10
SAFE is a member-governed, not-for- SAFE is a member-governed, not-for- profit enterprise that: profit enterprise that: Manages and promotes the SAFE standard Manages and promotes the SAFE standard Provides a legal and contractual framework Provides a legal and contractual framework Provides technical infrastructure to Provides technical infrastructure to bridge different credentialing systems bridge different credentialing systems Provides SAFE identity credentials, both Provides SAFE identity credentials, both directly and through vendors directly and through vendors Supports vendors who supply SAFE-enabled Supports vendors who supply SAFE-enabled products. products. SAFE project initiated in November 2003 SAFE project initiated in November 2003

SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

Embed Size (px)

Citation preview

Page 1: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

SAFE is a member-governed, not-for-profit SAFE is a member-governed, not-for-profit enterprise that:enterprise that:

Manages and promotes the SAFE standard Manages and promotes the SAFE standard

Provides a legal and contractual framework Provides a legal and contractual framework

Provides technical infrastructure to bridge different Provides technical infrastructure to bridge different credentialing systems credentialing systems

Provides SAFE identity credentials, both directly Provides SAFE identity credentials, both directly and through vendors and through vendors

Supports vendors who supply SAFE-enabled Supports vendors who supply SAFE-enabled products. products.

SAFE project initiated in November 2003SAFE project initiated in November 2003

Page 2: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

Pharma APharma B

Pharma X Pharma CSite ID

Pharma DUser ID/

Password

Current environmentCurrent environment

Many Credentials Many Credentials

Access control OnlyAccess control Only

Physical paper signing requiredPhysical paper signing required

High user complexityHigh user complexity

High costHigh cost

SAFE environmentSAFE environment

One CredentialOne Credential

Access control and eSignatureAccess control and eSignature

Eliminate paper signaturesEliminate paper signatures

Lower aggregate costsLower aggregate costs

Page 3: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

SAFE-BioPharma Association incorporated May 2005SAFE-BioPharma Association incorporated May 2005

Page 4: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

SAFE Registration

System(RACCA)

Subscriber

SAFECA

(CyberTrust)

SAFEBridge CA

(CyberTrust)

CitiBank

JJEDS

JJEDSSubscriber

CitibankSubscriber

Page 5: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

Pfizer:Pfizer:eLab NotebookseLab Notebooks

Regulatory submissionsRegulatory submissions

AstraZeneca:AstraZeneca:150+ regulatory 150+ regulatory submissions via FDA’s submissions via FDA’s ESG: 2252, 1571, 356h ESG: 2252, 1571, 356h and eCTDand eCTD

GSK:GSK:eCTD submissionseCTD submissions

J&J:J&J:All J&J certificates are All J&J certificates are SAFE SAFE

P&G:P&G:

Enterprise digital signature Enterprise digital signature

4,500 eLab Notebooks4,500 eLab Notebooks

ePurchasingePurchasing

eHR – formseHR – forms

ePatent FilingsePatent Filings

BMS:BMS:

External partner External partner authenticationauthentication

Page 6: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

SAFE Member reps with QA/Compliance/Reg backgroundsSAFE Member reps with QA/Compliance/Reg backgrounds

FDA key offices engaged since inceptionFDA key offices engaged since inception

Jointly-developed SAFE/FDA Auditor Familiarization ProgramJointly-developed SAFE/FDA Auditor Familiarization Program

FDA statement on SAFEFDA statement on SAFE

Complies with appropriate guidance, especially as related to 21CFR11Complies with appropriate guidance, especially as related to 21CFR11

When used as the basis for implementation of a digital signature When used as the basis for implementation of a digital signature capability, the SAFE standard facilitates user compliance with 21CFR11capability, the SAFE standard facilitates user compliance with 21CFR11

SAFE-FDA Auditor/Compliance Workshop SAFE-FDA Auditor/Compliance Workshop

Training audit of SAFE-signed submissionTraining audit of SAFE-signed submission

The FDA’s goal is to eliminate paper from application receipt and review processes. A paperless application process must include legally

binding electronic signatures.

Page 7: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

ParticipantsParticipants

SAFE Evaluation Team: EMEA, GSK, Organon, PfizerSAFE Evaluation Team: EMEA, GSK, Organon, Pfizer

SAFE EU Advisory CouncilSAFE EU Advisory Council

EU and Member State regulationsEU and Member State regulations

EU implementationsEU implementations

Next StepsNext Steps

eCTD submission by SAFE membereCTD submission by SAFE member

Auditor workshop – EMEA and Member State RegulatorsAuditor workshop – EMEA and Member State Regulators

The SAFE Evaluation Team (EMEA, EFPIA, Companies) determined that SAFE meets EU Electronic Signature and Clinical

Trial Directives requirements.

Page 8: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

• Adobe• Aladdin• Arcot• Bearing Point• CoreStreet • Cybertrust

SAFE Premier Partners• ARX• DataLabs• IntraLinks• Solabs• Open Text

SAFE Issuers

• Citibank• Cybertrust• IdenTrust• J&J• BMS• P&G

SAFE Partners

• IBM• IDBS• Microsoft• Northrop

Grumman

Page 9: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

FBCA cross certificationFBCA cross certification

In progress, mid-2007In progress, mid-2007

Token-less CredentialsToken-less Credentials

Simplify deployment to Research PartnersSimplify deployment to Research Partners

Page 10: SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical

Existing PKI Cross certified with SAFE September 2005Existing PKI Cross certified with SAFE September 2005

Issued ~75,000 certificates to date (employees, partners)Issued ~75,000 certificates to date (employees, partners)

Regulatory FilingsRegulatory Filings

Remote Access (VPN) Remote Access (VPN)

Policies require two-factor authenticationPolicies require two-factor authentication

Signed/Encrypted emailSigned/Encrypted email

Certificate-based logon – to the LAN and applicationsCertificate-based logon – to the LAN and applications

Hard disk (“media”) and file/folder encryptionHard disk (“media”) and file/folder encryption

Digital Signatures Digital Signatures

QA documentationQA documentation

System Build documentationSystem Build documentation

Site Monitor Trip ReportsSite Monitor Trip Reports

E-Trial Master File applicationE-Trial Master File application