I work at a medical device company under 21CFR 820 and ISO 13485, and we are starting to get into Cloud tools to develop software as a medical device. There is also a large push to use the cloud platform to distribute the software to our end users/customers. We currently do not work a lot with software as a product and I do not have a lot of experience in cloud systems or deploying software. I have put together some questions that keep coming up and would appreciate any advice anyone has about creating a compliant process.
1- How can you validate cloud software/environments that are hosted in leased servers?
2- What controls need to be in place in the cloud environment to maintain compliance?
3- In general what controls need to be in place around the storage and deployment of software?
4- What US and EU regulations/standards/guidances cover software as a product? (I know that software must be treated as a product under CFR and ISO I am asking if there is more specific information to cover software)
1- How can you validate cloud software/environments that are hosted in leased servers?
2- What controls need to be in place in the cloud environment to maintain compliance?
3- In general what controls need to be in place around the storage and deployment of software?
4- What US and EU regulations/standards/guidances cover software as a product? (I know that software must be treated as a product under CFR and ISO I am asking if there is more specific information to cover software)