This is well thought out. I am going to hold on to this in case I ever get raked over the coals by some auditor regarding this issue. Greg Ventura ... From:...
Let me start off by saying that within my own company we sometimes have the test script writer execute the test script. We try not to because we do believe...
One additional comment I would like to add is that requiring the writer and executor to be different people does not allow you to use testing methods like...
We all have processes that require several signature rounds from beginning to end. It is time consuming and inefficient. Is it conceivable that you use a BPM...
<snip> Is it conceivable that you use a BPM and/or a document routing system where, instead of capturing hand signatures Serge Jonnaert </snip> Short answer -...
The standard at most companies I have worked at is a document management system where documents are routed and approved all electronically. If you are using...
Serge At ClinPhone, we use some software called CoSign which digitally signs the document so we can capture signatures from people in UK, US and working from...
Sims, Fraser
fsims@...
Sep 5, 2006 2:16 pm
15896
The key point here is that Part 11 is not a validation requirement but it is a design requirement to provide information security for those electronics records...
I would like to exchange thoughts with other interested people on the idea that Sarbanes-Oxley (SOX) Section 404 compliance for IT systems also meets the FDA...
I'd like to get some feedback on whether or not it's acceptable to have a seperate E-signature password than a user's log in password. Our software utilizes...
Short answer: Not only is that acceptable, but some organizations prefer it. Mark ________________________________ From: 21cfrpart11@yahoogroups.com...
Hello, Can anyone tell me what additional work needs to be done to validate a web based, or open, application compared to a closed application? Also, the same...
My organization – eSign Consulting, represents, and works with several companies in the e-signature space. Utilizing fully integrated components, Documents...
Here are two considerations: 1. 21 CFR Part 11.10, 11.50, 11.100, 11.200 and 11.300 provide the regulatory guidance for e-signatures relative to this topic,...
Can anyone point me to a sample (or actual) company policy on Part 11, please ? Thanks, Ned Harris Align Technology Santa Clara, Calif. ...
Ned Harris
nharris@...
Sep 6, 2006 2:13 am
15905
We do encompass both of these regulations in our compliance approach, for the obvious reasons given below. These are still two distinct assessment forms as the...
Schmitt, Siegfried (G...
siegfried.schmitt@...
Sep 6, 2006 1:26 pm
15906
Hi, The SOX regulations regarding the IT are very similar to those imposed on pharma companies by Part 11 (of course in regards to ER). We found out that basic...
Ron Baruchi
ron.baruchi@...
Sep 11, 2006 7:55 pm
15907
My immediate thoughts are: 1) I hope you are getting two tokens (not just the different password clause 11.200 a)) 2) How do you manage password aging? (11.300...
Sims, Fraser
fsims@...
Sep 11, 2006 7:56 pm
15908
Yes, you need additional validation steps, as per my philosophy....
No where in Part 11 does it state that passwords for esigs and logon must be the same. In fact, this would act as a second layer of protection in my eyes. If...
I will add my two bits worth here. I agree completely with Paul Motise, that you need to identify what is needed to achived the security of information...
Just because an application is on the web doesn't mean its open. An open system means an environment where system access is not controlled such as a public...
If there are any additional desktop requirements of the application that are required (e.g., IE settings), they should be verified on the users' desktop....
Kari Habeck
kari_viking@...
Sep 12, 2006 8:05 pm
15916
We develop software that can run in a validated environment. As standard documentation, we provide the IQ and OQ docs to customers, but do not provide or write...
Hi Dawn, A PQ, in general, is a "day in the life" of the computer application. It tests the User Requirements. As such, is strongly dependent on what the...