FDA 21 CFR Part 11
21 CFR Part 11 Subpart C - Electronic Signatures (§11.200 + §11.300 Components, Controls, ID Codes and Passwords)

FDA 21 CFR Part 11 Part11.300: Controls for identification codes and passwords (21 CFR §11.300)

Section 11.300 establishes the controls for identification codes + passwords used as electronic signature components: (a) MAINTAINING THE UNIQUENESS of each combined identification code + password such that no two individuals have the same combination of identification code + password; (b) ENSURING that identification code + password issuances are periodically checked + recalled + or revised (e.g. to cover such events as password aging); (c) FOLLOWING LOSS MANAGEMENT PROCEDURES TO ELECTRONICALLY DEAUTHORIZE LOST + STOLEN + MISSING + or otherwise potentially compromised tokens + cards + and other devices that bear or generate identification code or password information + to issue temporary or permanent replacements using suitable + rigorous controls; (d) USE OF TRANSACTION SAFEGUARDS to prevent unauthorised use of passwords and / or identification codes + to detect and report in an immediate and urgent manner any attempts at their unauthorised use to the system security unit + and, as appropriate + to organisational management; (e) INITIAL AND PERIODIC TESTING of devices, such as tokens or cards, that bear or generate identification code or password information to ensure that they function properly and have not been altered in an unauthorised manner.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 48 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures
  • AMLCTF-35 Identity Verification Standard

BSI IT-Grundschutz · 1 control

  • BSI-03 Multi-factor authentication requirements
  • DSO-3 Data Access Management
  • IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

MITRE D3FEND · 1 control

  • OWASPAPI-2 Broken Authentication and Token Management

OWASP ASVS · 1 control

  • OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4)
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 21 CFR Part 11 Subpart C - Electronic Signatures (§11.200 + §11.300 Components, Controls, ID Codes and Passwords)

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.