19 OpenTox Principles and Best Practices for Trusted Reproducible …
395
19.8 Use of Software Containers
Web services are increasingly deployed using software container technologies like
docker; they are already versioned with a cryptographic hash (since this is how
docker containers are layered internally). This information should then be included
in the audit log when a query is performed against such a system. If the container
is publically available, a researcher reproducing a workflow could then recreate an
analysis even if the Web service itself is no longer running or a newer version produces
different results. Besides all used data (raw data of experiments specifically generated
for the submission and all public sources), these containers could also become part
of a regulatory submission guaranteeing that the analysis will always be exactly
reproducible. Software needing a license to be run could be offered in a specific
version only allowing this one calculation to be run. Additionally, data produced in
intermediate steps (data snapshots) should also be stored in data containers. This
would have the advantage that data integrity could be validated from snapshot to
snapshot; e.g., copy errors could be identified by comparing the before and after state
of the data, as long as such manual manipulations are still needed due to missing
interoperability of the tools.
19.9 Regulatory Acceptance Practices
The regulatory acceptance for a test method is represented by its formal acceptance by
regulatory authorities indicating that the test method can be used to provide information to meet a specific regulatory requirement. This includes a formal validation (i.e.,
reliability and relevance assessment of the method considering its reproducibility,
transferability, predictive capacity, applicability domain, and performance standards)
[15] and adoption by the International Organizations (i.e., OECD and EC) before
implementation into specific regulations and related guidelines [16, 17]. Similarly,
for the in silico methods, as they are playing an increasing role in predicting properties for hazard and risk assessment, the acceptance of computational approaches
should be based on standards and criteria of reliability and relevance prior to be
applied within a specific regulatory context. As an example, EU REACH Regulation
explicitly includes the need to use QSAR models to reduce the extent of experimental
testing, emphasizing the principle that information generated by QSARs may be used
to indicate the presence or absence of a certain dangerous property instead of experimental data, provided that the following conditions are met: The results are derived
from a QSAR model whose scientific validity has been established, the substance
falls within the applicability domain of the QSAR model, the results are adequate for
the purpose of classification and labelling and/or risk assessment, and adequate and
reliable documentation of the applied method is provided [18]. Moreover, in order
to facilitate the consideration of a QSAR model for regulatory purposes, it should
be associated with the following information: a defined endpoint, an unambiguous
395
19.8 Use of Software Containers
Web services are increasingly deployed using software container technologies like
docker; they are already versioned with a cryptographic hash (since this is how
docker containers are layered internally). This information should then be included
in the audit log when a query is performed against such a system. If the container
is publically available, a researcher reproducing a workflow could then recreate an
analysis even if the Web service itself is no longer running or a newer version produces
different results. Besides all used data (raw data of experiments specifically generated
for the submission and all public sources), these containers could also become part
of a regulatory submission guaranteeing that the analysis will always be exactly
reproducible. Software needing a license to be run could be offered in a specific
version only allowing this one calculation to be run. Additionally, data produced in
intermediate steps (data snapshots) should also be stored in data containers. This
would have the advantage that data integrity could be validated from snapshot to
snapshot; e.g., copy errors could be identified by comparing the before and after state
of the data, as long as such manual manipulations are still needed due to missing
interoperability of the tools.
19.9 Regulatory Acceptance Practices
The regulatory acceptance for a test method is represented by its formal acceptance by
regulatory authorities indicating that the test method can be used to provide information to meet a specific regulatory requirement. This includes a formal validation (i.e.,
reliability and relevance assessment of the method considering its reproducibility,
transferability, predictive capacity, applicability domain, and performance standards)
[15] and adoption by the International Organizations (i.e., OECD and EC) before
implementation into specific regulations and related guidelines [16, 17]. Similarly,
for the in silico methods, as they are playing an increasing role in predicting properties for hazard and risk assessment, the acceptance of computational approaches
should be based on standards and criteria of reliability and relevance prior to be
applied within a specific regulatory context. As an example, EU REACH Regulation
explicitly includes the need to use QSAR models to reduce the extent of experimental
testing, emphasizing the principle that information generated by QSARs may be used
to indicate the presence or absence of a certain dangerous property instead of experimental data, provided that the following conditions are met: The results are derived
from a QSAR model whose scientific validity has been established, the substance
falls within the applicability domain of the QSAR model, the results are adequate for
the purpose of classification and labelling and/or risk assessment, and adequate and
reliable documentation of the applied method is provided [18]. Moreover, in order
to facilitate the consideration of a QSAR model for regulatory purposes, it should
be associated with the following information: a defined endpoint, an unambiguous
