Personal tools

Sponsorname

Your company could advertise here

www.fla-consulting.eu

Reference:USA 21 CFR Part 11 09-Apr-2025 § 11.300

From GxPlex

Revision as of 14:27, 29 June 2026 by gxplex>GxPlexBot (Import from GxPlex Excel)
Jump to: navigation, search



Document information
Reference USA 21 CFR Part 11 09-Apr-2025
Validity area USA
Scope(s) G
Document name 21 CFR Part 11
Version / Revision 09-Apr-2025
Status Current
Document type Legal act
Language(s) EN
Description Title 21 —Food and Drugs

Chapter I —Food and Drug Administration, Department of Health and Human Services Subchapter A—General Part 11 Electronic Records; Electronic Signatures https://www.ecfr.gov/current/title-21

Official source Official link
Restricted access No
Submitted by Florian Adragna
Contributors


Reference Details
Scope G
Document part § 11.300
Language EN
Original entry by Florian Adragna
Contributors
Tags (EN)
Tags (original language)
Tags (FR)
Comment Controls for identification codes and passwords

Content

§ 11.300 Controls for identification codes/passwords. Persons who use electronic signatures based upon use of identification codes in combination with passwords shall employ controls to ensure their security and integrity. Such controls shall include: (a) Maintaining the uniqueness of each combined identification code and password, such that no two individuals have the same combination of identification code and password. (b) Ensuring that identification code and password issuances are periodically checked, recalled, or revised (e.g., to cover such events as password aging). (c) Following loss management procedures to electronically deauthorize lost, stolen, missing, or otherwise potentially compromised tokens, cards, and other devices that bear or generate identification code or password information, and to issue temporary or permanent replacements using suitable, rigorous controls. (d) Use of transaction safeguards to prevent unauthorized use of passwords and/or identification codes, and to detect and report in an immediate and urgent manner any attempts at their unauthorized use to the system security unit, and, as appropriate, to organizational management. (e) Initial and periodic testing of devices, such as tokens or cards, that bear or generate identification code or password information to ensure that they function properly and have not been altered in an unauthorized manner.