SDLC Methodologies and Validation



Similar documents
Computerised Systems. Seeing the Wood from the Trees

Computer System Validation for Clinical Trials:

CONTENTS. List of Tables List of Figures

The Software Development Life Cycle (SDLC)

Validating Enterprise Systems: A Practical Guide

Page 1 of 7 Effective Date: 12/18/03 Software Supplier Process Requirements

How To Write An Slcm Project Plan

Project Risk and Pre/Post Implementation Reviews

Computerized System Audits In A GCP Pharmaceutical Laboratory Environment

Unit I. Introduction

International Journal of Advance Research in Computer Science and Management Studies

Services Providers. Ivan Soto

Installation and Operational Qualification Protocol (Reference: SOP )

Computer System Validation - It s More Than Just Testing

Testing Automated Manufacturing Processes

Introduction to Cloud Computing What is SaaS? Conventional vs. SaaS Methodologies Validation Requirements Change Management Q&A

Your Software Quality is Our Business. INDEPENDENT VERIFICATION AND VALIDATION (IV&V) WHITE PAPER Prepared by Adnet, Inc.

PHASE 6: DEVELOPMENT PHASE

Template K Implementation Requirements Instructions for RFP Response RFP #

PHASE 8: IMPLEMENTATION PHASE

Re: RFP # 08-X MOTOR VEHICLE AUTOMATED TRANSACTION SYSTEM (MATRX) FOR MVC ADDENDUM #10

Implementing Title 21 CFR Part 11 (Electronic Records ; Electronic Signatures) in Manufacturing Presented by: Steve Malyszko, P.E.

PHASE 9: OPERATIONS AND MAINTENANCE PHASE

Considerations When Validating Your Analyst Software Per GAMP 5

Overview of STS Consulting s IV&V Methodology

Information Technology Policy

Independent Verification and Validation of SAPHIRE 8 Software Project Plan

The SaaS LMS and Total Cost of Ownership in FDA-Regulated Companies

TIBCO Spotfire and S+ Product Family

CS 389 Software Engineering. Lecture 2 Chapter 2 Software Processes. Adapted from: Chap 1. Sommerville 9 th ed. Chap 1. Pressman 6 th ed.

CDC UNIFIED PROCESS JOB AID

STS Federal Government Consulting Practice IV&V Offering

Software Engineering Introduction & Background. Complaints. General Problems. Department of Computer Science Kent State University

Chapter 8 Approaches to System Development

Essentials of the Quality Assurance Practice Principles of Testing Test Documentation Techniques. Target Audience: Prerequisites:

CLINICAL DATA MANAGEMENT

Computer and Software Validation Volume II

PHASE 5: DESIGN PHASE

When printed the document is for reference only and is considered uncontrolled - refer to the Document Control System for the most current version

unless the manufacturer upgrades the firmware, whereas the effort is repeated.

Welcome Computer System Validation Training Delivered to FDA. ISPE Boston Area Chapter February 20, 2014

Control No: QQM-02 Title: Quality Management Systems Manual Revision 10 07/08/2010 ISO 9001:2008 Page: 1 of 22

Attachment 7 Requirements Traceability Matrix (RTM) ATMS RFP. New York State Department of Transportation Advanced Traffic Management System

RTP s NUCLEAR QUALITY ASSURANCE PROGRAM

Risk-Based Validation of Computer Systems Used In FDA-Regulated Activities

CORPORATE QUALITY MANUAL

Domain 1 The Process of Auditing Information Systems

IT General Controls Domain COBIT Domain Control Objective Control Activity Test Plan Test of Controls Results

Montana Department of Transportation Information Services Division. System Development Life Cycle (SDLC) Guide

Overview of how to test a. Business Continuity Plan

U. S. Department of Energy Consolidated Audit Program Checklist 5 Laboratory Information Management Systems Electronic Data Management

A Systems Implementation Project Planning Guide. Solutions & Project Management Services for Systems & Operations Projects

Camar Aircraft Products Co. QUALITY MANUAL Revision D

ABSTRACT INTRODUCTION WINDOWS SERVER VS WINDOWS WORKSTATION. Paper FC02

Clinical database/ecrf validation: effective processes and procedures

QUALITY MANAGEMENT SYSTEM REQUIREMENTS General Requirements. Documentation Requirements. General. Quality Manual. Control of Documents

4.13 System Testing. Section 4 Bidder's Products, Methodology, and Approach to the Project System Training

ISO 9001:2008 Audit Checklist

Business Analysis Essentials

Pharma IT journall. Regular Features

The Software Life Cycle. CSE 308: Software Engineering

Objectives. The software process. Basic software process Models. Waterfall model. Software Processes

Test Plan (a Real Sample) SoftwareTestingHelp.com Live Project Training - OrangeHRM

Pharma CloudAdoption. and Qualification Trends

Software Development Process Models

The software process. Generic software process models. Waterfall model. Software Development Methods. Bayu Adhi Tama, ST., MTI.

International GMP Requirements for Quality Control Laboratories and Recomendations for Implementation

Guidance for electronic trial data capturing of clinical trials

PHASE 3: PLANNING PHASE

PHASE 3: PLANNING PHASE

Quality management systems

How to Survive an FDA Computer Validation Audit

SDLC- Key Areas to Audit in IT Projects ISACA Geek Week /21/2013. PwC

Table of Contents. Page 1 of 39

Computer System Configuration Management and Change Control

Using SharePoint 2013 for Managing Regulated Content in the Life Sciences. Presented by Paul Fenton President and CEO, Montrium

The Quality Assurance Centre of Excellence

TITLE: Control of Software

Validation of Digital Pathology Systems in the Regulated Nonclinical Environment

System Build 2 Test Plan

Elite: A New Component-Based Software Development Model

GOOD DOCUMENTATION AND QUALITY MANAGEMENT PRINCIPLES. Vimal Sachdeva Technical Officer (Inspector), WHO Prequalification of Medicines Programme

Updating Your Skills from Microsoft Exchange Server 2003 or Exchange Server 2007 to Exchange Server 2010 SP1

Colorado Department of Health Care Policy and Financing

Validated SaaS LMS SuccessFactors Viability

SEVEN KEY TACTICS FOR ENSURING QUALITY

PHASE 6: DEVELOPMENT PHASE

Preparing for an FDA Pre-Approval Inspection (PAI)

Internal Control Deliverables. For. System Development Projects

To introduce software process models To describe three generic process models and when they may be used

Powerful information management services and software for the oil, gas, and chemical industries

What is a life cycle model?

Overview. Disasters are happening more frequently and Recovery is taking on a different perspective.

Kern Health System CORE Software Professional Services RFP Responses to Questions/Request for Explanation

Software Engineering. Software Processes. Based on Software Engineering, 7 th Edition by Ian Sommerville

Revision Date Author Description of change Jun13 Mark Benton Removed Admin. Manager from approval

Updating Your Skills from Microsoft Exchange Server 2003 or Exchange Server 2007 to Exchange Server 2010 Course 10165; 5 Days, Instructor-led

Transcription:

SDLC Methodologies and Validation Presented by: Pamela Campbell Lead Consultant, Compliance Services DataCeutics, Inc. campbelp@dataceutics.com Presented for: DIA Annual Meeting, June 2004 Session 330 VA Validation, EDM, IT June 16, 2004 8:30am

Who We Are. The Leader in Information Technology Support and Services for the Clinical Research Environment Headquartered in Pottstown, PA Solutions include Services and Software Products Three Business Lines: Clinical Systems Services (CSS) Clinical Reporting Services (CRS) Computer Systems Compliance Services (CSCS) Expert Consultants

Our Computer Systems Compliance Philosophy... Computer Systems must be planned, designed, developed, tested, installed, operated, maintained, and archived according to regulations and acceptable industry and company standards

Agenda Validation The Phases of a Project Project Conception System Study Programming Acceptance Operational Maintenance Decommission Conclusions

Validation Validation The establishing of documented evidence through defined tests & challenges, that a system or process meets design criteria & that adequate provisions have been established to keep it in a state of control so it will produce a product that meets predetermined specifications and quality attributes. When done correctly validation creates sustainable, repeatable success! When done incorrectly validation becomes a burden that hinders business and results in audit findings and Form 483s.

Phases of a Project Project Management Conception Define Scope SDLC Validation Plan Validation System Study (Design) Programming Acceptance Operational Maintenance User / Function Requirements Design Code Unit Testing System and Integration Performance and User Acceptance Testing Installation Release User / Function Requirements Specification System Design Specification Vendor and Risk Assessments Code Reviews Unit Test Plan, Scripts, Matrix, Report System and Integration Plan, Scripts, Matrix, Report PQ/UAT Test Plan, Scripts, Matrix, Report IQ/OQ Plan, Execution, IQ/OQ Report, Validation Report Change Control, Backup Functioning under SOPs for change and Recovery, Archiving control, etc.

Project Conception Critical function definition of scope Both the project scope and the scope of the validation must be defined in this phase! Both should be defined in the validation plan. Scope creep will kill a project! Determine what is not covered by the project, examples: Network qualification Data Center qualification

System Study Chosen methodology for designing system should be spelled out in a SDLC SOP or the validation plan. Validation and project deliverables: User & Functional Requirement Specifications Remember requirements must be testable! Don t forget 21 CFR Part 11 & Predicate Rules! System Design Specification edms purchased system describe how the system is to be installed, configured, and programmed Matrix from UFRS to Design For Vendor systems Vendor Assessment! Risk Assessment

Development Methodologies (System Study) Waterfall Whirlpools Incremental / Spiral Prototyping Whichever is selected it must be documented in the validation plan and any matching SOPs!

Waterfall Conception Requirements Design Programming Code Review Unit Test SIT UAT Installation Operation Maintenance

Waterfall - issues Studies show waterfall method is 90% project management and 10% what is to be done and how to do it. Each phase feeds into the next and therefore there is no feedback creating a gap between end user and developers. No way to go back and fix mistakes. Very expensive to use. Takes a long time.

Whirlpool Conception Initial Iteration Conception Requirements Design Programming Code Review Unit Test SIT UAT Installation Operation Verification Loop Reconcile system to expectations Maintenance

Whirlpool Basics More interaction between initiators and staff implementing requirements. Verification Loop second iteration to remove bugs found in testing. Loop to reconcile system to user expectations was the correct system built? Steps move and shift to save time and money when answering this question.

Whirlpool Difficulties Very complex methodology. Difficult to manage due to number of iterations. Hand off to maintenance tends to be shaky. Still gaps between - What and How Developers present system instead of users presenting requirements.

Incremental / Spiral Conception Reconciliation Requirements Requirements Reconciliation Reconciliation Design Requirements Design Verification Reconciliation Programming Verification Design Code Review Programming Unit Test Verification Code Integration Review Unit Test Programming Integration SIT Code Review Unit Test UAT SIT Integration UAT Installation SIT Operations Installation& UAT Maintenance Operations & Reconciliation Maintenance Installation Reconciliation Operations & Maintenance Reconciliation

Incremental / Spiral Perform the waterfall in sections. Several mini projects are undertaken to implement the goal. Gap between what and how is narrowed. Requirements and Design are closely related. Clean Interfaces must be maintained between the modules.

Prototyping Conception Requirements Design Programming Code Review Prototyping Each phase feed into the next, But there is feedback among the first three phases Unit Test SIT UAT Installation Operation Maintenance

Prototyping Prototyping is a process that permits the developer to create a model or mock-up of the system to be built. It must be decided in advance if the prototype is a throwaway or to be kept as the initial version of the system. If the prototype is the initial version of the system the code must be placed under configuration management. The choice must be documented in the validation plan.

Prototyping Prototyping begins with some type of protosystem or model. Then an initial set of requirements is created. The model is then updated with modifications. A matching update of the requirements is made. This process is repeated until the requirements are finalized.

Prototyping Issues Keeping code under control. Customer does not realize the prototype is not a working supportable code model and does not understand additional time required to go from prototype to deliverable system. An inappropriate operating system or programming language may have been used to create the model and everything must be reworked. Rules must be defined before prototyping begins! Validation Plan Prototyping SOP

Programming Validation and Project Deliverables Code Code walk throughs Memos Responses Unit Testing Plan (Matrix from UFRS to Design to Scripts) Scripts Report of results (include resolutions to errors) System and Integration testing Plan (Matrix from UFRS to Design to Scripts) Scripts Report of results (include resolutions to errors)

Programming Code should be written in a controlled manner. Standards help promote the writing of maintainable code. Code / configuration management Permits the easy backing out of changes. Allows for repeatability. Metrics. Code walk throughs! Verify standards are being followed. Match code to what is being stored and tracked in Code Management tools.

Programming Unit Testing Test the individual modules. Do the requirements track to a module or will an SOP need to be written to meet a requirement? Users should be told as soon as possible. System and Integration Testing When modules interface with each other and the target Operating System do they continue to work? Again do requirements track?

Acceptance Validation and Project Deliverables IQ/OQ for testing Installation and Operation Qualification for Test System Execution Report of Results Performance Qualification / User Acceptance Testing Plan Scripts Execution of scripts Resolution of non-conformances Traceability Matrix Report of results

Acceptance Performance Testing This is only useful if performance requirements were defined so that they are measurable. Internet speed can not be meaningfully tested! No one company has end to end control of an Internet connection. Performance testing should be executed on manufacturing systems and laboratory systems that function in real-time! Other items such as scanners for edms may also require testing for data transfer tolerances.

Acceptance User Acceptance Testing Scripts should mimic actual plan use of the system. If instruments or devices will be connected and transferring data, check those interfaces! Remember to do all those security tests for 21 CFR Part 11! This is critical for edms that will use electronic signatures. If a SOP will be used for missing functionality make sure this is documented in the PQ/UAT Traceability Matrix and PQ/UAT Report.

Operational Validation and Project Deliverables Installation and Operation Qualification for Production System Test items such as backup and physical security if not tested in PQ/UAT Execution Report of Results Validation Report Deviations from the Validation Plan Any non-conformances from testing - include resolution

Maintenance The system is now in a controlled, successfully functioning state, how will you keep it there? SOPs Change Control Validation and Re-validation Security Anti-Virus Disaster Recovery Business Continuity User Management Auditing

Decommission When the system becomes obsolete, how will the data from it be stored to match the data retention policy? Migrate information to another system? Mothball the system? Retire the system but keep it running?

Other things to worry about... Security Do your backups really work? Test them! Disaster Recovery (did you test that plan?) Network Qualification Data Center Qualification Training in the new application On going training for new hires

Training Make sure your developers data center staff receives validation training! Also help your staff understand the end product that actually brings in the money that pays their salary. Give them a reason to take pride in the validation and compliance process.

Conclusions and Summary Validation need not be a burden. Incorporate it into daily operations! Results Functioning systems Supportable systems Repeatable performance Improved business processes Fewer audit findings!

References DeGrace, P. & Stahl, L. H. (1990). Wicked Problems, Righteous Solutions: A Catalogue of Modern Software Engineering Paradigms. Englewood Cliffs, NJ: Yourdon Press Computing Series. Pressman, R. S., (1993). A Manager s Guide to Software Engineering. New York: McGraw- Hill. The Validation Dictionary. Royal Palm Beach, FL: Institute of Validation Technology.