Related Articles

4 Comments

  1. Surendra Pal says:

    Hi Saket,
    Is there any specific requirements for password complexity in any guideline?

    1. Hi Surendra,
      I would recommend you reading Section 11.300(a) to (e) for what FDA wants as password complexity requirements. Once you know WHAT, HOW becomes another story. Ensure access to electronic records and using digital signatures is limited to only authorized individuals.
      For example, Section 21 CFR 11.300(b) states that it is important to ensure that identification codes and passwords are periodically checked, recalled, or revised to maintain the security and integrity of electronic records and signatures.

      Interpretation: To enhance security, one method is to mandate that employees update their passwords regularly, such as every 90 days. This practice lowers the chances of unauthorized individuals gaining access to electronic data through illegal means like hacking. Furthermore, protocols should be established to promptly deactivate or change identification codes and passwords when an employee departs from the organization or suspects a security breach.

Leave a Reply

Your email address will not be published. Required fields are marked *