Products
 
Microsoft Certified Partner
 

eInfotree Electronic Document Management System 21 CFR Part 11 Compliance

21 CFR 11 Sn.

21 CFR 11 Text

eInfotree
Compliance

eInfotree Implementation

Subpart C- Electronic Signatures

11.100

General requirements.

11.100(a)

Each electronic signature shall be unique to one individual and shall not be reused by, or reassigned to, anyone else.

eInfotree enforces the uniqueness of each user ID and password combination. This combination can not be reused or reassigned to anyone else, even after the original userid has been deactivated or is no longer active.
 

11.100(b)

Before an organization establishes, assigns, certifies, or otherwise sanctions an individual's electronic signature, or any element of such electronic signature, the organization shall verify the identity of the individual.
 

Not Applicable

Procedural Control.

11.100(c)

Persons using electronic signatures shall, prior to or at the time of such use, certify to the agency that the electronic signatures in their system, used on or after August 20, 1997, are intended to be the legally binding equivalent of traditional handwritten signatures…
 

Not Applicable

Procedural Control.

11.200 - Electronic signature components and controls.

11.200(a)
11.200(a)(1)

Electronic signatures that are not based upon biometrics shall: 

Employ at least two distinct identification components such as an identification code and password.
 

eInfotree employs a non-biometric model that requires a unique user id and password combination.

11.200(a)(1)(i)

When an individual executes a series of signings during a single, continuous period of controlled system access, the first signing shall be executed using all electronic signature components; subsequent signings shall be executed using at least one electronic signature component that is only executable by, and designed to be used only by, the individual.

eInfotree requires the first signing to use both a userid and password combination.


Subsequent signings during a continuous period of controlled user access require the user password which is authenticated against the userid, and the unique combination is verified.
 

11.200(a)(1)(ii)

When an individual executes one or more signings not performed during a single, continuous period of controlled system access, each signing shall be executed using all of the electronic signature components.

Both userid and password are required for signatures not executed during a single, continuous period of access.

© Copyright 2000-2008. CIMCON Software, Inc. All rights reserved.