Document Control
| Role | Name | Title | Department |
|---|---|---|---|
| Author | Hooman Mohajeri | Security Architect | ECDi ACE Infra |
| Approver | Saima Sherazi | Infrastructure Lead & Manager | ECDi ACE Infra |
Purpose
This is the Qualification Summary Report for the DDC application infrastructure. It describes how the DDC application infrastructure is qualified to operate consistently and reliably.
Conditions
The qualification of to the DDC application infrastructure is not subject to any conditions, and can be used once this report is approved. This qualification only applies to DDC application infrastructure and not the application itself.
Issues in Individual Qualifications
There were no issues encountered.
Activities Adapt
General Qualification Approach
The qualification of the DDC application infrastructure included SRA and DCR. As a part of the DCR, we mapped our environment controls to the Roche Cloud Security Directive to ensure adequate and proper coverage. The application underwent its own specific SRA and DCR. To manage the infrastructure in a consistent and secure manner, we utilize Infrastructure as Code (IaC) practices using Terraform Cloud Enterprise.
Deviations from Qualification Plan
There were no deviations from the qualification plan.
Qualification Activities / Registry
The following were created and approved for the DDC application infrastructure.
| Document or Activity | Status | Location |
|---|---|---|
| Jira is used to track all infrastructure related work | Approved | Jira |
| DDC IaC Code Repo | Approved | Github link to repo |
| Install Verification Document | Approved | Install Verification Wiki Document |
| DDC Infrastructure Wiki | Approved | DDC Infrastructure Wiki |
Conclusion
Review of all documentation indicates that the qualification activities were successfully completed. The infrastructure for the DDC application is qualified and is released for use/handover with no conditions.