FDA 21 CFR Part 11
21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking)

FDA 21 CFR Part 11 Part11.30: Controls for open systems (21 CFR §11.30)

Section 11.30 establishes the controls for OPEN SYSTEMS. Persons who use open systems to create + modify + maintain + transmit electronic records must employ procedures + controls designed to ensure the authenticity + integrity + as appropriate the confidentiality of electronic records from the point of their creation to the point of their receipt. Such procedures + controls must include those identified in §11.10 (closed system controls) AS APPROPRIATE + ADDITIONAL MEASURES such as: (a) DOCUMENT ENCRYPTION + (b) USE OF APPROPRIATE DIGITAL SIGNATURE STANDARDS to ensure record authenticity + integrity + confidentiality. Open systems are those where access is not controlled by the persons responsible for the content of electronic records on the system - typically systems where multiple organisations or external parties have access (e.g. cloud-hosted multi-tenant systems + EDC platforms shared across CROs + clinical sites + sponsors + external sites + IoT-connected medical devices transmitting data to external repositories). The §11.30 additional measures (encryption + digital signatures) are intended to maintain trustworthiness when the §11.10 closed-system controls are insufficient.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 106 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.3 Cryptography and key management
  • 27011-8.6 Data protection and backup
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

India DPDP Act · 2 controls

  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • AL-DPA-14 Direct Marketing

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
  • IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection
  • 62351-9 Cyber security key management

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection
  • 29115-7.4 Level of Assurance 4 (LoA4)

MITRE D3FEND · 1 control

  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • RUSPD-4 Special Categories, Biometric Data
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking)

Query this from an agent

The graph holds this control, the 106 it maps to, and the evidence behind each claim, over MCP and REST.