Procedure · SOP-19
Control of Data and Information Management
Validation, security, backup, integrity and change control of laboratory information systems and spreadsheets.
Purpose
To define how the Laboratory validates, protects, backs up, maintains and controls changes to the information systems, software, spreadsheets and data used to collect, process, record, report, store and retrieve calibration data, so that data integrity, confidentiality and availability are assured.
What is inside
10 sections, about 4 pages when printed.
- 1. Purpose
- 2. Scope
- 3. References
- 4. Definitions
- 5. Responsibilities
- 6. Procedure
- Records generated by this procedure
- Monitoring and performance indicators
- Assessment readiness notes
- Related documents
Records it generates
Applying this procedure produces the following records, which are the evidence an assessor samples.
- –System inventory and classification
- –Validation records
- –Change requests, impact assessments and re-validation
- –Backup logs and restoration tests
- –Access rights reviews
- –Incident log
What an assessor looks for
The document closes with these points, so you can check your own practice before someone else does.
- –Asking for the validation evidence for the spreadsheet used to calculate a sampled certificate, including the test cases.
- –Checking cell protection and version of the spreadsheet actually on the engineer's PC against the controlled version.
- –Confirming that a departed employee's accounts were removed.
- –Asking when restoration was last tested and seeing the record.
- –Checking the audit trail for an amended electronic record.
Before you use it
- Replace every square-bracket token, starting with [LABORATORY NAME], [ADDRESS] and [EFFECTIVE DATE]. The full token list is in GD-01 Read Me First.
- Have the content technically reviewed against how your laboratory actually works, then approved by the responsible manager before it becomes a controlled document.
- Update the Word fields after editing so the table of contents and page numbers are correct: select all, then press F9.
- Record the document in your own document register and set its review date.
- Delete the assessment readiness notes if you do not want them in your controlled version; they are guidance for you, not requirements.
Related documents
- QM-01
Quality Manual
Top-level description of the management system against every clause of ISO/IEC 17025:2017.
- FRM-49
Software and Spreadsheet Validation Record
Validation of calculation software and spreadsheets before use and after change.
- CHK-01
ISO/IEC 17025:2017 Gap Analysis and Self-Assessment
Clause-by-clause self-assessment with evidence, gap and action columns.
- SOP-01
Control of Documents
Creation, review, approval, issue, change and withdrawal of internal and external documents.
- SOP-02
Control of Records and Technical Records
Identification, storage, protection, retention, amendment and disposal of quality and technical records.
- SOP-03
Internal Audit
Planning, conducting, reporting and following up internal audits of the management system and technical activities.
- SOP-04
Management Review
Annual top-management review with every input and output the standard requires.
- SOP-05
Corrective Action and Improvement
Raising, investigating, implementing and verifying corrective actions; capturing improvement opportunities.