Upload
arleen-patterson
View
255
Download
18
Embed Size (px)
Citation preview
Yokogawa Electric Corporation
Exaquantum/Batch Validation Planning Guide – Issue ACopyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Industrial Automation Systems Division
Validation Configuration Guidance
Page 2Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Contents
Time Issues– Time Zones
– Time Synchronization
System Security– Limiting Access
– Accounts & Passwords
– BatchWeb Clients
Audit Trail– Operational audit trail
– Configuration data
– System data
Part 11 License Features
CS Batch 3000 Configuration for ABDC
Yokogawa Electric Corporation
Exaquantum/Batch Validation Planning Guide – Issue ACopyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Industrial Automation Systems Division
Time Issues
Page 4Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Issues
Time Zones– Time Scenarios
– Reports
– Summer Time
Time Synchronization Scenarios– Auto Batch Data Collection (ABDC)
– Custom Batch Data Collection (CBDC)
– ABDC & CBDC
– Time Synchronization with External Time Source
Time Recommendations
Page 5Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Zones
All data is stored as UTC– UTC = Universal Coordinated Time (~GMT)
When collected and written to the database time stamps are converted from local time to UTC– The original time zone is not saved
When data is displayed in BatchWeb time stamps are converted from UTC to the web server’s local time– If the web server is in the same time zone as the DCS was then
• displayed time will match local time records
– If the web server is in a different time zone than the DCS then • there will be a time difference
Reports– Report designer has option to fetch time in UTC or Local Time
• Database Table time columns are in UTC• Database View have both UTC and Local Time columns for each time
value
Page 6Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time – Scenario #1
Exaquantum/Batch located with DCS in eastern U.S.
BatchWeb clients in eastern U.S. and Europe see the same times in BatchWeb since the Web Server’s time zone is –05:00
DCSEQB
ServerWeb
Server
BatchWeb Client
BatchWeb Client
Time Zone–05:00
Time Zone 2+01:00
Event occurs at 3:12 PM (15:12) local time
Stored in database as 20:12 UTC
BatchWeb displays time as 3:12 PM using Web Server’s time and locale settings
Report designers have option of Table data in UTC or View data in the server’s local time
Report configuration sets how BatchWeb views will see times in reports
ReportPackag
e
Page 7Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time – Scenario #2 - Recommended
Exaquantum/Batch located with DCS in eastern U.S.
Exaquantum/Batch Server’s and Web Server’s local time is UTC
All BatchWeb clients and all reports use UTC time
DCS-05:00
EQB Server
UTC
Web Server
UTC
BatchWeb Client-05:00
BatchWeb Client+01:00
Time Zone–05:00
Time Zone 2+01:00
Event occurs at 3:12 PM (15:12) local time
Stored in database as 20:12 UTC
BatchWeb displays time as 20:12 (UTC) using Web Server’s time and locale settings
Report designers have option of Table data in UTC or View data in the server’s local time
Report configuration sets how BatchWeb views will see times in reports
ReportPackag
e
Page 8Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Reports – Time Zones
Reports may obtain – Raw data from the
database Tables or– Data from the database
Views
There is no difference for data other than time values
There is a difference in Time Values– Tables return data in UTC– Views contain time values
in both UTC and server’s local time
– Report Designer decides which time value to use
BatchWeb always uses the Web Server’s local time
Local TimeWeb Server’s Date/Time Format Used
Local TimeDate/Time Format set in Excel
UTC Time
Page 9Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time – Summer Time
When the Exaquantum/Batch Server’s operating system changes between summer and normal time time stamps are converted to UTC using the correct offset
No need for human intervention
1 amEST
0600UTC
3 amEDT
4 amEDT
0800UTC
0700UTC Time
1 amEDT
0500UTC
1 amEST
2 amEST
0700UTC
0600UTC
Start of Summer Time(Daylight Savings Time)
End of Summer Time(Daylight Savings Time)
EST = Eastern Standard Time (U.S.)EDT = Eastern Daylight Time (U.S. Summer Time)UTC = Universal Coordinated Time (GMT)
Page 10Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Synchronization
Clocks of Exaquantum/Batch and all data sources must be synchronized– Lack of synchronization will lead to conflicting date/time data
Exaquantum/Batch server’s clock should be synchronized to the Exaopc Station– Exaopc Station is synchronized by V-Net
– Refer to CS 3000 Part 11 TI for information CS 3000 time management
• Explains how system clock can be synchronized with external time sources
Web Server should be synchronized with the Exaquantum/Batch server or directly to the Exaopc Station
BatchWeb clients are each responsible for their own synchronization– BatchWeb times are set by the web server, not the client
Page 11Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Synchronization – ABDC Scenario
When Automatic Batch Data Collection (ABDC) is used– Exaquantum/Batch should be synchronized with CS Batch 3000 via the
Exaopc server
Exaquantum/Batch Server
Web Server
BatchWeb Client
FCS
Exaopc
Server
HIS
Vnet or Vnet/IP
Ethernet
Exaquantum/Batch Server’s time is
synchronized to the Exaopc Server’s Time
Vnet or Vnet/IP is a synchronized bus
All station’s clocks are automatically synchronized
If a separate Web Server is used it
should be synchronized to
the Exaopc Server
BatchWeb Clients do not have to be synchronized to
server
OK to use Windows Domain time
synchronization
Page 12Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Synchronization – CBDC Scenario
When Custom Batch Data Collection (CBDC) is used– Synchronization scheme depends upon capabilities of the OPC server
Options:– Exaquantum/Batch synchronizes with the OPC Data Access Server– OPC Data Access Server synchronizes with Exaquantum/Batch server– Exaquantum/Batch synchronizes with the control system
Exaquantum/Batch Server
Web Server
BatchWeb Client
OPC Serve
r
Ethernet
Control System
Page 13Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Synchronization – ABDC & CBDC Scenario
When Automatic Batch Data Collection (ABDC) and Custom Batch Data Collection (CBDC) are used– Exaquantum/Batch, OPC servers and all control/lab/information systems
should be synchronized with a single time source– Synchronization paths dependent upon capabilities of the systems– All systems should use the same time zone
Exaquantum/Batch Server
Web Server
Exaopc Server
Ethernet
Exaopc Server
CS 3000
CS Batch 3000
OPC Server
PLC
OPC Server
LIMS
Page 14Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Synchronization – External Time Source
Synchronization provides system wide time consistency– Not necessary the correct time
Accurate time values can only be achieved using an external time source– Example: GPS time – The time master should be configured to synch to the external time source
Exaquantum/Batch Server
Web Server
Exaopc Server
Ethernet
Exaopc Server
CS 3000
CS Batch 3000
OPC Server
PLC
OPC Server
LIMS
External Time
Source
Page 15Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Time Recommendations
Synchronize Exaquantum/Batch with the control systems– For Automatic Batch Data Collection
• Sync Exaquantum/Batch server to the Exaopc Station
– For Custom Batch Data Collection• Sync Exaquantum/Batch Data Collection to the control system
• If multiple control systems are involved assign one as the master and synchronize Exaquantum/Batch and other control systems to it
– Use an external time source when time accuracy is critical
– Refer to TI33Q01A61-01E, “CENTUM CS 1000/CS 3000 Yokogawa’s Approach to meeting FDA 21 CFR Part 11”, section 4 for information about CS Batch 3000 time synchronization
Use a single time zone for entire system– Recommend using UTC (GMT)
– Do not use daylight savings time (summer time) adjustment• Can cause confusion when reading historical data
– Remember: BatchWeb time values use the Web Server’s time zone
• They do not use the web client’s time zone
Yokogawa Electric Corporation
Exaquantum/Batch Validation Planning Guide – Issue ACopyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Industrial Automation Systems Division
System Security
Page 17Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
System Security
Limiting access– Physical
– Electronic
Windows security
Database security
Web Server security
Access control
Page 18Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
System Security
Exaquantum/Batch should be operated within a secure intranet
System security should be an on-going activity – Must be done in cooperation with corporate policies and IT group
No pre-set list of recommendations will work in all cases
This presentation provides configuration guidance for certain aspects of security configuration
Yokogawa can provide consulting services to customize system security measures
Page 19Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Limiting Access
Unauthorized access– An intruder who has breached the corporate firewall or physical
security
– An employee who is not authorized to access specific Exaquantum/Batch functions or has bypassed procedures
Physical Access– Physical access to Exaquantum/Batch servers should be
controlled• Normal plant security• Locked doors on server room• Limit access to trusted and trained personnel
Electronic Access– Firewalls limit external access
– Account management limits internal access
Page 20Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Microsoft Products
Microsoft publishes extensive information on securing their products
Windows 2000/2003www.microsoft.com/security
www.microsoft.com/security/guidance/prodtech/Windows2000.mspx
SQL Server 2000www.microsoft.com/technet/security/prodtech/dbsql/default.mspx
www.microsoft.com/sql/techinfo/administration/2000/security/
Internet Information Server (IIS) – Microsoft’s Web Serverhttp://support.microsoft.com/default.aspx?scid=fh;EN-US;iis50
http://support.microsoft.com/default.aspx?scid=kb;en-us;300390&sd=tech
Windows updates– Apply only apply after Yokogawa has announced support for an
update
– Windows 2000/2003 Server (includes IIS Web Server)
– SQL Server 2000
Page 21Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
User Account Settings
Use standard Windows account options– Lockout after 3 failed attempts
– Automatic reset after timeout
Disable accounts – do not delete them– Deleted account names cannot be used again
– Disabling accounts prevents duplicating account names over time
Disable Guest account– Create custom Guest account with different name if needed
Windows 2000/2003 Administrative Tools– Computer Management Program
• Use “Local Users and Groups” to manage accounts
– Local Security Settings• Use to set security policy
Page 22Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Account Policy Settings
Local Security Settings– Access in Administrative Tools menu
– Use to set • Account policies• Rights (e.g. ability to shutdown the computer)• Security options (e.g. not displaying last logged last user name in
logon screen)• Audit trail policy (e.g. types of events to log)
Page 23Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Intrusion detection
Enable Windows security auditing– Done in Local Security Settings program
– Writes security events to event log
SOP to monitor security event log to detect intrusion attempts
Page 24Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Registering Users
1 time setup– Create “role” based domain groups
– Add “role” based domain groups to local EQB server groups
for each new user– Domain account
– Assign to a domain “role” group
– Fill in Full Name field for each account• Used to identify account owner• Account name not used to minimize
publicizing it
Page 25Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Registering Users
Each person using Exaquantum/Batch must1. Have a Windows 2000 or Windows 2003 account
2. The account must have the privilege to access Exaquantum/Batch
Managing Windows 2000/2003 accounts– System Administrators create Windows 2000/2003 accounts
– Domain or local (local to the computer) accounts may be used• Domain administrators must manage domain accounts
Page 26Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Adding New Windows User (1 of 2)
Use Computer Management program– In Windows 2000/2003 Administrative Tools on the Start Menu
Select “System Tools”, “Local Users and Groups”, “Users”
Page 27Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Adding New Windows User (2 of 2)
Select “New User” on the “Action” menu
New User dialog box opens
Complete this to create a new user
Page 28Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Assigning Privileges
Double click on the account name in Computer Management – Account Properties dialog is
displayed
– Click on the “Member Of” tab to view current privileges
Privileges are assigned by placing an account in a Windows 2000/2003 Group– Same technique as making a
user an Administrator or Power User
Add Privileges– Use Add button to add local
groups to the list
Remove Privileges– Select group in the list, click
Remove button
Page 29Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Using Domain Groups
Domain administrators must assign privileges
Domain groups should be role based– QBAdministrator
– QBEngineer
Domain accounts made members of domain group
Dialog as viewed on Domain Controller
Page 30Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Using Domain Groups
Add domain group to the Exaquantum/Batch server’s groups to grant privileges to a role
Example– Exaquantum/Batch servers
QAdministrator group
– Add domain QBAdministrator group as a member of the local QAdministrator group
• Gives all members of domain QBAdministrator group privilege of the local QAdministrator group
Page 31Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Automatic Lockout During Inactivity
Reduces chance of unauthorized actions at unattended consoles– If user does not log out/lock computer when away unauthorized
user may use their account
Screen saver can lock computer after period of inactivity– Standard Windows 2000/2003 screen
saver sufficient for most cases
– Require logon after lock-out
– No industry standard for duration of period of inactivity
3rd party transparent screen saver can be used to allow viewing of screen during lock-out– One example ishttp://www.e-motional.com/TScreenLock.htm
Page 32Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Logon
BatchWeb uses Windows Authentication
If domain accounts are used BatchWeb requires access to a domain controller– User must logon
If local groups are used– Matching account/password on Remote
user’s computer and web server provides unchallenged logon
If web server and web client have matching account name and different passwords or web server does not have the account name locally– User must logon
If web server has account and the account does not have QUserGroup access– Access denied
Page 33Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Password Management
Key Exaquantum/Batch and CS Batch 3000 accounts– Accounts:
• Quantumuser – Exaquantum/Batch administrator account• Exa – Exaopc server’s default account• Centum – CS Batch 3000 default account• sa – SQL Server administrator account
Password policies– Use strong passwords for administrator accounts
– Do not change frequently• Changing passwords increase possibility of mis-matches and
operational interruptions
Create procedure password management procedure– Frequency of changes
– Method, order & checklist for changing accounts
Page 34Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Password Complexity
Windows 2000/2003 can be configured to force passwords to have a minimum level of complexity – Default password filter (passfilt.dll) requires that a password:
• Does not contain all or part of the user's account name • Is at least six characters in length • Contains characters from three of the following four
categories: • English upper case characters (A..Z) • English lower case characters (a..z) • Base 10 digits (0..9) • Nonalphanumeric (For example, !,$#,%)
– Complexity requirements are enforced upon password change or creation.
– To create custom password filters, refer to the Microsoft Platform Software Development Kit and the Microsoft Knowledge Base.
– From:http://msdn.microsoft.com/library/default.asp?url=/library/en-us/gp/
504.asp
Page 35Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Clients
Internet Explorer settings
Secure Browser
Data entry
Page 36Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Required IE Settings for BatchWeb (1/2)
Settings required for Exaquantum ActiveX Controls
Internet Options | Security– Local Intranet– Custom Level
Page 37Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Required IE Settings for BatchWeb (2/2)
Security tab– Enable
• Download signed ActiveX controls
• Initialize and script ActiveX controls
• Run ActiveX controls and plug-ins
• Script ActiveX controls marked as safe for scripting
– User Authentication • “Automation logon with current name and
password”
Connections tab– LAN Settings
• If proxy used, check “Bypass proxy server for local addresses”
Advanced tab | Security– Enable Integrated Windows Authentication
Page 38Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Yokogawa Secure Browser
Secure Browser is part of the YCA ETSPortal product– Available as a separate installation
Custom program encompassing the Microsoft Internet Explorer ActiveX control
Limits users access to IE functions
Page 39Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Secure Browser Features
Only limited set of features exposed– Toolbars
• Back/Forward• Stop• Refresh• Home• Print• Read only URL selection
– Menus• Print, Print Setup, Exit, Toolbar and Navigation Bar(hide/show), Help
No access to other IE features– File system using File | Open/Save/Save As
– Favorites
– Internet Options
– Mail and News
– Windows Update …
Page 40Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Secure Browser Uses
Use with CS Batch 3000 HIS to restrict file system access by operators
Plant floor kiosk type computers
Any environment where users required to have limited web access
Dedicated BatchWeb program– Home batch can be BatchWeb
• Normal IE can be used with a different home page
– Desktop shortcuts to BatchWeb• IE can be used for normal web uses
Page 41Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Data Entry
BatchWeb is primarily for viewing data
Entering data in BatchWeb– Operational Data
• Formula items, values• Performance ratings• Report
– Approve, Check-out/in, Delete
– Personalization data• System wide• Account specific
Page 42Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Personalization data
System wide– Batch trend templates
– Quick Link entries
Account specific– MyList
– View options
– Related Links settings
– Filter settings
– Selected items
Yokogawa Electric Corporation
Exaquantum/Batch Validation Planning Guide – Issue ACopyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Industrial Automation Systems Division
Audit Trail
Page 44Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Audit Trail
Operational audit trail– Identification of manually entered data
– Reporting
– Exporting
Configuration data
System data– Windows logs
– SQL Server logs
– IIS logs
Page 45Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Operational Audit Trail
Operations records– Actions taken by operators on using CS Batch 3000 are recorded
as events• If associated with a batch this association is maintained in
Exaquantum/Batch• If not associated with a batch the timestamp may be used to find
actions taken during the time a batch was running
– Changes to property values are recorded in the PropertyHistory table
• Changes in property values from start of batch to end of batch are recorded
• Record made even if no human intervention– Formula value changes are recorded so changes made by SEBOL or CS
Batch 3000 operators are recorded
Reports for FDA inspectors– Use Excel or 3rd party report package
Page 46Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Manual Entry Audit Trail
Recorded in AuditLog table in QBatch database– BatchWeb
• New formula item• Change formula item value• Approve report• Change performance rating value
– Reports run • Manually from BatchWeb• Scheduled on time or batch event
– Performance rating calculations• Option to enable or disable log messages
Database view “AuditLogReportView” has same information with time stamps in both local and UTC– Data from table or view may be included in reports
• Recommend the view be used
Page 47Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Data Collection Program Audit Trail
The Property History Table in the QBatch database contains an audit trail of all changes to batch properties by the data collection programs– Properties of batches, unit recipes and operations
– Formula item values • E.g. from the start of the batch to the end of the batch any changes
of to a value are recorded
Property history data includes– Time stamp (UTC)
– Identification of the property changed
– Old and new value
– Identification if the change represents a new item or a modified item
All changes are by ABDC or CBDC programs, not manual entries
May be included in reports
Page 48Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Audit Trail Contents
Time stamp
User name– Not for PropertyHistory changes
(all changes by programs)
Computer name or IP address– Not for PropertyHistory changes
(all changes by server)
Identification of data changed
Old and new values
Reason for change– Not for PropertyHistory changes
(all changes due to normal data collection)
Page 49Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Reports for FDA Audits
Reports used to meet FDA audit requests– Exaquantum/Batch Report Package may be used
• Excel based• PDF output
– 3rd Party report package may be used• Crystal reports• Corporate reporting packages
All operational, configuration and meta-data are stored in the database and available to any report
Page 50Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Configuration Data
Configuration changes not recorded by an audit trail– Must be covered by procedures– Reports can be created to record snapshots of configuration data
• Reports could be triggered on database changes (programming required)
Configuration programs– System Configuration Tool– Report Template Manager– Equipment Configuration Tool– Custom Batch Data Collection Tool– Administration Tools– Other Exaquantum configuration tools may optionally be used:
• Exaquantum Explorer, Database Creation Tool, Graphics Editor,…
Report template approvals are recorded– Esig data stored in ReportTemplateVersion table
Page 51Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
System Data
Log files are the audit trails for system level events
There are different log files for each product
Windows 2000/2003– Application, Security, System log files
SQL Server– Logon data may be logged to the Windows Application Log
– C2 Level security logging may be used• Extensive, adds performance load• Monitors database administrator also
– Database Tracing may be used• Set and managed by database administrator
IIS (Internet Information Server)– Logging may be enabled to track web site access
– Use to check for unauthorized access and/or analyze which parts of BatchWeb users use most/least
Page 52Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Window Log File Management
Windows Logs– Application
• Contains Exaquantum/Batch program messages– Normal operation and error messages
– Security• Empty unless Local Security Policy used to turn on security auditing
– System• Contains operating system and some program messages
Windows log files must be periodically examined for– Size – save and empty log file before it is full and information log
– Contents – look for errors, security problems, normal behavior
View log files using Event Viewer– Control Panel | Administrative Tools | Event Viewer
Page 53Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Windows Log Configuration
Set log file size
Periodically save and clear the logs
Permit overwriting of logs as needed
Set max log size to 4096 KB or greater– Reduces risk that a repetitive
error will obscure other messages
Either manually (via SOP) or automatically (via 3rd party software) save contents of logs prior to log file filling up and older contents overwritten– If manual – check size frequently,
save and clear contents before itfills up
Current Size
Prompted to save file before it is cleared
Page 54Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Tracking Administrators Actions
Ultimately rely on trust
Options for tracking administrator actions – Not recommended, but if necessary
– Use separate Windows and Database administrators• All administrators should report outside of the production and quality
organizations to minimize production performance pressure
– Have non-Windows administrator check Window log files for continuity and abnormal actions in addition to checks by Windows administrator
– Enforce C2 security in SQL Server• Monitor SQL Server log files
– Use 3rd party packages to analyze log files
Yokogawa Electric Corporation
Exaquantum/Batch Validation Planning Guide – Issue ACopyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Industrial Automation Systems Division
Part 11 License Features
Page 56Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Exaquantum/Batch Part 11 License
Exaquantum/Batch has an optional license that enables features useful when working with Part 11
Features enabled with the license:– Electronic signature for manual data entry
– Signature manifest data and icon is displayed to indicate manually changed values
– Report output must be approved with an electronic signature
– Report check out/in feature is disabled to increase report data integrity
Other features such as audit trails and access controls are part of the base product offering
Page 57Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Electronic Signatures
Electronic signatures required for data entry (Single Signature per entry)– BatchWeb
• New formula item value• New formula item• Manual performance rating value• Approve report
– Report Template Manager• Report template approval
Signature manifest data and/or icon displayed in BatchWeb to indicate manually changed values– Signature Manifest Data:
• Signed By• Date Signed• Reason
Report Excel Files cannot be checked out
Page 58Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Manual Performance Rating Impact
View Esig Esig Icon Esig Manifest
For Batches
For Unit Recipes
Performance Rating Manual Entry
X X X
Batch List X X
Batch Property Sheet
X X
Batch Performance Rating Chart
X X X
Gantt Chart X X X
Unit Recipe List X X X
Unit Recipe Property Sheet
X X
Unit Utilization Chart X X
Page 59Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Performance Rating Manual Entry (Batch)
Signature Manifest shows data for previous rating value change
Electronic Signature required to change rating value
With Part 11 License
Page 60Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Performance Rating Manual Entry (Batch)
Electronic Signature NOT required to change rating value
Without Part 11 License
Page 61Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Performance Rating Manual Entry (Unit Recipe)
Same type of display features for manual unit recipe performance ratings as for batch ratings.
With Part 11 License
Page 62Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Performance Rating Manual Entry (Unit Recipe)
Without Part 11 License
Electronic Signature NOT required
Same type of display features for manual unit recipe performance ratings as for batch ratings.
Page 63Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch List
Signature Manifest Icon indicates value was changed using electronic signature
Signature Manifest may be viewed by clicking the Batch ID to display the Batch Property Sheet
With Part 11 License
Page 64Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch List
Without Part 11 License
No Signature Manifest Icon to indicate Performance Rating was manually changed
Page 65Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Property Sheet
Signature Manifest for manually entered batchperformance rating
With Part 11 License
Page 66Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Property Sheet
Without Part 11 License
Signature Manifest Icon & Signature Manifest are NOT displayed
Page 67Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Performance Rating Chart
Batches with changed rating values are shown with a red bar
Signature Manifest is listed in a table below the chart
With Part 11 License
Page 68Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Performance Rating Chart
Without Part 11 License
Batches with changed rating values are shown with a red bar
Signature Manifest Table is not displayed
Page 69Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Performance Rating Chart (for Unit Recipe)
Unit recipes with changed rating values are shown with a red bar
Signature Manifest is listed in a table below the chart
Unit Recipe Selected
With Part 11 License
Page 70Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Without Part 11 License
Unit recipes with changed rating values are shown with a red bar
No Signature Manifest Table
Unit Recipe Selected
Batch Performance Rating Chart (for Unit Recipe)
Page 71Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Gantt Chart
Manually entered Performance Ratings preceded with an asterisk
Table below chart shows the Signature Manifest information
With Part 11 License
Batch
Unit Recipe
Batch
Unit Recipe
Page 72Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Gantt Chart
Without Part 11 License
Manually entered Performance Ratings Not preceded with an asterisk
No Signature Manifest Table
Page 73Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Unit Recipe List
Signature Manifest icon
When clicked it calls up Signature Pop-up window containing Signature Manifest information
With Part 11 License
Page 74Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Unit Recipe List
Without Part 11 License
No Signature Manifest icon
Page 75Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Unit Recipe Property Sheet
Signature Manifest for manually entered unit recipe performance rating
With Part 11 License
Page 76Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Unit Recipe Property Sheet
Without Part 11 License
No Signature Manifest
Page 77Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Unit Utilization Chart
Manually entered Performance Ratings preceded with an asterisk
Table below chart shows the Signature Manifest information
With Part 11 License
Page 78Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Unit Utilization Chart
Without Part 11 License
Manually entered Performance Ratings Not preceded with an asterisk
No Signature Manifest Table
Page 79Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Formula Item Impact
View
New Formula Item Formula Item Value
Esig Esig Icon
Esig Manifes
t
Esig Esig Icon
Esig Manifes
t
Formula Data EntryNew Item
X
Batch Formula X X X X
Formula Item Value Entry
X X
Formula Item Array X X
Page 80Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Formula Data Entry New Item
Electronic Signature required to add formula item
With Part 11 License
Page 81Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Formula Data Entry New Item
Without Part 11 License
Electronic SignatureNOT required to add formula item
Page 82Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Formula
Manually created formula values
marked with Signature Manifest icon
Clicking Signature Manifest icon calls
upSignature Window
With Part 11 License
Page 83Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Formula
Without Part 11 License
Manually created formula values NOT marked with Signature Manifest icon
Page 84Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Formula Item Value Entry
Signature Manifest shows data for previous value change
Electronic Signature required to change value
With Part 11 License
Page 85Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Formula Item Value Entry
Without Part 11 License
Electronic Signature Not required to change value
Page 86Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Formula Item Array
Signature Manifest icon shows value was changed
Clicking on Signature Manifest icon calls up Signature window
With Part 11 License
Page 87Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Formula Item Array
Without Part 11 License
No Signature Manifest icon for changed values
Page 88Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Formula
Signature Manifest icon shows value was
changed
Signature Manifest icon shows formula item was manually created
With Part 11 License
Page 89Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Batch Formula
Without Part 11 LicenseNo Signature Manifest
icon for changed values
No Signature Manifest icon for new formula items
Page 90Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
BatchWeb Report Impact
Esig Check-out/in Disabled
Report Archive X
Report Approval X
Delete Report X
Page 91Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Archive
Check-out and Check-in options not displayed
With Part 11 License
Page 92Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Archive
Check-out and Check-in options displayed(based upon access rights)
Without Part 11 License
Page 93Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Approval
Electronic Signature required to approve report
With Part 11 License
Page 94Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Approval
Without Part 11 License
Electronic Signature NOT required
to approve reports
Page 95Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Delete Report
Electronic Signature required to delete report
With Part 11 License
Page 96Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Delete Report
Without Part 11 License
Electronic Signature NOT required
to delete reports
Page 97Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Template Manager Report Impact
Esig
Report Approval X
Page 98Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Template Approval
Electronic Signature required to Approve report template
With Part 11 License
Page 99Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Report Template Approval
Without Part 11 License
Electronic Signature NOT required
to delete reports
Yokogawa Electric Corporation
Exaquantum/Batch Validation Planning Guide – Issue ACopyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
Industrial Automation Systems Division
CS Batch 3000 Configuration
for
Automatic Batch Data
Collection
Page 101Copyright © Yokogawa Electric Corporation1st Edition April 18, 2005
Exaquantum/Batch Validation Configuration Guidance(PM36J04B91-01E_001)
CS Batch 3000 Configuration for ABDC
Use the master recipe audit trail feature– Package PHS5170
Ensures all versions of master recipes are saved to Exaquantum/Batch– Without it some versions may not be collected during
Exaquantum/Batch downtime or during loss of communication– With the package CS Batch 3000 maintains a copy of every master
recipe version• Exaquantum/Batch will collect missed versions upon recovery of the
server or communications
Use “Automatic Management of Recipe Version” option on Recipe Group properties– Forces master recipe version to be incremented when built– Reduces confusion regarding Exaquantum/Batch revision based
upon date loaded to HIS and CS Batch 3000 Master Recipe Version field
• Without option turned on all Exaquantum/Batch revisions may have the same CS version number
– Even if they have different contents