For those of you that have undergone an FDA inspection where you use electronic signatures, what did they look at? how in depth was the review? How knowledgable was the inspector?
We are planning on implementing electronic signatures, but I'm wondering how tight I should make my belt and braces. I was consdiering setting up my on internal PKI and issueing key pairs to individuals, however I have many questions:
Do the inspectors even understand the terminology above?
We are planning on implementing electronic signatures, but I'm wondering how tight I should make my belt and braces. I was consdiering setting up my on internal PKI and issueing key pairs to individuals, however I have many questions:
- Do the inspectors care whether you have an intermediate CA, or can all keys be issued off the Root?
- Do they care about the Root CA being isolated from the network?
- Do they require a seperate authoratative time server for when documents are signed?
- Do they care about certificate revocation lists and the insecurities they bring vs OSCP
Do the inspectors even understand the terminology above?
Last edited by a moderator: