Some companies have the internal resources, although not necessarily trained in the development language/environments that your package is written in. I...
I've seen this come up mostly with encrypt/decrypt functionality that is used by a vendor in their software which manages clinical data on behalf of a...
Dear All below is a set of requirements that you can use to evaluate if the system you are going to buy or already have is capable of meeting 21 CFR Part 11,...
The longer the time you spend in validation, the more things come into the proper perspective. Eventually, you will realize that all of your validation work...
Greg, This is an interesting question. I have direct experience of retrieving and using software that has been escrowed. I worked with an enterprise that had a...
Hi All, New Part 11 Guidance on Scope and Application: Section 3.C.5 Records Retention. Does it state that retention of both forms of data is no longer ...
Hi Paul, Your URS is great, but what do you mean by: URS3.1 The system will have a mechanism that will only allow a single instance of a unique user logon to...
This is where I disagree and agree with Mr. Anderson. We're in the pharma (or biotech) business, not the software business. Now before everyone jumps in, I'm...
I was never aware that both forms were required. The intent here is to not obscure/lose information and still be able to read it if it is archived. Greg...
Hi Benjamin URS3.1 means that a user can't have two log-ons that are the same set up in the same system. e.g user1, user1. Now most systems won't let you do...
I've looked through the archives, but did not see this specific question addressed so here goes.... Recently I reviewed a system for part 11 relevancy and it...
<<Eventually, you will realize that all of your validation work is simply some completed binders on a shelf in the library.>> How sad!! A large majority of...
Graham Tinsley
Graham_Tinsley@...
Nov 2, 2004 4:09 pm
12562
Hi Ben, If the guest is read only, has no access to data, and cannot perform any functions then this account cannot really "use" the system. I don't know why...
I am working on LIMS and here is a question out of curiosity: In the web-based LIMS the onw which I am using, a user can open multiple web-pages to access...
Hi, I need validation templates for IQ, OQ, PQ etc. for various types of entities. Are there any vendors or open sources available to get these templates? ...
Following PaulS's post om uniqueness of log-in: When a system lets a user have two open sessions, the "security, integrity and uniqueness of identification"...
Hi, Unless the system contains records that may not be divulged to all persons that may possibly access it (e.g. drug plasma concentrations from blinded...
... When pharma used software is risk assessed as critical to product or patient, the FDA and other regulators dictate that a life cycle validation approach...
Hi Greg, I don't believe the main reason for obtaining source code escrow is to self support in the event of a vendor failure. In fact, there are good reasons...
Being able to use the same account several times to login to a system is not really covered by the regulation. Given the way technology goes, I can see the...
You would still be in compliance if those sessions had an inactivity timer and logged you out after the inactivity period expiration. Multiple browser ...
The first place to start is with the software vendor. If they are selling to this market, they should at least have IQ/OQ templates and procedures and should...
As long as he/she is still logged in, I don't see where it would matter. The only thing that might raise eyebrows is if one were to electronically sign data in...
So are you saying that what is really desired for escrow is the validation documentation? Greg Ventura ... From: albridgeuk [mailto:camcal@...] Sent:...
You are right, it does keep options open. And the example you cite is valid (although I'd hope during the audit of the vendor I'd hope you had determined ...
... not ... What type of data is stored in the system? (Did I miss that in the original posting?) If it's anything that could be considered Protected Health...
I think that if you ever have to pull to software out of escrow, it is a solution... Because the mess has already occurred and after investing big bucks in...
Just a few thoughts, Using commercially developed code that has been widely used by regulated customers has an advantage of being widely 'tested in the...
Web based apps are definately not like thick clients. Http is a stateless protocol there is no way for one session to know about another. The vendor does have...