Unauthorized system access
A person without the required authority reads, enters or alters a regulated record because access is shared, over-provisioned, or never withdrawn when a role changed.
- Give every user a unique, non-shared account
- Provision access by authorised role
- Review granted access periodically
- Enforce authority checks in the system
- Manage identification codes and passwords
- Define roles and responsibilities in writing
- Enforce the two-component signature controls
- Add open-system controls where access is not controlled
- Restrict batch certification to the authorised person