1. 定期检查时钟:负责系统安全的人员应定期进时钟安全性检查,以检测和阻止未经授权的时钟更改。
2. 时间戳准确性:必须使用第11部分规定的程序和控制措施,确保电子记录的真实性和完整性。时间戳应基于准确可靠的计算机系统时钟。
3. 同步:计算机时钟应正确设置并持续正确设置。网络上的计算机应自动与指定的网络计算机同步,未连接到网络的计算机应定期与标准时钟同步。
4. 系统时钟安全:应建立和遵循程序,以检测和阻止计算机时钟的不当更改。员工应接受培训,了解未经授权更改时钟设置的严重性。
5. 时区管理:应明确使用的时区参考,并在系统文档中解释。时间戳应包含时区参考,以确保电子记录的真实性和完整性。
以下是原文……
当然,这里是按照序号进行的双语翻译:
---
5.Key Principles and Practices
5. 关键原则和实践
5.1.Time Stamp Accuracy
5.1.时间戳准确性
Persons must use procedures and controls for time stamps under part 11(as described above),designed to ensure,among other things,the authenticity and integrity of electronic records.Accordingly,procedures and controls should be implemented to ensure time stamps are accurate and reliable.It is extremely important for time stamps to be based on computer system clocks that are accurate and reliable.
人员必须使用第11部分(如上所述)中描述的时间戳程序和控制措施,以确保电子记录的真实性和完整性。因此,应实施程序和控制措施以确保时间戳的准确性和可靠性。对于时间戳来说,基于准确可靠的计算机系统时钟是极其重要的。
5.1.1.Synchronization
5.1.1.同步
Computer clocks should be set correctly and continue to be set correctly.You should establish and follow procedures to ensure that computer clocks are set properly.For example,computers on a network should automatically synchronize their clocks with that of a designated network computer(e.g.,as part of the process of logging on to the network).The network“master clock”or time server should,itself,be synchronized to a recognized standard computer clock.Computers not connected to a network should have their clocks synchronized to a recognized standard clock and should be periodically verified against the standard clock.
计算机时钟应正确设置并持续正确设置。您应建立和遵循程序,以确保计算机时钟设置正确。例如,网络上的计算机应自动与指定的网络计算机(例如,作为登录网络过程的一部分)同步其时钟。网络“主时钟”或时间服务器本身应与公认的标准计算机时钟同步。未连接到网络的计算机应将其时钟与公认的标准时钟同步,并应定期与标准时钟进行验证。
5.2.Systems Clock Security
5.2.系统时钟安全
You should be able to detect inappropriate changes to computer clocks.You should establish and follow procedures to detect and deter inappropriate changes to computer clocks.For example,employees should be made aware that unauthorized changes to clock settings are serious and unacceptable actions.We believe employee training and awareness programs are especially important where computer systems lack a technical means of preventing people from changing clock settings.For example,in general,laptop computers lack a means of preventing clock changes.
您应能够检测到计算机时钟的不当更改。您应建立和遵循程序,以检测和阻止计算机时钟的不当更改。例如,应让员工意识到未经授权的时钟设置更改是严重且不可接受的行为。我们认为,员工培训和意识计划尤为重要,尤其是在计算机系统缺乏技术手段防止更改时钟设置的情况下。例如,一般来说,笔记本电脑缺乏防止更改时钟设置的手段。
5.3.Time Zones
5.3.时区
In the preamble to the final rule for part 11,entitled“21 CFR Part 11 Electronic Records;Electronic Signatures,”we stated:“[R]egarding systems that may span different time zones,the agency advises that the signer’s local time is the one to be recorded.”(See comment paragraph 101 in 62 Fed.Reg.13430,at 13453(March 20,1997).)We have reconsidered this position,and the guidance presented here reflects our current thinking,and supersedes the position in comment 101 with respect to the time zone that should be recorded.
在第11部分最终规则的前言中,题为“21 CFR 第11部分 电子记录;电子签名”,我们指出:“关于可能跨越不同时区的系统,机构建议记录签署者的本地时间。”(参见62 Fed.Reg.13430,第13453条(1997年3月20日))。我们已经重新考虑了这一立场,这里提供的指导反映了我们当前的思考,并取代了评论101中关于应记录的时区的位置。
You should implement time stamps with a clear understanding of what time zone reference you use.Systems documentation should explain time zone references as well as zone acronyms or other naming conventions.For example,the time zone reference might be a central point like Greenwich Mean Time,a point local to the computer where the activity linked to the time stamp occurs,or a point where the time stamp clock(e.g.,a time stamp server)is located.
您应实施时间戳,明确了解您使用的时区参考。系统文档应解释时区参考以及区域缩写或其他命名约定。例如,时区参考可能是一个中央点,如格林尼治标准时间,或者是与时间戳活动相关的计算机上的一个点,或者是时间戳时钟(例如,时间戳服务器)所在的点。
The time zone reference should be part of the time stamp itself and appear in human readable forms of the time stamp.In our view,this procedure would help to ensure the authenticity and integrity of the electronic record(as well as the electronic audit trail)because it potentially eliminates confusion with respect to the timing of a particular event or action that could be attributed to different time zones.
时间戳参考应是时间戳本身的一部分,并以人类可读的形式出现。我们认为,这一程序将有助于确保电子记录(以及电子审计跟踪)的真实性和完整性,因为它可能消除了与特定事件或行动的时间可能归因于不同时区的混淆。
We recognize,however,that you might not elect to include the time zone reference in the time stamp itself or as part of the human readable form of the time stamp.We believe this approach can be potentially problematic if records are copied or transferred within(or accessed from)different organizations,or different components of an organization,that use different time zone references.In such cases,the reader could easily become confused as to exactly what time zone reference was used.Nonetheless,if you decide to adopt this approach,you should have readily available systems documentation that clearly explains what time zone references apply,and you should establish mechanisms to ensure that the reader has a clear and accurate understanding of the correct time zone printout).
然而,我们认识到,您可能不会选择在时间戳本身或人类可读形式中包含时区参考。我们认为这种方法可能在记录在不同组织之间(或从)复制或传输时,或组织的不同组件使用不同时区参考时,具有潜在问题。在这种情况下,读者可能容易对使用的时区参考感到困惑。尽管如此,如果您决定采用这种方法,您应有现成的系统文档,清楚地解释适用的时区参考,并应建立机制,确保读者对正确的时间戳有清晰准确的理解。