Understanding ITAR vs EAR vs FAR vs DFARS Cybersecurity Requirements

It is possible for data related to International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) to fall outside of the US National Archives (NARA) classification of export-controlled information (e.g., CUI//SP-EXPT). However, the reality is NIST SP 800-171 controls constitute the minimum cybersecurity requirements for ITAR/EAR due to NARA's CUI Notice 2020-04. Additionally, an entity needs to ensure "access" and "release" requirements are specified according to 22 CFR 120.56:

22 CFR 120.56 - Release
1. Release. Technical data is released through:
  a. Visual or other inspection by foreign persons of a defense article that reveals technical data to a foreign person;
  b. Oral or written exchanges with foreign persons of technical data in the United States or abroad;
  c. The use of access information to cause or enable a foreign person, including yourself, to access, view, or possess unencrypted technical data; or
  d. The use of access information to cause technical data outside of the United States to be in unencrypted form.
2. Provision of access information. Authorization for a release of technical data to a foreign person is required to provide access information to that foreign person, if that access information can cause or enable access, viewing, or possession of the unencrypted technical data.

This requirements to control “release” forces an entity to define authorized users based on:

  1. Nationality as an explicit criteria (e.g., NOFORN); and
  2. Access location as an explicit criteria.

This access control applies for the user’s allowed assigned functions (e.g., roles) and privileged functions (e.g., system administrator). EAR is similar, but allows for a broader list of nationalities and countries that can be authorized for release.

While NIST SP 800-171 is considered a "minimum" to protect Controlled Unclassified Information (CUI) from a compliance perspective, those controls are likely not sufficient the entirety of an entity's overall needs to be secure, compliant and resilient. Therefore, additional administrative, technical and physical controls may be necessary (e.g., overlayed on top of NIST SP 800-171 controls).

NOTE: It is important to understand that NIST SP 800-171 will not solely address an entity's needs for a broader export control program. This program-level understanding is needed to govern how ITAR/EAR compliance is administered across the entity, not just within cybersecurity (e.g., registering for licenses, maintaining records, disclosures, etc.). To authorize release of export-controlled information an entity must communicate with the appropriate authority within the US government:

To understand ITAR vs EAR vs DFARS vs FAR requirements, it is important to understand the multiple stakeholders and their roles:

ITAR vs EAR vs DFARS vs CUI

ITAR vs EAR vs CUI

If you take the time to read through ITAR/EAR requirements, you will not find a specified set of cybersecurity controls that are required to protect ITAR/EAR data. This is where NARA comes into play through its authority to operate the US Government's CUI Program, where "export controlled" information has its own unique CUI category - https://www.archives.gov/cui/registry/category-detail/export-control.html

ITAR/EAR CUI Category:  Export Controlled (CUI//SP-EXPT) 

NARA Definition: Unclassified information concerning certain items, commodities, technology, software, or other information whose export could reasonably be expected to adversely affect the United States national security and nonproliferation objectives. To include dual use items; items identified in export administration regulations, international traffic in arms regulations (ITAR) and the munitions list; license applications; and sensitive nuclear technology information.

What Are Minimum Cybersecurity Requirements for ITAR & EAR?

While it might be possible that there is some ITAR/EAR that falls outside of NARA's classification of "export-controlled" information, the reality is NIST SP 800-171 CUI and Non-Federal Organization (NFO) controls are the minimum cybersecurity requirements for ITAR/EAR due to NARA's CUI Notice 2020-04. However, it is important to understand that NIST SP 800-171 will not address an organization's need for a broader export control program that governs how ITAR/EAR compliance is administered (e.g., registering for licenses, maintaining records, disclosures, etc.). The reason that NIST SP 800-171 is considered a "minimum" is that the controls may not be sufficient to address your organization's specific risk profile, so additional administrative, technical and physical controls may be necessary to become both secure and compliant.

What is ITAR/EAR?

ITAR/EAR are two (2) different, but complimentary sets of requirements:

ITAR and EAR combine to govern the export and import of sensitive technologies and defense-related materials:

ITAR regulates defense-related articles and services on the US Munitions List (USML).

EAR controls the export of commercial and dual-use goods, software and technology that can have both civilian and military applications.

Compliance with ITAR/EAR is critical for companies working with defense contracts, aerospace, or technologies with potential national security implications. Violations can lead to severe penalties, including fines and export restrictions. ITAR and EAR information may be handled under CUI protections if it falls within CUI categories, but ITAR/EAR compliance involves additional controls such as strict export licensing and access restrictions.

What Are Applicable NIST SP 800-171 Controls For ITAR & EAR?

NARA does not specify which controls are applicable to ITAR and/or EAR, so the expectation is all applicable NIST SP 800-171 controls and NIST SP 800-171A Assessment Objectives (AOs). However, there are a few specific controls and AOs that need to have explic nationality and location criteria defined for ITAR/EAR compliance:

Applicable NIST SP 800-171 R2 Controls & Assessment Objectives

3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

3.1.3: Control the flow of CUI in accordance with approved authorizations.

3.1.15: Authorize remote execution of privileged commands and remote access to security-relevant information.

Applicable NIST SP 800-171 R3 Controls & Assessment Objectives

03.01.01 (Access Enforcement): Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.

03.01.03 (Information Flow Enforcement): Enforce approved authorizations for controlling the flow of CUI within the system and between connected systems.

03.01.07 (Least Privilege – Privileged Functions):

  1. Prevent non-privileged users from executing privileged functions.
  2. Log the execution of privileged functions.

Browse Our Products

  • Secure Controls Framework (SCF) Policy, Standards, Controls & Metrics Template - SCRP

    Policies & Standards - Secure Controls Framework (SCF)

    Secure Controls Framework (SCF)

    Secure Controls Framework (SCF)-Based Policies, Control Objectives, Standards, Guidelines, Controls & Metrics ComplianceForge is a Licensed Content Provider (LCP) by the Secure Controls Framework (SCF). This means ComplianceForge is authorized to...

    $10,400.00
    Choose Options
  • ComplianceForge NIST 800-53 Compliance Documentation Templates Policy & Standards Template - NIST 800-53 R5 (moderate)

    Policies & Standards - NIST 800-53 R5 (moderate)

    ComplianceForge NIST 800-53 Compliance Documentation Templates

    NIST 800-53 Rev5 Policy Template  LOW & MODERATE BASELINE   Product Walkthrough Video When you click the image or the link below, it will direct you to a different page on our website that contains a short product walkthrough video...

    $1,980.00
    Choose Options
  • ComplianceForge - NIST 800-171 & CMMC NIST 800-171 Compliance Program (NCP): CMMC Level 2

    NIST 800-171 Compliance Program (NCP)

    ComplianceForge - NIST 800-171 & CMMC

    NIST 800-171 Rev 2 & Rev 3 / CMMC 2.0 Compliance Made Easier! The NCP is editable & affordable cybersecurity documentation to address your NIST 800-171 R2 / R3 and CMMC 2.0 Levels 1-2 compliance needs. When you click the image or the link...

    $8,950.00
    $5,300.00
    $5,200.00
    Choose Options
  • ComplianceForge NIST 800-53 Compliance Documentation Templates Policies & Procedures Bundle - NIST 800-53 R5 (Moderate)

    NIST 800-53 R5 (Moderate) Policies, Standards & Procedures

    ComplianceForge NIST 800-53 Compliance Documentation Templates

    IST 800-53 R5 MODERATE Bundle 1 -  NIST SP 800-53 R5 Low & Moderate Baselines  (20% discount) This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing NIST SP 800-53 R5 (low &...

    $6,680.00
    $6,680.00
    $5,344.00
    Choose Options