Description
WORM is an acronym for Write Once Read Many. It is similar to how data is stored on a Compact Disc (CD). In short, FINRA WORM refers to a specific regulation issued by FINRA relating to WORM storage systems within the financial industry. The NinjaOne SaaS Backup product is built on WORM principles, but there is also an option to enable a FINRA-compliant WORM setting if that is needed for your environment.
Some features affected by FINRA WORM are the Data Protection Officer (DPO) role and the retention policy. Additionally, this FINRA configuration can't be undone once it is activated. To have the option enabled at the partner level, please contact Manage Protect support.
(support@manageprotect.com)
The Process
Activate FINRA WORM for an Organization (after the option has been enabled by Manage Protect support at the partner level):
- Log in to the portal.
- Go to the Organization page and find the Organization you wish to activate FINRA on.
- Click on the organization to view its details.
- Go to the Features tab and
- The system shows a confirmation popup — click the Set Active button.
- Once successful, the system displays a success banner and locks the WORM Storage toggle, as the configuration can't be disabled again, and the DPO toggle will no longer appear. Frequently Asked Questions
Can sub-resellers access WORM?
Yes, as long as the configuration is active.
Which partner roles can access WORM?
Partners with owner, super admin, and admin roles can access WORM.
I logged in to the partner portal but couldn't find the WORM toggle. Why is that?
In the interface, the WORM toggle is only available for the Archiver SKU. However, backup and archiver SKUs generally use logical WORM storage that implements a write-once, read-many-times model.
I am unable to activate WORM and receive an error message. What does it mean?
The error indicates that DPO is in an active state. To enable WORM, please disable the DPO feature first.
Why do WORM and DPO appear to be in conflict?
One of the purposes of WORM is to maintain data integrity, so the deletion process performed by DPO is not compatible with it.
What are the advantages of WORM storage?
- Data immutability: Once written, data cannot be altered or deleted, ensuring data integrity and compliance with regulatory requirements.
- Secure archival: WORM storage provides a secure means of storing sensitive data for long-term archival purposes, protecting it from unauthorised access or tampering.
- Compliance readiness: WORM storage solutions are often designed to meet regulatory compliance requirements, such as HIPAA, GDPR, or SEC Rule 17a-4, making them suitable for industries with stringent data retention policies.
- What happens if we activate WORM on an existing Organization that has a DPO role?
After the DPO feature is disabled in the user interface, the DPO role will appear as "User View & Restore", while in the database it remains labelled as DPO.
Is WORM applicable to email products only?
Yes. WORM storage is applicable only to email products.
Do the email retention settings apply to WORM?
Yes. Email retention is applied, and the data will not be available after the retention period. The system will show an error message if a user creates a retention policy with less than a 3-year retention period.
How does WORM work in an existing Organization with less than a 3-year retention period?
The system will automatically convert it to a 3-year retention period.
While WORM is active, can I delete an account?
No. The Archiver SKU only allows users to deactivate an account, not delete it, whether or not WORM is active.
Can I request that certain accounts be removed while WORM is active?
- click the WORM Storage toggle.
Accounts can still be purged on request. Likewise, if the organization as a whole is purged, the data will not be retained.
How do we handle customer requests for WORM in non-US regions? Is there an alternative solution?
Our WORM implementation is logical and built into the solution, so no special request is required.