FDA 21 CFR Part 11 Part11.AccessAndAuth: Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))
Section 11.10 access + control elements: (d) LIMITING SYSTEM ACCESS TO AUTHORISED INDIVIDUALS - role-based access control (RBAC) + least-privilege + provisioning + de-provisioning lifecycle + periodic access reviews + segregation of duties; (f) USE OF OPERATIONAL SYSTEM CHECKS TO ENFORCE PERMITTED SEQUENCING OF STEPS AND EVENTS AS APPROPRIATE - workflow + step-by-step controls preventing out-of-order execution (e.g. release approval before product release; review before submission); (g) USE OF AUTHORITY CHECKS to ensure that only authorised individuals can use the system + electronically sign a record + access the operation or computer system input or output device + alter a record or perform the operation at hand - the authority check is the just-in-time verification at the moment of action that the user has the right to perform the specific action; (h) USE OF DEVICE (e.g. TERMINAL) CHECKS to determine the validity of the source of data input + operational instruction - typically network-level controls + device-fingerprint or terminal-identification ensuring the data + instruction comes from a registered + authorised device. Combined § 11.10(d)/(f)/(g)/(h) form the operational-security backbone of Part 11.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 73 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.