Processes: System Lifecycle Management
No processes match the current filters.
Agile GxP Release Management
System Lifecycle Management
ID: P010
End-to-end process for authorizing and executing a product release to the Production Environment as described in SRD-0145688. Spans completion of all release-level Definition of Done criteria, creation and approval of the Release Summary, and raising of a Change Control record to authorize deploymen
Source Documents (1)
Mapped Citations (1)
Agile Sprint Execution
System Lifecycle Management
ID: P011
Repeatable iterative sprint cycle for GxP computerized system delivery as defined in SRD-0145688. Covers selection of sprint backlog items, design and build of user stories, testing against acceptance criteria, defect management, and verification of the Definition of Done for the Product Increment b
Source Documents (1)
Mapped Citations (5)
CS Decommissioning
System Lifecycle Management
ID: P012
Describes the controlled shutdown of a withdrawn computerized system as defined in sop031555. The System Owner is accountable for ensuring decommissioning activities are defined, executed, and documented, with the CS removed from the active inventory and configuration management updated to reflect t
Source Documents (1)
Mapped Citations (9)
Roles (2)
CS Inventory Setup and Maintenance
System Lifecycle Management
ID: P013
Defines the step-by-step procedure for creating, maintaining, and retiring Computerised System records (Business Applications) in ServiceNow APM, as specified in WI-0301164. Covers the full lifecycle from initial registration through compliance data population to retirement, with specific role assig
Source Documents (1)
Mapped Citations (40)
- 1.1 Establish and Maintain Detailed Enterprise Asset Invento...
- 2.1 Establish and Maintain a Software Inventory
- 3.2 Establish and Maintain a Data Inventory
- AS.164.308.a2
- AS.164.308.a4-ii-c
- Associate Active Ports, Services and Protocols to Asset Inve...
- CS Inventory
- DCS-05 Assets Classification
- DCS-06 Assets Cataloguing and Tracking
- DSP-03 Data Inventory
- DSP-06 Data Ownership and Stewardship
- Ensure Software is Supported by Vendor
- GV.OC-04
- GV.OC-05
- GV.RR-02
- GV.SC-04
- IAM-03 Identity Inventory
- IAM-06 User Access Provisioning
- ID.AM-01
- ID.AM-02
- ID.AM-05
- ID.AM-08
- ID.BE-P3
- ID.IM-P1
- ID.IM-P2
- Information security roles and responsibilities
- Integrate Software and Hardware Asset Inventories
- Inventory and Control of Hardware Assets
- Inventory and Control of Software Assets
- Inventory of information and other associated assets
- Maintain Asset Inventory Information
- Maintain Detailed Asset Inventory
- Maintain Inventory of Authorized Software
- Maintain an Inventory of Authentication Systems
- Monitoring Inventory
- OS-1.A.1
- Track Software Inventory Information
- UEM-04 Endpoint Inventory
- Use DHCP Logging to Update Asset Inventory
- Utilize Software Inventory Tools
Artifacts (1)
CS Retirement Planning
System Lifecycle Management
ID: P014
Defines the scope, strategy, change control, and risk assessment for retiring a computerized system as described in sop031555. The Process Owner is accountable for ensuring all retirement activities are planned, documented, and approved before commencement of any retirement activities.
CS Training Management for Release
System Lifecycle Management
ID: P015
Process for identifying, developing, and delivering training required before a computerized system is released for GxP use. Covers both business end-user and IT support personnel training. Defined in sop031553 section 7.2.
Source Documents (1)
Mapped Citations (8)
Roles (2)
Artifacts (1)
CS Withdrawal
System Lifecycle Management
ID: P016
Describes the process of removing a computerized system from active end-user operations as defined in sop031555. The Process Owner is accountable for defining and executing withdrawal activities, including account deactivation, interface disabling, and communication, with results documented in a Wit
Source Documents (1)
Mapped Citations (3)
Roles (2)
Artifacts (2)
CSV Deliverable Review and Approval in SolMan Focused Build
System Lifecycle Management
ID: P018
Defines the review and approval lifecycle for CSV deliverables (URS, FS, DS, Test Plans, Release) within the ASPIRE-SOLMAN Focused Build methodology in SAP Solution Manager. Specifies role accountabilities (QA, Validation Lead, Business Analyst, Process Owner, Test Coordinator, Test Engineer, Soluti
Source Documents (1)
Mapped Citations (5)
Roles (9)
Artifacts (11)
CSV Implementation Lifecycle
System Lifecycle Management
ID: P020
End-to-end process for implementing and validating a GxP computerized system, covering validation approach definition through release to production and inventory registration. Defined in sop031553 sections 10.1 through 10.16, supporting waterfall, agile, and hybrid delivery methodologies.
Source Documents (1)
Mapped Citations (69)
- 16.1 Establish and Maintain a Secure Application Development...
- 16.8 Separate Production and Non-Production Systems
- 3.12 Segment Data Processing and Storage Based on Sensitivit...
- 3.8 Document Data Flows
- 4.8 Uninstall or Disable Unnecessary Services on Enterprise ...
- AIS-01 Application and Interface Security Policy and Procedu...
- AIS-02 Application Security Baseline Requirements
- AIS-04 Secure Application Design and Development
- AIS-05 Automated Application Security Testing
- AIS-06 Automated Secure Application Deployment
- AS.164.308.a7-i
- Application Software Security
- Application security requirements
- Apply Static and Dynamic Code Analysis Tools
- Business Continuity
- CCC-02 Quality Testing
- CS Inventory
- CT.DM-P8
- CT.DM-P9
- CT.PO-P4
- Create Test Bed for Elements Not Typically Tested in Product...
- DL-2.B.1
- DSP-05 Data Flow Documentation
- DSP-07 Data Protection by Design and Default
- Documented operating procedures
- Electronic Records (Audit trail)
- Electronic Records (Data Review)
- Electronic Signature
- Ensure Explicit Error Checking is Performed for All In-house...
- Establish Secure Coding Practices
- GV.OC-03
- GV.OC-04
- GV.PO-P2
- GV.PO-P5
- ID.AM-03
- ID.AM-08
- ID.IM-P7
- IVS-05 Production and Non-Production Environments
- IVS-08 Network Architecture Documentation
- Information security in project management
- Inventory of information and other associated assets
- Legal, statutory, regulatory and contractual requirements
- Operational Checks
- Outsourced development
- PR.DS-P7
- PR.PO-P7
- PR.PS-06
- PR.PT-P2
- PR.PT-P4
- Qualified Test Environment
- Secure coding
- Secure development life cycle
- Secure system architecture and engineering principles
- Security testing in development and acceptance
- Separate Production and Non-Production Systems
- Separation Of development, test and production environments
- System Description
- System Performance
- Test Evidences
- Test information
- Testing Tools Validation
- Time-stamped Audit Trails
- Traceability
- Use Standard Hardening Configuration Templates for Databases
- User requirement specifications
- Validation
- Validation Approach
- Validation Documentation (Planning and Reporting)
- Validation of Systems
Artifacts (12)
- A037 Computerised Systems Inventory
- A043 Configuration Specifications
- A064 Design Specifications
- A079 Functional Specifications
- A087 Implementation Risk Assessment
- A091 Infrastructure Qualification Documentation
- A137 Requirements Specifications
- A151 System Description
- A166 Test Summary Report
- A168 Traceability Matrix
- A177 Validation Plan
- A179 Validation Summary Report
CSV Periodic Review
System Lifecycle Management
ID: P021
The CSV Periodic Review process defined in SOP-0107426 verifies whether GxP computerized systems and IT Infrastructure platforms remain in a validated or qualified state. It covers planning and scheduling, executing structured verification checks across defined areas, reporting results in a formal r
Source Documents (2)
Mapped Citations (12)
Data Archival
System Lifecycle Management
ID: P032
Covers the controlled process of moving regulated data from an operational computerized system to a long-term repository as defined in sop031555. The Process Owner is accountable for ensuring archived data is accessible, retrievable in human-readable format, and integrity-maintained throughout the r
Source Documents (1)
Mapped Citations (23)
- 11.3 Protect Recovery Data
- 3.1 Establish and Maintain a Data Management Process
- 3.10 Encrypt Sensitive Data in Transit
- 3.11 Encrypt Sensitive Data at Rest
- 3.4 Enforce Data Retention
- 8.10 Retain Audit Logs
- Ability to Generate Copies
- Archiving
- Audit Log Retention
- CT.PO-P2
- DL.2.A.1
- DSP-16 Data Retention and Deletion
- Electronic Records (Security and Access Management)
- Encrypt Sensitive Information at Rest
- PP.164.316.b2-i
- PP.164.316.b2-ii
- PR.DS-01
- PR.DS-P1
- PR.DS-P3
- PR.DS-P6
- Protection of records
- Protection/Retention
- Remove Sensitive Data or Systems Not Regularly Accessed by O...
Roles (2)
Data Certification Execution
System Lifecycle Management
ID: P033
Defines the procedure for processing Data Certification Tasks in ServiceNow to periodically verify and validate the accuracy of Business Application compliance data, as described in WI-0301164. Certifiers receive task notifications, review and correct Business Application fields, and formally attest
Data Migration
System Lifecycle Management
ID: P035
Process for migrating data between computerized systems, covering planning, risk assessment, tool qualification, execution, verification, and reporting. Initiated as part of an implementation project or via change management. Defined in sop031553 Appendix C.
Source Documents (1)
Mapped Citations (9)
Artifacts (2)
IT Infrastructure Maintenance
System Lifecycle Management
ID: P046
Maintains IT infrastructure components, solutions, and platforms in a qualified state during productive use. Covers technical maintenance, IaC code migration, and periodic review activities as defined in SOP-0303080.
Source Documents (1)
Mapped Citations (29)
- 12.1 Ensure Network Infrastructure is Up-to-Date
- 4.6 Securely Manage Enterprise Assets and Software
- 7.1 Establish and Maintain a Vulnerability Management Proces...
- 7.3 Perform Automated Operating System Patch Management
- 7.4 Perform Automated Application Patch Management
- 7.5 Perform Automated Vulnerability Scans of Internal Enterp...
- 7.7 Remediate Detected Vulnerabilities
- 9.1 Ensure Use of Only Fully Supported Browsers and Email Cl...
- AS.164.308.a5-ii-b
- Address unapproved software
- Capacity management
- Compare Back-to-back Vulnerability Scans
- Continuous Vulnerability Management
- Deploy Automated Operating System Patch Management Tools
- Deploy Automated Software Patch Management Tools
- Documented operating procedures
- Ensure Anti-Malware Software and Signatures are Updated
- Equipment maintenance
- ICT readiness for business continuity
- Install the Latest Stable Version of Any Security-related Up...
- Malware Defenses
- Management of technical vulnerabilities
- OS-1.A.3
- PR.DS-P4
- PR.MA-P1
- PR.MA-P2
- PR.PS-02
- PR.PS-03
- PS.164.310.a2-iv
IT Infrastructure Qualification Implementation
System Lifecycle Management
ID: P047
Implements the qualification lifecycle for IT infrastructure components, solutions, and platforms supporting GxP processes. Covers planning through deployment with tailored approaches for manual and IaC delivery methods as defined in SOP-0303080.
Source Documents (1)
Mapped Citations (33)
- 12.2 Establish and Maintain a Secure Network Architecture
- 12.4 Establish and Maintain Architecture Diagram(s)
- 4.8 Uninstall or Disable Unnecessary Services on Enterprise ...
- Application security requirements
- Change Default Passwords
- Ensure Only Approved Ports, Protocols and Services Are Runni...
- Establish Secure Configurations
- ID.RA-09
- IVS-05 Production and Non-Production Environments
- IVS-08 Network Architecture Documentation
- Infrastructure Baselines
- Infrastructure Qualification
- Installation of software on operational systems
- Maintain Secure Images
- Maintain Standard Security Configurations for Network Device...
- OS-1.A.5
- PR.AC-P5
- PR.DS-P2
- PR.DS-P7
- PR.DS-P8
- PR.IR-02
- PR.IR-03
- PR.IR-04
- PR.PO-P1
- PR.PT-P2
- PR.PT-P3
- PR.PT-P4
- Physically or Logically Segregate High Risk Applications
- Secure system architecture and engineering principles
- Segment the Network Based on Sensitivity
- Separate Production and Non-Production Systems
- Separation Of development, test and production environments
- Validation
Artifacts (10)
- A012 Architecture Landscape Documentation
- A094 Installation Verification Protocol
- A106 Operational Support Plan
- A124 Qualification Plan
- A125 Qualification Protocol
- A126 Qualification Registry
- A127 Qualification Summary Report
- A157 Technical Requirement Specification
- A161 Test Plan and Strategy
- A167 Testing Summary Report
IT Infrastructure Retirement
System Lifecycle Management
ID: P048
Retires IT infrastructure components, solutions, and platforms through controlled data archival, decommissioning, and disposal activities triggered through change management as defined in SOP-0303080.
Source Documents (1)
Mapped Citations (16)
- 15.7 Securely Decommission Service Providers
- 3.4 Enforce Data Retention
- 3.5 Securely Dispose of Data
- CT.DM-P5
- DL.2.A.1
- DSP-02 Secure Disposal
- DSP-16 Data Retention and Deletion
- Information deletion
- PP.164.316.b2-i
- PR.DS-P3
- PR.PS-03
- PS.164.310.d1
- PS.164.310.d2-i
- PS.164.310.d2-ii
- Remove Sensitive Data or Systems Not Regularly Accessed by O...
- Secure disposal or re-use Of equipment
Roles (1)
Periodic Review of GxP Computerised Systems in ServiceNow IRM
System Lifecycle Management
ID: P060
This process (WI-0300929) defines the end-to-end execution of Periodic Reviews for GxP-relevant Computerised Systems using ServiceNow IRM Engagements. It covers planning, fieldwork (control testing), issue creation, approval, and closure, with automated steps triggered by the CS Inventory master dat
Source Documents (1)
Mapped Citations (1)
System Backup and Restore
System Lifecycle Management
ID: P068
Ensures regular backup of CS software, configuration, and operational data with periodic log review and restoration testing to guarantee data recovery capability. System Owner is accountable for the entire backup and restore process per SOP-0109167.
Source Documents (1)
Mapped Citations (38)
- 11.1 Establish and Maintain a Data Recovery Process
- 11.2 Perform Automated Backups
- 11.5 Test Data Recovery
- 3.11 Encrypt Sensitive Data at Rest
- 8.11 Conduct Audit Log Reviews
- AS.164.308.a7-i
- AS.164.308.a7-ii-a
- AS.164.308.a7-ii-b
- AS.164.308.a7-ii-d
- Ability to Generate Copies
- BCR-08 Backup
- Backup and Restore
- Business Continuity
- Data Recovery Capabilities
- Electronic Records (Security and Access Management)
- Ensure Backups Have At least One Non-Continuously Addressabl...
- Ensure Protection of Backups
- Ensure Regular Automated Back Ups
- ICT readiness for business continuity
- Information backup
- Information security during disruption
- PR.DS-11
- PR.DS-P1
- PR.DS-P4
- PR.IR-03
- PR.PO-P3
- PR.PO-P8
- PR.PS-04
- PR.PT-P4
- PS.164.310.a2-i
- PS.164.310.d2-iv
- Perform Complete System Backups
- Protection of records
- Protection/Retention
- RC.RP-03
- RC.RP-05
- Regularly Review Logs
- Test Data on Backup Media
Roles (1)
Artifacts (1)