Reference:ICH ICH E6 Guideline R3 (2025) III. Annex 1 4.3.8
From GxPlex
| Document information | |
|---|---|
| Reference | ICH ICH E6 Guideline R3 (2025) |
| Validity area | ICH |
| Scope(s) | HM |
| Document name | ICH E6 Guideline |
| Version / Revision | R3 (2025) |
| Status | Current |
| Document type | International guideline |
| Language(s) | EN |
| Description | GUIDELINE FOR GOOD CLINICAL PRACTICE |
| Official source | Official link |
| Restricted access | No |
| Submitted by | Florian Adragna |
| Contributors | |
| Reference Details | |
|---|---|
| Scope | G |
| Document part | III. Annex 1
4.3.8 |
| Language | EN |
| Original entry by | Florian Adragna |
| Contributors | |
| Tags (EN) | |
| Tags (original language) | |
| Tags (FR) | |
| Comment | User management and access controls in computerised systems |
Content
4.3.8 User Management
(a) Access controls are integral to computerised systems used in clinical trials to limit system access to authorised users and to ensure attributability to an individual. The security measures should be selected in such a way that they achieve the intended security.
(b) Procedures should be in place to ensure that user access permissions are appropriately assigned based on a userâs duties and functions, blinding arrangements and the organisation to which users belong. Access permissions should be revoked when they are no longer needed. A process should be in place to ensure that user access and assigned roles and permissions are periodically reviewed, where relevant.
(c) Authorised users and access permissions should be clearly documented, maintained and retained. These records should include any updates to a userâs roles, access permissions and time of access permission being granted (e.g., time stamp).