Difference between revisions of "Template:LIMSpec for Cannabis Testing/System administration"

From CannaQAWiki
Jump to navigationJump to search
(Formatting)
Line 5: Line 5:
   ! colspan="2" style="text-align:left; padding-left:20px; padding-top:10px; padding-bottom:10px;"|
   ! colspan="2" style="text-align:left; padding-left:20px; padding-top:10px; padding-bottom:10px;"|
  |-
  |-
   ! style="color:brown; background-color:#ffffee; width:175px;"| Regulation, Specification, or Guidance
   ! style="color:brown; background-color:#ffffee; width:150px;"| Regulation, Specification, or Guidance
   ! style="color:brown; background-color:#ffffee; width:700px;"| Requirement
   ! style="color:brown; background-color:#ffffee; width:700px;"| Requirement
  |-  
  |-  

Revision as of 18:01, 30 January 2021

Regulation, Specification, or Guidance Requirement

21 CFR Part 11.200 (a)
45 CFR Part 164.312
45 CFR Part 170.315 (d-5)
ASTM E1578-18 S-3-1
CJIS Security Policy 5.5.5
NIST 800-53, Rev. 4, AC-11

25.1 The system shall provide administrators with a configurable period of time to apply to user access or inactivity before again prompting a user for authentication credentials.
 


 
ASTM E1578-18 S-3-2 25.2 The system should provide a means for modifying personnel data in a batch.
 


 
ASTM E1578-18 S-3-3 25.3 The system should support the storage and export of data in standard and industry-specific data formats, e.g., CSV, especially for regulatory reporting purposes.
 


 

7 CFR Part 331.11
9 CFR Part 121.11
21 CFR Part 11.10 (d)
21 CFR Part 211.68 (b)
42 CFR Part 73.11
45 CFR Part 164.308
45 CFR Part 164.514
ASTM E1578-18 S-3-7
CJIS Security Policy 5.5.1
CJIS Security Policy 5.5.2.4
CJIS Security Policy Appendix G.5
EPA 815-R-05-004 Chap. IV, Sec. 8.6
EPA 815-R-05-004 Chap. VI, Sec. 8.6
EPA ERLN Laboratory Requirements 4.1.14–15
ISO 15189:2012 5.10.2
NIST 800-53, Rev. 4, AC-2(7) and AC-3
NIST 800-53, Rev. 4, IA-2 and IA-8
NIST 800-53, Rev. 4, MA-4
NIST 800-53, Rev. 4, PS-4 and PS-5
USDA Administrative Procedures for the PDP 5.2.4
USDA Administrative Procedures for the PDP 5.5.1.2

25.4 The system shall support the ability to define, record, and change the level of access for individual users to system groups, roles, machines, processes, and objects based on their responsibilities, including when those responsibilities change. The system should be able to provide a list of individuals assigned to a given system group, role, machine, process, or object.
 


 
ASTM E1578-18 S-3-8 25.5 The vendor should provide maintenance agreements and support services for its applications and services.
 


 
ASTM E1578-18 S-3-9

E.U. Annex 11-3.3
NIST 800-53, Rev. 4, SA-16
USDA Administrative Procedures for the PDP 5.2.4

25.6 The vendor shall provide help desk, training, and installation support, as well as high-quality system documentation. The documentation should be reviewed to ensure that user requirements are fulfilled.
 


 

7 CFR Part 331.11
9 CFR Part 121.11
21 CFR Part 11.10 (c)
42 CFR Part 73.11
45 CFR Part 164.310
AAVLD Requirements for an AVMDL Sec. 5.4.4.3
ABFT Accreditation Manual Sec. D-5–D-8
ASCLD/LAB Supp. Reqs. for the Accreditation of Forensic Science Testing Laboratories 5.4.7.2.1
ASTM E1492-11 4.2.4
CJIS Security Policy 5.5.2
CJIS Security Policy 5.8.1
EPA ERLN Laboratory Requirements 4.9.6
E.U. Annex 11-7.1
E.U. Annex 11-12
ISO 15189:2012 5.10.2
ISO/IEC 17025:2017 7.11.3
NIST 800-53, Rev. 4, MA-5
NIST 800-53, Rev. 4, MP-2
NIST 800-53, Rev. 4, PE-3, PE-3(1), PE-6, PE-6(1), and PE-6(4)
USDA Administrative Procedures for the PDP 5.2.1

25.7 The vendor shall restrict logical access to database storage components to authorized individuals. If providing a hosted service, the vendor should also restrict physical access to database storage components to authorized individuals. (In the case of an on-site solution, the buyer is responsible for limiting physical access to database storage components to meet 21 CFR Part 11, HIPAA, and CJIS guidelines.)
 


 
CJIS Security Policy 5.5.1 25.8 The system shall be able to tag and document an individual, group, and system account as having been validated for regulatory purposes, and remind the administrator or authorized personnel on a configurable schedule when the account should be validated again.
 


 

7 CFR Part 331.17
9 CFR Part 121.17
42 CFR Part 73.17
ASTM E1578-18 S-3-10

25.9 The system should provide a means of integrating with an enterprise personnel security directory, as well as physical security systems.
 


 

7 CFR Part 331.11
9 CFR Part 121.11
42 CFR Part 73.11
ASTM E1578-18 S-3-11
CJIS Security Policy 5.10.4.1
EPA ERLN Laboratory Requirements 4.9.13
NIST 800-53, Rev. 4, SI-2(5)

25.10 The vendor should provide timely upgrades and patches, with complete documentation, that have been tested before installation and can be rolled back.
 


 
ASTM E1578-18 S-3-12 25.11 The system shall provide a means for migrating data to a new release upon system upgrade.
 


 
ASTM E1578-18 S-3-13 25.12 The system should be expedient with the retrieval of stored items.
 


 
21 CFR Part 11.10 (b)
E.U. Annex 11-5
E.U. Annex 11-8.1
25.13 The system shall allow the printing of stored electronic records in a complete, accurate, and human-readable format.
 


 
ASTM E1578-18 S-3-14 25.14 The system should provide some sort of support for use on mobile technologies, particularly for the purpose of receiving notifications and monitoring processes.
 


 
ASTM E1578-18 S-3-15

EPA ERLN Laboratory Requirements 4.9.13
NIST 800-53, Rev. 4, CM-3(2)
NIST 800-53, Rev. 4, SI-2

25.15 The system shall be able to install an upgrade into a test environment for testing purposes before upgrading the actual production environment.