Regulatory Background – Important Issues to consider from the Point of View of an Inspector
- Requirements for CSP (cloud service providers) resulting from Annex 11
- To dos for regulated users with respect to chapter 7 of the EU GMP Guide
- German Drug Law – does the German Drug Law or European Law effect the business of CSP; enforcement of corrective actions
Definition and Types of Cloud Computing
- Service models: Private Cloud, Public Cloud, Community Cloud, Hybrid Cloud
- Infrastructure as a Service (IaaS)
- Platform as a Service (PaaS)
- Software as a Service (SaaS)
- Cloud Computing scenarios, reference architectures, examples
Case Study: Cloud Computing Risk Assessment
- In this workshop the participants will perform a risk assessment for a given cloud strategy. A practical exercise that helps to understand and get on top of the risks involved with cloud computing.
Inspections and Findings
- European Framework to conduct inspections
- Availability, data integrity and confidentiality of data
- Possibility to perform inspections of CSP
- State of the art defined by BSI, ENISA and NIST
- Inspections: experiences and findings
Cloud Computing: IT Security
- Examples of incidents
- Strategic planning and preparation for going to cloud services
- Security management and security architecture
- Security certifications (e.g. ISO 27001) and what they really mean
- Physical and logical security, encryption
- Incident prevention and response
- Professional security patch management
- Identity management, authentication, authorization
- Integration of cloud services with internal IT landscape
The Technology behind Multi-Tenant Cloud Services
- Why Multi-tenancy
- Typical service provided and their delivery processes
- Technology and resource pools
- Risk and opportunities
Compliance Requirements for the Cloud Infrastructure
- Regulatory requirements
- Qualification of the cloud
- Validation of the cloud
Cloud Computing in a GxP Environment from a Service Provider Perspective
- Cloud Computing in a GxP Environment from a Service Provider Perspective
- Current adoption of Cloud Computing in GxP Areas
- Expectations from a Customer perspective, pre-requisites on the Service Provider side
- Shared operating model and handling of planned/unplanned Events
- What information does a CSP need from the customer before signing a contract?
- Transparency & Auditability of CSP operations, e.g., compliance of data storage
- Future progression of partnering models
Contracts with Cloud Service Providers
- Business & Technology Risks
- Intellectual Property
- Service Access / Service Quality KPIs
- Data storage requirements
- Inspection & audit Support
- Example Contract/SLA
- Lessons learned
Case Study: Audit of a Cloud Provider
- Audit preparation based on risk-based approach
- How to interpret audit results
- How to manage various CSPs of SaaS solutions
- Tips and tricks about the audit topics
GxP, Data Integrity, Best Practice: How to partner with your Cloud Provider
- Understanding GxP Applicability based on intended use
- Assessing risks that include GxP, but also broader (e.g., Data Integrity, Privacy, Security)
- Applying intended use to applicable GxPs, regulatory guidance, etc. expectations
- Effectively leveraging an FRA - What does it drive and where efforts should be focused by the Supplier and Life Science company?
- Review Case Study with examples of risk assessment, validation, and associated deliverables. And, discussion on how to effectively leverage and supplement internal requirements
Discussion: How to effectively partner with your Cloud Provider
- This will be a facilitated Panel Discussion that allows the participants to ask the speakers specific questions.
Cloud Computing: Data Protection
- Data protection and privacy – legal requirements
- Responsibilities of the cloud service provider
- Responsibilities of the cloud customer
Impact of the EU Court of Justice Ruling (311/18 – “Schrems-II”) on the Use of Cloud Services
Data Classification
- Responsibility and integration in the IT project management framework
- Handling, processing, commissioned processing of data
- Forced disclosure
- Applicable regulations
- Examples and lessons learned
Cloud Computing: Use Cases in a GxP Environment
- Risk-based approach
- Specific responsibilities of the cloud service provider
- Specific responsibilities of the cloud customer
- Separation of GxP vs. non GxP
- Examples
How to validate a Cloud Process – Manage the Risks and stay in Compliance
- URS / GxP/functional risk assessment
- Validation planning and testing
- Validation report
- Change control, bug fixes, monitoring
Government Agencies and Cloud Computing
- Objectives and capabilities of government agencies
- How and where do they hook in
- Internet surveillance and specific attacks
- Industry espionage
- Countermeasures and their limitations
Experiences With Outsourcing and Cloud Computing
- QA involvement
- Pain points
Cloud Computing: Pros and Cons
- Opportunities and risks of cloud computing
- Rationale for using cloud services
- Rationale for not using cloud services
- Conclusions and recommendations