Sei sulla pagina 1di 14

21 CFR Chapter 11 with Exact Globe

Exact Solutions for Regulatory Compliance

Author: Pieter Hamans


Date: October 2010

[Exact Globe is implemented at pharmaceutical and veterinary companies world-wide.


This white paper demonstrates how Exact Globe contributes to 21 CFR Chapter 11
compliance with such companies. Exact Globe is a solution of Exact. www.exact.com]

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
Title 21 CFR Chapter 11 Compliance with the Exact Globe Solution

Title 21 CFR Chapter 11 of the Code of Federal Regulations (CFR) deals with the Food
and Drug Administration (FDA) guidelines on electronic records and electronic signatures
for the life science industry in the USA. These guidelines have served as a model for
regulations in other jurisdictions and many elements can be found back in the rules for
(European) Good Manufacturing Practice (GMP) and the (currently: 37 members)
Pharmaceutical Inspection Convention (PIC/S). Title 21 CFR Chapter 11 describes how
electronic records and electronic signatures can be used as a substitute for paper records
and handwritten signatures. The Title 21 CFR Chapter 11 rules apply to drug makers,
medical equipment manufacturers, biotech companies and other FDA regulated
companies.

What are electronic records?

According to the FDA, an “electronic record means any combination of text, graphics,
data, audio, pictorial, or other information representation in digital form that is created,
modified, maintained, archived, retrieved, or distributed by a computer system.” Not all
electronic records are subject to 21 CFR Chapter 11, only those that are maintained in
accordance with FDA published predicate rules.
These rulings, such as the Good Laboratory Practice (GLP) and Current Good
Manufacturing Practice (CGMP), mandate what records must be maintained, what needs
to be contained in the record, whether signatures are required and how long records
must be maintained.

What is an electronic signature?

Electronic signatures are intended to be binding digital equivalents of handwritten


signatures. The FDA states that an “electronic signature is a computer data compilation
of any symbol or series of symbols executed, adopted, or authorized by an individual to
be the legally binding equivalent of the individual’s handwritten signature.” It is
important to note the FDA does not equate an electronic signature with a digital
signature, such as those provided by commercial entities VeriSign, Entrust, etc. FDA
predicate rules specify which electronic records require signatures, electronic or
otherwise. If signatures are necessary, and they are collected electronically, then
compliance with 21 CFR Chapter 11 is mandatory.

How does this ruling impact on the use of Exact Globe?

Ultimately, it is the life science industry that has to comply with 21 CFR Chapter 11 and
not the software manufacturer or its product. Therefore, there is no certification
guideline or certifying institute for software products. Moreover, the guidelines also deal
with the issuance and physical protection of passwords or the requirement that users be
adequately trained, which is all in the organizational realm. This white paper serves to
demonstrate where Exact Globe reinforces the compliance with 21 CFR Chapter 11, but
this white paper is not a proof that compliance is or will be achieved by using Exact
Globe.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
Subpart A: General Provisions

21 CFR 11.1 - Scope Exact Globe Compliance


(a) The regulations in this part set forth Exact Globe supports electronic signatures
the criteria under which the agency by positively identifying the user through a
considers electronic records, electronic unique username and password
signatures, and handwritten signatures combination. This information is used for
executed to electronic records to be the login to the network domain or active
trustworthy, reliable, and generally directory. When a database connection is
equivalent to paper records and made to SQL Server, integrated security
handwritten signatures executed on paper. (Windows Authentication) is enforced.
(b) This part applies to records in acknowledged
electronic form that are created, modified,
maintained, archived, retrieved, or
transmitted, under any records
requirements set forth in agency
regulations. This part also applies to
electronic records submitted to the agency
under requirements of the Federal Food,
Drug, and Cosmetic Act and the Public
Health Service Act, even if such records
are not specifically identified in agency
regulations. However, this part does not
apply to paper records that are, or have
been, transmitted by electronic means.
(c) Where electronic signatures and their Exact Globe supports electronic signatures
associated electronic records meet the by positively identifying the user through a
requirements of this part, the agency will unique username and password
consider the electronic signatures to be combination.
equivalent to full handwritten signatures,
initials, and other general signings as
required by agency regulations, unless
specifically accepted by regulation(s)
effective on or after August 20, 1997.
(d) Electronic records that meet the acknowledged
requirements of this part may be used in
lieu of paper records, in accordance with
Sec. 11.2, unless paper records are
specifically required.
(e) Computer systems (including hardware acknowledged
and software), controls, and attendant
documentation maintained under this part
shall be readily available for, and subject
to, FDA inspection.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
21 CFR 11.2 - Implementation Exact Globe Compliance
(a) For records required to be maintained, acknowledged
but not submitted to the agency, persons
may use electronic records in lieu of paper
records or electronic signatures in lieu of
traditional signatures, in whole or in part,
provided that the requirements of this part
are met.
(b) For records submitted to the agency, acknowledged
persons may use electronic records in lieu
of paper records or electronic signatures in
lieu of traditional signatures, in whole or in
part, provided that:
(1) The requirements of this part are met; acknowledged
and
(2) The document or parts of a document Acknowledged
to be submitted have been identified in
public docket No. 92S-0251 as being the
type of submission the agency accepts in
electronic form. This docket will identify
specifically what types of documents or
parts of documents are acceptable for
submission in electronic form without
paper records and the agency receiving
unit(s) (e.g., specific center, office,
division, branch) to which such
submissions may be made. Documents to
agency receiving unit(s) not specified in
the public docket will not be considered as
official if they are submitted in electronic
form; paper forms of such documents will
be considered as official and must
accompany any electronic records. Persons
are expected to consult with the intended
agency receiving unit for details on how
(e.g., method of transmission, media, file
formats, and technical protocols) and
whether to proceed with the electronic
submission.

21 CFR 11.3 – General Provisions Exact Globe Compliance


(a) The definitions and interpretations of Acknowledged
terms contained in section 201 of the act
apply to those terms when used in this
part.
(b) The following definitions of terms also Acknowledged
apply to this part:
(1) Act means the Federal Food, Drug, and Acknowledged
Cosmetic Act (sections 201-903 (21 U.S.C.
321-393)).
(2) Agency means the Food and Drug Acknowledged
Administration.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(3) Biometrics means a method of verifying The use of biometrics is not currently
an individual’s identity based on supported by Exact Globe.
measurement of the individual’s physical
feature(s) or repeatable action(s) where
those features and/or actions are both
unique to that individual and measurable.
(4) Closed system means an environment Exact Globe is configured as a closed
in which system access is controlled by system.
persons who are responsible for the
content of electronic records that are on
the system.
(5) Digital signature means an electronic Exact Globe uses the Windows login
signature based upon cryptographic settings for the network domain or active
methods of originator authentication, directory that uniquely identifies the user
computed by using a set of rules and a set from their username and password
of parameters such that the identity of the combination. The internal user rights and
signer and the integrity of the data can be roles in Exact Globe determine the access
verified and privileges of the signed in user.
(6) Electronic record means any Acknowledged
combination of text, graphics, data, audio,
pictorial, or other information
representation in digital form that is
created, modified, maintained, archived,
retrieved, or distributed by a computer
system.
(7) Electronic signature means a computer Exact Globe supports electronic signatures
data compilation of any symbol or series of by positively identifying the user through a
symbols executed, adopted, or authorized unique username and password
by an individual to be the legally binding combination.
equivalent of the individual’s handwritten
signature.
(8) Handwritten signature means the The use of biometrics is not currently
scripted name or legal mark of an supported by Exact Globe.
individual handwritten by that individual
and executed or adopted with the present
intention to authenticate in writing in a
permanent form. The act of signing with a
writing or marking instrument such as a
pen or stylus is preserved. The scripted
name or legal mark, while conventionally
applied to paper, may also be applied to
other devices that capture the name or
mark
(9) Open system means an environment in Exact Globe is configured as a closed
which system access is not controlled by system.
persons who are responsible for the
content of electronic records that are on
the system.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
Subpart B: Electronic Records

The FDA distinguishes between open and closed systems. Closed systems are those
where access is controlled by persons who are responsible for the content of electronic
records on the system. Open systems are accessible by those who are not directly
responsible for the electronic records on the system.

(figure 1)

21 CFR 11.10 – Controls for Closed Exact Globe Compliance


Systems
Persons who use closed systems to create, Because Exact Globe manages access to
modify, maintain, or transmit electronic the database with integrated security
records shall employ procedures and (Windows Authentication) and requires a
controls designed to ensure the unique username and password
authenticity, integrity, and, when combination, the administrator can set up
appropriate, the confidentiality of a closed system in which access is limited
electronic records, and to ensure that the internally to the database.
signer cannot readily repudiate the signed
record as not genuine. Such procedures
and controls shall include the following:
(a) Validation of systems to ensure Exact Globe can be configured as a closed
accuracy, reliability, consistent intended system with an audit trail. The organization
performance, and the ability to discern can use the audit trail to discern between
invalid or altered records. valid and invalid records.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(b) The ability to generate accurate and Exact Globe reports include who made
complete copies of records in both human changes, when they made them, and the
readable and electronic form suitable for type of change. Changes are date/time-
inspection, review, and copying by the stamped. Change comments are included.
agency. Persons should contact the agency A verbose log file can be enabled to
if there are any questions regarding the capture the full detail and history of any
ability of the agency to perform such changes to records.
review and copying of the electronic The full record history can be tracked and
records. reassembled from this log. These reports
can be distributed in paper or electronic
form.
(c) Protection of records to enable their The assignment of rights and roles within
accurate and ready retrieval throughout Exact Globe gives complete control over
the records retention period. which users can complete specified actions
under use. The organization is ultimately
responsible for backing up and protecting
the records. (figure 1)
(d) Limiting system access to authorized Exact Globe applies individual rights and
individuals. roles set by the system administrator to
regulate access to menus and data.
(e) Use of secure, computer-generated, Exact Globe maintains a distinct audit trail
time-stamped audit trails to independently that can retained indefinitely. A verbose
record the date and time of operator log file can be enabled to capture the full
entries and actions that create, modify, or detail and history of any changes to
delete electronic records. Record changes records.
shall not obscure previously recorded
information. Such audit trail documentation
shall be retained for a period at least as
long as that required for the subject
electronic records and shall be available for
agency review and copying.
(f) Use of operational system checks to The ability to complete any given action is
enforce permitted sequencing of steps and controlled by individually assigned roles
events, as appropriate. and rights and is under the control of the
administrator to set what permissions are
allowed to what users to make what
changes at any given point in the process.
The configurable workflow allows
administrators to set up a workflow that is
appropriate for the process being
managed. The history of actions completed
within Exact Globe contains timestamp
information for when the action was
completed and by what user, showing the
sequence in which actions occurred. The
organization is ultimately responsible for
enforcing proper sequencing of steps and
events.
(g) Use of authority checks to ensure that Exact Globe uniquely identifies the user
only authorized individuals can use the from their username and password
system, electronically sign a record, access combination. The individually assigned
the operation or computer system input or roles and rights determine the access and
output device, alter a record, or perform privileges of the logged in user.
the operation at hand.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(h) Use of device (e.g., terminal) checks to The administrator of Exact Globe can
determine, as appropriate, the validity of enforce additional identification of each
the source of data input or operational device by enforcing a check of the MAC
instruction. address of each connecting client against a
permitted MAC address.
(i) Determination that persons who Access is controlled via usernames and
develop, maintain, or use electronic passwords assigned to those individuals
record/electronic signature systems have deemed appropriate. The organization is
the education, training, and experience to ultimately responsible for this requirement.
perform their assigned tasks.
(j) The establishment of, and adherence to, The organization is ultimately responsible
written policies that hold individuals for this requirement.
accountable and responsible for actions
initiated under their electronic signatures,
in order to deter record and signature
falsification.
(k) Use of appropriate controls over acknowledged
systems documentation including:
(1) Adequate controls over the distribution There is online help and documentation. It
of, access to, and use of documentation for is recommended that the organization
system operation and maintenance. maintains customized user guides that
reflect the specific workflows and settings
of the organization and access patterns of
the predefined user roles. The organization
is ultimately responsible for that
requirement.
(2) Revision and change control procedures The organization is ultimately responsible
to maintain an audit trail that documents for this requirement.
time-sequenced development and
modification of systems documentation.

21 CFR 11.30 – Controls for Open Exact Globe Compliance


Systems
Persons who use open systems to create, Exact Globe can be configured with Exact
modify, maintain, or transmit electronic Synergy or Exact Synergy Enterprise to
records shall employ procedures and provide for a customer portal and/or
controls designed to ensure the supplier portal access. Through the use of
authenticity, integrity, and, as appropriate, the username and password combination
the confidentiality of electronic records and regulated access rights the
from the point of their creation to the point administrator has the ability to secure the
of their receipt. Such procedures and system as required for compliance.
controls shall include those identified in
Sec. 11.10, as appropriate and additional
measures such as document encryption
and use of appropriate digital signature
standards to ensure, as necessary under
the circumstances, record authenticity,
integrity, and confidentiality.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(figure 2)

21 CFR 11.50 – Signature Exact Globe Compliance


Manifestations
(a) Signed electronic records shall contain Exact Globe uses the username and
information associated with the signing password combination to uniquely identify
that clearly indicates all of the following: the logged in user.
(1) The printed name of the signer; The name of the signer is displayed, (figure
2)
(2) The date and time when the signature and a date and timestamp are contained in
was executed; the history. (figure 2)
(3) The meaning (such as review, A description of the action is provided.
approval, responsibility, or authorship) (figure 2)
associated with the signature.
(b) The items identified in paragraphs Acknowledged
(a)(1), (a)(2), and (a)(3) of this section
shall be subject to the same controls as for
electronic records and shall be included as
part of any human readable form of the
electronic record (such as electronic
display or printout).

21 CFR 11.70 – Signatures/Record Exact Globe Compliance


Linking
Electronic signatures and handwritten The history of any action performed in
signatures executed to electronic records Exact Globe is not modifiable and contains
shall be linked to their respective electronic the details of the action taken as well as a
records to ensure that the signatures timestamp and the user who performed the
cannot be excised, copied, or otherwise action. A verbose log can be enabled to
transferred to falsify an electronic record capture the full history of any committed
by ordinary means. changes.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
Subpart C: General Provisions

21 CFR 11.100 – General Exact Globe Compliance


Requirements
(a) Each electronic signature shall be The unique username and password
unique to one individual and shall not be combination required by Exact Globe
reused by, or reassigned to, anyone else. ensures the user is authenticated when
logging in. All records created by a user
are permanently linked to the creator’s
unique username. The administrator can
configure the system so that passwords
cannot be reused.
(b) Before an organization establishes, The administrator is responsible for
assigns, certifies, or otherwise sanctions an verifying that each user entered into the
individual’s electronic signature, or any system is properly identified before
element of such electronic signature, the entering a unique username and password
organization shall verify the identity of the combination for said user.
individual. Administrators can set strong passwords
rules in the network domain or active
directory server that are applied
universally, including the ability to enforce
a minimum password length, minimum
number of letter characters, numeric
characters, and minimum number of non-
alphanumeric characters in a password.
Passwords can be restricted so they cannot
be set to the user’s username, first name,
or last name. Passwords can optionally
expire in “x” days.
All records created by a user are
permanently linked to the creator’s unique
username.
The organization is ultimately responsible
for this requirement.
(c) Persons using electronic signatures The organization is ultimately responsible
shall, prior to or at the time of such use, for this requirement.
certify to the agency that the electronic
signatures in their system, used on or after
August 20, 1997, are intended to be the
legally binding equivalent of traditional
handwritten signatures.
(1) The certification shall be submitted in The organization is ultimately responsible
paper form and signed with a traditional for this requirement.
handwritten signature, to the Office of
Regional Operations (HFC-100), 5600
Fishers Lane, Rockville, MD 20857.
(2) Persons using electronic signatures The organization is ultimately responsible
shall, upon agency request, provide for this requirement.
additional certification or testimony that a
specific electronic signature is the legally
binding equivalent of the signer’s
handwritten signature.

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(figure 3)

21 CFR 11.200 – Electronic Signature Exact Globe Compliance


Components and Controls
(a) Electronic signatures that are not based Exact Globe uses the user name and
upon biometrics shall: password combination to uniquely identify
the user logging into the system. Privileges
and access to actions is controlled by roles
and rights applied to the user. The roles to
which the user belongs are determined by
an administrator who has appropriate
security access to manage such roles.
Users can be members of multiple roles in
Exact Globe. Roles control the level of
access for all users in that role. (figure 3)
(1) Employ at least two distinct Exact Globe uses a username and
identification components such as an password combination to identify the
identification code and password. logged in user.

10

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(i) When an individual executes a series of Exact Globe requires the user initiate a
signings during a single, continuous period continuous period of controlled system
of controlled system access, the first access with a username and password
signing shall be executed using all combination. Each action that the
electronic signature components; individual executes within this period
subsequent signings shall be executed creates a historical record that contains
using at least one electronic signature information about the action and user.
component that is only executable by, and
designed to be used only by, the individual.
(ii) When an individual executes one or Exact Globe requires the user initiate a
more signings not performed during a continuous period of controlled system
single, continuous period of controlled access with a username and password
system access, each signing shall be combination. Each action that the
executed using all of the electronic individual executes within this period
signature components. creates a historical record that contains
information about the action and user.
(2) Be used only by their genuine owners; The organization is ultimately responsible
and for this requirement.
(3) Be administered and executed to This is a procedural issue since the
ensure that attempted use of an “Administrator” user has the ability to
individual’s electronic signature by anyone manage and maintain all users and
other than its genuine owner requires passwords. The “Administrator” user can
collaboration of two or more individuals. change any user’s password if necessary.
(b) Electronic signatures based upon The use of biometrics is not currently
biometrics shall be designed to ensure that supported by Exact Globe. A unique
they cannot be used by anyone other than username and password combination is
their genuine owners. required that identifies the individual
logged in and completing actions.
Administrators can set strong passwords
rules in the network domain or active
directory server that are applied
universally, including the ability enforce a
minimum password length, minimum
number of letter characters, numeric
characters, and minimum number of non-
alphanumeric characters in a password.
Passwords can be restricted so they cannot
be set to the user’s username, first name
or last name. Passwords can optionally
expire in “x” days. LDAP can be used
instead of these features to centrally
manage users.
All records created by a user are
permanently linked to the creators unique
user name.

21 CFR 11.300 – Controls for Exact Globe Compliance


Identification Codes/Passwords
Persons who use electronic signatures Exact Globe requires that a named user
based upon use of identification codes in logs into the application. Administrators
combination with passwords shall employ can set strong passwords rules in the
controls to ensure their security and network domain or active directory server
integrity. Such controls shall include: that are applied universally.

11

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
(a) Maintaining the uniqueness of each Exact Globe uses a username and
combined identification code and password, password to uniquely identify the person
such that no two individuals have the same logged into the system. The password is
combination of identification code and not required by default but can be
password. enforced. Usernames must be unique and
are not case sensitive. All records created
by a user are permanently linked to the
user’s unique username.
(b) Ensuring that identification code and Administrators can set strong passwords
password issuances are periodically rules in the network domain or active
checked, recalled, or revised (e.g., to cover directory server that are applied
such events as password aging). universally.
(c) Following loss management procedures Exact Globe does not use tokens, cards, or
to electronically de-authorize lost, stolen, other devices at this time.
missing, or otherwise potentially
compromised tokens, cards, and other
devices that bear or generate identification
code or password information, and to issue
temporary or permanent replacements
using suitable, rigorous controls.
(d) Use of transaction safeguards to Exact Globe is a true client/server
prevent unauthorized use of passwords application that is accessed through a local
and/or identification codes, and to detect area network. Intruders would first have to
and report in an immediate and urgent have access to the network and then to the
manner any attempts at their unauthorized specific (database) server. Security is
use to the system security unit, and, as further enhanced as users are validated
appropriate, to organizational with a unique username and password
management. combination. In addition before the user is
logged in they must receive authorization
from the license server. Failed login
attempts are recorded. Administrators can
set strong password rules in the network
domain or active directory server that are
applied universally.
(e) Initial and periodic testing of devices, Exact Globe does not use tokens, cards, or
such as tokens or cards, that bear or other devices at this time.
generate identification code or password
information to ensure that they function
properly and have not been altered in an
unauthorized manner.

12

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)
Exact. And it all comes together.

We started serving the entrepreneurial world in 1984. We have


grown from a student start-up to a global solution provider and
have been listed on the NYSE Euronext Amsterdam since June
1999. Our entrepreneurial roots constantly remind us that adding
value for our customers is what we are here for.
With employees spread across subsidiaries in 40 countries we
serve local and international companies in more than 125 countries
and provide our solutions in more than 40 languages.

Serving entrepreneurial businesses is at the heart of what we do.


We understand their mindsets, how they collaborate within their
business community and the structure they need to achieve results.
With this knowledge we provide software solutions that support
every business activity and give real-time insight into the entire
business. This gives our customers the freedom to successfully
address challenges and opportunities, creating value for their
customers and ultimately for themselves.

www.exact.com

The information contained in this document represents the current view of Exact on the issues discussed as of
the date of publication. Because Exact must respond to changing market conditions, this document should not
be interpreted to be a commitment on the part of Exact, and Exact cannot guarantee the accuracy of any
information presented after the date of publication.

This White Paper is for informational purposes only.

EXACT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS


DOCUMENT.

Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under
copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or
transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or
for any purpose, without the express written permission of Exact.
Exact may have patents, patent applications, trademarks, copyrights, or other intellectual property rights
covering subject matter in this document. Except as expressly provided in any written license agreement from
Exact, the furnishing of this document does not give you any license to these patents, trademarks, copyrights,
or other intellectual property.

Copyright 2010 Exact Holding NV. All rights reserved.


Exact, Exact Software, the Exact logo, Exact Globe, Exact Synergy and Exact Synergy Enterprise are either
registered trademarks or trademarks of Exact Holding NV in the Netherlands and/or other countries.

13

Create PDF files without this message by purchasing novaPDF printer (http://www.novapdf.com)

Potrebbero piacerti anche