Machine translation: this English text was automatically translated from the original Dutch article. If anything is unclear or differs, please refer to the Dutch original.
Event language: This event was held in Dutch.
On 28 November, DARQA’s GLP Committee organised a theme day on a topical subject: the connection between Good Laboratory Practice (GLP) and IT security. The event was prompted by the publication of the latest OECD document, No. 25, entitled “Good Laboratory Practice and IT Security”. As is customary when new OECD publications appear, the Dutch Health and Youth Care Inspectorate (IGJ) was also present.
The meeting attracted around 50 participants, including new DARQA members and several visitors attending a DARQA event for the first time.
Secure storage of GLP data
The day began with a presentation by Frans Boeijen, who addressed the question: How do you safeguard electronic GLP data? He outlined the similarities between measures for paper and digital data and emphasised additional steps for optimal protection, such as incident recording, penetration testing, and backup and restore procedures, alongside familiar measures such as firewalls and antivirus software.
Improving QA audits with OECD GLP Document No. 25
John Cheshire of Headway Quality Evolution Ltd joined as an external speaker. He provided an overview of QA responsibilities in the various OECD GLP documents and explained the link with Document No. 25. He also offered practical questions that QA professionals can ask during audits based on this document.
Cyberattack: what now?
Frans Brouwer then guided the participants through a realistic scenario: a cyberattack on a GLP laboratory. Working in groups, they considered the steps needed to get “back in business” after such an incident. The session produced valuable insights into crisis management and recovery planning.
Practical examples from the IGJ
After lunch, IGJ inspector Mirjam Smeets presented a series of real-world examples of what can go wrong when electronic data are managed. It was an instructive overview that made clear just how crucial care and awareness are.
Panel discussion: from patching to the human firewall
All speakers, including Hans de Raad, took part in a lively panel discussion. Topics included:
- How should differences between global and local User Requirement Specifications be handled?
- What are the requirements for patching operating systems?
- How should the frequency and scope of backups be determined on the basis of risk?
- How can behavioural analytics support intrusion detection?
The human factor also received considerable attention: many incidents are caused by human actions. Training and awareness are therefore indispensable—the “human firewall” is at least as important as technical safeguards.
Q&A with the inspectors
The concluding Q&A covered questions including the validation of Excel spreadsheets. The advice was to avoid Excel for generating GLP data, but to use it for analysing existing data only when it has been validated. The role of the Archivist in cloud storage and the importance of clearly allocating responsibilities between IT and archiving were also discussed.
Main conclusion
All presentations showed that IT security measures in GLP environments are primarily intended to reduce the risks of data loss or damage. Every organisation must be aware of these risks and take appropriate measures to achieve and maintain compliance.
The day ended with informal drinks, providing ample opportunity to exchange knowledge and experiences—exactly as DARQA intended.
Frans Brouwer
Chair, GLP Committee
