Citations: FDA 21 CFR Part 11
No citations match the current filters.
Trustworthiness & Reliability
Mapping
Reference: § 11.1 - a
The regulations in this part set forth the criteria under which the agency considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures executed on pape
Authority Document
Mapped Control Objectives (2)
Mapped Documents (5)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- RDT Document Standards (SOP)
- Good Documentation Practices (Other)
- Password Management Standard Directive (Other)
Applicability to ER/ES
Mapping
Reference: § 11.1 - b
This part applies to records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted, under any records requirements set forth in agency regulations. This part also applies to electronic records submitted to the agency under requirements of the Federal Food, Dr
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Definition of Direct and Indirect Regulatory Impact (Other)
Signature Equivalence
Mapping
Reference: § 11.1 - c
Where electronic signatures and their associated electronic records meet the requirements of this part, the agency will consider the electronic signatures to be equivalent to full handwritten signatures, initials, and oth5er general signings as required by agency regulations, unless specifically exc
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- RDT Document Standards (SOP)
- Good Documentation Practices (Other)
Electronic in lieu of Paper
Mapping
Reference: § 11.1 - d
Electronic records that meet the requirements of this part may be used in lieu of paper records, in accordance with § 11.2, unless paper records are specifically required.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- RDT Document Standards (SOP)
- Good Documentation Practices (Other)
Availability for Inspection
Mapping
Reference: § 11.1 - e
Computer systems (including hardware and software), controls, and attendant documentation maintained under this part shall be readily available for, and subject to, FDA inspection.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (6)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Records Management Directive (Directive)
- Informatics IT Self Inspection Management SOP (SOP)
- Good Documentation Practices (Other)
Mapped Processes (1)
Validation of Systems
Mapping
Reference: § 11.10 - a
Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (13)
- Informatics Computerised System Risk Management Policy (Policy)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Group Informatics CSV Lifecycle Operations and Maintenance S... (SOP)
- Group Informatics CSV Lifecycle Retirement SOP (SOP)
- Informatics CSV Periodic Review SOP (SOP)
- CSV SOLMAN Roles and Responsibilities Deliverable Approval S... (Other)
- Definition of Direct and Indirect Regulatory Impact (Other)
- GI CSV Guidance and Aid of ERES Requirements for CS Implemen... (Other)
- Guideline for use of Agile Frameworks for GxP Systems (Other)
- Informatics Risk-Based Testing SPT (Other)
- Password Management Standard Directive (Other)
Mapped Processes (1)
Ability to Generate Copies
Mapping
Reference: § 11.10 - b
The ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection, review, and copying by the agency.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (8)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Group Informatics CSV Lifecycle Operations and Maintenance S... (SOP)
- Group Informatics CSV Lifecycle Retirement SOP (SOP)
- Informatics CSV Periodic Review SOP (SOP)
- Good Documentation Practices (Other)
- Password Management Standard Directive (Other)
Mapped Processes (2)
Protection/Retention
Mapping
Reference: § 11.10 - c
Protection of records to enable their accurate and ready retrieval throughout the records retention period.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (16)
- Informatics Computerised Systems Validation Policy (Policy)
- Informatics Policy Data Protection (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Directive on Data Classification (Directive)
- Group Records Management Directive (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Group Informatics CSV Lifecycle Operations and Maintenance S... (SOP)
- Group Informatics CSV Lifecycle Retirement SOP (SOP)
- Informatics Process SOP Backup and Restoration Man (SOP)
- Informatics SOP Continuity Framework: Recovery (SOP)
- RDT Document Standards (SOP)
- Standard for the Management and Retention of Elect (SOP)
- Classifying and Securing Data Work Instruction (Other)
- Good Documentation Practices (Other)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (2)
Limiting System Access
Mapping
Reference: § 11.10 - d
Limiting system access to authorized individuals.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (12)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Directive K 19 (Directive)
- Group Records Management Directive (Directive)
- Roche Information Security Directive (Directive)
- Roche Privileged Access Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Time-stamped Audit Trails
Mapping
Reference: § 11.10 - e
Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
Mapped Processes (2)
Operational Checks
Mapping
Reference: § 11.10 - f
Use of operational system checks to enforce permitted sequencing of steps and events, as appropriate.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (5)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Authority Checks
Mapping
Reference: § 11.10 - g
Use of authority checks to ensure that only authorized individuals can use the system, electronically sign a record, access the operation or computer system input or output device, alter a record, or perform the operation at hand.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (11)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Directive K 19 (Directive)
- Group Records Management Directive (Directive)
- Roche Information Security Directive (Directive)
- Roche Privileged Access Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
Mapped Processes (1)
Device (Terminal) Checks
Mapping
Reference: § 11.10 - h
Use of device (e.g., terminal) checks to determine, as appropriate, the validity of the source of data input or operational instruction.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (9)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- IT Infrastructure Qualification SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Network Security Standard (SOP)
- Password Management Standard Directive (Other)
- Secure Development of Web Applications (Other)
Mapped Processes (1)
Education & Training
Mapping
Reference: § 11.10 - i
Determination that persons who develop, maintain, or use electronic record/electronic signature systems have the education, training, and experience to perform their assigned tasks.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Informatics SOP Training Management (SOP)
- Informatics Mandatory Training Catalogue (Other)
Mapped Processes (2)
Individual Accountability
Mapping
Reference: § 11.10 - j
The establishment of, and adherence to, written policies that hold individuals accountable and responsible for actions initiated under their electronic signatures, in order to deter record and signature falsification.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (9)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Directive Using Electronic Communication Tools (Directive)
- Roche Information Security Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
System Documentation Ctrl
Mapping
Reference: § 11.10 - k
Use of appropriate controls over systems documentation including: (1) Adequate controls over the distribution of, access to, and use of documentation for system operation and maintenance. (2) Revision and change control procedures to maintain an audit trail that documents time-sequenced development
Authority Document
Mapped Control Objectives (1)
Mapped Documents (7)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics Process SOP Change Management (SOP)
- RDT Document Standards (SOP)
- CSV SOLMAN Roles and Responsibilities Deliverable Approval S... (Other)
- GI CSV Guidance and Aid of ERES Requirements for CS Implemen... (Other)
- GI Document Review and Approval Matrix SPT (Other)
Signature Uniqueness
Mapping
Reference: § 11.100 - a
Each electronic signature shall be unique to one individual and shall not be reused by, or reassigned to, anyone else.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (11)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (1)
Identity Verification
Mapping
Reference: § 11.100 - b
Before an organization establishes, assigns, or certifies an individual's electronic signature, the organization shall verify the identity of the individual.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (11)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (2)
Legal Binding Certification
Mapping
Reference: § 11.100 - c
Persons using electronic signatures shall certify to the agency that the electronic signatures in their system are intended to be the legally binding equivalent of traditional handwritten signatures.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
Non-Repudiation Letter
Mapping
Reference: § 11.100 - c (1)
The certification shall be signed with a traditional handwritten signature and submitted in electronic or paper form. Information on where to submit the certification can be found on FDA's web page on Letters of Non-Repudiation Agreement.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
Ongoing Validation
Mapping
Reference: § 11.100 - c (2)
Persons using electronic signatures shall, upon agency request, provide additional certification or testimony that a specific electronic signature is the legally binding equivalent of the signer's handwritten signature.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (7)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Group Informatics CSV Lifecycle Operations and Maintenance S... (SOP)
- Group Informatics CSV Lifecycle Retirement SOP (SOP)
- Informatics CSV Periodic Review SOP (SOP)
- Password Management Standard Directive (Other)
Electronic records/signatures in lieu of paper (Maintained records)
Mapping
Reference: § 11.2 - a
For records required to be maintained but not submitted to the agency, persons may use electronic records in lieu of paper records or electronic signatures in lieu of traditional signatures, in whole or in part, provided that the requirements of this part are met.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- RDT Document Standards (SOP)
- Good Documentation Practices (Other)
Submissions to the Agency (Specific formats/media)
Mapping
Reference: § 11.2 - b
For records submitted to the agency, persons may use electronic records in lieu of paper records or electronic signatures in lieu of traditional signatures, in whole or in part, provided that:
(1) The requirements of this part are met; and
(2) The document or parts of a document to be submitted ha
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
Dual-Component Requirement: Single Session and New Session Protocols
Mapping
Reference: § 11.200 - a (1)
Electronic signatures that are not based upon biometrics shall:
(1) Employ at least two distinct identification components such as an identification code and password.
(i) When an individual executes a series of signings during a single, continuous period of controlled system access, the first si
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
Mapped Processes (1)
Owner Exclusivity
Mapping
Reference: § 11.200 - a (2)
Electronic signatures that are not based upon biometrics shall:
Be used only by their genuine owners; and
Authority Document
Mapped Control Objectives (2)
Mapped Documents (11)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (1)
Collusion Prevention
Mapping
Reference: § 11.200 - a (3)
Electronic signatures that are not based upon biometrics shall:
Be administered and executed to ensure that attempted use of an individual's electronic signature by anyone other than its genuine owner requires collaboration of two or more individuals.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (11)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Biometric Safeguards
Mapping
Reference: § 11.200 - b
Electronic signatures based upon biometrics shall be designed to ensure that they cannot be used by anyone other than their genuine owner.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (4)
- Roche Information Security Policy (Policy)
- Roche Information Security Directive (Directive)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
Definition: Act (FD&C Act)
Mapping
Reference: § 11.3 - b (1)
Act means the Federal Food, Drug, and Cosmetic Act (secs. 201-903 (21 U.S.C. 321-393)).
Authority Document
Mapped Control Objectives (1)
Mapped Documents (3)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (Other)
Definition: Agency (FDA)
Mapping
Reference: § 11.3 - b (2)
Agency means the Food and Drug Administration.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (3)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (Other)
Definition: Biometrics
Mapping
Reference: § 11.3 - b (3)
Biometrics means a method of verifying an individual's identity based on measurement of the individual's physical feature(s) or repeatable action(s) where those features and/or actions are both unique to that individual and measurable.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (6)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Definition: Closed System
Mapping
Reference: § 11.3 - b (4)
Closed system means an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Definition: Digital Signature
Mapping
Reference: § 11.3 - b (5)
Digital signature means an electronic signature based upon cryptographic methods of originator authentication, computed by using a set of rules and a set of parameters such that the identity of the signer and the integrity of the data can be verified.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (5)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Definition: Electronic Record
Mapping
Reference: § 11.3 - b (6)
Electronic record means any combination of text, graphics, data, audio, pictorial, or other information representation in digital form that is created, modified, maintained, archived, retrieved, or distributed by a computer system.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Definition: Electronic Signature
Mapping
Reference: § 11.3 - b (7)
Electronic signature means a computer data compilation of any symbol or series of symbols executed, adopted, or authorized by an individual to be the legally binding equivalent of the individual's handwritten signature.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Definition: Handwritten Signature
Mapping
Reference: § 11.3 - b (8)
Handwritten signature means the scripted name or legal mark of an individual handwritten by that individual and executed or adopted with the present intention to authenticate a writing in a permanent form.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (4)
- Informatics Computerised Systems Validation Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Definition: Open System
Mapping
Reference: § 11.3 - b (9)
Open system means an environment in which system access is not controlled by persons who are responsible for the content of electronic records that are on the system.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (5)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- No mapping available (SOP)
- Handling Computerised System Glossary (Other)
Open System Controls
Mapping
Reference: § 11.30
Persons who use open systems to create, modify, maintain, or transmit electronic records shall employ procedures and controls designed to ensure the authenticity, integrity, and, as appropriate, the confidentiality of electronic records from the point of their creation to the point of their receipt.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (13)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Informatics Vendor Quality Assessment SOP (SOP-030 (SOP)
- MSB for Web Applications (SOP)
- Privacy) (20455202)" (SOP)
- Roche Certificate Policy (Standard Context) (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Security (SOP)
- Informatics Vendor Quality Assessment Questionnaire SPT (Other)
- Password Management Standard Directive (Other)
- Secure Development of Web Applications (Other)
Mapped Processes (1)
Uniqueness of ID/Password
Mapping
Reference: § 11.300 - a
Maintaining the uniqueness of each combined identification code and password.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (10)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Directive Using Electronic Communication Tools (Directive)
- Roche Information Security Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (1)
Credential Maintenance
Mapping
Reference: § 11.300 - b
Ensuring that identification code and password issuances are periodically checked, recalled, or revised (e.g., password aging).
Authority Document
Mapped Control Objectives (2)
Mapped Documents (10)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Informatics CSV Periodic Review SOP (SOP)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
- Periodic Review with ServiceNow IRM TOP (Other)
Mapped Processes (2)
Loss Management
Mapping
Reference: § 11.300 - c
Following loss management procedures to electronically deauthorize lost/stolen tokens or devices and to issue replacements using suitable controls.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (8)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
Mapped Processes (1)
Security Monitoring
Mapping
Reference: § 11.300 - d
Use of transaction safeguards to prevent unauthorized use of passwords/codes and report attempts at unauthorized use to security and management.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (8)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
Device Testing
Mapping
Reference: § 11.300 - e
Initial and periodic testing of devices (tokens/cards) to ensure they function properly and have not been altered in an unauthorized manner.
Authority Document
Mapped Control Objectives (2)
Mapped Documents (8)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche Information Security Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Roche Information Security Directive (Directive)
- Informatics Identity & Access Management SOP (SOP)
- Roche Minimum Security Baseline (MSB) Security Sta (SOP)
- Roche Password Management Standard (SOP)
- Password Management Standard Directive (Other)
Signature Manifestations
Mapping
Reference: § 11.50 - a
Signed electronic records shall contain information associated with the signing that clearly indicates:
(1) Printed name of signer;
(2) Date and time of execution;
and (3) The meaning associated with the signature.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (6)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (1)
Signature/Record Linking
Mapping
Reference: § 11.70
Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means.
Authority Document
Mapped Control Objectives (1)
Mapped Documents (6)
- Informatics Computerised Systems Validation Policy (Policy)
- Roche GxP Data Integrity Policy (Policy)
- Computerized Systems Validation Lifecycle Directiv (Directive)
- Group Informatics CSV Lifecycle Implementation SOP (SOP)
- Password Management Standard Directive (Other)
- Roche GxP Data Integrity Standard (Other)
Mapped Processes (1)