients pay for. Choosing one, or reviewing the one you have, is a decision with security implications that last for years. Moving later is painful, so it pays to ask the right questions up front.

This guide is vendor-neutral. Platforms such as NetDocuments and iManage are widely used in legal, and many firms use Microsoft 365 with SharePoint or other tools. Use these questions with whichever vendors you evaluate and get answers in writing.

Hosting model

  1. Is the system cloud-hosted, on-premises or hybrid? What does each option mean for who patches and secures what?
  2. For cloud, which infrastructure provider and which regions host our data? Can we choose or restrict location?
  3. How does the vendor handle availability and disaster recovery? Ask for recovery objectives, not only uptime promises.

Access control and ethical walls

Law firms need to restrict access by matter, client and sometimes individual.

  1. Can permissions be set at the matter, workspace and document level, and are they easy to audit?
  2. Does the system support ethical walls or screens, so that a lateral hire's conflicts are enforced technically rather than by honor system?
  3. Can we see who has access to a given matter without an administrator spending hours?
  4. How are external users, such as clients and co-counsel, granted access? Is access time-limited?
  5. Does it integrate with single sign-on and enforce multi-factor authentication?

Encryption and key management

  1. Is data encrypted in transit and at rest, and with what standards?
  2. Who holds the keys? Some vendors offer customer-managed keys. Ask whether this option is available and what it costs.
  3. How are backups of the DMS data encrypted and protected?

Audit trails and monitoring

  1. Does the system log who opened, edited, downloaded, shared or deleted documents?
  2. How long are logs retained, and can we export them?
  3. Can the system alert on unusual activity, such as mass downloads by one user?
  4. How does the vendor monitor its own environment, and how will we be told of an incident?

Versioning, deletion and recovery

  1. Is every version retained, and can we restore a prior version?
  2. What happens when a user deletes a document? Is there a recycle period, and can administrators recover content?
  3. Does the vendor offer protection against ransomware, such as immutable snapshots or rollback?
  4. How do retention and legal hold features work, and can they be applied by matter?

Integrations and add-ins

The DMS rarely stands alone. Ask about connections to email, Microsoft Office, practice management, billing, e-discovery and mobile apps.

  • Which integrations are provided by the vendor, and which by third parties?
  • What permissions do add-ins request?
  • Can we restrict who may install integrations?
  • Where does data go when an integration syncs it?

Vendor oversight

Model Rule 5.3 addresses supervision of nonlawyer assistance, and the ABA has discussed outside technology vendors in that context.

  1. Can the vendor provide an independent security audit report, such as SOC 2, under confidentiality?
  2. Which subprocessors does it use?
  3. What contractual commitments exist for confidentiality, breach notification and data return?
  4. Will the vendor support client audits or questionnaires if a corporate client asks?

Exit and portability

This is the question buyers forget.

  1. Can we export all documents, versions, metadata and permissions in a usable format?
  2. What does an export cost and how long does it take?
  3. How long does the vendor retain our data after termination, and how is deletion confirmed?

Usability matters for security

If attorneys find the DMS cumbersome, they will save files to desktops and email documents to themselves. A system that is easy to use is a security control. Include real users in the demo and in a trial, and watch how long it takes to save, search and share a document.

Scoring and decision

Create a short scorecard with categories such as security, usability, integration, cost and support. Weigh them according to your firm's priorities and write down the rationale. Request references from firms of similar size and ask what surprised them after go-live.

Plan the migration

Migration is a security event: data is copied, permissions are mapped and old systems linger. Plan how permissions will be transferred, who verifies the result and when legacy repositories are securely retired.

How Counsel Cyber can help

Counsel Cyber supports law firms using NetDocuments, iManage, Clio and Microsoft 365, including security reviews and migration planning. If you are evaluating a change, we are glad to help you compare options.