Cloud Infrastructure Regulations Compliance
Cloud Infrastructure Regulations Compliance
Cloud Infrastructure Regulations Compliance
SaaS: Software application hosted by the cloud service provider to perform functions or processes. In this
model, a regulated user uses a vendor's software application from a web browser or program interface. The
regulated user does not manage or control the underlying cloud infrastructure; including the network, servers,
operating systems, storage, or application capabilities; with the possible exception of application configuration
settings.
1
Service provider - An organization supplying services to one or more internal or external customers. (ITIL Service Design,
2011 Edition)
1
Cloud Infrastructure Compliance
The regulated user must implement a Cloud Governance Policy to establish a standard and effective cloud SLC.
This SLC contains your approach to the selection, integration, ongoing management and subsequent
decommissioning of cloud-based services.
The Cloud Governance Policy points to procedures and records that indicate how and on what basis (e.g., risk
assessment and requirements) the cloud service provider is evaluated and selected (PIC/S PI-011-3-11.2), the
tools for assessing fitness for purpose against predetermined requirements, specifications and anticipated
risks, and periodic reviews to assess if the cloud service is maintained and operated following the specified
requirements and quality agreement. How to add new services and how these services are developed,
qualified/validated and deployed must be part of this evaluation.
The evaluation may consist of technical capabilities, security-related evaluation and, procedural and technical
control evaluations. Other critical evaluations are financial and contract.
Specifically, applicable to security, the selection criteria to be considered for the capabilities of a cloud service
provider are as follows2:
Network Security
• Connection security (encrypted)
Reliability
• Disaster recovery
Trustworthiness
• Auditing
As part of the above evaluation, the cloud service E-records Integrity Governance is assessed.
2
ECA IT Compliance Working Group, "SOP - Selection Process for Cloud Service Providers," Rev 1.0, Draft.
2
Cloud Infrastructure Compliance
The following table lists a few sections in the cGMP regulations applicable to computer systems performing
manufacturing-related regulated functions. Equivalent sections can be found in the other FDA predicate
regulations.
US Drugs GMP Description
3
Aide-mėmoire of German ZLG regarding EU GMP Annex 11, September 2013.
3
Cloud Infrastructure Compliance
References.
1. ECA, "Ensuring the data integrity of cloud service providers," August 2019.
2. ECA, "GMP Data Governance and Data Integrity," Rev 2, January 2018.
3. López, O., "Electronic Records and Cloud Computing," in Best Practices Guide to Electronic Records
Compliance, López, O., Ed. (CRC Press, Boca Raton, FL, 1st ed., 2017), pp. 193-197.
4. López, O., "Regulatory Requirements," in Computer Infrastructure Qualification for FDA Regulated
Industries, López, O., Ed. (DHI Publishing, LLC, River Grove, IL, 1st ed., 2006), pp. 41-47.
4
1996 CGMP proposed regulations, FR, Vol. 61, No. 87, May 3, 1996.