21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking)
FDA 21 CFR Part 11 Part11.30: Controls for open systems (21 CFR §11.30)
Section 11.30 establishes the controls for OPEN SYSTEMS. Persons who use open systems to create + modify + maintain + transmit electronic records must employ procedures + controls designed to ensure the authenticity + integrity + as appropriate the confidentiality of electronic records from the point of their creation to the point of their receipt. Such procedures + controls must include those identified in §11.10 (closed system controls) AS APPROPRIATE + ADDITIONAL MEASURES such as: (a) DOCUMENT ENCRYPTION + (b) USE OF APPROPRIATE DIGITAL SIGNATURE STANDARDS to ensure record authenticity + integrity + confidentiality. Open systems are those where access is not controlled by the persons responsible for the content of electronic records on the system - typically systems where multiple organisations or external parties have access (e.g. cloud-hosted multi-tenant systems + EDC platforms shared across CROs + clinical sites + sponsors + external sites + IoT-connected medical devices transmitting data to external repositories). The §11.30 additional measures (encryption + digital signatures) are intended to maintain trustworthiness when the §11.10 closed-system controls are insufficient.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 106 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)