Functional Requirements to Ensure the Creation, Maintenance, and Preservation of Electronic Records
3 . System Reliability
System should be administered in line with best practices in the information resource management (IRM) field to ensure the reliability of the records it produces.
Justification: The acceptance of records for legal, audit, and other purposes is contingent on establishing their authenticity and reliability by demonstrating the trustworthiness of the system used to produce them. Systems that produce records must be shown to do so in the normal course of business and in an accurate and timely manner. System administration must incorporate established best practices in the data processing field. Policies, procedures, training and support programs, and controls must be documented.
-
Recordkeeping system employed exclusively in normal course of business.
-
Redundant (paper) recordkeeping system is discontinued.
-
System management roles and responsibilities are assigned.
-
Principle of separation of duties is implemented.
-
Adequate system controls are in place.
-
Audit trails developed and implemented within the system.
-
Routine tests of system performance are conducted.
-
Reliability of hardware and software is tested.
-
Adequate security is provided to prevent unauthorized access, changes, and premature destruction of records.
-
Controls for the accuracy and timeliness of input and output are established.
-
Problem resolution procedures are in place.
-
Disaster recovery plan is in place.
-
All system management policies and procedures are defined and documented.
-
Changes in policy and procedure are documented and implemented.
-
Training and user support are adequate to ensure system procedures will be implemented by users.