Cloud Computing and Outsourcing in a GxP Environment

12-13 March 2015, Berlin, Germany

Course No. 9058

header-image

Speakers

Dr Karel Bastiaanssen, Iperion Life Sciences, The Netherland
Dr Wolfgang Schumacher, F. Hoffmann-La Roche Ltd.
Dr Arno Terhechte, Bezirksregierung Münster
Michael Wegmann, F. Hoffmann-La Roche Ltd.

Objectives

Get to know the different types of cloud computing, their technical basics and their validation approaches
What are the pharmaceutical authorities’ requirements with regard to cloud computing and what regulations have to be observed? An inspector will present his perspective to these questions and the experience gained so far in audits and will further cover critical points
You can assess the use of cloud computing from the perspective of IT security and data protection rules, and based on that you can formulate requirements for cloud service providers
You can evaluate the opportunities and risks of cloud computing in the GxP environment.

Background

As well as in other sectors, the use of cloud computing is discussed in the pharmaceutical industry. For commercial reasons there is a lot speaking for the use.

However, is cloud computing an acceptable way in a GxP environment of the pharmaceutical industry? And, if yes, what has to be observed from the point of view of IT and quality assurance, as well as from the perspective of a pharmaceutical inspector?

From the points of view of the user and the pharmaceutical inspector this event gives you an overview of the current state of the technical possibilities. The speakers evaluate opportunities and risks of the use of cloud computing in the GxP environment and make recommendations for the pharmaceutical practice.

Target Group

The event is aimed at employees who are entrusted with the planning and implementation of “cloud” projects in the GxP environment. The event also offers support for decision-making, whether cloud services are available as an alternative in the GxP environment.

Programme

Regulatory Background – important issues to consider from the point of view of an inspector
Requirements for CSP (cloud service providers) resulting from Annex 11
To do’s for regulated users with respect to chapter 7 of the EU GMP Guide
German drug law – does the German drug law or European Law effect the business of CSP; enforcement of corrective actions

Definition and types of Cloud Computing
Service models: Private Cloud, Public Cloud,
Community Cloud, Hybrid Cloud
Infrastructure as a Service (IaaS)
Platform as a Service (PaaS)
Software as a Service (SaaS)
Cloud computing scenarios, reference architectures, examples

Cloud Computing: IT Security
Examples of incidents
Strategic planning and preparation for going to cloud services
Security management and security architecture
Security certifications (e.g. ISO 27001) and what they really mean
Physical and logical security, encryption
Incident prevention and response
Professional security patch management
Identity management, authentication, authorization
Integration of cloud services with internal IT landscape

The cloud service provider business
Service provided and their delivery processes
Technology and resource pools
Business model(s) and achieving sound economics
Risk and challenges

Operating as a Cloud service Provider
Chain of command: How do SaaS cloud providers manage their PaaS or IaaS providers or the other way around
Inspections by customers (or authorities)
Cooperations between cloud providers (e.g. for common standards)
How to become the ideal customer for a CSP?

Contracts with cloud service providers
Business & Technology Risks
Intellectual Property
Service Access / Service Quality KPIs
Data Storage requirements
Inspection & audit support
Example Contract/SLA
Lessons learnt

Cloud Computing: Use cases in a GxP environment
Risk-based approach
Specific responsibilities of the cloud service provider
Specific responsibilities of the cloud customer
Separation of GxP vs. non GxP
Examples

Compliance requirements for the cloud infrastructure
Regulatory requirements
Qualification of the cloud
Validation of the cloud

Inspections and Findings
European Framework to conduct inspections
Availability, data integrity and confidentiality of data
Possibility to perform inspections of CSP
State of the art defined by BSI, ENISA and NIST
Inspections: experiences and findings

Inspections and audit experiences: The pharmaceutical industry perspective
Inspection Trends EMA – Annex 11
Inspection Trends FDA
Inspection Trends other countries
Hot Buttons

Cloud Computing: Data protection
Data protection and privacy – legal requirements
Responsibilities of the cloud service provider
Responsibilities of the cloud customer

Data classification
Responsibility and integration in the IT project management framework
Handling, processing, commissioned processing
of data
Forced disclosure
Applicable regulations
Examples and lessons learnt

Business continuity management
Necessity for Sales/Patients/Annex 11?
Assessing the Business Continuity Risk
Buss. Cont. Plan – BCP
Disaster Recovery - MTPD - RTO - RPO

Government agencies and cloud computing
Objectives and capabilities of government agencies
How and where do they hook in
Internet surveillance and specific attacks
Industry espionage
Countermeasures and their limitations

Experiences with outsourcing and cloud computing
QA involvement
Pain points

Cloud computing: Pros and cons – includes closing discussion
Opportunities and risks of cloud computing
Rationale for using cloud services
Rationale for not using cloud services
Conclusions and recommendations

stop

This course is part of the GMP Certification Programme "ECA Certified Computer Validation Manager" Learn more

This training/webinar cannot be booked. Send us your inquiry by using the following contact form.

To find alternative dates for this training/webinar or similar events please see the complete list of all events.

For many training courses and webinars, there are also recordings you can order and watch any time. Just take a look at the complete list of all recordings.

* also payable by credit card
American Express Visa Mastercard

icon
Further dates on-site
Further dates on-site
Not available
icon
Further dates online
Further dates online
Not available
icon
Recording
Not available

Do you have any questions?

Please contact us:
Tel.: +49 6221 8444-0
E-Mail: info@gmp-compliance.org

Woman with headset

Go back

Testimonials about our courses and conferences

“Fantastic course – I really enjoyed the interactive structure & greatly appreciate social activity.”

Anthony Cummins, Sebela Pharmaceuticals, Ireland
GMP Auditor Practice, September 2023

 

“Very well organized, information on point without being overwhelming.”

Eleni Kallinikou, Pharmathen
Live Online Trainng - Pharmaceutical Contracts - Febuary 2024

 

“Good overview of different types of agreements, good to see both the GMP and the legal angle”

Ann Michiels, Johnson&Johnson
Live Online Trainng - Pharmaceutical Contracts, Febuary 2024

 

 

“Well prepared presentations and good presenters. I also like the way of asking questions.”

Alexandra Weidler, Hookipa Biotech GmbH, Austria
Live Online Training – QP Education Course Module A, November 2023