Reference:ICH ICH E6 Guideline R3 (2025) III. Annex 1 4.3.3
From GxPlex
| Document information | |
|---|---|
| Reference | ICH ICH E6 Guideline R3 (2025) |
| Validity area | ICH |
| Scope(s) | HM |
| Document name | ICH E6 Guideline |
| Version / Revision | R3 (2025) |
| Status | Current |
| Document type | International guideline |
| Language(s) | EN |
| Description | GUIDELINE FOR GOOD CLINICAL PRACTICE |
| Official source | Official link |
| Restricted access | No |
| Submitted by | Florian Adragna |
| Contributors | |
| Reference Details | |
|---|---|
| Module | Module 4 â Unit 4.2.3 |
| Scope | G |
| Document part | III. Annex 1
4.3.3 |
| Language | EN |
| Original entry by | Florian Adragna |
| Contributors | |
| Tags | Systems validation, Data integrity, Data protection, Requirements |
| Comment | Security management for trial data and records |
Content
4.3.3 Security
(a) The security of the trial data and records should be managed throughout the data life cycle.
(b) The responsible party should ensure that security controls are implemented and maintained for computerised systems. These controls should include user management and ongoing measures to prevent, detect and/or mitigate security breaches. Aspects such as user authentication requirements and password management, firewall settings, antivirus software, security patching, system monitoring and penetration testing should be considered.
(c) The responsible party should maintain adequate backup of the data.
(d) Procedures should cover the following: system security measures, data backup and disaster recovery to ensure that unauthorised access and data loss are prevented. Such measures should be periodically tested, as appropriate.