21 CFR Part 11 Flashcards
What does 21 CFR Part 11 cover?
Electronic Records; Electronic Signatures
What is a closed system?
An environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system.
What is an open system?
An environment in which system access is NOT controlled by persons who are responsible for the content of electronic records that are on the system.
What is a digital signature?
It is an electronic signature based on cryptographic methods of originator authentication, computer by using a set of rules and set of parameters such that the identity of the signer and the integrity of the data can be verified.
What is an electronic signature?
it is a computer data compilation of any symbol or series of symbols executed, adopted, or digital form that is created, modified, maintained, archived, retrieved, or distributed by a computer system.
What is a handwritten signature?
a scripted name or legal mark of an individual handwritten by that individual and executed or adopted with the present intention to authenticate a writing in a permanent form.
What does biometrics mean?
it is a method of verifying an individual’s identity based on measurement of the individual’s physical features or repeatable actions where those features and/or actions are both unique to that individual and measurable.
Act means…
The Federal Food, Drug, and Cosmetic Act
Agency means…
Food and Drug Administration
General Requirements for electronic signatures are…
1) Each electronic signature should be unique & shall not be reused or reassigned to anyone else.
2) Before the organization certifies the signature they have to verify the identity of the individual.
3) Persons shall certify that electronic signatures used after 20AUG1997 are legally binding.
Electronic signatures NOT based on biometrics shall
1) employ at least two distinct identification components (ID code and password).
2) be used only by genuine owners.
3) attempted use of the signature by anyone other than its genuine owner requires collaboration of two or more individuals.
Electronic signatures that ARE based on biometrics shall
be designed to ensure that they cannot be used by anyone other than their genuine owner.
Controls for ID codes and passwords shall include these 5 components:
1) maintain the uniqueness of each ID code and pw
2) Ensure that the ID code and pw issuances are periodically checked, recalled, or revised.
3) Following loss management procedures to electronically deauthorize lose, stolen, missing or otherwise potentially compromised tokens, cards, and other devices.
4) use of transaction safeguards to prevent unauthorized use of pws and/or ID codes
5) initial and periodic testing of devices that bear or generate id code or pw info.
Signed electronic records shall include the following:
1) The printed name of the signer
2) The date and time when the signature was executed
3) The meaning (such as review, approval, responsibility, or authorship) associated with the signature