Difference between revisions of "User:Shawndouglas/sandbox/sublevel22"
Shawndouglas (talk | contribs) |
Shawndouglas (talk | contribs) |
||
Line 91: | Line 91: | ||
[https://www.ams.usda.gov/datasets/pdp/pdp-standard-operating-procedures USDA Administrative Procedures for the PDP 5.5.1.2] | [https://www.ams.usda.gov/datasets/pdp/pdp-standard-operating-procedures USDA Administrative Procedures for the PDP 5.5.1.2] | ||
| style="background-color:white;" |'''33.4''' The system shall support the ability to define, record, and change the level of access for individual users to system groups, roles, machines, processes, and objects based on their responsibilities, including when those responsibilities change. The system should be able to provide a list of individuals assigned to a given system group, role, machine, process, or object. | | style="background-color:white;" |'''33.4''' The system shall support the ability to define, record, and change the level of access for individual users to system groups, roles, machines, processes, and objects based on their responsibilities, including when those responsibilities change. The system should be able to provide a list of individuals assigned to a given system group, role, machine, process, or object. | ||
|- | |||
| style="padding:5px; width:500px;" |[https://www.astm.org/Standards/E1578.htm ASTM E1578-18 S-3-8] | |||
| style="background-color:white;" |'''33.5''' The vendor should provide maintenance agreements and support services for its applications and services. | |||
|- | |||
| style="padding:5px; width:500px;" |[https://www.astm.org/Standards/E1578.htm ASTM E1578-18 S-3-9]<br />[https://ec.europa.eu/health/sites/health/files/files/eudralex/vol-4/annex11_01-2011_en.pdf E.U. Annex 11-3.3]<br />[https://www.ams.usda.gov/datasets/pdp/pdp-standard-operating-procedures USDA Administrative Procedures for the PDP 5.2.4] | |||
| style="background-color:white;" |'''33.6''' The vendor shall provide help desk, training, and installation support, as well as high-quality system documentation. The documentation should be reviewed to ensure that user requirements are fulfilled. | |||
|- | |||
| style="padding:5px; width:500px;" | | |||
[https://www.law.cornell.edu/cfr/text/7/331.11 7 CFR Part 331.11]<br /> | |||
[https://www.law.cornell.edu/cfr/text/9/121.11 9 CFR Part 121.11]<br /> | |||
[https://www.law.cornell.edu/cfr/text/21/11.10 21 CFR Part 11.10 (c)]<br /> | |||
[https://www.law.cornell.edu/cfr/text/42/73.11 42 CFR Part 73.11]<br /> | |||
[https://www.law.cornell.edu/cfr/text/45/164.310 45 CFR Part 164.310]<br /> | |||
[https://www.aavld.org/accreditation-requirements-page AAVLD Requirements for an AVMDL Sec. 5.4.4.3]<br /> | |||
[http://www.abft.org/files/ABFT_LAP_Standards_May_31_2013.pdf ABFT Accreditation Manual Sec. D-5–D-8]<br /> | |||
[http://des.wa.gov/sites/default/files/public/documents/About/1063/RFP/Add7_Item4ASCLD.pdf ASCLD/LAB Supp. Reqs. for the Accreditation of Forensic Science Testing Laboratories 5.4.7.2.1]<br /> | |||
[https://www.astm.org/Standards/E1492.htm ASTM E1492-11 4.2.4]<br /> | |||
[https://www.fbi.gov/services/cjis/cjis-security-policy-resource-center CJIS Security Policy 5.5.2]<br /> | |||
[https://www.fbi.gov/services/cjis/cjis-security-policy-resource-center CJIS Security Policy 5.8.1]<br /> | |||
[https://www.epa.gov/sites/production/files/documents/erln_lab_requirements.pdf EPA ERLN Laboratory Requirements 4.9.6]<br /> | |||
[https://ec.europa.eu/health/sites/health/files/files/eudralex/vol-4/annex11_01-2011_en.pdf E.U. Annex 11-7.1]<br /> | |||
[https://ec.europa.eu/health/sites/health/files/files/eudralex/vol-4/annex11_01-2011_en.pdf E.U. Annex 11-12]<br /> | |||
[https://www.iso.org/standard/56115.html ISO 15189:2012 5.10.2]<br /> | |||
[https://www.iso.org/standard/66912.html ISO/IEC 17025:2017 7.11.3]<br /> | |||
[https://www.ams.usda.gov/datasets/pdp/pdp-standard-operating-procedures USDA Administrative Procedures for the PDP 5.2.1] | |||
| style="background-color:white;" |'''33.7''' The vendor shall restrict logical access to database storage components to authorized individuals. If providing a hosted service, the vendor should also restrict physical access to database storage components to authorized individuals. (In the case of an on-site solution, the buyer is responsible for limiting physical access to database storage components to meet 21 CFR Part 11, HIPAA, and CJIS guidelines.) | |||
|- | |||
| style="padding:5px; width:500px;" |[https://www.fbi.gov/services/cjis/cjis-security-policy-resource-center CJIS Security Policy 5.5.1] | |||
| style="background-color:white;" |'''33.8''' The system shall be able to tag and document an individual, group, and system account as having been validated for regulatory purposes, and remind the administrator or authorized personnel on a configurable schedule when the account should be validated again. | |||
|- | |- | ||
|} | |} | ||
|} | |} |
Revision as of 16:55, 19 September 2019
This is sublevel22 of my sandbox, where I play with features and test MediaWiki code. If you wish to leave a comment for me, please see my discussion page instead. |
Sandbox begins below
32. System Validation and Commission
|
33. System Administration
|