{
"id": "21 CFR Part 11",
"name": "21 CFR Part 11",
"logo": {
"light": "",
"dark": ""
},
"controls": [
{
"id": "11.10(a)",
"name": "System Validation",
"description": "Validate electronic record systems to ensure accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records."
},
{
"id": "11.10(b)",
"name": "Record Copies",
"description": "Generate accurate and complete copies of electronic records in both human-readable and electronic form suitable for FDA inspection, review, and copying."
},
{
"id": "11.10(c)",
"name": "Record Protection and Retention",
"description": "Protect electronic records to ensure accurate and ready retrieval throughout the required retention period."
},
{
"id": "11.10(d)",
"name": "Access Control",
"description": "Limit system access to authorized individuals."
},
{
"id": "11.10(e)",
"name": "Audit Trails",
"description": "Use secure, computer-generated, time-stamped audit trails to record creation, modification, or deletion of electronic records; ensure prior information is not obscured and audit trails are retained with the records."
},
{
"id": "11.10(f)",
"name": "Operational Controls",
"description": "Implement system checks to enforce permitted sequencing of steps and events."
},
{
"id": "11.10(g)",
"name": "Authority Controls",
"description": "Ensure only authorized individuals can use the system, sign records, access devices, or alter records."
},
{
"id": "11.10(h)",
"name": "Device Controls",
"description": "Verify the validity of data input sources and operational instructions where applicable."
},
{
"id": "11.10(i)",
"name": "Personnel Competency",
"description": "Ensure individuals who develop, maintain, or use electronic record or signature systems are trained, qualified, and competent."
},
{
"id": "11.10(j)",
"name": "Accountability Policies",
"description": "Establish and enforce written policies holding individuals accountable for actions taken under electronic signatures."
},
{
"id": "11.10(k)(1)",
"name": "Documentation Access Controls",
"description": "Control the distribution, access, and use of system documentation."
},
{
"id": "11.10(k)(2)",
"name": "Documentation Change Control",
"description": "Maintain an audit trail of time-sequenced development and changes to system documentation."
},
{
"id": "11.30",
"name": "Open System Protections",
"description": "Apply additional safeguards (e.g., encryption, digital signatures) to protect the authenticity, integrity, and confidentiality of records in open systems."
},
{
"id": "11.50(a)",
"name": "Signature Manifestation",
"description": "Ensure signed electronic records display the signer's name, date/time of signing, and meaning of the signature."
},
{
"id": "11.50(b)",
"name": "Signature Record Integrity",
"description": "Subject signature information to the same controls as electronic records and include it in human-readable outputs."
},
{
"id": "11.70",
"name": "Signature-to-Record Linking",
"description": "Securely link electronic signatures to their respective records to prevent excision, copying, or transfer."
},
{
"id": "11.100(a)",
"name": "Signature Uniqueness",
"description": "Ensure each electronic signature is unique to one individual and is not reused or reassigned."
},
{
"id": "11.100(b)",
"name": "Identity Verification",
"description": "Verify an individual's identity before assigning or authorizing an electronic signature."
},
{
"id": "11.100(c)",
"name": "Signature Legal Certification",
"description": "Certify to the FDA that electronic signatures are intended to be legally binding equivalents of handwritten signatures."
},
{
"id": "11.200(a)(1)",
"name": "Multi-Factor Signature Components",
"description": "Require at least two distinct identification components (e.g., ID and password) for non-biometric electronic signatures."
},
{
"id": "11.200(a)(2)",
"name": "Signature Ownership Control",
"description": "Ensure electronic signatures are used only by their genuine owners."
},
{
"id": "11.200(a)(3)",
"name": "Signature Misuse Prevention",
"description": "Implement controls requiring collaboration of two or more individuals for unauthorized signature use."
},
{
"id": "11.200(b)",
"name": "Biometric Signature Protection",
"description": "Ensure biometric electronic signatures cannot be used by anyone other than their genuine owners."
},
{
"id": "11.300(a)",
"name": "Credential Uniqueness",
"description": "Maintain the uniqueness of identification code and password combinations."
},
{
"id": "11.300(b)",
"name": "Credential Lifecycle Management",
"description": "Periodically check, recall, or revise identification codes and passwords."
},
{
"id": "11.300(c)",
"name": "Credential Loss Management",
"description": "Deauthorize lost, stolen, or compromised authentication devices and issue replacements securely."
},
{
"id": "11.300(d)",
"name": "Unauthorized Access Detection",
"description": "Implement safeguards to detect and immediately report unauthorized use of credentials."
},
{
"id": "11.300(e)",
"name": "Authentication Device Integrity Testing",
"description": "Perform initial and periodic testing of authentication devices to detect unauthorized alteration."
}
]
}