Reference:USA 21 CFR Part 11 09-Apr-2025 § 11.300
From GxPlex
| Document information | |
|---|---|
| Reference | USA 21 CFR Part 11 09-Apr-2025 |
| Validity area | USA |
| Scope(s) | G |
| Document name | 21 CFR Part 11 |
| Version / Revision | 09-Apr-2025 |
| Status | Current |
| Document type | Legal act |
| Language(s) | EN |
| Description | Title 21 —Food and Drugs
Chapter I —Food and Drug Administration, Department of Health and Human Services Subchapter A—General Part 11 Electronic Records; Electronic Signatures https://www.ecfr.gov/current/title-21 |
| Official source | Official link |
| Restricted access | No |
| Submitted by | Florian Adragna |
| Contributors | |
| Reference Details | |
|---|---|
| Module | Module 4 — Unit 4.2.4 |
| Scope | G |
| Document part | § 11.300 |
| Language | EN |
| Original entry by | Florian Adragna |
| Contributors | |
| Tags | Electronic signature, Remote access, Device system |
Content
§ 11.300 Controls for identification codes/passwords. Persons who use electronic signatures based upon use of identification codes in combination with passwords shall employ controls to ensure their security and integrity. Such controls shall include: (a) Maintaining the uniqueness of each combined identification code and password, such that no two individuals have the same combination of identification code and password. (b) Ensuring that identification code and password issuances are periodically checked, recalled, or revised (e.g., to cover such events as password aging). (c) Following loss management procedures to electronically deauthorize lost, stolen, missing, or otherwise potentially compromised tokens, cards, and other devices that bear or generate identification code or password information, and to issue temporary or permanent replacements using suitable, rigorous controls. (d) Use of transaction safeguards to prevent unauthorized use of passwords and/or identification codes, and to detect and report in an immediate and urgent manner any attempts at their unauthorized use to the system security unit, and, as appropriate, to organizational management. (e) Initial and periodic testing of devices, such as tokens or cards, that bear or generate identification code or password information to ensure that they function properly and have not been altered in an unauthorized manner.