IMPLEMENTATION OF AN ELECTRONIC DOCUMENT MANAGEMENT SYSTEM
|
|
|
- Kerrie Allison
- 10 years ago
- Views:
Transcription
1 IMPLEMENTATION OF AN ELECTRONIC DOCUMENT MANAGEMENT SYSTEM TECHNICAL SPECIFICATIONS FOR AGENCIES AND BROKERS ACTING ON THEIR ACCOUNT DATA PRESERVATION EXPLANATORY NOTES : The preservation of information refers particularly to two aspects that should be distinguished : - Storage: Recording information for future re- use. Storage must make information available to the persons authorized to re- use it. - Backup: Backup is the action of duplicating system data and keeping it in a safe place so that the system data can be restored following an equipment breakdown (hard drive system failure) or an undesired or accidental modification of the data. Content: The designer should describe the files that are included in the backup procedure and the full content that is backed up. Specify if the system data is stored in a file system or in a database or both. o Examples: System data is backed up in a database. The whole database used for the solution is backed up, including system management data. System data is backed up in files and not in a database. Only the files of active brokers are backed up. Storage unit: The designer should indicate the type of storage units that are used for file backup. o Examples: Local external hard drive; Network Attached Storage (NAS); Backup sent to an enterprise specialized in data backup; Magnetic tape.
2 Procedure: The designer should describe the backup procedure by indicating the strategy (use of full backup, incremental backup; differential backup). The procedure must indicate the frequency, the period of retention of different types of backup, the daily, weekly, monthly and annual backup techniques, if applicable. o Examples: A full backup of database is carried out every night. This copy is then sent to an enterprise specialized in backup and is kept for two months. A full back up is made every week on Monday at midnight (kept for 2 weeks) and a differential backup is done every day at midnight (kept for 2 weeks). A full backup is made every day at midnight (kept for one month on an external local hard drive and sent on a daily basis to the external backup department for conservation for a week). An incremental backup is performed every hour (kept for two days on a network hard drive). Storage location: The designer must indicate the storage location of the backup copies. These copies must be stored offsite of the residence location of the source information, in a secure location protected from bad weather and damage. o Examples: The backup is made on a network hard drive located outside of the system operation site; the servers location containing these hard drives is secured and its access is possible only for persons responsible for backups; As the backup is made on magnetic tapes in the system operation premises, this necessitates bringing these tapes, on a daily basis, in a fireproof safe to an external location to [ ]. Retrieval: The designer must explain the procedure for file retrieval in the event of a major breakdown as well as the estimated time of retrieval. System Redundancy: The designer must indicate the redundancy strategy in place. o If there is no strategy/ system redundancy in place, the designer must indicate : The maximum period during which a data loss may occur as a result of the data backup strategy.
3 The process that he intends to put in place to guard against data losses, should an equipment breakdown occur between two data backups. Backup log: The designer must be able to present a backup log (or an execution log) indicating the various parameters of performing backups. The backup log must contain at least the following elements: the backup date, backup type, and anomalies, if any.
4 DATA INTEGRITY EXPANATORY NOTE: The integrity of a document results from two elements : - When there is a possibility to verify that data is not altered and is fully maintained. - When the medium carrying this data provides it with the stability and durability required. The criteria below aim at ensuring that these two elements are respected. Proof of integrity: The designer must describe the mechanisms that ensure data integrity. The designer must prove beyond all reasonable doubt that the data cannot be altered fraudulently or inadvertently. Recording of transactions: The designer must demonstrate the procedure for tracking transactions effected in the system. The record must indicate the person carrying out the transaction, the time and date of the transaction, and the data that was affected. List all actions and the users group that made them and triggered an entry in the transactions log. Provide a copy of the transactions log and the details of a log entry.
5 SECURITY OF ACCESS EXPLANATORY NOTE: The OACIQ has the mandate to certify that the EDM systems respond well to the following concepts : - Confidentiality: Only the legitimate recipient (or owner) of a document may have an intelligible vision of it. - Authentication: When sending a document or when connecting to a system, we surely know the identity of the sender or the identity of the user who logged in. - Integrity: We have the guarantee that a document has not been altered, either accidently of intentionally. - Non- repudiation: the author of a document cannot deny his work. The criteria below aims at ensuring that these four concepts are respected. Allocation of access: The designer must indicate the access management tools used; and indicate which group of individuals or which individual authorizes which individuals and the mechanisms that guarantee individual access privacy (password modification). User groups: The designer must indicate the user groups that have access to the system. This description must define the users who are part of these groups, their rights and their privileges. Indicate the functionalities to which each group has access (E.g. consultation, edition, deletion, transmission, etc.) Indicate what data these groups may consult, modify, add, delete, and transmit. Maintenance of privacy of access: The designer must indicate the mechanisms that ensure the maintenance of the users' privacy of access, particularly in the case where the application is accessible to clients and an online authentication is required Cancellation of access rights: The designer must describe the process for interrupting system access to those who no longer have privileges, whatever the reason is: agency change, end of the subscription to the service, etc. The process must allow timely recognition of access cancellation and immediate interruption of access. System access management through Internet: in the case of an EDM system accessible via Internet, the designer must demonstrate system authentication mechanisms that meet the minimal class 2 standard. This level requires:
6 o Allocating a user ID and password after presentation of supporting documents, either in person or otherwise. The individuals responsible for allocating access must ensure that they allocate it to the right user. In the case where it is the agency that manages brokers access to the Web system. The designer must provide the agency with the appropriate procedure for managing system access while respecting the minimal standard as described above. Network system access management: If the solution is accessible through the agency internal network, the agency must then include the access methods to the physical location from which the solution is accessible.
7 SYSTEM CONTENT TYPES Management of registers and records prescribed by the Regulation respecting records, books and registers, trust accounting and inspection of brokers and agencies: The system must allow the management of all registers and records prescribed by the Regulation or some of them. The designer must identify the type of registers or records assumed by the system and describe the mechanisms that ensure the inclusion of documents according to the record evolution context and dependency between documents. Depending on the record type (listing, transaction, etc.), it cannot be completed without including in it the mandatory documents and information. The system must allow attaching to a record any type of document required for its completion. During the record evolution, some documents become mandatory. Therefore, they must be mandatory at certain times, depending on the record status. o Examples: A listing record must include a brokerage contract. The sale of a co- ownership must contain an agreement of co- ownership. When submitting an accepted promise to purchase with a down payment, the copy and the trust cheque receipt must be added to the record. Etc.
8 INFORMATION SHARING Description of information- sharing tool: The designer shall present the information- sharing tool that is included in the application. The designer must define the elements that may be shared using this tool, and the information- sharing automation level. If possible, provide s screen shot to illustrate the information- sharing functionality. o Example: The tool enables brokers to send, by only, a document that is a part of a record, or all documents contained in a record. Management of access to information- sharing tool: The designer must detail the process of security and restriction of access to the information- sharing system. Indicate which user groups that can use the information- sharing tool. Indicate what information these users can share. Indicate how the agency manager shall define the roles and responsibilities of the users of the information sharing application. o Examples: Only users of "Brokers" group can use the information sharing tool, and they can send only their own records or the documents contained in their records. Users of "Administrative assistant" group can only send the records (or documents of a record) belonging to "Brokers" users group with which they are associated. Background: the designer shall describe the mechanisms for recording information- sharing transactions. The log must include, at minimum, the date, the time the sharing began and the recipient. List all sending actions and the user groups that made them and triggered an entry in the information- sharing transactions log. Provide a copy of information- sharing transactions log as well as details of an entry in the information- sharing transactions log.
9 DOCUMENT AUTHENTICATION Document digitization: The designer shall describe the digitization procedure that ensures maximum efficiency and security. The procedure must specify the required steps for digitization to avoid the loss or improper tagging of a document. Procedure must also describe the settings that will ensure the best image quality depending on the type of digitized document. The designer must abide by the requirement of the Legal framework for information technology Act concerning digitization. For more details, consult the article No "Document before you destroy!"and the article No " Electronic document management: Digitisation, give it more importance " available on the OACIQ website. Note: The OACIQ recognizes the digitization settings recommended by the Bibliothèque et Archives Nationales du Québec (BANQ) i.e., an image resolution of 300 dpi. Authentication of documents: The designer shall indicate the procedure put in place to ensure that the information will be viewed only by the persons concerned, that the author of the block of information is known, that the information has not been altered either accidentally or intentionally, and that the author cannot deny having made the change. Handwritten Signature: The designer must prove that all documents that have been hand signed cannot be altered from the time they are signed until the time they are filed in the EDM system. o Example : Documents that have to be signed and that are attached to a record must be in PDF format. Thus, these documents cannot be altered accidently, and it is impossible for a broker (or any other user) to change a document that is already in the system.
10 RECORDS TRANSFER EXPLANATORY NOTE: The record transfer function manages the exchange of real estate brokerage records during movements of real estate brokers (broker change of agency, termination of broker s employment, or an agency shutdown, etc.). The designer must give details of a transfer of the records of an agency ( or of a broker acting on his own account) that uses the system described below, according to three scenarios: To an agency that uses the same system. To another EDM system. To paper (no EDM system). Definition of the functionality or the records transfer process: the designer must describe the functionality or the record transfer process or both. Access management to the record transfer tool: the designer must define the access security mechanisms to the record transfer tool. This criterion is related to the "ACCESS SECURITY" section, particularly to the "User groups" and "Allocation of access" criteria. o Example: Only users of the "Agency administrator" group can access the transfer functionalities of the solution. Transfer mechanisms: the designer must indicate the transfer mechanisms depending on the case where the recipient uses the same system, uses another EDM system or does not use any system. Information security: the designer must indicate the methods of respect of information privacy when transferring records. o Example: Transfer of records from system X to another system X are carried out by a secured (SFTP) transfer FTP, which crypts the data sent and, therefore, guarantees the privacy of information transmitted. o History: the designer shall establish a history of all record transfer transactions. o Example :
11 This history can be generated automatically by the system if the latter allows the automatic transfer of broker or agency records. The history shall include the date and time of the transfer, the requester, the files impacted, the recipient, and the acknowledgment of receipt. It can also be done in writing, in the form of acknowledgment of receipt signed by the EDM system designer and the broker or agency. This acknowledgment of receipt must include the date and time of the transfer, the requester, the files impacted, and the recipient. List all transfer actions and user groups that made them and triggered an entry in the information- sharing log. Provide a copy of the transfer transactions log or the acknowledgment of receipt of the transfer transaction. Sending a notification to the OACIQ: the designer or the agency must inform the OACIQ when an agency using the EDM system ceases its activities, by indicating the date the records were sent, the name of the applicant, the affected files and the name of the recipient. Data backup: Data must have a secured residence location at all times. In the case where the agency ceases it activity and that no recipient agency is assigned, the agency or the broker working on his account must inform the OACIQ of the storage location of documents for the next six years.
12 SEARCH CRITERIA FOR RECORDS AND DOCUMENTS EXPLANATORY NOTE: Search criteria of an application are the representation of the system designer of the needs of users. In this case; the OACIQ constitutes a group of users. Therefore, the designer must take into consideration the research needs of the OACIQ inspection and syndic groups. These consultation methods must be protected and reserved for the OACIQ inspection and investigation purposes in order to preserve the information privacy. OACIQ search methods: The designer must describe the search mechanisms of records and documents reserved for the Organization. If possible, provide a screen shot to illustrate the search functionality reserved for the OACIQ. OACIQ search tools security: The designer must demonstrate that the search tools reserved for the OACIQ are secure and that only the OACIQ recognized authorities have access to this functionality. This criterion is related to the "ACCESS SECURITY" section, particularly to the "User groups" and "Allocation of access" criteria Search method: The designer must demonstrate that the search mechanisms reserved for users allow retrieving only the documents to which the user is authorized. This criterion is related to the "ACCESS SECURITY" section, particularly to the "User groups" and "Allocation of access" criteria
13 RECOMMENDATIONS MADE TO USERS AND USE PROCEDURES A system designed in full conformity with the confidentiality, integrity and information preservation rules may be used inappropriately. This would cause a contravention of the ethical and professional requirements, established by the Real Estate Brokerage Act (R.S.Q., c. C- 73.2) and its different application regulations. Therefore, it is important that the designers of an EDM system provide with their solution a user guide and recommendations so that all users should be informed of the measures to take to ensure that these requirements are met and that the integrity, confidentiality and the information preservation are not compromised. To complete his accreditation, the designer must provide to the OACIQ the relevant documentation that given to their system users. These documents must provide all necessary information to all user groups (agency managers, brokers, office staff, etc.) so that the system is used in a way that does not contravene the ethical and professional requirements, established by the Real Estate Brokerage Act (R.S.Q., c. C- 73.2) and its different application regulations. The recommendations should focus, among others, on the following points: system access allocation, access withdrawal, management of access given to external third parties (clients, etc.), system access management in case of a network system or a system functioning through Internet, procedure to follow for digitizing documents, preservation of the integrity of documents, etc.
IMPLEMENTATION OF AN ELECTRONIC DOCUMENT MANAGEMENT SYSTEM TECHNICAL SPECIFICATIONS FOR AGENCIES AND BROKERS ACTING ON THEIR ACCOUNT
IMPLEMENTATION OF AN ELECTRONIC DOCUMENT MANAGEMENT SYSTEM TECHNICAL SPECIFICATIONS FOR AGENCIES AND BROKERS ACTING ON THEIR ACCOUNT IMPORTANT The OACIQ reserves the right to change its requirements based
A broker or agency must maintain six types of registers and five types of records at their establishment.
Instructions to agencies and brokers acting on their own account for maintaining records and registers Unless otherwise dictated by context and for ease of reading, the term AGENCY in this document includes
DIGITIZATION S GUIDE. Go for quality and document your process!
DIGITIZATION S GUIDE Go for quality and document your process! DIGITIZATION: GO FOR QUALITY AND DOCUMENT YOUR PROCESS! (Source: La numérisation des documents administratifs Méthodes et recommandations
AP 417 Information and Communication Services
AP 417 Information and Communication Services Background Access and use of information and communication services (ICS) are an integral component of the learning and working environment. The ability for
This policy is not designed to use systems backup for the following purposes:
Number: AC IT POL 003 Subject: Backup and Restore Policy 1. PURPOSE The backup and restore policy establishes the need and rules for performing periodic system backup to permit timely restoration of Africa
FRONTIER REGIONAL/UNION#38 SCHOOL DISTRICTS. Records Retention Policy for Electronic Correspondence
EH I. Introduction FRONTIER REGIONAL/UNION#38 SCHOOL DISTRICTS Records Retention Policy for Electronic Correspondence All business conducted by government agencies are subject to the Public Records law
CoSign for 21CFR Part 11 Compliance
CoSign for 21CFR Part 11 Compliance 2 Electronic Signatures at Company XYZ Company XYZ operates in a regulated environment and is subject to compliance with numerous US government regulations governed
Supplement to the Guidance for Electronic Data Capture in Clinical Trials
Supplement to the Guidance for Electronic Data Capture in Clinical Trials January 10, 2012 Drug Evaluation Committee, Japan Pharmaceutical Manufacturers Association Note: The original language of this
Data Management Policies. Sage ERP Online
Sage ERP Online Sage ERP Online Table of Contents 1.0 Server Backup and Restore Policy... 3 1.1 Objectives... 3 1.2 Scope... 3 1.3 Responsibilities... 3 1.4 Policy... 4 1.5 Policy Violation... 5 1.6 Communication...
Chapter 8: Security Measures Test your knowledge
Security Equipment Chapter 8: Security Measures Test your knowledge 1. How does biometric security differ from using password security? Biometric security is the use of human physical characteristics (such
Guideline on Auditing and Log Management
CMSGu2012-05 Mauritian Computer Emergency Response Team CERT-MU SECURITY GUIDELINE 2011-02 Enhancing Cyber Security in Mauritius Guideline on Auditing and Log Management National Computer Board Mauritius
Policy for the Acceptable Use of Information Technology Resources
Policy for the Acceptable Use of Information Technology Resources Purpose... 1 Scope... 1 Definitions... 1 Compliance... 2 Limitations... 2 User Accounts... 3 Ownership... 3 Privacy... 3 Data Security...
Newcastle University Information Security Procedures Version 3
Newcastle University Information Security Procedures Version 3 A Information Security Procedures 2 B Business Continuity 3 C Compliance 4 D Outsourcing and Third Party Access 5 E Personnel 6 F Operations
Vendor Questions. esignatures Request for information InsureSign
InsureSign Vendor Questions 1. Legal Compliance Questionnaire This section corresponds to legal requirements as outlined in the CSIO esignatures Advisory Report prepared by Fasken Martineau LLP. 1. Signing
SUBJECT: SECURITY OF ELECTRONIC MEDICAL RECORDS COMPLIANCE WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)
UNIVERSITY OF PITTSBURGH POLICY SUBJECT: SECURITY OF ELECTRONIC MEDICAL RECORDS COMPLIANCE WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA) DATE: March 18, 2005 I. SCOPE This
APGO GUIDANCE ON DOCUMENT AUTHENTICATION. Table of Contents
1.0 Introduction Table of Contents 2.0 Document Authentication: The Basics 2.1 The Purpose of the Seal 2.2 The Practice of Authentication 3.0 Document Authentication: Application 3.1 The Authentication
Cyber Security: Guidelines for Backing Up Information. A Non-Technical Guide
Cyber Security: Guidelines for Backing Up Information A Non-Technical Guide Essential for Executives, Business Managers Administrative & Operations Managers This appendix is a supplement to the Cyber Security:
Backup and Recovery. What Backup, Recovery, and Disaster Recovery Mean to Your SQL Anywhere Databases
Backup and Recovery What Backup, Recovery, and Disaster Recovery Mean to Your SQL Anywhere Databases CONTENTS Introduction 3 Terminology and concepts 3 Database files that make up a database 3 Client-side
Code - A Date Approved: July 24/01
Page 1 of 10 Date Last Revision: Feb 12/08 POLICY STATEMENT AND PURPOSE The County of Elgin provides employees, elected officials, and other organizations and individuals with access to computer and network
InfinityQS SPC Quality System & FDA s 21 CFR Part 11 Requirements
InfinityQS SPC Quality System & FDA s 21 CFR Part 11 Requirements www.infinityqs.com Copyright InfinityQS International Table of Contents Overview... FDA s 21 CFR Part 11 Requirements... PART 11 ELECTRONIC
CERTIFICATION POLICY QUEBEC CERTIFICATION CENTRE. 2015 Notarius Inc.
CERTIFICATION POLICY QUEBEC CERTIFICATION CENTRE 2015 Notarius Inc. Document Version: 4.5 OID: 2.16.124.113550 Effective Date: July 17, 2015 TABLE OF CONTENTS 1. GENERAL PROVISIONS...8 1.1 PURPOSE...8
IBX Business Network Platform Information Security Controls. 2015-02- 20 Document Classification [Public]
IBX Business Network Platform Information Security Controls 2015-02- 20 Document Classification [Public] Table of Contents 1. General 2 2. Physical Security 2 3. Network Access Control 2 4. Operating System
Electronic Record Management Guidelines for Arkansas State Government. Developed by the Arkansas Records Retention Workgroup
Electronic Record Management Guidelines for Arkansas State Government Developed by the Arkansas Records Retention Workgroup October 2005 This page is blank to allow for correct pagination for duplex printing.
HIPAA Security Alert
Shipman & Goodwin LLP HIPAA Security Alert July 2008 EXECUTIVE GUIDANCE HIPAA SECURITY COMPLIANCE How would your organization s senior management respond to CMS or OIG inquiries about health information
The Impact of 21 CFR Part 11 on Product Development
The Impact of 21 CFR Part 11 on Product Development Product development has become an increasingly critical factor in highly-regulated life sciences industries. Biotechnology, medical device, and pharmaceutical
rsdm and 21 CFR Part 11
rsdm and 21 CFR Part 11 Meeting the 21 CFR Part 11 Burden without Overburdening The right solutions for smaller biopharma. Nothing more. Nothing less. Prepared by: Ken VanLuvanee www.virtualregulatorysolutions.com
REGULATIONS COMPLIANCE ASSESSMENT
ALIX is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation. REGULATIONS COMPLIANCE ASSESSMENT BUSINESS
CANADIAN PAYMENTS ASSOCIATION ASSOCIATION CANADIENNE DES PAIEMENTS STANDARD 012 IMAGE SECURITY STANDARD
CANADIAN PAYMENTS ASSOCIATION ASSOCIATION CANADIENNE DES PAIEMENTS STANDARD 012 IMAGE SECURITY STANDARD 2013 CANADIAN PAYMENTS ASSOCIATION 2013 ASSOCIATION CANADIENNE DES PAIEMENTS This Rule is copyrighted
United States Citizenship and Immigration Services (USCIS) Enterprise Service Bus (ESB)
for the United States Citizenship and Immigration Services (USCIS) June 22, 2007 Contact Point Harry Hopkins Office of Information Technology (OIT) (202) 272-8953 Reviewing Official Hugo Teufel III Chief
How To Backup Your Hard Drive With Pros 4 Technology Online Backup
Pros 4 Technology Online Backup Features Introduction Computers are the default storage medium for most businesses and virtually all home users. Because portable media is quickly becoming an outdated and
Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID MOS10
Microsoft Online Subscription Agreement/Open Program License Amendment Microsoft Online Services Security Amendment Amendment ID This Microsoft Online Services Security Amendment ( Amendment ) is between
E-mail Management: A Guide For Harvard Administrators
E-mail Management: A Guide For Harvard Administrators E-mail is information transmitted or exchanged between a sender and a recipient by way of a system of connected computers. Although e-mail is considered
Table of Contents. Chapter No. 1. Introduction 1. 2. Objective 1. 3. E-mail Use Compliance 1. 4. Definitions 2. 5. Roles and Responsibilities 2
Table of Contents Chapter Subject Page No. 1. Introduction 1 2. Objective 1 3. E-mail Use Compliance 1 4. Definitions 2 5. Roles and Responsibilities 2 6. Creation and Use of E-mails 3 7. Managing E-mails
How To Protect Documents From Being Stolen
SECOND SESSION THIRTY-SIXTH LEGISLATURE Bill 161 (2001, chapter 32) An Act to establish a legal framework for information technology Introduced 14 November 2000 Passage in principle 30 November 2000 Passage
Empower TM 2 Software
Empower TM 2 Software 21 CFR PART 11 COMPLIANCE ASSESSMENT Revision A, December, 2005 1 of 14 Waters Corporation Note: Information presented in this document assumes that the appropriate Empower 2 System
Local Government Cyber Security:
Local Government Cyber Security: Guidelines for Backing Up Information A Non-Technical Guide Essential for Elected Officials Administrative Officials Business Managers Multi-State Information Sharing and
Implementation of 21CFR11 Features in Micromeritics Software Software ID
Implementation of 21CFR11 Features in Micromeritics Software Software ID PART 11 ELECTRONIC RECORDS; ELECTRONIC SIGNATURES Subpart A General Provisions Sec. 11.1 Scope. 11.2 Implementation. 11.3 Definitions.
FINAL May 2005. Guideline on Security Systems for Safeguarding Customer Information
FINAL May 2005 Guideline on Security Systems for Safeguarding Customer Information Table of Contents 1 Introduction 1 1.1 Purpose of Guideline 1 2 Definitions 2 3 Internal Controls and Procedures 2 3.1
1 Purpose... 2. 2 Scope... 2. 3 Roles and Responsibilities... 2. 4 Physical & Environmental Security... 3. 5 Access Control to the Network...
Contents 1 Purpose... 2 2 Scope... 2 3 Roles and Responsibilities... 2 4 Physical & Environmental Security... 3 5 Access Control to the Network... 3 6 Firewall Standards... 4 7 Wired network... 5 8 Wireless
InfoCenter Suite and the FDA s 21 CFR part 11 Electronic Records; Electronic Signatures
InfoCenter Suite and the FDA s 21 CFR part 11 Electronic Records; Electronic Signatures Overview One of the most popular applications of InfoCenter Suite is to help FDA regulated companies comply with
DeltaV Capabilities for Electronic Records Management
January 2013 Page 1 DeltaV Capabilities for Electronic Records Management This paper describes DeltaV s integrated solution for meeting FDA 21CFR Part 11 requirements in process automation applications
21 CFR PART 11 ELECTRONIC RECORDS, ELECTRONIC SIGNATURES 21.11.2013. 21 CFR Part 11 Compliance PLA 2.1
21 CFR PART 11 ELECTRONIC RECORDS, ELECTRONIC SIGNATURES Compliance of PLA 2.1 21.11.2013 21 CFR Part 11 Compliance PLA 2.1 SEC. 11.2 IMPLEMENTATION. (a) For records required to be maintained but not submitted
Recommendations for companies planning to use Cloud computing services
Recommendations for companies planning to use Cloud computing services From a legal standpoint, CNIL finds that Cloud computing raises a number of difficulties with regard to compliance with the legislation
Information Security Basic Concepts
Information Security Basic Concepts 1 What is security in general Security is about protecting assets from damage or harm Focuses on all types of assets Example: your body, possessions, the environment,
SVA Backup Plus Features
1221 John Q. Hammons Drive Madison, WI 53717 P.O. Box 44966, Madison, WI 53717 P: 608.826.2400 TF: 800.366.9091 F: 608.831.4243 www.sva.com Introduction Computers are the default storage medium for most
THE ELECTRONIC TRANSACTIONS LAW,
CAYMAN ISLANDS Supplement No.2 published with Gazette No.19 dated Monday 11 th September, 2000 THE ELECTRONIC TRANSACTIONS LAW, 2000 (LAW 7 OF 2000) 2 THE ELECTRONIC TRANSACTIONS LAW, 2000 ARRANGEMENT
MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE
WHITE PAPER MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE 1. OVERVIEW Do you want to design a file transfer process that is secure? Or one that is compliant? Of course, the answer is both. But it s
University of Liverpool
University of Liverpool Information Security Policy Reference Number Title CSD-003 Information Security Policy Version Number 3.0 Document Status Document Classification Active Open Effective Date 01 October
<Choose> Addendum Windows Azure Data Processing Agreement Amendment ID M129
Addendum Amendment ID Proposal ID Enrollment number Microsoft to complete This addendum ( Windows Azure Addendum ) is entered into between the parties identified on the signature form for the
Declaration of Conformity 21 CFR Part 11 SIMATIC WinCC flexible 2007
Declaration of Conformity 21 CFR Part 11 SIMATIC WinCC flexible 2007 SIEMENS AG Industry Sector Industry Automation D-76181 Karlsruhe, Federal Republic of Germany E-mail: [email protected] Fax: +49
State of Michigan Records Management Services. Frequently Asked Questions About E mail Retention
State of Michigan Records Management Services Frequently Asked Questions About E mail Retention It is essential that government agencies manage their electronic mail (e mail) appropriately. Like all other
HIPAA Security. assistance with implementation of the. security standards. This series aims to
HIPAA Security SERIES Security Topics 1. Security 101 for Covered Entities 2. Security Standards - Administrative Safeguards 3. Security Standards - Physical Safeguards 4. Security Standards - Technical
Online Backup Solution Features
CCC Technologies, Inc. 700 Nicholas Blvd., Suite 300 Elk Grove Village, IL 60007 877.282.9227 www.ccctechnologies.com Online Backup Solution Features Introduction Computers are the default storage medium
Gatekeeper PKI Framework. February 2009. Registration Authority Operations Manual Review Criteria
Gatekeeper PKI Framework ISBN 1 921182 24 5 Department of Finance and Deregulation Australian Government Information Management Office Commonwealth of Australia 2009 This work is copyright. Apart from
Oracle WebCenter Content
Oracle WebCenter Content 21 CFR Part 11 Certification Kim Hutchings US Data Management Phone: 888-231-0816 Email: [email protected] Introduction In May 2011, US Data Management (USDM) was
CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline)
CORPORATE RECORD RETENTION IN AN ELECTRONIC AGE (Outline) David J. Chavolla, Esq. and Gary L. Kemp, Esq. Casner & Edwards, LLP 303 Congress Street Boston, MA 02210 A. Document and Record Retention Preservation
INDEPENDENT AUDIT REPORT BASED ON THE REQUIREMENTS OF ETSI TS 101 456. Aristotle University of Thessaloniki PKI (www.pki.auth.gr) WHOM IT MAY CONCERN
Title INDEPENDENT AUDIT REPORT BASED ON THE REQUIREMENTS OF ETSI TS 101 456 Customer Aristotle University of Thessaloniki PKI (www.pki.auth.gr) To WHOM IT MAY CONCERN Date 18 March 2011 Independent Audit
Introduction. Ease-of-Use
Remote Data Backup Introduction Computers are the default storage medium for most businesses and virtually all home users. Because portable media is quickly becoming an outdated and expensive method for
15 Organisation/ICT/02/01/15 Back- up
15 Organisation/ICT/02/01/15 Back- up 15.1 Description Backup is a copy of a program or file that is stored separately from the original. These duplicated copies of data on different storage media or additional
Full Compliance Contents
Full Compliance for and EU Annex 11 With the regulation support of Contents 1. Introduction 2 2. The regulations 2 3. FDA 3 Subpart B Electronic records 3 Subpart C Electronic Signatures 9 4. EU GMP Annex
Information Systems Security Assessment
Physical Security Information Systems Security Assessment 1. Is the server protected from environmental damage (fire, water, etc.)? Ideal Answer: YES. All servers must be housed in such a way as to protect
21 CFR Part 11 Compliance Using STATISTICA
21 CFR Part 11 Compliance Using STATISTICA Last Updated: April 2003 This document was updated to reflect the FDA s latest guidance (released February, 2003) and the withdrawal of previous guidance.! STATSOFT
Southern Law Center Law Center Policy #IT0004. Title: Email Policy
Southern Law Center Law Center Policy #IT0004 Title: Email Policy Authority: Department Original Adoption: 7/20/2007 Effective Date: 7/20/2007 Last Revision: 9/17/2012 1.0 Purpose: To provide members of
Music Recording Studio Security Program Security Assessment Version 1.1
Music Recording Studio Security Program Security Assessment Version 1.1 DOCUMENTATION, RISK MANAGEMENT AND COMPLIANCE PERSONNEL AND RESOURCES ASSET MANAGEMENT PHYSICAL SECURITY IT SECURITY TRAINING AND
Evolved Backup Features Computer Box 220 5th Ave South Clinton, IA 52732 www.thecomputerbox.com 563-243-0016
Evolved Backup Features 1 Contents 3 Introduction 3 Ease-of-Use Simple Installation Automatic Backup Off-Site Storage Scalability File Restoration 24/7 6 Security File Compression Encryption Transmission
Authentication of Documents/Use of Professional Stamps
Authentication of Documents/Use of Professional Stamps 1 Introduction The intention of this guideline is to amplify and clarify requirements for authentication of documents and use of the stamp, based
Frequently Asked Questions About WebDrv Online (Remote) Backup
Frequently Asked Questions About WebDrv Online (Remote) Backup GENERAL INFORMATION Why backup? What is online backup? What if we already have a tape backup system? How secure are online backups? What tasks
EFFECTIVE DATE: JULY 1, 2010
Town of Florence POLICY TITLE: EMAIL RETENTION POLICY RESPONSIBLE DEPARTMENT: Town Clerk Office APPROVAL: EFFECTIVE DATE: JULY 1, 2010 AP / RESOLUTION NO.: 2010-02 REFERENCES: TOWN MANAGER SIGNATURE: TOWN
KAZAKHSTAN STOCK EXCHANGE
KAZAKHSTAN STOCK EXCHANGE A p p r o v e d by Kazakhstan Stock Exchange Board of Directors decision (minutes No. 15 of November 6, 2002) Effective from November 7, 2002 N O T I C E Rules have been translated
Certification Practice Statement
FernUniversität in Hagen: Certification Authority (CA) Certification Practice Statement VERSION 1.1 Ralph Knoche 18.12.2009 Contents 1. Introduction... 4 1.1. Overview... 4 1.2. Scope of the Certification
Information Technology Security Policies
Information Technology Security Policies Randolph College 2500 Rivermont Ave. Lynchburg, VA 24503 434-947- 8700 Revised 01/10 Page 1 Introduction Computer information systems and networks are an integral
Compliance Matrix for 21 CFR Part 11: Electronic Records
Compliance Matrix for 21 CFR Part 11: Electronic Records Philip E. Plantz, PhD, Applications Manager David Kremer, Senior Software Engineer Application Note SL-AN-27 Revision A Provided By: Microtrac,
Content Teaching Academy at James Madison University
Content Teaching Academy at James Madison University 1 2 The Battle Field: Computers, LANs & Internetworks 3 Definitions Computer Security - generic name for the collection of tools designed to protect
TRANSACTION MANAGEMENT IN ARIZONA
TRANSACTION MANAGEMENT IN ARIZONA AN ARIZONA ASSOCIATION OF REALTORS WHITE PAPER OCTOBER 2015 PURPOSE The purpose of this White Paper is to serve as a guideline to provide Arizona brokers information and
REVENUE REGULATIONS NO. 9-2009 issued on December 29, 2009 defines the requirements, obligations and responsibilities imposed on taxpayers for the
REVENUE REGULATIONS NO. 9-2009 issued on December 29, 2009 defines the requirements, obligations and responsibilities imposed on taxpayers for the maintenance, retention and submission of electronic records.
STATUTORY INSTRUMENTS 2012 No. _
STATUTORY INSTRUMENTS 2012 No. _ THE ELECTRONIC SIGNATURES REGULATIONS 2012 ARRANGEMENT OF REGULATIONS Regulation PART I-PRELIMINARY 1. Title. 2. Interpretation PART II - LICENSING AND RECOGNITION OF CERTIFICATION
TECHNOLOGY RESPONSIBLE USE Policy Code: 3225/4312/7320
TECHNOLOGY RESPONSIBLE USE Policy Code: 3225/4312/7320 The Edgecombe County Board of Education (the Board ) provides its students and staff access to a variety of technological resources. These resources
INFORMATION TECHNOLOGY MANAGEMENT CONTENTS. CHAPTER C RISKS 357-7 8. Risk Assessment 357-7
Information Technology Management Page 357-1 INFORMATION TECHNOLOGY MANAGEMENT CONTENTS CHAPTER A GENERAL 357-3 1. Introduction 357-3 2. Applicability 357-3 CHAPTER B SUPERVISION AND MANAGEMENT 357-4 3.
DeltaV Capabilities for Electronic Records Management
September 2004 Page 1 An integrated solution for meeting FDA 21CFR Part 11 requirements in process automation applications using a configurable off-the-shelf (COTS) solution Emerson Process Management.
Rackspace Archiving Compliance Overview
Rackspace Archiving Compliance Overview Freedom Information Act Sunshine Laws The federal government and nearly all state governments have established Open Records laws. The purpose of these laws is to
Document Management Getting Started Guide
Document Management Getting Started Guide Version: 6.6.x Written by: Product Documentation, R&D Date: February 2011 ImageNow and CaptureNow are registered trademarks of Perceptive Software, Inc. All other
Electronic records and electronic signatures in the regulated environment of the pharmaceutical and medical device industries
White Paper No 01 I December 2010 Implementation of 21 CFR Part 11 in the epmotion Software Electronic records and electronic signatures in the regulated environment of the pharmaceutical and medical device
