Mitigating Pharma Risk in the Cloud
ISPE's revised IT Infrastructure Control and Compliance Guide provides comprehensive guidance on regulatory expectations for both traditional and cloud-based IT platforms. Have we done enough?
ISPE's revised IT Infrastructure Control and Compliance Guide provides comprehensive guidance on regulatory expectations for both traditional and cloud-based IT platforms. Have we done enough?
That’s the question Stephen Ferrell, core team leader for the ISPE GAMP® Good Practice Guide: IT Infrastructure Control and Compliance (Second Edition), wants readers to ask themselves. IT infrastructure outsourcing, he says, has made risk mitigation particularly difficult.
“Because we are not allowed on-site audits of third-party suppliers, data and system verification rely more heavily on third-party certifications,” explains Ferrell, Vice President, Product Strategy, ByteGrid. “This GPG (good practice guide) explains how a company is exposed to risk in this new environment, and what to do about it.”
The advent of third-party suppliers and cloud services drove the revision of the GPG, which first appeared in 2005. At that time, recalls Ferrell, “people were buying their own servers and setting them up; they largely were contained within their own facility. They then subjected them to a quality assessment within their own ‘four walls.’ IT infrastructure was a low-risk proposition at that time because it was tangible: you could see it, you could touch it.”
The advent of the cloud changed all that. “You lose the ability to control the infrastructure and that really drove the revision,” he explained. The revised GPG expands the scope of the first edition to include guidance on the emergence of cloud and virtualized technologies. Information has also been added to reflect significant changes in the technologies that make up IT infrastructure, including:
Ferrell acknowledges that most pharma companies have some form of cloud engagement, but for those that do not, the Guide serves as a road map, and identifies risk mitigation strategies. It tackles areas such as how to build your risk assessment, how to design your supplier qualification, how to structure your audit, and what questions you should ask.
And for those already using the cloud, the Guide will help them assess whether their risk-mitigation efforts have been sufficient.
GAMP® 5 Series: IT Infrastructure Compliance and Control
Stephen R. Ferrell, CISA, CRISC, Vice President, Product Strategy, ByteGrid, USA
Lorrie Vuolo-Schuessler has been involved with ISPE and GAMP® projects since 2002. She has authored or co-led 11 ISPE GAMP-focused guidance documents, including ISPE GAMP® 5: A Risk-Based Approach to Compliant GxP Computerized Systems (Second Edition) and the ISPE GAMP® Good Practice Guide: Enabling Innovation - Critical Thinking, Agile, IT Service Management. She is Immediate Past Chair of...
An ISPE member since 1999, Charlie Wakeham has been active within the ISPE GAMP® community since 2001. A founding member of the GAMP UK Community of Practice (CoP), she is currently Chair of the GAMP Global CoP Steering Committee, one of the leaders of the GAMP Computer Software Assurance Special Interest Group (SIG), and a member of the ISPE Guidance Documents Committee. She has co-led or...
Pharmaceutical Engineering® magazine is proud to announce that the 2022 Roger F. Sherwood Article of the Year is “Supporting Cell and Gene Therapy through...