Skip to main content
Guidance

Public content provenance for organisations

Explaining why content provenance matters and how organisations can use it to verify and protect their online information.

Page 5 of 6

4. Deploying public content provenance systems: considerations and example use cases


4.1.1 Strategy to establish public information trust

Public information trust strategies will vary depending on factors such as the subject domain, the audience, and the objectives of actors seeking to use the organisation’s public information against them. 

Many organisations already have some capability for establishing trust in their public information and countering claims made against them. Using public provenance will help establish trust for an organisation’s content but it may not be as effective or have the same return on investment as other strategies. 

Organisations should decide whether to use provenance as an approach to countering the challenges they face. Those choosing to use provenance technologies will also have to consider how to implement them.

4.1.2 Introduction of provenance in content lifecycle

Organisations can have a lot of content. Some of this content is publicly available. Other content, such as drafts, may not be publicly available now but will become public in the future. 

The content may be at various stages of update and editing in preparation for publication. It may be distributed across a variety of systems and may be subject to changes by many individuals. 

Organisations may also have some content that they never intend to make public. Some content may pose challenges or risks to the organisation itself. As a result, organisations may choose strong provenance measures only for some types of content. They may also choose to protect content at the point of publication rather than at point of creation. 

4.1.3 Timeframe for content verification

The public’s requirements for information verification can vary in timeframe depending on the information context. Some information verification requirements will be aimed at short-term concerns such as elections, while others will be aimed at generational issues such as evidence concerning distant historical events. 

For short-term events, the organisational risk is that it will take longer to verify the provenance information than the event timeframe requires. Timeframe issues can impact how long provenance records must be maintained, as well as how readily-accessible the records need to be. 

4.1.4 Cost

Digital provenance mechanisms are relatively new and have associated implementation, operation, and maintenance costs. In most cases, organisations will have to change business processes to make effective use of provenance mechanisms. In addition, provenance technologies are evolving rapidly, and near-term implementations may quickly become obsolete. 

Organisations may choose to prioritise non-provenance public information trust responses or they may choose to implement interim or partial solutions, for example using public provenance measures only for critical content.

4.1.5 Audience and format
 

The audience for provenance information may not necessarily be the same as an organisation's core audience. This will depend on an organisation's strategic and tactical response to the use of their information. 

Formats for provenance information will be different depending on the system used by the specific audience. 

Media companies have copyright on their information and may be able to use copyright tools to remove infringing material from the internet. In this case, the audiences for provenance evidence are legal professionals, Internet Service Providers and social media companies. Provenance information would need to be formatted to meet their different evidence requirements. A media company's implementation of provenance mechanisms will likely differ from that used by organisations whose provenance information audience is the public.

4.1.6 Maturity of public provenance technologies
 

Organisations should also consider the maturity of public provenance technologies. Technologies for versioning and logging to meet an organisation’s internal provenance requirements are mature. Public provenance technologies are less developed, although some of the related technologies used in private provenance, such as cryptographic hashing, can be used in public systems. 

Publicly accessible provenance systems have additional requirements, for example, end-point devices such as cameras that can cryptographically sign content, and tamper-proof ledgers. These technologies are developing, but immature. 

Organisations may choose to do partial and trial implementations. They may also choose to establish architectures that allow newer technologies to be integrated as they become available.


Published

Reviewed

Version

1.0