Section 11.10 establishes the 11 control requirements for CLOSED SYSTEMS used to create + modify + maintain + transmit electronic records. Persons who use closed systems must employ procedures + controls designed to ensure the authenticity + integrity + when appropriate the confidentiality of electronic records + to ensure that the signer cannot readily repudiate the signed record as not genuine. Such procedures + controls must include: (a) VALIDATION of systems to ensure accuracy + reliability + consistent intended performance + the ability to discern invalid or altered records; (b) the ability to generate ACCURATE + COMPLETE COPIES of records in both human readable and electronic form suitable for inspection + review + and copying by the agency; (c) PROTECTION of records to enable their accurate + ready retrieval throughout the records retention period; (d) LIMITING SYSTEM ACCESS to authorised individuals; (e) USE OF SECURE + COMPUTER-GENERATED + TIME-STAMPED AUDIT TRAILS to independently record the date and time of operator entries and actions that create + modify + or delete electronic records (Audit trails must be maintained for as long as required for the subject records + must be available for agency review + copying); (f) USE OF OPERATIONAL SYSTEM CHECKS to enforce permitted sequencing of steps and events as appropriate; (g) USE OF AUTHORITY CHECKS to ensure that only authorised individuals can use the system + electronically sign a record + access the operation or computer system input or output device + alter a record or perform the operation at hand; (h) USE OF DEVICE (e.g. terminal) CHECKS to determine the validity of the source of data input + operational instruction; (i) DETERMINATION THAT PERSONS WHO DEVELOP + MAINTAIN + OR USE ELECTRONIC RECORD / ELECTRONIC SIGNATURE SYSTEMS HAVE THE EDUCATION + TRAINING + and EXPERIENCE to perform their assigned tasks; (j) ESTABLISHMENT OF + and ADHERENCE TO WRITTEN POLICIES that hold individuals accountable + responsible for actions initiated under their electronic signatures + in order to deter record falsification; (k) USE OF APPROPRIATE CONTROLS OVER SYSTEMS DOCUMENTATION INCLUDING: (1) adequate controls over the distribution of + access to + and use of documentation for system operation + maintenance; (2) revision + change control procedures to maintain an audit trail that documents time-sequenced development + modification of systems documentation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.