The laboratory needs to be able to reach the information and data its activities require. Laboratory information management systems used for gathering, processing, recording, reporting, storing or retrieving data shall be validated for their functions, interfaces included, before they are brought into use, and every change, including to software configuration or to commercial software, needs authorizing, documenting and validating before it takes effect. The systems shall be protected against unauthorized access and safeguarded against loss and tampering; run in an environment that meets the supplier's or the laboratory's specifications (or, for manual systems, in conditions that keep recording and transcription accurate); maintained so that data integrity is preserved; and any failure recorded together with the immediate and corrective actions taken. Where an external provider runs a system, or it is run off site, the laboratory shall make sure the provider meets the relevant requirements. Instructions, manuals and reference data for the systems shall be easy to obtain, and calculations and transfers of data need suitable, systematic checking.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.