System Name:

CAMAG winCATS planar Chromatography Manager

Version / Date:

1.3.0

Manufacturer:

CAMAG, Sonnenmattstrasse 11, CH-4132 Muttenz

Is the system supposed to be used as a closed or open system?

Closed system
Closed system means an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system.

Assessment done by:

CAMAG, November 2003

 

21CFR11

Reference

Requirements

Manufacturerâs Solution

21CFR11 compliant?

Comment

Subpart A‑Electronic Records - ¤11.10 Controls for closed systems.

¤ 11.10 (a)

Does the vendor have a Quality Management System which supports the qualification / validation of the computerized laboratory system?

CAMAG supports IQ/OQ Services for all parts of winCATS.Ê The system has been developed according to our certificated ISO 9000 requirements

Yes

 

¤ 11.10 (b)

Does the system support the generation of accurate and complete copies of records? This includes the viewing, printing and archiving of data such as:

 -        Methods

 -        Pre/Post-run macros

 -        Calibration and calculation tables

-        Physical parameters such as temperature, pressure, flow, speed, pH, rH, wavelengths, mV, mA, time, retention time, etc.)

-        Actual sample data (weight, volume, sample size)

-        Integration parameters leading to peak identification, peak areas, baseline definitions, etc

-        Sampling rates and signal filtering conditions

-        Spectra

-        Sequence of events, injection sequences, order of processing, including:

á        Start date & time

á        Stop date & time

á        Operator ID who started and / or stopped the macro / sequence.

-        Audit trails, including date & time stamp and operator ID

Rather than using a data base (e.g. Oracle) winCATS saves all data to analysis files using a private file format

 

All data are saved to .cme files.

winCATS does not use macros

All parameter input, raw data, calculated results and data automatically generated by the system finally building up an analysis are saved to .cna files

 

 

 

 

 

 

 

 

 

 

 

 

 

Separate audit trails for logging system events (open/save/delete file, user account changes etc.) and analysis changes (parameters, re-integration, images, etc) are created automatically.

 

Yes

 

¤ 11.10 (b)

(1)

Are the information associated with archiving occurrences available for viewing and printing (this includes in particular the filename, file size, date & time when the archive record was generated)?

Stored files can be reloaded and viewed at any time. As winCATS uses a file based data system the customer is responsible for file management outside of winCATS, using the operating system capabilities.

Yes

File access and archiving has to be covered by a customer SOP

¤ 11.10 (b)

Does the vendor provide user manuals which address the generation of electronic copies and the printout of electronic records?

Yes. Manual is part of the winCATS help file that also can be viewed outside of winCATS using the operating system capabilities.

Yes

 

¤ 11.10 (b)

Does the system support a file format that can be provided to regulators or is it able to export data to such a format?

CAMAG supplies foc demo SW as Îviewerâ and 3rd party printout wrappers such as Adobe pdf writer or NewGenesis can be used.

Yes

 

¤ 11.10 (c)

Is the system able to support archiving of data mentioned above (&11.10. (b))?

See 10.11(b)Ê (1)

Yes

 

¤ 11.10 (c)

Does the system have a mechanism to modify analytical output data (actual results / calculated values)? (It should not).

No. winCATS stores all data in a private file format and no measured or calculated data can be edit within winCATS.

Yes

 

¤ 11.10 (c)

Are files write protected before, during and after archival and does the system provide a mechanism that deletion cannot occur before archival?

This item does not really apply to a file based data system. See 11.10(b)Ê (1)

Yes

File access and archiving has to be covered by a customer SOP

¤ 11.10 (c)

Does the system verify the integrity of stored data through archiving of the associated "archiving information": Archive file names, file size, last saving date & time?

Archiving is not part of winCATS.

Yes

Archiving has to be covered by a customer SOP

¤ 11.10 (c)

Is the system able to restore archived data?

Archiving is not part of winCATS.

Yes

Archiving has to be covered by a customer SOP

¤ 11.10 (d)

 

(2)

Systems being accessed through workstations which can be operated by multiple users and which bear more then one controlled application:

Is the system designed to allow for functional access controls?

Does the application have it's own security layer (application specific User-ID / password versus workstation "power-up" user-ID / password only)?

 

 

 

 

Yes

 

Each user has a unique UserID / Password

 

 

Yes

 

¤ 11.10 (d)

Are raw data / process data files created with write access limited to the system only?

File based system, restrictions have to be solved by the operating system using the Account Security settings

Yes

Must be covered by a customer SOP describing the Account rights assignment. This document is required during IQOQ.

¤ 11.10 (d)

Is the system designed to allow for user confirmation and supervisory approval options?

Covered by E-Signature functionality

Yes

 

¤ 11.10 (d)

Does the system support password-aging processes (prompts for password renewal after x days) and enforce minimum password lengths (if possible with at least 8 alphanumeric characters)?

Part of Îpoliciesâ dialog.

Yes

This document is required during IQOQ.

¤ 11.10 (d)

Does the system lock out users after a predefined number of login failures?

Part of Îpoliciesâ dialog.

Yes

This document is required during IQOQ.

¤ 11.10 (d)

(3)

Does the system provide a mechanism to log out / interrupt access of any user after a configurable period of non- attendance?

Supported by using operating system feature ( screensaver )

Yes

 

¤ 11.10 (d)

Does the system provide security audit logs, including audit trails for changes of user privileges?

All interactions by the winCATS Administrator are part of the winCATS system log. Changes to the operating system account manager can be logged by the operating system

Yes

 

¤ 11.10 (e)

Do changes to data not obscure or destroy original data and are they audit trailed?

Where comments can be added to existing records:

Are these comments audit trailed?

It is not possible to obscure or destroy any raw data

  

All changes to parameters are audit trailed.

Yes

 

¤ 11.10 (e)

Is the audit trail information modifiable (It must not)

No

Yes

 

¤ 11.10 (e)

Is the audit trail data archived as described above under ¤11.10 (c)?

Audit trail data are part of the analysis file and archived with it. winCATS system log data are stored / archived separately.

Yes

 

¤ 11.10 (e)

Does the laboratory system provide a mechanism whereby users can alter audit trails with standard security access? (It should not)

No

Yes

 

¤ 11.10 (e)

Is the system able to print out the audit trail in a human readable format?

Both analysis and system log information can be printed.

Yes

 

¤ 11.10 (e)

Is the audit trail information available in an electronic format that can be provided to regulators?

CAMAG supplies foc demo SW as Îviewerâ and 3rd party printout wrappers such as Adobe pdf writer or NewGenesis can be used.

Yes

 

¤ 11.10 (e)

Does the audit trail include the following information:

á        Start / hold / stop / resume programs

á        Change of any parameter, including selection of modes of operation, settings, etc.

á        Auto-calibration / simulation of inputs and outputs

á        Analyst acknowledgement of messages

á         Event messages / alarms?

Yes to all

Yes

 

¤ 11.10 (f)

Does the laboratory system support the logical execution of sequences such as:

 

á           Initialization / stabilization phase,

á           Setting / selection of key parameters,

á           Calibration / auto-calibration / reference measurements,

á           Sample measurement (execution of analysis),

á           Data acquisition and exploitation of results,

á           Stand-by steps, stop routines?

Yes.

winCATS supports logical workflow according to planar chromatography requirements.

 

All used TLC steps can be added to the analysis. Running the analysis starts at the 1st step and proceeds to the next after the previous step has been completed

Yes

 

¤ 11.10 (g)

Is the system designed to allow for functional access controls?

See 11.10(d) (2)

Yes

 

¤ 11.10 (g)

Where multiple users can access an application from one workstation:

Does the data entry screen display the name or unique User ID of the individual who enters data into a system?

Name and UserID are displayed on screen.

Yes

 

¤ 11.10 (g)

When electronic signatures are executed:

Does the system apply security checks to ensure validity and integrity of the signatures?

All E-Signature related data is (hashed) part of the analysis file it belongs to.

Yes

 

¤ 11.10 (g)

Does the system store passwords in encrypted form? Or is the access to files, which include passwords secure and is their access strictly controlled?

When password entry fields are shown on the screen:

Are the passwords hidden (e.g. "********")?

Passwords, UserIDs etc. are always saved in encrypted form.

 

 

 

Yes

Yes

 

¤ 11.10 (h)

In cases where the physical identity of an input (or output) device is relevant:

Does the system check the identity of this device? (This may apply to devices such as: specific workstations on the network, barcode readers, devices communicating through modems, radio frequency terminals, etc.)

Covered by use of private device handlers and or private communication protocol

Yes

 

¤ 11.10 (i)

Does the vendorâs personnel, who develop and maintain IT systems, have an adequate level of education and have they been trained appropriately?

Is the training documented?

CAMAG is ISO 9001 certified since 1994 and we just recently passed the recertification according to ISO9001/2000

Yes

Yes

Our certificate can be downloaded from www.camag.com

¤ 11.10 (k)

Does the vendor provide accurate and updated documentation for system operation and maintenance?

CAMAG supplies a complete set of user manual/help files, service manuals and IQ/OQ Services

Yes

 

Subpart B‑Electronic Records - ¤11.30 Controls for open systems

¤11.30

If the system invokes Internet or uses transfer protocols such as FTP over the Internet:

Are the files transferred encrypted?

Not applicable

 

 

Subpart C - ¤11.50 Signature manifestations

¤11.50 (a)

Where electronic signatures are used:

Is the laboratory system designed to provide the following data:

á         Full name of signer,

á         Date and time stamp,

á         Meaning of signature?

Yes

Yes

 

¤11.50 (b)

Is the system able to display / print the full name of the signer, date/time of signature execution, and meaning of the signature whenever the signed record is displayed via one of the computer terminals or when the record is printed out?

Yes

Yes

 

Subpart D- ¤11.70 Signature-record linking

¤11.70

Is the system designed such that electronic signature information cannot be excised, copied or transferred?

The signature is a hashed part of the file it belongs to.

Yes

 

Subpart E‑Electronic Signatures - ¤11.100 General requirements.

¤11.100 (a)

Does the system accept duplicate user accounts? (It should not)

No

Yes

 

Subpart F- ¤ 11.200 Electronic signature components and controls.

¤11.200 (a)

Where biometrics are not used:

Is the laboratory system designed to require the entry of two components of which one is private, such as User ID and password?

winCATS uses UserID and private password

Yes

 

¤11.200 (a)

Does the system provide a mechanism to log out / interrupt access of any user after a configurable period of non- attendance (e.g. 10 minutes)?

Yes. See 11.10(d)Ê (3)

Yes

Screen saver

¤11.200 (b)

If biometrics identification devices are used to execute an electronic signature:

Are these devices validated and is it demonstrated that only the genuine owner of a signature can execute it?

Biometric devices can only be supported by the OS.

Yes

 

Subpart G- ¤11.300 Controls for identification codes/ passwords.

¤11.300 (a)

If the system uses electronic signatures:

Does it provide individual user IDs and are passwords kept confidentially and submitted to an aging / renewal process?

Yes

Yes

 

¤11.300 (b)

Does the system include a feature for automatic password aging (e.g. passwords will automatically expire? Is the setting of the expiry configuration parameter limited to authorized personnel only?

Yes

Yes

 

¤11.300 (d)

Is the laboratory system designed to track unsuccessful attempted access to the system?

All winCATS login attempts are logged in the system log

Yes

 

¤11.300 (d)

Is the laboratory system designed so that only authorized persons can view the 'access log' information?

Viewing the system log information is restricted to winCATS Administrators only.

Yes