{"id":646,"date":"2025-12-03T06:37:40","date_gmt":"2025-12-03T05:37:40","guid":{"rendered":"https:\/\/www.darqa.org\/?p=646"},"modified":"2026-08-11T12:55:50","modified_gmt":"2026-08-11T10:55:50","slug":"report-glp-theme-day-quality-meets-security-bridging-glp-principles-and-it-practice","status":"publish","type":"post","link":"https:\/\/www.darqa.org\/index.php\/language\/en\/2025\/12\/03\/report-glp-theme-day-quality-meets-security-bridging-glp-principles-and-it-practice\/","title":{"rendered":"Report on the GLP Theme Day \u2013 Quality Meets Security: Bridging GLP Principles and IT Practice"},"content":{"rendered":"<p><em>Machine translation: this English text was automatically translated from the original Dutch article. If anything is unclear or differs, please refer to the Dutch original.<\/em><\/p>\n<p><strong>Event language:<\/strong> This event was held in Dutch.<\/p>\n<p>On 28 November, DARQA\u2019s GLP Committee organised a theme day on a topical subject: the connection between <strong>Good Laboratory Practice (GLP)<\/strong> and <strong>IT security<\/strong>. The event was prompted by the publication of the latest OECD document, No. 25, entitled <em>\u201cGood Laboratory Practice and IT Security\u201d<\/em>. As is customary when new OECD publications appear, the Dutch Health and Youth Care Inspectorate (IGJ) was also present.<\/p>\n<p>The meeting attracted around 50 participants, including new DARQA members and several visitors attending a DARQA event for the first time.<\/p>\n<p><strong>Secure storage of GLP data<\/strong><\/p>\n<p>The day began with a presentation by <strong>Frans Boeijen<\/strong>, who addressed the question: <em>How do you safeguard electronic GLP data?<\/em> He outlined the similarities between measures for paper and digital data and emphasised additional steps for optimal protection, such as incident recording, penetration testing, and backup and restore procedures, alongside familiar measures such as firewalls and antivirus software.<\/p>\n<p><strong>Improving QA audits with OECD GLP Document No. 25<\/strong><\/p>\n<p><strong>John Cheshire<\/strong> of Headway Quality Evolution Ltd joined as an external speaker. He provided an overview of QA responsibilities in the various OECD GLP documents and explained the link with Document No. 25. He also offered practical questions that QA professionals can ask during audits based on this document.<\/p>\n<p><strong>Cyberattack: what now?<\/strong><\/p>\n<p><strong>Frans Brouwer<\/strong> then guided the participants through a realistic scenario: a cyberattack on a GLP laboratory. Working in groups, they considered the steps needed to get \u201cback in business\u201d after such an incident. The session produced valuable insights into crisis management and recovery planning.<\/p>\n<p><strong>Practical examples from the IGJ<\/strong><\/p>\n<p>After lunch, IGJ inspector <strong>Mirjam Smeets<\/strong> presented a series of real-world examples of what can go wrong when electronic data are managed. It was an instructive overview that made clear just how crucial care and awareness are.<\/p>\n<p><strong>Panel discussion: from patching to the human firewall<\/strong><\/p>\n<p>All speakers, including <strong>Hans de Raad<\/strong>, took part in a lively panel discussion. Topics included:<\/p>\n<ul>\n<li>How should differences between global and local User Requirement Specifications be handled?<\/li>\n<li>What are the requirements for patching operating systems?<\/li>\n<li>How should the frequency and scope of backups be determined on the basis of risk?<\/li>\n<li>How can <strong>behavioural analytics<\/strong> support intrusion detection?<\/li>\n<\/ul>\n<p>The human factor also received considerable attention: many incidents are caused by human actions. <strong>Training and awareness<\/strong> are therefore indispensable\u2014the \u201chuman firewall\u201d is at least as important as technical safeguards.<\/p>\n<p><strong>Q&amp;A with the inspectors<\/strong><\/p>\n<p>The concluding Q&amp;A covered questions including the validation of Excel spreadsheets. The advice was to avoid Excel for generating GLP data, but to use it for analysing existing data only when it has been validated. The role of the Archivist in cloud storage and the importance of clearly allocating responsibilities between IT and archiving were also discussed.<\/p>\n<p><strong>Main conclusion<\/strong><\/p>\n<p>All presentations showed that IT security measures in GLP environments are primarily intended to reduce the risks of data loss or damage. Every organisation must be aware of these risks and take appropriate measures to achieve and maintain compliance.<\/p>\n<p>The day ended with informal drinks, providing ample opportunity to exchange knowledge and experiences\u2014exactly as DARQA intended.<\/p>\n<p><strong>Frans Brouwer<\/strong><\/p>\n<p>Chair, GLP Committee<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The GLP Theme Day explored the connection between Good Laboratory Practice and IT security, with practical insights into data protection, audits, cyber incidents, backups and the human factor.<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[68],"tags":[],"class_list":["post-646","post","type-post","status-publish","format-standard","hentry","category-uncategorised-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/posts\/646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/comments?post=646"}],"version-history":[{"count":1,"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/posts\/646\/revisions"}],"predecessor-version":[{"id":665,"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/posts\/646\/revisions\/665"}],"wp:attachment":[{"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/media?parent=646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/categories?post=646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darqa.org\/index.php\/wp-json\/wp\/v2\/tags?post=646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}