FDA 21 CFR Part 11
21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

FDA 21 CFR Part 11 Part11.AccessAndAuth: Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

Section 11.10 access + control elements: (d) LIMITING SYSTEM ACCESS TO AUTHORISED INDIVIDUALS - role-based access control (RBAC) + least-privilege + provisioning + de-provisioning lifecycle + periodic access reviews + segregation of duties; (f) USE OF OPERATIONAL SYSTEM CHECKS TO ENFORCE PERMITTED SEQUENCING OF STEPS AND EVENTS AS APPROPRIATE - workflow + step-by-step controls preventing out-of-order execution (e.g. release approval before product release; review before submission); (g) USE OF AUTHORITY CHECKS to ensure that only authorised individuals can use the system + electronically sign a record + access the operation or computer system input or output device + alter a record or perform the operation at hand - the authority check is the just-in-time verification at the moment of action that the user has the right to perform the specific action; (h) USE OF DEVICE (e.g. TERMINAL) CHECKS to determine the validity of the source of data input + operational instruction - typically network-level controls + device-fingerprint or terminal-identification ensuring the data + instruction comes from a registered + authorised device. Combined § 11.10(d)/(f)/(g)/(h) form the operational-security backbone of Part 11.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 73 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting
  • ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
  • IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

India DPDP Act · 1 control

  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

MITRE D3FEND · 1 control

MiFID II / MiFIR · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

Query this from an agent

The graph holds this control, the 73 it maps to, and the evidence behind each claim, over MCP and REST.