版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
PAGEPAGE10/Annex11:Computerised11TOC\o"1-2"\h\z\uIntroduction引 Scope范 PersonnelandTraining人员与培 SystemRequirements系统要 Alarms报 QualificationandValidation确认与验 HandlingofData数据处 AuditTrails审计追 PeriodicReviews定期审 Security安 Archiving归 术 Application应用程 Audittrail审计追 Backup备 Changecontrol变更控 Commercialoff-the-shelf现成商用(产品 ComputerisedSystem计算机化系 Configuration配 Customisation定 Infrastructure基础设 Migration迁 Multifactorauthentication(MFA)多因素认证 Operatingsystem操作系 Qualification确 Regulateduser受监管用 Specification规 Testcase测试用 User用 Userrequirementspecifications(URS)用户需求规范 Validation验 Verification确 Reasonsforchanges:TheGMPGDPInspectorsWorkingGroupandthePIC/SCommitteejointlyrecommendedthatthecurrentversionofAnnex11onComputerisedSystemsberevisedtoreflectchangesinregulatoryandmanufacturingenvironments.Therevisedguidelineshouldclarifyrequirementsandexpectationsfromregulatoryauthorities,andremoveambiguityandinconsistencies.变更原因:药品GMP/GDP检查员工作组与PIC/S 对现行《计算机化系统》附录11进行修订,以适应监管环境和生产环境的变化。修订后的指南应IntroductionWithanever-evolvingITlandscape,increaseduseofcloudservices,andintroductionofnewtechnologiesincomputerisedsystemsusedinGMPactivities,thereisagrowingneedforupdatedguidanceonregulatoryrequirements,andforadoptingacommonapproachbetweenmemberstatesoftheEuropeanUnion(EU)andthePharmaceuticalInspectionCo-operationScheme(PIC/S).TheupdatedAnnex11outlinestherequirementsfortheuseofcomputerisedsystemsinGMP-regulatedactivities,therebyensuringproductquality,patientsafetyanddataintegrity.随着信息技术环境的不断发展、云服务使用的日益增多,以及药品GMP活动所用计算机化系统中11GMP监管的活动中使用计算机化系统的要求,进而确保产品质量、患者安全和数据完整性。 Thisannexappliestoalltypesofcomputerisedsystemsusedinthemanufacturingofmedicinalproductsandactivesubstances.PrinciplesLifecyclemanagement.Computerisedsystemsshouldbevalidatedbeforeuseandmaintainedinavalidatedstatethroughouttheirlifecycle.生命周期管理:计算机化系统应在使用前进行验证,并在其QualityRiskManagement.QualityRiskManagement(QRM)shouldbeappliedthroughoutalllifecyclephasesofacomputerisedsystemusedinGMPactivities.Theapproachshouldconsiderthecomplexityofprocesses,thelevelofautomation,andtheimpactonproductquality,patientsafetyanddata质量风险管理:质量风险管理(QualityRiskManagementQRM)GMP活动所用计Alternativepractices.Practiceswhichconstitutealternativestotheactivitiesrequiredinthisdocumentmaybeused,iftheyhavebeenprovenanddocumentedtoprovidethesameorhigherlevelofcontrol替代Dataintegrity.Itiscriticallyimportantthatdatacaptured,analysedandreportedbysystemsusedinGMPactivitiesaretrustworthy.AsdefinedbytheALCOA+principles,dataintegritycoversmanytopicsincludingbutnotlimitedtorequirementsdefinedinthesectionsHandlingofData,IdentityandAccessManagement,AuditTrails,ElectronicSignatures,andSecurity.数据完整性:药品GMP活动所用系统捕获、分析和报告的数据必须可靠,这一点至关重要。根ALCOA+原则的定义,数据完整性涵盖多个方面,包括但不限于“数据处理”“身份与访问管理”“”“电子签名”“安全性”Systemrequirements.SystemrequirementswhichdescribethefunctionalitytheregulateduserhasautomatedandisrelyingonwhenperformingGMPactivities,shouldbedocumentedandkeptupdatedtofullyreflecttheimplementedsystemanditsintendeduse.Therequirementsshouldserveastheverybasisforsystemqualificationandvalidation.GMP活动时已实现自动化且所依赖的功能的系统要求,应Outsourcedactivities.Whenusingoutsourcedactivities,theregulateduserremainsfullyresponsibleforadherencetotherequirementsincludedinthisdocument,formaintainingtheevidenceforit,andforprovidingitforregulatoryreview外包活动:当采用外包活动时,受监管用户仍需对遵守本文件中的Security.RegulatedusersshouldkeepupdatedaboutnewsecuritythreatstoGMPsystems,measurestoprotecttheseshouldbeimplementedandimprovedinatimelymanner,whereneeded.安全性:受监管用户应及时了解针对药品GMP系统的新安全威胁,必要时,应及时实施并改进保护这些系Noriskincrease.Whereacomputerisedsystemreplacesanothersystemoramanualoperation,thereshouldbenoresultantdecreaseinproductquality,patientsafetyordataintegrity.Thereshouldbenoincreaseintheoverallriskoftheprocess.3.1.Pharmaceuticalqualitysystem.Aregulatedusershouldimplementapharmaceuticalqualitysystem(PQS),whichcoversallcomputerisedsystemsusedinGMPactivitiesandpersonnelinvolvedwiththese.Itshouldincludeallactivitiesrequiredinthisdocumentandinaddition,itshouldbeensuredthat:药品质量体系:受监管用户应实施药品质量体系(PQS),GMP活动中使用的所应确保:Alldeviationsoccurringduringvalidationoroperationofcomputerisedsystemsarerecordedandsignificantdeviationsinvestigatedwiththeobjectiveofdeterminingtherootcauseandanyimpactonproductquality,patientsafetyordataintegrity.Suitablecorrectiveandpreventiveactions(CAPA)shouldbeidentifiedandimplemented,andtheeffectivenessoftheseshouldbeverified.Anychangetoacomputerisedsystemincludingbutnotlimitedtoitsconfiguration,itshardwareandsoftwarecomponents,anditsplatformandoperatingsystem,aremadeinacontrolledmannerandinaccordancewithdefinedprocedures.Anysignificantchangewhichmayimpactproductquality,patientsafetyordataintegrity,shouldbesubjecttore-qualificationandvalidation.Internalauditsareplanned,conducted,reportedandfollowedupontodetectproceduraldeviationsandensureproductqualitypatientsafetyanddataintegrity应规划、实施、报告内部审计并跟进,以发Regularmanagementreviewscoverrelevantperformanceindicatorsforthecomputerisedsystemandtheprocessitisusedin(qualitymetrics)andensurethatadequateactionistaken.定期管理评审应涵Seniormanagementeffectivelyoverseethestateofcontrolthroughoutthesystemlifecycle,allocateappropriateresources,andimplementaculturethatpromotesdataintegrity,securityandatimelyandeffectivehandlingofdeviations.RiskManagementLifecycle.QualityRiskManagement(QRM)shouldbeappliedthroughoutthelifecycleofacomputerisedsystemconsideringanypossibleimpactonproductquality,patientsafetyordataintegrity.Identificationandanalysis.RisksassociatedwiththeuseofcomputerisedsystemsinGMPactivitiesshouldbeidentifiedandanalysedaccordingtoanestablishedprocedure.ExamplesofriskmanagementmethodsandtoolscanbefoundinICHQ9(R1).风险管理方法和工具的示例可参见ICHQ9(R1)。Appropriatevalidation.Thevalidationstrategyandeffortshouldbedeterminedbasedontheintendeduseofthesystemandpotentialriskstoproductqualitypatientsafetyanddataintegrity适当的验证:验证Mitigation.Whereapplicable,risksassociatedwiththeuseofcomputerisedsystemsinGMPactivitiesshouldbemitigatedandbroughtdowntoanacceptablelevel,ifpossible,bymodifyingprocessesorsystemdesign.Theoutcomeoftheriskmanagementprocessshouldresultinthechoiceofanappropriatecomputerisedsystemarchitectureandfunctionality.缓解措施:在适用情况下,与MP活动中使用计算机化系统相关的风险应尽可能通过修改流程或系统设计来缓解,并降低至可接受的水平。风险管理过程的结果应是选择合适的计算机化系统架构和功能。Dataintegrity.Qualityriskmanagementprinciplesshouldbeusedtoassessthecriticalityofdatatoproductquality,patientsafetyanddataintegrity,thevulnerabilityofdatatodeliberateorindeliberatealteration,deletionorloss,andthelikelihoodofdetectionofsuchactions.数据完整性:应运用质量风险管理原则,评估数据对产品质量、患者安全和数据完整性的关键程度、PersonnelandTrainingCooperation.Whenconductingtheactivitiesrequiredinthisdocument,thereshouldbe,whereapplicable,closecooperationbetweenallrelevantparties.Thisincludesprocessowner,systemowner,users,subjectmatterexperts(SME),QA,QP,theinternalITdepartment,vendors,andserviceproviders.协作:在开展本文件要求的活动时,在适用情况下,所有相关方之间应密切协作。这包括流程负责人、系统负责人、用户、主题专家(SME)、QA、QPIT部门、供应商和服务提供商。Training.AllpartiesinvolvedwithcomputerisedsystemsusedinGMPactivitiesshouldhaveadequatesystemspecifictraining,andappropriatequalificationsandexperience,correspondingtotheirassignedresponsibilities,dutiesandaccessprivileges.GMP活动所用计算机化系统的所有相关方,应接受充分的系统专项的培训,且应具SystemRequirementsGMPfunctionality.Aregulatedusershouldestablishandapproveasetofsystemrequirements(e.g.aUserRequirementsSpecification,URS),whichaccuratelydescribeGMPfunctionalitytheregulateduserhasautomatedandisrelyingonwhenperformingGMPactivities.Thisprincipleshouldbeappliedregardlessofwhetherasystemisdevelopedin-house,isacommercialoff-the-shelfproduct,orisprovidedas-a-service,andindependentlyonwhetheritisdevelopedfollowingalinearoriterativesoftwaredevelopmentprocess. GMP活动时已自动化且所依赖的功能。无论系统是内部开发、商用现成产品,Extentanddetail.Theextentanddetailofdefinedrequirementsshouldbecommensuratewiththerisk,complexityandnoveltyofasystem,andthedescriptionshouldbesufficienttosupportsubsequentriskanalysis,specification,design,purchase,configuration,qualificationandvalidation.Itshouldinclude,butmaynotbelimitedto,operational,functional,dataintegrity,technical,interface,performance,availability,security,andregulatoryrequirements.Whererelevant,requirementsshouldincludeprocessmapsanddataflowdiagrams,andusecasesmaybeapplied.范围与详细程度:已界定要求的范围和详细程度应与系统的风险、复杂性和新颖性相匹配,且描述能、数据完整性、技术、接口、性能、可用性、安全性和监管要求。在相关情况下,要求应包含流Ownership.Ifasystemispurchasedorconsistsofsoftware-as-a-service,arequirementsspecificationmaybeprovidedbythevendor.However,theregulatedusershouldcarefullyreviewandapprovethedocumentandconsiderwhetherthesystemfulfilsGMPrequirementsandcompanyprocessesasis,orwhetheritshouldbeconfiguredorcustomised.Theregulatedusershouldtakeownershipofthedocumentcoveringtheimplementedversionofthesystemandformallyapproveandcontrolitaftermakinganynecessarychanges.所有权:若系统是采购的或由软件即服务(aS)构成,供应商可能会提供需求规范。然而,受监管用户应仔细审核并批准该文件,并考虑系统是否按现状满足MP要求和公司流程,或者是否应进行配置或定制。受监管用户应拥有涵盖系统已实施版本的文件的所有权,并在进行必要变更后,Update.Requirementsshouldbeupdatedandmaintainedthroughoutthelifecycleofasystemtoensurethattheycontinuetogiveacompleteandaccuratedescriptionofsystemfunctionalityasthesystemundergoessubsequentchangesandcustomisations.Updatedrequirementsshouldformtheverybasisforqualificationandvalidationofasystem.Traceability.Documentedtraceabilitybetweenindividualrequirements,underlayingdesignspecificationsandcorrespondingqualificationandvalidationtestcasesshouldbeestablishedandmaintained.TheuseofeffectivetoolstocaptureandholdrequirementsandPage5of19facilitatethetraceabilityisencouraged.可追溯性:应建立并维护单个需求、底层设计规范以及相应的确认和验证Configuration.Itshouldbeclearwhatfunctionality,ifany,ismodifiedoraddedbyconfigurationofasystem.Optionsallowingconfigurationofsystemfunctionalityshouldbedescribedintherequirementsspecificationandthechosenconfigurationshouldbedocumentedinacontrolledconfigurationspecification.配置:应明确通过系统配置修改或增加了哪些功能(如有)。允许配置系统功能的选项应在需求规SupplierandServiceManagement供应商与Responsibility.Whenaregulateduserisrelyingonavendor’squalificationofasystemusedinGMPactivities,aserviceprovider,oraninternalITdepartment’squalificationand/oroperationofsuchsystem,thisdoesnotchangetherequirementsputforthinthisdocument.Theregulateduserremainsfullyresponsiblefortheseactivitiesbasedontherisktheyconstituteonproductquality,patientsafetyanddata.技术(IT)部门对该系统的确认和/或操作时,这并不会改变本文件规定的要求。基于这些活动对Audit.Whenaregulateduserisrelyingonavendor’soraserviceprovider’squalificationand/oroperationofasystemusedinGMPactivities,theregulatedusershould,accordingtoriskandsystemcriticality,conductanauditorathoroughassessmenttodeterminetheadequacyofthevendororserviceprovider’simplementedprocedures,thedocumentationassociatedwiththedeliverables,andthepotentialtoleveragetheseratherthanrepeatingtheactivities.GMP/或操作时,受监管Oversight.Whenaregulateduserisrelyingonaserviceprovider’soraninternalITdepartment’soperationofasystemusedinGMPactivities,theregulatedusershouldexerciseeffectiveoversightofthisaccordingtodefinedservicelevelagreements(SLA)andkeyperformanceindicators(KPI)agreedwiththeserviceproviderortheinternalITdepartment.ITGMP活动所用系统的操作时,受监管用户实施有效监督。Documentationavailability.Whenaregulateduserreliesonavendor’s,aserviceprovider’soraninternalITdepartment’squalificationand/oroperationofasystemusedinGMPactivities,theregulatedusershouldensurethatdocumentationforactivitiesrequiredinthisdocumentisaccessibleandcanbeexplainedfromtheirfacility.Inthis,theregulatedusermaybesupportedbythevendor,theserviceproviderortheinternalITdepartment./或操作时,受监管用户应确保本文件要求的活动相关文件可获取,且可从其设施处进行解释说明。TContracts.Whenaregulateduserisrelyingonaserviceprovider’soraninternalITdepartment’squalificationand/oroperationofasystemusedinGMPactivities,theregulatedusershouldhaveacontractwithaserviceproviderorhaveapprovedprocedureswithaninternalITdepartmentwhich:ITGMP/或操作时,受监管用户应与服务提供商签订合同,或与内部IT部门制定经批准的程序,其中应规定:DescribestheactivitiesanddocumentationtobeEstablishesthecompanyproceduresandregulatoryrequirementstobeAgreesonregular,adhocandincidentreportingandoversight(incl.SLAsandKPIs),answertimes,标(KPIs))、响应时间、解决时间等达成一致AgreesonconditionsforsupplierAgreesonsupportduringregulatoryinspections,ifAgreesonresolutionofissuesbroughtupduringnormaloperation,auditsandregulatoryinspectionsDefinesrequirementsandprocessesforcommunicationofqualityandsecurityrelatedDefinesanexitstrategybywhichtheregulatedusermayretaincontrolofsystemAgreesontheprocessforreleaseofnewsystemversionsandontheregulateduser’spossibilitytotestthesepriortorelease.就新系统版本的发布流程,以及受监管用户在发布前对其进行测试的可能AlarmsRelianceonsystem.Alarmsshouldbeimplementedincomputerisedsystemswherearegulateduserisrelyingonthesystemtonotifyaboutanevent.Thisisrequiredwhentheusermusttakeaspecificaction,withoutwhichproductquality,patientsafetyordataintegritymightotherwisebecompromised.依赖系统:在受监管用户依赖系统就某一事件进行通知的计算机化系统中,应设置报警功能。当用户必须采取特定行动(若不采取该行动,产品质量、患者安全或数据完整性可能会受到损害)时,Settings.Alarmlimits,delays,andanyearlywarningsoralerts,shouldbeappropriatelyjustified,andsetwithinapprovedandvalidatedprocessandproductspecifications.Setting,changingordeactivationshouldonlybeavailabletouserswithappropriateaccessprivilegesandshouldbemanagedbyanapprovedprocedure.设置:报警限值、延迟时间以及任何预警或警报,都应经过合理论证,并在已Signalling.Alarmsshouldsetoffvisibleand/oraudiblesignalswhensetalarmlimitsareexceededandafteranydefineddelay.Thesignallingshouldaccommodateatimelyreactionandshouldbeappropriatetotheworkenvironment.信号发出:当超出设定的报警限值且经过任何规定的延迟时间后,报警应触发可见和/或可听信号。Acknowledgement.Criticalalarmspotentiallyimpactingproductquality,patientsafetyordataintegrityshouldonlybeacknowledgedbyuserswithappropriateaccessprivileges.Aspartoftheacknowledgement,i.e.aconfirmationthatthealarmhasbeenseenandappropriateactionwillbetaken,acommentshouldbeaddedaboutwhythealarmwasacknowledged(see12AuditTrails).确认:可能影响产品质量、患者安全或数据完整性的关键报警,仅应由具备相应访问权限的用户进行确认。作为确认的一部分(即确认已看到报警并将采取适当行动),应添加一条关于为何确认该报警的注释(见12审计追踪)。Log.Allalarmsandacknowledgementsshouldbeautomaticallyaddedtoanalarmlog.Thisshouldcontainthenameofthealarm,dateandtimeofthealarm,dateandtimeoftheacknowledgement,usernameandroleoftheuseracknowledgingthealarmandanycommentaboutwhythealarmwasacknowledged.ItshouldnotbepossibleforusersworkingaccordingtoGMPtodeactivateoreditalarmlogs.记录:所有报警及确认信息都应自动添加到报警日志中。日志应包含报警名称、报警发生的日期和时间、确认的日期和时间、确认报警的用户的用户名和角色,以及关于为何确认该报警的任何注释。遵循药品MPSearchabilityandsortabilityAlarmlogsshouldbesearchableandsortableintheoriginatingsystemoritshouldbepossibletoexportlogstoatoolwhichprovidesthisfunctionality.Othermethodsofreviewingalarmsmayalsobeused,iftheyprovidethesameeffectiveness.可搜索性和可排序性:报警日志应能在生成系统中进行搜索和排序,或者应能够将日志导出到具备该功能的工具中。若其他查看报警的Review.Alarmlogsshouldbesubjecttoappropriateperiodicreviewsbasedonapprovedprocedures,inwhichitshouldbeevaluatedwhethertheyhavebeentimelyacknowledgedbyauthorisedusersandwhetherappropriateactionhasbeentaken.Reviewsshouldbedocumented,andresultsshouldbeevaluatedtoidentifyanytrendsthatcouldindicatenegativeperformanceofasystemorprocess,orimpactontheproduct.ThefrequencyandPage7of19detailofreviewsshouldbebasedontherisktoproductquality,patientsafetyanddataintegrity.审核:应依据已批准的程序,对报警日志进行适当的定期审核。审核中应评估报警是否已被授权用户及时确认,以及是否已采取适当行动。审核应形成文件记录,且应对结果进行评估,以识别任何可能表明系统或流程存在不良表现或对产品产生影响的趋势。审核的频率和详细程度应基于对产品QualificationandValidationPrinciples.QualificationandvalidationactivitiesforcomputerisedsystemsshouldfollowthegeneralprinciplesoutlinedinGMPAnnex15.Theactivitiesshouldaddressbothstandardandconfiguredsystemfunctionality,aswellasanyfunctionalityrealisedthroughcustomisation.GMP15中概述的一般原则。这些活动应涵盖标Qualityriskmanagement.Computerisedsystemsshouldbequalifiedandvalidatedinaccordancewiththeprinciplesofqualityriskmanagement.Decisionsonthescopeandextentofqualificationandvalidationofspecificfunctionalityandentiresystemsshouldbebasedonajustifiedanddocumentedriskassessmentofindividualrequirementsand,whererelevant,functionalspecifications,consideringtheriskforproductquality,patientsafetyanddataintegrity.质量风险管理:计算机化系统应依照质量风险管理原则进行确认和验证。关于特定功能和整个系统的确认与验证范围及程度的决策,应基于对单个需求以及相关功能规范(如适用)的合理且有文件Installationandconfiguration.Priortocommencinganytestactivity,itshouldbeverifiedthatacomputerisedsystemanditscomponentshavebeencorrectlyinstalledandconfiguredaccordingtospecifications,andwhereapplicable,thatrelevantcomponentshavebeenproperlycalibrated.Operatingsystemsandplatformsshouldbeupdatedtosupportedversionsandrelevantsecuritypatchesshouldbedeployed(see15.10Updatedplatformsand15.13Timelypatching).安装与配置:在开展任何测试活动之前,应验证计算机化系统及其组件已根据规范正确安装和配置,且在适用情况下,相关组件已正确校准。操作系统和平台应更新至受支持的版本,并应部署相关安全补丁见151015.3。Evidence.Systemqualificationandvalidationshouldprovideevidenceintheformofexecutedtestscripts,andwhererelevant,screendumps,thatrequirements,andwhereapplicable,derivedfunctionalspecifications,aremetbythesystem.证据:系统确认和验证应通过已执行的测试脚本(以及相关的屏幕截图,如适用)的形式提供证据,证明系统满足需求以及(如适用)衍生的功能规范。Traceability.Testcasesshouldbetraceabletoindividualrequirementsorspecifications,e.g.bymeansofarequirementstraceabilitymatrix.Testcasesnotreferring(traceable)torequirementsorapplicablespecificationsdonotmeettherequirementstoqualificationandvalidation.可追溯性:测试用例应可追溯到单个需求或规范,例如通过需求追溯矩阵。无法追溯至需求或适用Focus.Increasedfocusshouldbeontestingasystem’shandlingofkeyfunctionalrequirements,onfunctionalityintendedtoensurethatactivitiesareconductedaccordingtoGMP,andonfunctionalitydesignedtoensuredataintegrity.Thisincludesbutisnotlimitedtoaccessprivileges,releaseofproductsandresults,calculations,audittrails,errorhandling,handlingofalarmsandwarnings,boundaryandnegativetesting,reportsandinterfaces,andrestorefrombackup.重点:应更加注重测试系统对关键功GMP开展的功能,以及为确保数据完整性而设计的功能。这包括但不限于访问权限、产品和结果的放行、计算、审计追踪、错误处理、报警和警告的处理、边Planandapproval.Qualificationandvalidationactivitiesshouldbeconductedaccordingtoapprovedplans,protocolsandtestscripts.Testscriptsshouldbedescribedinsufficientdetailtoensureacorrectandrepeatableconductofteststepsandprerequisites.计划与批准:确认和验证活动应依照已批准的计划、方案和测试脚本开展。测试脚本的描述应足够Completionpriortouse.Qualificationandvalidationactivitiesshouldbesuccessfullycompletedandreportedpriortoapprovalandtakingasystemintouse.Conditionalapprovaltoproceedtotakingasystemintousemaybegrantedwherecertainacceptancecriteriahavenotbeenmet,ordeviationshavenotbeenfullyaddressed.Aconditionforthisis,thatthereisadocumentedassessment,thatanydeficienciesintheaffectedsystemfunctionalityorPage8of19GMPprocesses,willnotimpactproductquality,patientsafetyordataintegrity.Whereaconditionalapprovalisissued,itshouldbeexplicitlystatedinthevalidationreportandthereshouldbeclosefollow-uponapprovalofoutstandingactionsaccordingtoplan.使用前完成:确认和验证活动应在批准并启用系统之前成功完成并报告。在某些接受标准未满足或偏差未完全解决的情况下,可有条件批准启用系统。条件是要有文件记录GMP流程中的任何缺陷不会影响产品质量、患者安全或数据完整性。若颁发有条件批准,应在验证报告中明确说明,并需根据计划密切跟进未完成行动的Authorisation.Qualificationandvalidationdocumentationmaybeprovidedbyaserviceprovider,avendororaninternalITdepartmentinpartsorinwhole.However,theregulateduserisfullyaccountableandshouldcarefullyreviewandauthorisetheuseofthedocumentation.TheyshouldcarefullyconsiderwhetheritcoverstheimplementedversionandsupportsGMP,andcompanyprocessesasis,orwhetheritshouldberepeatedinpartsorcompletelybytheregulateduser.批准:确认和验证文件可由服务提供商、供应商或内部信息技术(T)部门部分或全部提供。然而,GMPHandlingofDataInputverification.Wherecriticaldataisenteredmanually,systemsshould,wereapplicable,havefunctionalitytoverifytheplausibilityoftheinputs(e.gwithinexpectedrangesandalerttheuserwhentheinputisnotplausible.输入验证:在手动输入关键数据的情况下,系统应在适用时具备验证输入有效性(如在预期范围内)的功能,并在输入不合理时向用户发出警报。Datatransfer.Wherearoutineworkprocessrequiresthatcriticaldatabetransferredfromonesystemtoanother(e.g.fromalaboratoryinstrumenttoaLIMSsystem),thisshould,wherepossible,bebasedonvalidatedinterfacesratherthanonmanualtranscriptions.Ifcriticaldataistranscribedmanually,effectivemeasuresshouldbeinplacetoensurethatthisdoesnotintroduceanyrisktodataintegrity.Datamigration.Whereanadhocprocessrequiresthatcriticaldataorawholedatabasebemigratedfromonesystemtoanother(e.g.whenmovingdatafromaretiredtoanewsystem),thisshouldbebasedonavalidatedprocess.Amongotherthings,itshouldconsidertheconstraintsonthesendingandreceiving数据迁移:当特定临时流程要求将关键数据或整个数据库从一个系统迁移到另一个系统(如将数据从旧系统迁移到新系统)时,应基于经验证的流程进行。除其他事项外,还应考虑发送方和接收方的约束条件。Encryption.Whereapplicable,criticaldatashouldbeencryptedonaIdentityandAccessManagement Uniqueaccounts.Allusersshouldhaveuniqueandpersonalaccounts.Theuseofsharedaccountsexceptforthoselimitedtoread-onlyaccess(nodataorsettingscanbechanged),constituteaviolationofdataintegrity.的账户除外)构成对数据完整性的违规。Continuousmanagement.Useraccessesandrolesshouldbegranted,modifiedandrevokedasrelevantandinatimelymannerasusersjoin,change,andendtheirinvolvementinGMPactivities.持续GMP活动,应及时且适当地授予、修改和撤销用户Certainidentification.Themethodofauthenticationshouldidentifyuserswithahighdegreeofcertaintyandprovideaneffectiveprotectionagainstunauthorisedaccess.Typically,itmayinvolveauniqueusernameandapassword,althoughothermethodsprovidingatleastthesamelevelofsecuritymaybeemployed(e.g.biometrics).Authenticationonlybymeansofatokenorasmartcardisnotsufficient,ifthiscouldbeusedbyanotheruser.可靠识别:身份验证方法应能高度可靠地识别用户,并有效防止未经授(如生物识别够的。Confidentialpasswords.Passwordsandothermeansofauthenticationshouldbekeptconfidentialandprotectedfromallotherusers,bothatsystemandatapersonallevel.Passwordsreceivedfrome.g.amanager,orasystemadministratorshouldbechangedatthefirstlogin,preferablyrequiredbytheSecurepasswords.Passwordsshouldbesecureandenforcedbysystems.Passwordrulesshouldbecommensuratewithrisksandconsequencesofunauthorisedchangesinsystemsanddata.Forcriticalsystems,passwordsshouldbeofsufficientlengthtoeffectivelypreventunauthorisedaccessandcontainacombinationofuppercase,lowercase,numbersandsymbolsApasswordshouldnotcontaine.gwordsthatcanbefoundinadictionary,thenameofaperson,auserid,productororganisation,andshouldbesignificantlydifferent fromapreviouspassword.安全密码:密码应符合安全要求,并由系统强制管控。密码规则应与系统和数据中未经授权更改的风险及后果相匹配。对于关键系统,密码长度应IDStrongauthentication.Remoteauthenticationoncriticalsystemsfromoutsidecontrolledperimeters,shouldincludemultifactorauthentication(MFA强身份验证:从受控区域外对关键系统进行远程身份验证时,应包含多因素身份验证(MFA)。AutolockingAccountsshouldbeautomaticallylockedafterapre-definednumberofsuccessivefailedauthenticationattempts.Accountsshouldonlybeunlockedbythesystemadministratorafterithasbeenconfirmedthatthiswasnotpartofanunauthorisedloginattemptoraftertheriskforsuchattempthasbeenremoved.自动锁定:在连续多次身份验证失败(次数预先定义)后,账户应自动锁定。仅在确认该情况并非未经授权的登录尝试的一部分,或此类尝试的风险已消除后,系统管理员才可解锁Inactivitylogout.Systemsshouldincludeanautomaticinactivitylogout,whichlogsoutauserafteradefinedperiodofinactivity.Theusershouldnotbeabletochangetheinactivitylogouttime(outsidedefinedandacceptablelimits)ordeactivatethefunctionality.Uponinactivitylogout,are-authenticationshouldberequired(e.g.passwordentry).求重新进行身份验证(如输入密码).Accesslog.Systemsshouldincludeanaccesslog(separate,oraspartoftheaudittrail)which,eachlogin,automaticallylogstheusername,userrole(ifpossible,tochoosebetweenseveralroles),thedateandtimeforlogin,thedateandtimeforlogout(incl.inactivitylogout).Thelogshouldbesortableandseachale,rltrntiel,itshuldeposiletoeportthelogtoatolhchproidesthsfucionlt.)((Guidingprinciples.AccessprivilegesforusersofcomputerisedsystemsusedinGMPactivitiesshouldbemanagedaccordingtothefollowingtwoguidingprinciples:GMP活动所用计Segregationofduties,i.e.thatuserswhoareinvolvedinGMPactivitiesdonothaveadministrativeGMPLeastprivilegeprinciple,i.e.thatusersdonothavehigheraccessprivilegesthanwhatisnecessaryfortheirjobfunction.Recurrentreviews.Useraccountsshouldbesubjecttorecurrentreviewswheremanagersconfirmthecontinuedaccessoftheiremployeesinordertodetectaccesseswhichshouldhavebeenchangedorrevokedduringdailyoperation,butwereaccidentallyforgotten.Ifuseraccountsaremanagedbymeansofroles,theseshouldbesubjecttothesamekindofreviews,wheretheaccessesofrolesareconfirmed.Thereviewsshouldbedocumented,andappropriateactiontaken.Thefrequencyofthesereviewsshouldbecommensuratewiththerisksandconsequencesofchangesinsystemsanddatamadebyunauthorised定期审核:用户账户应接受定期审核,由管理人员确认其员工的持续访问权限,以便发现那些在日常操作中本应更改或撤销却未及时处理的访问权限。若用户账户通过角色进行管理,这些角色也应接受相同类型的审核,确认角色的访问权限。审核应形成文件记录,并采取适当行动。这些审核的频率应AuditTrailsManualuserinteractions.Systemswhichareusedtocontrolprocesses,capture,holdorreportdata,andwhereuserscancreate,modifyordeletedata,settingsoraccessprivileges,Page10of19acknowledgealarmsorexecuteelectronicsignaturesetc.,shouldhaveanaudittrailfunctionalitywhichautomatic
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 通知季度业绩评估会议时间通知函5篇
- 2026年合作项目进度汇报说明(5篇范文)
- 小学主题班会课件:梦想与努力同向未来与希望并肩
- 教育机构教研主任及教师绩效衡量表
- 跨部门项目进度协调的商洽函(7篇)
- 产品经理需求文档撰写与评审流程手册
- 新落地式钢管脚手架搭设与拆卸安全监理实施细则
- 房屋装修设计方案与材料选购指南
- 初学者掌握素描基础技法指导书
- 建筑师项目设计与进度控制绩效考核表
- 2026年宣城广德市大学生乡村医生专项计划招聘3名考试参考题库及答案详解
- 2026年广东广州越秀区社区专职工作人员招聘考试试卷-含答案解析
- GB/T 47651-2026温室气体产品碳足迹量化方法与要求光热发电
- 2026年上海高考英语(秋考)完整真题(考生回忆版)+ 参考答案与解析
- 高温天户外劳动者休息驿站建设
- (2026年)腹腔镜下食管裂孔疝修补术健康宣教课件
- 胃肠镜科普宣传
- 乳胶漆涂刷质量保证措施
- 小升初语文拼音与汉字专项练习(含解析)
- 作业标准培训教材
- 重症肺炎分层诊断与评估
评论
0/150
提交评论