Export Controls – Technology Control Plans Erin L. Sherman, Macc, CRA, CIP, CPIA Research Compliance Officer

advertisement
ExportControls– TechnologyControlPlans
ErinL.Sherman,Macc,CRA,CIP,CPIA
ResearchComplianceOfficer
Introduction
Federalexportcontrollawsregulatethe
transmissionofstrategicallyimportant
items,services,softwareandtechnologyto
foreignpersonsorentitiesintheUnited
Statesandabroad.
Introduction
EmployeesofTexasA&MUniversity‐Corpus
Christimustbeawareof,andare
responsiblefor,theexportcontrol
implicationsoftheirworkandmustensure
thattheiractivitiesconformtoexport
controlrulesandregulations.
ResearchMisconduct
Violationofexportcontrolregulationscan
resultinseveralinstitutionalandindividual
sanctions.Sanctionscanincludethelossof
researchfunding,criminalpenalties
(includingimprisonment)andcivil
penalties.
WhatisanExport?
An“export”generallyincludes:
 Actualshipmentofanycoveredgoodsoritems
 Theelectronicordigitaltransmissionofanycoveredgoods,
itemsorrelatedgoodsoritems
 Anyreleaseordisclosure,includingverbaldisclosuresand
visualinspections,ofanytechnology,softwareortechnological
datatoanyForeignPersonorentity
 Actualuseorapplicationofcoveredtechnologyonbehalfof,or
forthebenefitof,aForeignPersonanywhere
WhenacontrolleditemorinformationistransmittedtoaForeign
PersonintheUnitedStates,itisknownasa“deemedexport.”
WhoisaForeignPerson?
AForeignPerson,forexportcontrolpurposes,
includes:
anyindividualintheUnitedStatesin
nonimmigrantstatus(e.g.H‐1B,H‐3,L‐1,J‐1,F‐1,B‐1,
PracticalTraining)
individualsunlawfullyintheUnitedStates
anybranchofaforeigngovernment,foreign
corporationorgroupthatisnotincorporated
ororganizedtodobusinessintheUnited
States.
WhoisNOTaForeignPerson?
AForeignPerson,forexportcontrolpurposes,is
NOT:
anindividualwhoisaUnitedStatescitizen
anindividualwhoisalawfulpermanent
residentoftheUnitedStates
anindividualwhoisarefugee,protected
politicalasylee orsomeonegrantedtemporary
residencyunderamnestyorSpecial
AgriculturalWorkerprovisions
WhatisaTechnologyControlPlan(TCP)?
Atechnologycontrolplanisawrittendocumentusedtoidentify
specificphysicalandinformationalsecuritymeasuresnecessary
topreventunauthorizedaccessofexportcontrolleditems,
information,technologyorsoftwarebyunauthorizedForeign
Persons.
ThetwocomponentsrequiredforaTCPare:
 CompletedTCP
 CompletedTCPPersonnelBriefingandCertificationformfor
eachpersonwithaccesstotheexportcontrolleditems,
information,technologyorsoftware
WhatisaTechnologyControlPlan(TCP)?
Atechnologycontrolplan(TCP)includes:
 Acommitmenttoexportcontrolcompliance
 Identificationoftherelevantexportcontrolcategoriesand
controlledtechnologies
 Identificationofproject’ssponsors
 Identificationandnationalityofeachindividualparticipatingin
theprojectorhavingaccesstothecontrolleditem,technology,
informationorsoftware
 Appropriatephysicalandinformationalsecuritymeasures
 Personnelscreeningmeasuresandtraining
 Appropriatesecuritymeasuresforthedurationoftheproject
WhenisaTechnologyControlPlan(TCP)Required?
Atechnologycontrolplan(TCP)isrequired
when:
Aprojectorfacilityinvolvesexportcontrolled
items,informationand/orsoftwaretechnology
Anactivityinvolvesreceiptofexportcontrolled
information,items,technologyorsoftwarefrom
athirdpartysuchasasponsor
HowdoIKnowifMyProject,Activity,and/orEquipmentisControlled?
Afewexamplesofwhenanexportcontrolrestriction
may apply:
TheresultsofresearchconductedatTAMUCCorby
TAMUCCemployeesareintendedformilitarypurposes
orforotherrestrictedendusesspecifiedintheexport
controlregulations
(http://www.bis.doc.gov/policiesandregulations/index.htm#ear)
ForeignPersonswillhaveaccesstocontrolledphysical
items
Softwareincludingencryptionfeatureswillbe
developedorpurchased
HowdoIKnowifMyProject,Activity,and/orEquipmentisControlled?
Afewadditionalexamplesofwhenanexportcontrolrestriction
may apply:
 Facultyorstafftravelabroadandtakeexportcontrolled
informationoritemssuchaschemicals,biologicalmaterialsor
encryptedsoftwarewiththem(possiblyvialaptop,phoneorPDA)
 Theresearchsponsorrequirespre‐approvalrightsover
publicationsbeyondthecustomary30‐60dayperiodtoprotect
patentrights
 TheparticipationofForeignPersonsonaprojectisrestricted
 Theprojectrequirestheshippingofequipmenttoaforeign
countryortheequipmentwillbeusedinaforeigncountry
WhoDeterminesifMyProject/Activity/EquipmentisControlled?
Anyonewhosuspectshe/shemayhaveanexportcontrolled
project/activity/equipmentmustworkwiththeResearchCompliance
Officertomakethedetermination.
TheResearchComplianceOfficerwillworkwiththePrincipal
Investigator(PI)orResponsibleIndividual(RI)tocompleteatechnology
controlplan(TCP)tosecurecontrolleditems,information,technologyor
softwarefromaccessbyunauthorizedForeignPersons.
TheTCPmustbeapprovedbythedepartment/unitheadandthe
ResearchComplianceOfficer.
ExportcontroltrainingisrequiredforallpersonnelidentifiedinaTCP,
includingstudents.
ResearchComplianceOffice
IsaTCPRequiredifanExportControlExclusionApplies?
InstitutionalReviewBoard(IRB)
Maybe.Activitiesmayfallunderexclusions
toexportcontrolregulations(e.g.
fundamentalresearch,public
domain/publicinformation,educational
information).SuchexclusionsMAYNOT
applytoexportcontrolledinformationor
items.
ResearchComplianceOffice
WhatHappensAfteraTCPHasBeenApproved?
ThePI/RIwillreviewtheTCPwithallindividualswho
willparticipateontheprojectand/orbegrantedaccess
tothecontrolleditems,information,technologyor
software.
Allusers,includingstudents,mustbeidentifiedinthe
TCP.AllusersarerequiredtosigntheTCPBriefingand
Certificationacknowledgingandcertifyingtheyhave
readandunderstandtheTCPandwillcomplywithits
terms.
ResearchComplianceOffice
WhatHappensAfteraTCPHasBeenApproved?
ThePI/RIisresponsibleforimplementationoftheTCP
andfornotifyingtheTAMUCCResearchCompliance
OfficerifanychangesaffectingtheTCPareanticipated
(e.g.changeinpersonnel,scopeofproject,locationof
controlleditem,etc.).
AnticipatedeventsthatmayaffectthetermsoftheTCP
requireapprovalofanupdatedTCPbytheResearch
ComplianceOfficer.
ResearchComplianceOffice
ExamplesofAppropriateSecurityMeasures
TheTCPmustincludephysicalandinformational
securitymeasuresappropriatefortheexportcontrol
categoryinvolved.
Examplesinclude:
 Laboratorycompartmentalization
 Timeblocking:restrictingprojectoperationtotime
blockswhenunauthorizedindividualscannotobserve
orhaveaccess
 Marking:clearlyidentifyingandmarkingexport
controlitems,information,technologyorsoftwareas
exportcontrolled
ResearchComplianceOffice
ExamplesofAppropriateSecurityMeasures
TheTCPmustincludephysicalandinformationalsecurity
measuresappropriatefortheexportcontrolcategoryinvolved.
Examplesinclude:
 Personnelidentification:Individualsparticipatinginthe
projectorhaveaccessarerequiredtowearabadge,special
cardorothersimilardeviceindicatingauthoritytoaccess
designatedprojectareas.Physicalmovementintoandoutofa
designatedprojectareaislogged.
 Lockedstorage:Tangibleitemssuchasequipment,associated
operatingmanualsandschematicdiagramsarestoredin
roomswithkey‐controlledaccess.Softandhardcopydata,lab
notebooks,reportsandotherresearchmaterialsarestoredin
lockedcabinets.
ResearchComplianceOffice
ExamplesofAppropriateSecurityMeasures
TheTCPmustincludephysicalandinformationalsecuritymeasures
appropriatefortheexportcontrolcategoryinvolved.
Examplesinclude:
 Electronicsecurity:Projectcomputers,networks,andelectronic
transmissionsaresecuredandmonitoredthroughuserIDs,
passwordcontrols,128‐btsecuresocketslayerencryption,orother
federallyapprovedencryptiontechnology.Databaseaccessis
managedviaavirtualprivatenetwork(VPN).
 Confidentialcommunications:Discussionsabouttheprojectare
limitedtoidentifiedandauthorizedprojectparticipantsand
conductedonlyinareaswhereunauthorizedindividualsarenot
present.Discussionswiththirdpartysubcontractorsoccuronly
undersignedagreementswhichfullyrespecttheforeignperson
restrictionsassociatedwithsuchdisclosures.
ResearchComplianceOffice
ImplementingtheTCP
ThePI/RIisresponsibleforimplementingtheTCP.Any
anticipatedchangetotheTCP,suchasachangein
personnel,scope‐of‐work,safeguards,etc.mustbe
includedinarevisedTCPimmediatelyandmustbe
reviewedandapprovedbytheResearchCompliance
Officer.
Exportcontrollawsandregulationsarecomplexandfact
specific.TheResearchComplianceOfficerisavailableto
assistandshouldbeconsultedwheneverexportcontrol
guidanceisneeded.
ResearchComplianceOffice
TCPReviewQuestions
TrueorFalse
IamconductingresearchinmylabatTAMUCCinCorpus
Christi.IhaveaCanadiangraduatestudentworkingwith
meonmyresearchprojectwhichinvolvesunmanned
aircraft.ThestudentisonH‐1Bimmigrationstatus.Ido
notneedtobeconcernedaboutexportcontrolsbecause
myprojectdoesnotinvolvetheexportofanything
outsidetheUnitedStates.
FALSE
ResearchComplianceOffice
TCPReviewQuestions
Whichofthefollowingindividualsisnotconsidereda
ForeignPersonforexportcontrolpurposes?
A. PakistaninationalwithaH‐1Bvisa
B. NorwegiannationalwithaJ‐1visa
C. Belgiannationalwhoholdspermanentresidencyin
theUnitedStates(i.e.greencard)
D. Alloftheabove
C– Belgiannational
ResearchComplianceOffice
TCPReviewQuestions
ATCPdescribesthesecuritymeasurestoprotectanexportcontrolleditem
frombeingaccessedbyunauthorizedindividuals.Whichofthefollowing
securitymeasuresisleastappropriateforinclusioninaTCPforthisitem?
A.
B.
C.
D.
Operationalmanualsandschematicdiagramsarestoredinroomswith
key‐controlledaccess.
Individualsparticipatinginorgrantedaccesstotheprojectarerequiredto
wearabadge,andphysicalmovementintoandoutofadesignatedproject
areaislogged.
Individualsparticipatingintheprojectarebadgedappropriatelyor
wearingsomeotherdevicethatindicatesthattheyhaveauthoritytoaccess
thecontrolleditem.
Electronicdocumentssuchasschematics,drawings,formulasandparts
listsarestoredonnetworkdrivesonlyaccessibletothedepartmentin
whichthestudytakesplace.
D– allowsforthepossibilityofadeemedexporttoanyForeignPerson
workinginthedepartment
ResearchComplianceOffice
TCPReviewQuestions
InwhichcasewillaTCPnotberequiredtocompletemyproject?
A. MygraduatestudentfromChinawillbeworkingonanelementofmyresearch
projectthatultimatelywillbeusedonanonmilitaryexperimentaldrone
aircraft.
B. AmemberonmyresearchteamisaPakistaninationalwithagreencard.Sheis
goingtobeusingaMassSpectrometerinmylabinCorpusChristitoanalyze
theelementsinasampleofsnowtakenfromPikesPeakinColorado.
C. SeveralTAMUCCfacultyandstaffwilltraveltoPakistantoparticipateinan
internationalconferencewhichfocusesonthesafetyandethicsoffuel
reprocessingandenrichmentfacilities.
D. NASAissponsoringmyresearchprojectandtheresearchagreementhasa
clauseinitrequiringpre‐approvalrightsovermypublicationonastudy
dealingwiththenoveldesignofagyroscopeforflightstabilizationcontrol.The
pre‐approvalperiodextendsbeyondthecustomary60days.
B– ATCPisnotneededwhentheequipmentusedisnotcontrolledtoanyone
ontheprojectandwheretheprojectisnotcreatingsomethingthatis
otherwisecontrolledoreligibleforanexclusion.
ResearchComplianceOffice
TCPReviewQuestions
TrueorFalse
Iamdoingbasicresearch,whichfallsunderthe
FundamentalResearchExclusion,soIdonotneedaTCP.
FALSE
ResearchComplianceOffice
TCPReviewQuestions
IamaPI,andIhavetoreplaceapersonidentifiedonmyTCPasanauthorizeduser.
WhatshouldIdo?
A.
B.
C.
ContacttheResearchComplianceOfficerandsubmitanamendedTCP.TheTCP
willbereviewedandthechangecannotbemadeuntiltherevisedTCPis
approvedbytheResearchComplianceOfficer.
WaitfortheResearchComplianceOfficertocontactmeaspartofthepost
approvalmonitoringprocessandexplainthechangeatthatpoint.
AssumetheTCPisnotinvalidatedandstopmyexportcontrolledresearchuntil
Igetanewplanapproved.
A– WorkwiththeResearchComplianceOfficertohavearevisedTCP
approvedandimplemented.
Questions…
ErinL.Sherman
ResearchComplianceOfficer
erin.sherman@tamucc.edu
ResearchComplianceWebsite:
http://research.tamucc.edu/compliance/index.html
Download