Difference between revisions of "User:Shawndouglas/sandbox/sublevel3"

From LIMSWiki
Jump to navigationJump to search
 
(237 intermediate revisions by 2 users not shown)
Line 1: Line 1:
<div class="nonumtoc">__TOC__</div>
{{ombox
| type      = notice
| style    = width: 960px;
| text      = This is sublevel3 of my sandbox, where I play with features and test MediaWiki code. If you wish to leave a comment for me, please see [[User_talk:Shawndouglas|my discussion page]] instead.<p></p>
}}


==Sandbox begins below==
==The laws themselves==


* '''Y''': Meets requirement in commercial off-the-shelf solution as delivered/configured (or vendor provides service)
===1. Federal Telecommunications Act of 1996, Section 255 ([https://www.law.cornell.edu/uscode/text/47/255 47 U.S.C. § 255 - Access by persons with disabilities])===
* '''YC''': Meets requirement only with customization (additional code, using a third-party application, etc.)
* '''N''': Does not meet requirement
* '''I''': Informational response only, N/A
* '''U''': Unknown


<blockquote>'''(b) Manufacturing'''
A manufacturer of telecommunications equipment or customer premises equipment shall ensure that the equipment is designed, developed, and fabricated to be accessible to and usable by individuals with disabilities, if readily achievable.


==1.0 Demonstration==
'''(c) Telecommunications services'''
{|
| STYLE="vertical-align:top;"|
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="text-align:left; padding-left:20px; padding-top:10px; padding-bottom:10px;"| 1.0 '''Demonstration'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.0.000''' The system can be tried via an online and/or on-site demonstration.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The developers do not seem to host an online demo of Alfresco Community Edition.
|-
|}
|}


==1.1 Information technology==
A provider of telecommunications service shall ensure that the service is accessible to and usable by individuals with disabilities, if readily achievable.
{|
| STYLE="vertical-align:top;"|
===1.1.1 General IT===
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray; text-align:left; padding-left:40px;"| 1.1.1 '''General IT'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|-
  ! style="padding:5px;" | I
  | style="padding:5px; width:1200px;" |'''1.1.100''' The system operates with a traditional client-server architecture, with software installed on each machine that needs to access the system.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco uses client-server technology, though the client is web-based. See 1.1.101.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.101''' The system operates with a web-based interface, hosted on a server and accessed via a web browser on most any machine.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco [http://docs.alfresco.com/community/concepts/alfresco-arch-about.html operates] with a content application server, while users connect to it via web, mobile, and other types of clients. As Alfresco is integrated into the webLiMS suite of applications, the content application server is [http://weblimscom.wpengine.com/products/ hosted in the cloud].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.102''' The system contains a single, centralized database that supports multiple sites and departments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco's content repository "is comparable to a database, except that it holds more than data." The development team [http://docs.alfresco.com/community/concepts/content-repo-about.html describes this further] in their documentation:


:The actual binary streams of the content are stored in files managed in the repository, although these files are for internal use only and do not reflect what you might see through the shared drive interfaces. The repository also holds the associations among content items, classifications, and the folder/file structure. The folder/file structure is maintained in the database and is not reflected in the internal file storage structure.
'''(d) Compatibility'''
Whenever the requirements of subsections (b) and (c) are not readily achievable, such a manufacturer or provider shall ensure that the equipment or service is compatible with existing peripheral devices or specialized customer premises equipment commonly used by individuals with disabilities to achieve access, if readily achievable.</blockquote>


Alfresco also allows users to [http://docs.alfresco.com/community/concepts/sites-intro.html set up "sites"] for separate projects or user groups to manage custom content.
The term '''disability''' is [https://www.law.cornell.edu/uscode/text/42/12102 defined here]. You can read the full entry, but the basics are:
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.103''' The system's database conforms to the [[ODBC|Open Database Connectivity Standard]] (ODBC).
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community comes bundled with [[PostgreSQL]], which has an associated ODBC driver. The software can also be [https://wiki.alfresco.com/wiki/Database_Configuration run against] [[MySQL]].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.104''' The system is designed so upgrades to the back-end database do not require extensive reconfiguration or effectively cripple the system.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community allows administrators to extend and override database properties through [https://wiki.alfresco.com/wiki/Database_Configuration repository configuration files], presumably with little impact to the system.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.105''' The system is designed to not be impacted by multiple users or failover processes.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | One of the guiding design principles of Alfresco Community is to be [http://docs.alfresco.com/community/concepts/alfresco-principles.html enterprise scalable]. This aspect has been so important that the developers have created a [http://www.alfresco.com/resources/whitepapers/alfresco-scalability-blueprint Scalability Blueprint].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.106''' The system applies security features to all system files.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community system files, including configuration files, are only accessible to authorized administrators.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.107''' The system applies log-in security to all servers and workstations accessing it.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Users must provide a username and password before entering the system via web client. Administrators must also use a username and password to access server-side files. All of this accomplished through the [http://docs.alfresco.com/community/concepts/auth-subsystem-intro.html authentication subsystem].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.108''' The system provides a workstation and server authentication mechanism.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community employs an [http://docs.alfresco.com/community/concepts/auth-subsystem-intro.html authentication subsystem] to ensure authentication between client and server.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.1.109''' The system applies Secured Socket Layer (SSL) encryption on the web client interface.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community seems to be able to be used in HTTPS mode with some configuration , but it's not clear if it interfaces via HTTPS in default mode. The following suggests it's possible for the client to access the server via SSL: [https://forums.alfresco.com/forum/installation-upgrades-configuration-integration/configuration/howto-secure-alfresco-https Item One]; [http://forums.alfresco.com/forum/installation-upgrades-configuration-integration/configuration/change-alfresco-use-ssl-and Item Two]; [http://blyx.com/2014/04/01/alfresco-tip-how-to-enable-ssl-in-alfresco-sharepoint-protocol/ Item Three]
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.1.110''' The system encrypts client passwords in a database, with support for multi-case and special characters.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community does not seem to inherently include encryption capabilities, at least for repositories. The documentation for Community makes no mention of encryption on passwords. Several items seem to support the lack of encryption, though this matter needs to be researched further: [https://translate.google.com/translate?sl=auto&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fwww.skytizens.com%2F%25E0%25B8%25A3%25E0%25B8%25B0%25E0%25B8%259A%25E0%25B8%259A%25E0%25B8%2588%25E0%25B8%25B1%25E0%25B8%2594%25E0%25B8%2581%25E0%25B8%25B2%25E0%25B8%25A3%25E0%25B9%2580%25E0%25B8%25AD%25E0%25B8%2581%25E0%25B8%25AA%25E0%25B8%25B2%25E0%25B8%25A3-alfresco%2Frepository-encryption%2F&edit-text=&act=url Item One] with [http://www.youtube.com/watch?v=nc2DC6wTgTI associated video], and [https://addons.alfresco.com/addons/alfresco-encryption-module Item Two].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.111''' The system uses TCP/IP as its network transport.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Data can be transferred between client and server via FTP and HTTP high-level application protocols (among others).
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.112''' The system allows automated backup and restore capability without support intervention, as well as manual backups.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community allows for [https://wiki.alfresco.com/wiki/Backup_and_Restore manual backup and restore] by the administrator. Further backup and recovery tools can be added with the [https://addons.alfresco.com/addons/alfresco-bart-backup-and-recovery-tool Alfresco BART add-on].
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.1.113''' The system maintains the transactional history of system administrators.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | It's not clear what user information Alfresco Community logs, if any.
|-
|}


===1.1.2 Hardware environment===
<blockquote>'''(1) Disability''' The term “disability” means, with respect to an individual—
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
:'''(A)''' a physical or mental impairment that substantially limits one or more major life activities of such individual;
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.1.2 '''Hardware environment'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.200''' The system proves compatible with a variety of hardware environments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The developers state "Alfresco degrades gracefully on low powered hardware, and small installations can run well on any modern server." They also state [http://wiki.alfresco.com/wiki/Repository_Hardware the optimal hardware configuration].
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.1.201''' The system can be utilized with a touch-screen.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community can normally be accessed via the [https://wiki.alfresco.com/wiki/Mobile Alfresco Mobile] application for Android and iPhone. It's not clear if webLiMS users will be able to access their cloud-hosted SDMS using the mobile app, however.
|-
|}


===1.1.3 Software environment===
:'''(B)''' a record of such an impairment; or
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.1.3 '''Software environment'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.300''' The system proves compatible with a variety of software environments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community installation packages exist for [http://docs.alfresco.com/community/concepts/download-community.html Windows, Mac, and Linux].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.1.301''' The system utilizes a non-proprietary database such as Oracle or Microsoft SQL Server.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community comes bundled with [[PostgreSQL]] and can also be [https://wiki.alfresco.com/wiki/Database_Configuration run against] [[MySQL]].
|-
|}
|}


==1.2 Regulatory compliance and security==
:'''(C)''' being regarded as having such an impairment (as described in paragraph (3)).</blockquote>
{|
| STYLE="vertical-align:top;"|
===1.2.1 Regulatory compliance===
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray; text-align:left; padding-left:40px;"| 1.2.1 '''Regulatory compliance'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.100''' The system can generate accurate and complete copies of records in both a human-readable and original electronic format for review and copying.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community remains "[http://richard.esplins.org/siwi/2011/06/22/alfresco-content-formats/ format-agnostic]," meaning any file type can be uploaded. As long as the original file's MIME type allows for indexing, thumbnailing, metadata extraction, etc., the file will be human-readable while maintaining the original electronic format. Review and copy of the file is permission-based.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.101''' The system supports [[21 CFR Part 11]] and [[EU Annex 11]] requirements, including log-in security, settable automatic logouts, periodic requirements for mandatory password changes, limits on reusability of passwords, and full electronic signature.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community seems to support many 21 CFR Part 11 requirements. The inherent lack of digital signatures, however, [http://forums.alfresco.com/forum/non-technical-alfresco-discussion/fda-21-cfr-part-11-compliance-05172007-0124 has been referenced] on [https://forums.alfresco.com/forum/developer-discussions/add-ons/alfresco-21-cfr-part-11-digital-signatures-03022009-0629 multiple occasions] on the Alfresco site over the years. Are the [https://addons.alfresco.com/tags/digital-signature add-ons] enough? The same problem likely exists for EU Annex 11 requirements.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.102''' The system supports USP <232>/<233> requirements.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community does not support these requirements.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.103''' The system supports [[GALP]] and/or [[GAMP]] standards.
|- 
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community seems to support some GxP requirements; however, it's not clear if all requirements are met. Users can [https://addons.alfresco.com/tags/digital-signature add digital signatures] to PDFs via an add-on, but it's not clear if other non-PDF records can be digitally signed, for example.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.104''' The system supports the U.S. DoD 5015.2 Standard.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Through the Records Management module, the Records Management Site [http://docs.alfresco.com/rm2.2/tasks/rm-create-site.html can be set up] to be DoD 5015.2 Standard compliant.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.105''' The system maintains date- and time-stamped [[audit trail|audit trails]] of all data manipulation — such as changes to results, data analysis parameters, and methods — as consistent with all applicable regulations and standards, making the information available for review, copying, and reporting to authorized users.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | As long as [https://wiki.alfresco.com/wiki/Content_Auditing content auditing is enabled] via configuration, reportable audit trails will be captured. The documentation [http://docs.alfresco.com/rm2.2/concepts/rm-auditing.html states]:
: The audit log contains the entire history of an object since the point it was added to the File Plan, and can be useful for finding out about specific events that have occurred during an objects life cycle, and any users that have been involved. Every entry in the audit log is timestamped and where metadata has been changed, the original values and changed values are recorded.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.106''' The system audit log retains all data, prohibits any deletions, and allows user comments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | As stated in 1.2.105, the entire history of an object is retained. Access to view, export, or file the audit trail as a a record is allowed if the administrator [http://docs.alfresco.com/rm2.2/tasks/rm-audit-viewing.html assigns the "Access Audit" permission]. It's not explicitly stated whether or not the user can delete any audit content. If the audit log is filed as a record, then those with access to that record can comment on it. It's not explicitly clear if a non-filed audit log can be commented on.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.107''' The system maintains audit trails at least as long as the records to which they pertain.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | As stated in 1.2.105, the entire history of an object is retained. Additionally, disposition schedules allow associated metadata and an audit trail [http://docs.alfresco.com/rm2.2/tasks/rm-dispschedule-createsteps.html to remain] even after deletion as long as "Maintain Record Metadata after Delete" is enabled during the creation of a disposition schedule. Audit trails for [http://docs.alfresco.com/rm2.2/tasks/rm-create-hold.html held content] are also maintained.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.108''' The system provides additional persistent auditing capabilities, such as the audit of cancelled uploads and scheduled system functions.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The Audit Filter [https://wiki.alfresco.com/wiki/Content_Auditing can be customized] to include additional auditing of system and more complex user tasks.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.109''' The system provides the ability to both automatically and manually add secure [[ELN feature#Electronic signatures|electronic signatures]] to documents and other data.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | See discussions in 1.2.101 and 1.2.103.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.110''' The system can automatically validate and approve data prior to being moved to the main database.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The SDMS doesn't seem to inherently have automated data validation and approval tools. Users who [http://docs.alfresco.com/rm-community/concepts/rm-tutorials-08.html file records] will need to manually validate that metadata has been captured from the added record and mark the record as complete before it is filed.
|-
|}


===1.2.2 Security===
The term '''readily achievable''' is [https://www.law.cornell.edu/uscode/text/42/12181 defined here]. It is defines as:
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.2.2 '''Security'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.200''' The system allows administrators and other authorized users to configure multiple levels of user rights and security by site location, department, group, [[LIMS feature#Configurable roles and security|role]], and/or specific function.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The SDMS allows for [http://docs.alfresco.com/community/references/permissions_share.html four types of roles] out of the box, each with their own assigned permissions. More flexible security roles and groups can be added by either [https://wiki.alfresco.com/wiki/Custom_Permissions_in_Share setting up custom roles] on a clean install or [https://addons.alfresco.com/tags/security installing security add-ons].
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.201''' The system allows administrators and users to reset user passwords.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community doesn't seem to make it easy. An administrator can [https://wiki.alfresco.com/wiki/Security_and_Authentication#How_to_reset_the_admin_password change the admin password]. And users can be allowed to reset their password [http://docs.alfresco.com/community/tasks/profile-password.html in their dashboard] and with the addition of the [https://addons.alfresco.com/addons/reset-password-dialog Reset Password Dialog] add-on. But it's not clear if administrators can change user passwords without knowing the original user password: [http://stackoverflow.com/questions/15837068/alfresco-webservices-api-change-user-password Source].
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.202''' The system features and enforces adjustable rules concerning password complexity, reuse, and expiration.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software [https://forums.alfresco.com/forum/installation-upgrades-configuration-integration/authentication-ldap-sso/implementing-account does not have this functionality] by default.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.203''' The system can lock a user out after a specified number of consecutive failed log-in attempts.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software [https://forums.alfresco.com/forum/installation-upgrades-configuration-integration/authentication-ldap-sso/implementing-account does not have this functionality] by default.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.204''' The system provides the option for automatic user logout based on keyboard or mouse inactivity.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software doesn't appear to have this functionality.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.205''' The system makes authority checks to ensure only authorized individuals can use the system to perform an operation.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The system contains [https://wiki.alfresco.com/wiki/Authorization_And_Access_Control configurable authorization enforcement].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.206''' The system allows authorized users to modify records, while also maintaining an audit trail of such actions.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | [http://docs.alfresco.com/community/concepts/library-items-individual.html Users can] view, edit, delete, and download files. As long as [https://wiki.alfresco.com/wiki/Content_Auditing content auditing is enabled] via configuration, reportable audit trails will be captured.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.207''' The system allows authorized users to manually delete records, while also maintaining an audit trail of such actions.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Records can [http://docs.alfresco.com/community/tasks/library-item-delete.html manually be deleted] while retaining an audit trail as long as [https://wiki.alfresco.com/wiki/Content_Auditing auditing is enabled] via configuration. Records can also be deleted automatically as part of a [http://docs.alfresco.com/rm2.2/concepts/rm-dispschedule.html disposition schedule] in the Records Management module. Associated metadata and an audit trail [http://docs.alfresco.com/rm2.2/tasks/rm-dispschedule-createsteps.html will remain] as long as "Maintain Record Metadata after Delete" is enabled during the creation of a disposition schedule.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.208''' The system prompts users to declare a reason for making changes to or deleting data in the system.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software doesn't appear to have this functionality.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.209''' The system allows authorized users to generate a detailed user access record.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | As long as [https://wiki.alfresco.com/wiki/Content_Auditing content auditing is enabled] via configuration, authorized users can view reportable audit trails which include user access records.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.210''' The system provides email notification of lockout, security access, and improper workstation access.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software doesn't appear to have this functionality.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.211''' The system provides a mechanism to allow a user read-only access to stored data.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software [https://forums.alfresco.com/forum/developer-discussions/repository-services/restrict-user-downloading-document-12072012-0830 doesn't appear] to have this functionality.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.2.212''' The system allows automatic and/or manual holds or locks to be placed on data to ensure it goes unaltered or remains retrievable during a retention period.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Through the Records Management module, users can [http://docs.alfresco.com/rm2.2/concepts/rm-manage-holds.html manually set up holds] with user permissions and apply records or folders to the hold.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.213''' The system can first feed data from connected non-CFR-compliant instruments through a virtual environment that is compliant (audit trailed, secure, versioned, etc.) before being stored.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Not clear if information can be fed into webLiMS, be made complaint, and then stored in the SDMS.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.2.214''' The system can control whether users are able to export data to portable long-term storage media like a USB flash drive or recordable DVD.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software doesn't appear to have this functionality.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.2.215''' The system employs automatic file encryption on stored data.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Alfresco Community does not seem to inherently include encryption capabilities, at least for repositories. Several items seem to support the lack of encryption, though this matter needs to be researched further: [https://translate.google.com/translate?sl=auto&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fwww.skytizens.com%2F%25E0%25B8%25A3%25E0%25B8%25B0%25E0%25B8%259A%25E0%25B8%259A%25E0%25B8%2588%25E0%25B8%25B1%25E0%25B8%2594%25E0%25B8%2581%25E0%25B8%25B2%25E0%25B8%25A3%25E0%25B9%2580%25E0%25B8%25AD%25E0%25B8%2581%25E0%25B8%25AA%25E0%25B8%25B2%25E0%25B8%25A3-alfresco%2Frepository-encryption%2F&edit-text=&act=url Item One] with [http://www.youtube.com/watch?v=nc2DC6wTgTI associated video], and [https://addons.alfresco.com/addons/alfresco-encryption-module Item Two].
|-
|}
|}


==1.3 General system functions==
<blockquote>'''(9) Readily achievable''' The term “readily achievable” means easily accomplishable and able to be carried out without much difficulty or expense. In determining whether an action is readily achievable, factors to be considered include—
{|
| STYLE="vertical-align:top;"|
===1.3.1 General functions===
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray; text-align:left; padding-left:40px;"| 1.3.1 '''General functions'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.3.100''' The system offers non-SDMS trained personnel the ability to easily access system data via an intuitive, user-friendly Windows-type graphical user interface (GUI) which permits the display of stored data.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Users can easily access stored data without downloading it via [http://docs.alfresco.com/community/concepts/library-folder-intro.html the Document Details page].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.3.101''' The system allows authorized users to configure their GUI to a specific language, character set, and time zone.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The software allows users to change the language at the log-in screen, and additional language packs can be added with [http://wiki.alfresco.com/wiki/Language_Packs language packs]. The time zone can be set as a system-wide property.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.3.102''' The system permits remote access for users, system admins, and support agents.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The system can be accessed from anywhere using a valid web browser. It's not clear if the webLiMS-hosted SDMS can be accessed via the Alfresco Mobile application. (See 1.1.201)
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.3.103''' The system allows for the use of navigation keys to freely move from field to field.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | It's not clear if keyboard shortcuts or tabbing are inherent to the interface.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.3.104''' The system allows tabular data to be sorted and filtered.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | This feature was [http://blogs.alfresco.com/wp/kevinr/2013/08/22/alfresco-community-4-2-d/ added in version 4.2].
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.3.105''' The system can send on-screen output to a printer or file without contradicting read-only statuses.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | As read-only statuses [https://forums.alfresco.com/forum/developer-discussions/repository-services/restrict-user-downloading-document-12072012-0830 don't seem to be supported], this functionality is not available by extension.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.3.106''' The system contains one or more spell-check dictionaries that allow authorized users to add, edit, or remove entries.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The SDMS seems to have some minor spell check abilities [http://blogs.alfresco.com/wp/kevinr/2014/10/02/alfresco-community-5-0-b/ in the search box], but it's not clear if users can edit the dictionary. Additionally, it's not clear if spell check can be employed during [http://docs.alfresco.com/community/tasks/library-item-edit-inline.html inline editing] of documents.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.3.107''' The system uses human-readable metadata tags to better describe, index, and store all captured and archived data.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Metadata extraction occurs automatically via extractors, [http://docs.alfresco.com/community/tasks/metadata-config.html which can be configured].
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.3.108''' The system can generate metadata tags via derived value rules.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | That functionality is not supported.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.3.109''' The system allows users to manually add metadata tags to files.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The system appears to not allow users to add/edit metadata after upload without [https://forums.alfresco.com/forum/developer-discussions/alfresco-share-development/edit-metadata-upon-upload-08142013-1955 major customization].
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.3.110''' The system provides full metadata, keyword, and field [[LIMS feature#Query capability|search capability]], including the use of multiple search criteria.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The system allows users to [http://blogs.alfresco.com/wp/kevinr/2014/06/27/alfresco-community-5-0-a/ search based on numerous facets] like file type, creator, creation date, etc.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.3.111''' The system allows users to search for similar records based upon a set of metadata tag values.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | It's not clear if the latest version includes this advanced search capability. The assumption is it doesn't.
|-
  ! style="padding:5px;" | U
  | style="padding:5px; width:1200px;" |'''1.3.112''' The system allows users to build, save, and edit queries for future use.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | It's not clear if the latest version includes this advanced search capability. The assumption is it doesn't.
|-
  ! style="padding:5px;" | N
  | style="padding:5px; width:1200px;" |'''1.3.113''' The system can automate the search for and extraction of pertinent data, including the export of that data to external applications for additional processing and calculation.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | The system doesn't appear to have this functionality.
|-
  ! style="padding:5px;" | Y
  | style="padding:5px; width:1200px;" |'''1.3.114''' The system allows users to attach comments to data and files.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" | Users can add, edit, or delete comments, [http://docs.alfresco.com/community/concepts/library-comments.html based upon their role].
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.115''' The system's file viewer/explorer allow users to view native, processed, and archived data in its native file structure.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.116''' The system can link objects to other objects, e.g. linking a standard operating procedure (SOP) to a test result.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.117''' The system [[LIMS feature#Alarms and/or alerts|notifies users]] of events like the scheduling and completion of tasks.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.118''' The system includes the ability to set up alerts via email.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.119''' The system offers integrated or online user help screens.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.120''' The system includes data analysis and calculation tools.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
|}


===1.3.2 Configuration and customization===
:'''(A)''' the nature and cost of the action needed under this chapter;
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
:'''(B)''' the overall financial resources of the facility or facilities involved in the action; the number of persons employed at such facility; the effect on expenses and resources, or the impact otherwise of such action upon the operation of the facility;
|-
:'''(C)''' the overall financial resources of the covered entity; the overall size of the business of a covered entity with respect to the number of its employees; the number, type, and location of its facilities; and
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.3.2 '''Configuration and customization'''
:'''(D)''' the type of operation or operations of the covered entity, including the composition, structure, and functions of the workforce of such entity; the geographic separateness, administrative or fiscal relationship of the facility or facilities in question to the covered entity.</blockquote>
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.200''' The system architecture is modular or extensible and can easily and efficiently be modified to facilitate the addition of new functionality as business needs change.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.201''' The system has an application programming interface (API) or a similar software development toolkit (SDK). If web-based, the API should support Simple Object Access Protocol (SOAP), representational state transfer (REST), or both.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.202''' The system allows a user to [[LIMS feature#Customizable fields and/or interface|independently add fields]] without requiring reconfiguration of the system, even after routine upgrades and maintenance.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.203''' The system allows for the integration of additional printers and scanners both locally and externally.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
|}


===1.3.3 Data capture===
===2. Rehabilitation Act of 1973, Section 508, amended ([https://www.law.cornell.edu/uscode/text/29/794d 29 U.S.C. 794d] - Electronic and information technology)===
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.3.3 '''Data capture'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.300''' The system can manage and store both sample- and non-sample-related data, including images from microscopes, GCMS scans of peaks, PDF files, spreadsheets, or even raw data files from instrument runs for later processing.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.301''' The system can manage and store media objects like digital photos, bitmaps, movies, and audio files.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.302''' The system allows multiple native instruments and users to enter data into the system simultaneously without disruption.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.303''' The system can interface with and [[LIMS feature#Import data|import existing data]] from other databases and file shares.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.304''' The system supports data capture from a Citrix-based environment.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.305''' The system allows file indexes to be stored centrally while associated files are stored geographically.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.306''' The system allows users to organize captured data by project, date, location, instrument, etc.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.307''' The system can route captured data based upon specified metadata tags.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.308''' The system allows full on-screen review and approval of native instrument data prior to database commitment.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.309''' The system keeps all captured data and its format intact and captures modifications of that data as a version, including date and time of those modifications, for regulatory purposes.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.310''' The system has a tool that allows users to capture data printed to it as a searchable PDF file.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.311''' The system can automatically normalize and store incoming data to a technology-neutral format like XML.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.312''' The system allows incoming and entered files to be converted into other open formats like JCAMP-DX, TraML, mzML, mzXML, AnIML, pepXML, and protXML.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.313''' The system can capture and store native instrument and processed data based on a scheduled time or a real-time event, such as upon file creation.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.314''' The system allows users to manually upload instrument data files that are not part of a scheduled upload.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.315''' The system allows for the specification of a retention period for captured native instrument and processed data and can enact it based on date-based metadata fields or a future event.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.316''' The system can remove data from client machines upon upload and/or backup, based on a schedule or retention policy.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.317''' The system allows users to review, restore, and reprocess original native instrument data on the original instrument acquisition software.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.318''' The system allows users to open and view captured native instrument files without restoring them.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.319''' The system allows captured processed data to be reused by other applications without having to reprocess it.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.320''' The system provides a method to extract data points from captured processed data and present it in a human-readable format.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.321''' The system can parse captured data files containing specified metadata into a live results table.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
|}


===1.3.4 Data archiving and migration===
There's a government website dedicated to Section 508: [https://www.section508.gov/ https://www.section508.gov/] The related laws and polices can be [https://www.section508.gov/manage/laws-and-policies/ found here]. The intro states (italics emphasis mine):
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.3.4 '''Data archiving and migration'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.400''' The system provides data archiving functionality for all contained data, without requiring an off-line mode.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.401''' The system allows for a configurable scheduled archive, not requiring human interaction with the data to be archived.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.402''' The system allows for a scheduled archive of data directly captured from a specific native instrument.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.403''' The system permits native instrument data to be archived and restored with its original directory structure.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.404''' The system allows for the specification of a retention period for archived and migrated data and can enact it based on date-based metadata fields or a future event.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.405''' The system ensures that held or locked native instrument data not captured during a scheduled archive will be captured during the next scheduled archive.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.406''' The system can perform archive and restore functions simultaneously with data capture and viewing functions, without disruption.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.407''' The system allows native instrument and processed data migrated from an old SDMS version to be backed up and restored without alteration.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
|}


===1.3.5 Instruments===
<blockquote>In 1998, Congress amended the Rehabilitation Act of 1973 to require Federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. The law (29 U.S.C § 794 (d)) ''applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology''. Under Section 508, agencies must give ''disabled employees and members of the public'' access to information comparable to the access available to others.
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.3.5 '''Instruments'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|- 
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.500''' The system bilaterally [[LIMS feature#Instrument interfacing and management|interfaces]] with instruments and related software based on the Unix and Windows platforms.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.501''' The system can download data directly from laboratory instruments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.502''' The system can track and report on the usage of attached laboratory instruments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.503''' The system can automatically (or manually allow an authorized user to) remove an instrument from potential use when it falls out of tolerance limit or requires scheduled calibration.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.504''' The system maintains a reportable database of preventative maintenance, calibration, and repair records for attached laboratory instruments.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.505''' The system can schedule calibration, verification, and maintenance tasks on attached instruments and make that schedule available for viewing.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.506''' The system allows users to create and edit instrument maintenance profiles.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
|}


===1.3.6 External system interfaces===
The [https://www.access-board.gov/ U.S. Access Board] is responsible for developing Information and Communication Technology (ICT) accessibility ''standards'' to ''incorporate into regulations that govern Federal procurement practices.'' On January 18, 2017, the Access Board issued a final rule that updated accessibility requirements covered by Section 508, and refreshed guidelines for telecommunications equipment subject to Section 255 of the Communications Act. The final rule went into effect on January 18, 2018.
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
|-
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.3.6 '''External system interfaces'''
|-
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.600.''' The system supports a library of common electronic data deliverable (EDD) formats.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.601''' The system can transfer data to and from other record management systems.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.602''' The system [[LIS feature#Third-party software integration|integrates]] with Microsoft Exchange services.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.603''' The system can [[LIMS feature#Import data|import data]] from and export data to Microsoft Word, Excel, Access, and/or Powerpoint.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.604''' The system can interface with non-Microsoft programs.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.605''' The system can interface with enterprise resource planning (ERP) systems.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.606''' The system can interface with internal and external laboratory systems like laboratory information management systems (LIMS) and electronic laboratory notebooks (ELNs).
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.607''' The system can leverage the application programming interface (API) of other systems to establish integration between systems.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.608''' The system provides a real-time interface for viewing live and stored data transactions and errors generated by interfaced instruments and systems.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.609''' The system supports [[LIMS feature#Mobile device integration|dockable mobile devices]] and handles information exchange between them and the system.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.610''' The system supports the use of optical character recognition (OCR) software.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
|}


===1.3.7 Reporting===
The rule updated and reorganized the Section 508 Standards and Section 255 Guidelines ''in response to market trends and innovations in technology.'' The refresh also harmonized these requirements with other guidelines and standards both in the U.S. and abroad, including standards issued by the European Commission, ''and with the World Wide Web Consortium (W3C) Web Content Accessibility Guidelines (WCAG 2.0), a globally recognized voluntary consensus standard for web content and ICT.''</blockquote>
{| class="wikitable collapsible" border="1" cellpadding="10" cellspacing="0"
 
|-
In discussing ICT, the U.S. Access Board [https://www.access-board.gov/ict/#b-summary-of-key-provisions summarized the key provisions] as such:
  ! colspan="2" style="color:DarkSlateGray;text-align:left; padding-left:40px;"| 1.3.7 '''Reporting'''
 
|-
<blockquote>The Revised 508 Standards and 255 Guidelines replace the current product-based regulatory approach with an approach based on ICT functions. The revised technical requirements, which are organized along the lines of ICT functionality, provide requirements to ensure that covered hardware, software, electronic content, and support documentation and services are accessible to people with disabilities. In addition, the revised requirements include functional performance criteria, which are outcome-based provisions that apply in two limited instances: when the technical requirements do not address one or more features of ICT or when evaluation of an alternative design or technology is needed under equivalent facilitation.</blockquote>
  ! style="color:brown; background-color:#ffffee; width:100px;"| Requirement code
 
  ! style="color:brown; background-color:#ffffee; width:1200px;"| Requirement # and requirement
The full (lengthy) information about the ICT Accessibility 508 Standards and 255 Guidelines is found here: [https://www.access-board.gov/ict/ https://www.access-board.gov/ict/]
|-
 
  ! style="padding:5px;" |
The specific software requirements that LabLynx will likely need to consider under Section 508 appear to be found in [https://www.access-board.gov/ict/#chapter-5-software Chapter 5: Software] and [https://www.access-board.gov/ict/#chapter-6-support-documentation-and-services Chapter 6: Support Documentation and Services]. (If for some reason LLX is in the hardware domain, they'll want to also consider[https://www.access-board.gov/ict/#chapter-4-hardware Chapter 4: Hardware] If you're curious about the underlying standards, you can find them in [https://www.access-board.gov/ict/#chapter-7-%C2%A0-referenced-standards Chapter 7: Referenced Standards].
  | style="padding:5px; width:1200px;" |'''1.3.700''' The system includes a versatile report writer and forms generator that can generate reports from any data in the system.
 
|-
Finally, the Section 508 government website has a full Design & Develop section that may be applicable to development process: [https://www.section508.gov/develop/ https://www.section508.gov/develop/]
  ! style="background-color:white; width:100px;"| Response:
 
  | style="background-color:white; padding:5px;" |
==Additional information==
|-
 
  ! style="padding:5px;" |
1. The Section 508 website and its glossary mention LIMS under "[https://www.section508.gov/art/glossary/#S scientific instrument]," though only secondarily. At the end: "If a scientific instrument is integrated with a computer or a monitor, the computer (and associated operating system) and the monitor would be separate EIT deliverables, requiring their own Government Product Accessibility Templates (GPAT). If the computer included application software, this software would be another EIT deliverable requiring its own GPAT."
  | style="padding:5px; width:1200px;" |'''1.3.701''' The system can interface with a third-party reporting application.
   
|-
2. It appears some software can qualify for "a legally-defined Exception (Back Office)," as found in this example with STARLIMS and the VA: [https://www.oit.va.gov/Services/TRM/ToolPage.aspx?tid=7502 https://www.oit.va.gov/Services/TRM/ToolPage.aspx?tid=7502]
  ! style="background-color:white; width:100px;"| Response:
 
  | style="background-color:white; padding:5px;" |
3. Some additional posts and guides that may be revealing:
|-
* [https://www.levelaccess.com/how-do-i-determine-if-my-web-site-or-application-is-section-508-compliant/ How do I determine if my website or application is Section 508 compliant?]
  ! style="padding:5px;" |
* [https://ftp.cdc.gov/pub/Software/RegistryPlus/508%20Compliance/508softwareandos.doc GSA Guide For Making Software Applications and Operating Systems Accessible] (.doc file; NOTE: No date, so not sure if incorporates amended material, so be careful)
  | style="padding:5px; width:1200px;" |'''1.3.702''' The system allows the development of [[LIMS feature#Custom reporting|custom templates]] for different types of reports.
* [https://www.dhs.gov/publication/dhs-section-508-compliance-test-processes DHS Section 508 Compliance Test Processes]
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.703''' The system maintains template versions and renditions, allowing management and tracking of the template over time.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.704''' The system uses Microsoft Office tools for formatting reports.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.705''' The system provides multiple ways to visualize data in reports, including graphs, trend bars, pie charts, spectrum, etc. for the purpose of presenting information and identifying trends.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.706''' The system makes graphic and tabular data vector-scalable in reports.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.707''' The system allows for internal hyperlinking to source data in reports.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.708''' The system allows users to manually adjust inaccurate data parsing routines for reports.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.709''' The system can indicate whether a report is preliminary, amended, corrected, or final while retaining revision history.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.710''' The system can automatically generate laboratory reports of findings and other written documents.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.711''' The system provides an ad-hoc web reporting interface to report on user-selected criteria.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.712''' The system can automatically generate and post periodic static summary reports on an internal web server.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.713''' The system can transmit reports in a variety of ways including fax, e-mail, print, and website in formats like RTF, PDF, HTML, XML, DOC, XLS, and TXT.
  |-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.714''' The system supports PDF/A, an ISO-standardized version of the Portable Document Format (PDF).
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.715''' The system includes a rules engine to determine the recipients of reports and other documents based on definable parameters.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.716''' The system provides printer-friendly audit trails for cleaner reporting of audit data.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.717''' The system provides an interface for external clients to search, generate, and view processed data reports based on metadata tags.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-
  ! style="padding:5px;" |
  | style="padding:5px; width:1200px;" |'''1.3.718''' The system provides document workflow management tools for streamlining their creation, review, modification, and approval.
|-
  ! style="background-color:white; width:100px;"| Response:
  | style="background-color:white; padding:5px;" |
|-  
|}
|}

Latest revision as of 21:23, 28 February 2022

The laws themselves

1. Federal Telecommunications Act of 1996, Section 255 (47 U.S.C. § 255 - Access by persons with disabilities)

(b) Manufacturing

A manufacturer of telecommunications equipment or customer premises equipment shall ensure that the equipment is designed, developed, and fabricated to be accessible to and usable by individuals with disabilities, if readily achievable.

(c) Telecommunications services

A provider of telecommunications service shall ensure that the service is accessible to and usable by individuals with disabilities, if readily achievable.

(d) Compatibility

Whenever the requirements of subsections (b) and (c) are not readily achievable, such a manufacturer or provider shall ensure that the equipment or service is compatible with existing peripheral devices or specialized customer premises equipment commonly used by individuals with disabilities to achieve access, if readily achievable.

The term disability is defined here. You can read the full entry, but the basics are:

(1) Disability The term “disability” means, with respect to an individual—

(A) a physical or mental impairment that substantially limits one or more major life activities of such individual;
(B) a record of such an impairment; or
(C) being regarded as having such an impairment (as described in paragraph (3)).

The term readily achievable is defined here. It is defines as:

(9) Readily achievable The term “readily achievable” means easily accomplishable and able to be carried out without much difficulty or expense. In determining whether an action is readily achievable, factors to be considered include—

(A) the nature and cost of the action needed under this chapter;
(B) the overall financial resources of the facility or facilities involved in the action; the number of persons employed at such facility; the effect on expenses and resources, or the impact otherwise of such action upon the operation of the facility;
(C) the overall financial resources of the covered entity; the overall size of the business of a covered entity with respect to the number of its employees; the number, type, and location of its facilities; and
(D) the type of operation or operations of the covered entity, including the composition, structure, and functions of the workforce of such entity; the geographic separateness, administrative or fiscal relationship of the facility or facilities in question to the covered entity.

2. Rehabilitation Act of 1973, Section 508, amended (29 U.S.C. 794d - Electronic and information technology)

There's a government website dedicated to Section 508: https://www.section508.gov/ The related laws and polices can be found here. The intro states (italics emphasis mine):

In 1998, Congress amended the Rehabilitation Act of 1973 to require Federal agencies to make their electronic and information technology (EIT) accessible to people with disabilities. The law (29 U.S.C § 794 (d)) applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology. Under Section 508, agencies must give disabled employees and members of the public access to information comparable to the access available to others.

The U.S. Access Board is responsible for developing Information and Communication Technology (ICT) accessibility standards to incorporate into regulations that govern Federal procurement practices. On January 18, 2017, the Access Board issued a final rule that updated accessibility requirements covered by Section 508, and refreshed guidelines for telecommunications equipment subject to Section 255 of the Communications Act. The final rule went into effect on January 18, 2018.

The rule updated and reorganized the Section 508 Standards and Section 255 Guidelines in response to market trends and innovations in technology. The refresh also harmonized these requirements with other guidelines and standards both in the U.S. and abroad, including standards issued by the European Commission, and with the World Wide Web Consortium (W3C) Web Content Accessibility Guidelines (WCAG 2.0), a globally recognized voluntary consensus standard for web content and ICT.

In discussing ICT, the U.S. Access Board summarized the key provisions as such:

The Revised 508 Standards and 255 Guidelines replace the current product-based regulatory approach with an approach based on ICT functions. The revised technical requirements, which are organized along the lines of ICT functionality, provide requirements to ensure that covered hardware, software, electronic content, and support documentation and services are accessible to people with disabilities. In addition, the revised requirements include functional performance criteria, which are outcome-based provisions that apply in two limited instances: when the technical requirements do not address one or more features of ICT or when evaluation of an alternative design or technology is needed under equivalent facilitation.

The full (lengthy) information about the ICT Accessibility 508 Standards and 255 Guidelines is found here: https://www.access-board.gov/ict/

The specific software requirements that LabLynx will likely need to consider under Section 508 appear to be found in Chapter 5: Software and Chapter 6: Support Documentation and Services. (If for some reason LLX is in the hardware domain, they'll want to also considerChapter 4: Hardware If you're curious about the underlying standards, you can find them in Chapter 7: Referenced Standards.

Finally, the Section 508 government website has a full Design & Develop section that may be applicable to development process: https://www.section508.gov/develop/

Additional information

1. The Section 508 website and its glossary mention LIMS under "scientific instrument," though only secondarily. At the end: "If a scientific instrument is integrated with a computer or a monitor, the computer (and associated operating system) and the monitor would be separate EIT deliverables, requiring their own Government Product Accessibility Templates (GPAT). If the computer included application software, this software would be another EIT deliverable requiring its own GPAT."

2. It appears some software can qualify for "a legally-defined Exception (Back Office)," as found in this example with STARLIMS and the VA: https://www.oit.va.gov/Services/TRM/ToolPage.aspx?tid=7502

3. Some additional posts and guides that may be revealing: