SBS - The best value in QMS software

Inventory Listing and ISO 13485:2016

#1
My company manufactures "Software as a Medical Device" and I am trying to verify the extent of equipment that should be listed in our inventory/asset lists. Currently, we maintain a listing of hardware and software inventory used for design and development, but not sure how comprehensive the list for equipment used to control work environment needs to be. Should infrastructure that supports back-up and restore and, preventative maintenance processes also be listed? Can't really find anything that speaks to that. Would like to ensure that the scope in our inventory procedure is adequate and that only items that are necessary to be listed are maintained on that list. So for example, should laptops/desktops/monitors used by individuals involved in production be included? Any supporting reference would be appreciated?
 
Elsmar Forum Sponsor

Tagin

Trusted Information Resource
#2
6.3: "The organization shall document the requirements for the infrastructure needed to achieve conformity to product requirements, prevent product mix-up and ensure orderly handling of product. Infrastructure includes, as appropriate"

Just my opinion - for SaMD, to me that includes things like:
  • O/S versions
  • Compiler versions
  • Library revisions
  • Antivirus/antimalware
  • Firewalls
  • SIEM monitoring software
  • Software integrity monitoring
  • Custom development tools
  • Backups H/W & S/W - onsite & offsite. Backups encrypted?
  • Developers working remotely? Remote access s/w, remote access protections.
  • Network authentication (e.g., active directory)
  • etc.
Is you development network segmented from you business network?
Is your software distribution network likewise segmented from other networks?
  • What hardware/software does this segmentation?
Do you sell this as downloadable software, or hosted software? You don't want to be the next Solarwinds!
  • Web server software (O/S & web s/w, e.g., IIS or Apache)
  • Web server security monitoring software
  • Download integrity monitoring
  • Onsite? HVAC/environmental controls? Physical security?
  • Hosting service - what review/controls did you document?
  • Backups H/W & S/W - onsite & offsite. Backups encrypted?
  • etc.

That's a start.
 

Tidge

Trusted Information Resource
#3
My company manufactures "Software as a Medical Device" and I am trying to verify the extent of equipment that should be listed in our inventory/asset lists. Currently, we maintain a listing of hardware and software inventory used for design and development, but not sure how comprehensive the list for equipment used to control work environment needs to be. Should infrastructure that supports back-up and restore and, preventative maintenance processes also be listed? Can't really find anything that speaks to that. Would like to ensure that the scope in our inventory procedure is adequate and that only items that are necessary to be listed are maintained on that list. So for example, should laptops/desktops/monitors used by individuals involved in production be included? Any supporting reference would be appreciated?
My suggestion is that you consider these three "R" when deciding on documenting the tools used in SaMD development:
  1. Do you have sufficient documentation about the tools & methods such that you can repeat the development process? (if challenged)
  2. Do you have sufficient documentation about the tools & methods such that you can rebuild the application?
  3. Do you have sufficient documentation about the tools & methods such that you can repair the application? (in the event of a defect or anomaly)
If you are using software tools to manage requirements, you may want to know that such tools can help you to replace the software (with an upgrade) as well.
 
#4
Thanks for the feedback. We do have a lot of this information included. One concern was that maybe the listing was too comprehensive but I think, to accurately address the requirements, there may not be a lot that we can remove. Thanks again.


6.3: "The organization shall document the requirements for the infrastructure needed to achieve conformity to product requirements, prevent product mix-up and ensure orderly handling of product. Infrastructure includes, as appropriate"

Just my opinion - for SaMD, to me that includes things like:
  • O/S versions
  • Compiler versions
  • Library revisions
  • Antivirus/antimalware
  • Firewalls
  • SIEM monitoring software
  • Software integrity monitoring
  • Custom development tools
  • Backups H/W & S/W - onsite & offsite. Backups encrypted?
  • Developers working remotely? Remote access s/w, remote access protections.
  • Network authentication (e.g., active directory)
  • etc.
Is you development network segmented from you business network?
Is your software distribution network likewise segmented from other networks?
  • What hardware/software does this segmentation?
Do you sell this as downloadable software, or hosted software? You don't want to be the next Solarwinds!
  • Web server software (O/S & web s/w, e.g., IIS or Apache)
  • Web server security monitoring software
  • Download integrity monitoring
  • Onsite? HVAC/environmental controls? Physical security?
  • Hosting service - what review/controls did you document?
  • Backups H/W & S/W - onsite & offsite. Backups encrypted?
  • etc.

That's a start.
My suggestion is that you consider these three "R" when deciding on documenting the tools used in SaMD development:
  1. Do you have sufficient documentation about the tools & methods such that you can repeat the development process? (if challenged)
  2. Do you have sufficient documentation about the tools & methods such that you can rebuild the application?
  3. Do you have sufficient documentation about the tools & methods such that you can repair the application? (in the event of a defect or anomaly)
If you are using software tools to manage requirements, you may want to know that such tools can help you to replace the software (with an upgrade) as well.
 
Thread starter Similar threads Forum Replies Date
C AS9120 or AS9100 Cert pertaining to inventory? AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 1
I Laboratory Fridge / Freezer Inventory - Requirement(s) ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 6
S Inventory Control - Any thoughts would be appreciated ISO 13485:2016 - Medical Device Quality Management Systems 2
O Inventory control ideas - I have an open stock room with a "sign out" book Manufacturing and Related Processes 9
R Inventory management for a small startup device company Other Medical Device Related Standards 1
F Component Molding and Over-molding - Handling Resin Inventory Manufacturing and Related Processes 2
K Inventory Control - Class II (IIb for CE) medical device ISO 13485:2016 - Medical Device Quality Management Systems 6
Crimpshrine13 IATF 16949 and ISO 9001 Remote Support - Pass Through Inventory IATF 16949 - Automotive Quality Systems Standard 20
eule del ayre Manual Inventory System - Problem is discipline of the employees Lean in Manufacturing and Service Industries 7
qualprod Cycle times, value stream mapping, inventory, average values? Lean in Manufacturing and Service Industries 1
A Scheduled during our company's inventory activity - ISO 9001 audit question ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 5
S Labeling Requirements for Acquired Medical Device Inventory Other US Medical Device Regulations 2
M Are Critical Business Processes Assets that need to be included in Asset Inventory? IEC 27001 - Information Security Management Systems (ISMS) 1
E Where to go for inventory management and pricing help Manufacturing and Related Processes 1
D Inventory Move Ticket Form Wanted Document Control Systems, Procedures, Forms and Templates 2
A Non-Conforming Material Control and Inventory Software System Recommendations Quality Assurance and Compliance Software Tools and Solutions 5
S What is the accepted range for "Inventory Reconciliation" for RM and FG ? US Food and Drug Administration (FDA) 3
A Barcode Inventory System Validation ISO 13485:2016 - Medical Device Quality Management Systems 2
J Lean 5S - Setting Min/Max Inventory Levels Lean in Manufacturing and Service Industries 3
M Blood Collection Inventory Control Procedure example wanted Business Continuity & Resiliency Planning (BCRP) 3
S Inventory Management in a Company Misc. Quality Assurance and Business Systems Related Topics 1
R Accurate Quarterly Inventory Turn Numbers Quality Manager and Management Related Issues 3
M Inventory Parts Have Been Revised Quality Manager and Management Related Issues 7
S How can I inventory labels supplied by customer ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 4
B Root Cause Analysis and Corrective Action Program for Inventory Inaccuracies Nonconformance and Corrective Action 8
M Keeping Packaging Material and Photographs in Sync with Inventory Manufacturing and Related Processes 5
S Reworked DOA (Dead On Arrival) Return back to Inventory as New? 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 7
T How to ensure Inventory FIFO (First In First Out) by Suppliers Supplier Quality Assurance and other Supplier Issues 1
X Internal Audit of a Bank's 'Stationery' - Inventory Internal Auditing 22
N Company Name Change - Existing Inventory with Old Company Name Other US Medical Device Regulations 9
B Can returned goods go back into inventory? (EO Sterilized Surgical Sponges) Misc. Quality Assurance and Business Systems Related Topics 4
K What to look for when buying non-inventory products such as Gas & Electricity Service Industry Specific Topics 2
J Clause 7.5.5.1 (Storage and Inventory) requirements in ISO/TS 16949:2009 IATF 16949 - Automotive Quality Systems Standard 8
K Seeking a sample spreadsheet - Inventory of items with 2 units Document Control Systems, Procedures, Forms and Templates 3
S Returned Material Authorizations and Accepting Products back into Normal Inventory Misc. Quality Assurance and Business Systems Related Topics 10
B Inventory Control as an ISO 9001 Requirement ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 17
N Inventory, Calibration, Maintenance Docs. etc. - Do these Documents require control? General Measurement Device and Calibration Topics 6
T Incorrect Data in Inventory List - Internal Audit Nonconformance Nonconformance and Corrective Action 33
A Are bearings part of "Shelf Life" inventory? Federal Aviation Administration (FAA) Standards and Requirements 10
A Configuration Management and On-Hand/In-Transit Inventory Quality Manager and Management Related Issues 3
J Looking for CPIM (Certified in Production and Inventory Management) insight Professional Certifications and Degrees 2
N Quality Objectives - Inventory Accuracy Improvement ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 6
T Accounting Treatment for RMA Spares Inventory Misc. Quality Assurance and Business Systems Related Topics 1
W Validation of SAP for ERP - Inventory, shipping, and monitoring expiration dates Qualification and Validation (including 21 CFR Part 11) 18
K Inventory Management - Establishing a procedure for Inventory Management Document Control Systems, Procedures, Forms and Templates 2
C Unplanned Purchase Orders from Customers that affect the Inventory Forecast Manufacturing and Related Processes 9
somashekar Definition SMOI (Supplier Managed Owned Inventory) delivery terms - Pros and Cons Definitions, Acronyms, Abbreviations and Interpretations Listed Alphabetically 1
3 Numbering system for inventory of bolts, washer, and nuts Manufacturing and Related Processes 1
P FIFO Inventory Managment System - TS 16949 clause 7.5.5.1 IATF 16949 - Automotive Quality Systems Standard 11
Q Inventory and FIFO in our goods receiving area Lean in Manufacturing and Service Industries 3

Similar threads

Top Bottom