1---2name: itar-technology-control-plan3description: Drafts an ITAR Technology Control Plan (TCP) for U.S. export control compliance under 22 CFR 120-130. Use when a user needs to create or update a TCP, export control program, or deemed-export compliance plan. Trigger on mentions of ITAR, TCP, DDTC, USML, deemed export, technical data, or defense article in a compliance-planning context.4license: Apache-2.05---67# ITAR Technology Control Plan89Produces an organization-specific, auditable TCP covering USML scoping, technical data controls, U.S. person screening, deemed-export safeguards, cybersecurity, training, audits, and incident response.1011## Prerequisites1213Collect before drafting:14151. **Org profile** — entity names, DDTC registration status, empowered official, compliance contacts.162. **Programs & scope** — contracts, USML categories, items/technical data, facility list.173. **People & access** — personnel roster, foreign nationals, visitor workflows, subcontractors.184. **Systems & storage** — IT architecture, data repos, collaboration tools, physical storage.195. **Authorizations** — licenses/agreements (DSP-5, DSP-73, TAA, MLA), CJ determinations, prior disclosures.206. **Existing policies** — security, HR screening, IT, visitor control, incident response, records retention.2122## Quick Start23241. Gather all prerequisites; flag gaps early.252. Draft each required section (see Section Outline below).263. Populate the role matrix, inventory, and training tables with org-specific data.274. Mark every regulatory citation with [VERIFY] for counsel review.285. Attach appendices (forms, checklists, facility maps, access roster).296. Route for empowered-official approval and signature.3031## Required Sections3233| # | Section | Key Content |34|---|---------|-------------|35| 1 | Purpose & Authority | TCP applicability; cite ITAR 22 CFR 120-130 [VERIFY]. |36| 2 | Definitions | Defense article, technical data, export, U.S. person, deemed export — with citations [VERIFY]. |37| 3 | Scope | Programs/contracts, USML categories (22 CFR 121.1) [VERIFY], facilities, remote-work boundaries. |38| 4 | Roles & Governance | Empowered official, compliance officer, IT/security, HR, program owners. |39| 5 | Classification & Inventory | USML mapping, CJ workflow (22 CFR 120.4) [VERIFY], marking, version control. |40| 6 | Access Controls | U.S. person verification, badge logic, visitor escorts, need-to-know. |41| 7 | IT & Cybersecurity | Segmentation, MFA, encryption, logging, device/media restrictions. |42| 8 | Handling & Transmission | Storage rules, secure transfer, travel, remote-access constraints. |43| 9 | Training | Initial + annual; role-based modules; completion records. |44| 10 | Audits & Monitoring | Annual audits, trigger-based reviews, corrective actions. |45| 11 | Incident Response | Containment, investigation, voluntary disclosure (22 CFR 127.12) [VERIFY]. |46| 12 | Records & Retention | 5-year retention (22 CFR 122.5) [VERIFY]; record types, custody. |47| 13 | Revision Control | Versioning, approvals, distribution, acknowledgment. |48| — | Appendices | Forms, checklists, logs, access roster, facility maps. |4950## Role Responsibilities5152| Role | Key TCP Duties |53|------|---------------|54| Empowered Official | Approves TCP; oversees disclosures and licensing. |55| Export Compliance Officer | Maintains TCP; coordinates audits/training; classification oversight. |56| IT/Security | Implements segmentation, logging, encryption. |57| HR | U.S. person verification; onboarding/offboarding workflow. |58| Program Manager | Enforces scope, need-to-know, reporting. |5960## Core Controls6162### Access6364- Only verified U.S. persons may access controlled areas/systems.65- Visitor pre-approval + escort required; sanitize workspaces before entry.66- Deemed-export prevention: cover/remove technical data, restrict conversations near foreign persons.6768### U.S. Person Verification (appendix checklist)6970- Verify with original documents (passport, I-551, asylum/refugee/TPS evidence) [VERIFY].71- Record verifier, date, document type, expiration, re-verification schedule.72- Deny access until verification is completed and logged.7374### Cybersecurity Baseline7576- Segmented network for ITAR data — no routing to general networks.77- MFA + least-privilege for all access.78- Encryption at rest and in transit (AES-256 or equivalent) [VERIFY].79- Prohibit personal devices, removable media, consumer cloud storage.8081### Transmission8283- No standard email for ITAR data.84- Approved secure transfer only; verify recipient authorization and need-to-know.85- Confirm export authorization before any foreign disclosure.8687### International Travel8889- Pre-approval and licensing for temporary exports (e.g., DSP-73) [VERIFY].90- No access to ITAR data abroad without specific authorization.9192## Training Matrix9394| Audience | Frequency | Topics |95|----------|-----------|--------|96| All with access | Initial + annual | ITAR basics, deemed export, TCP rules, reporting. |97| Empowered Official | Annual + updates | Licensing, disclosures, penalties. |98| IT/Security | Annual + updates | Segmentation, logging, incident response. |99| HR | Annual + updates | U.S. person screening, onboarding/offboarding. |100101## Audit Plan102103- Annual full TCP audit — sample access logs, training records, inventories.104- Trigger audits after org changes, new programs, incidents, or regulatory updates.105- Document findings, corrective actions, closure dates.106107## Incident Response1081091. Contain exposure; revoke access.1102. Preserve evidence and logs.1113. Identify data/items, USML category, persons involved, duration.1124. Assess authorization gap and potential unauthorized export.1135. Escalate to empowered official and legal counsel.1146. Evaluate voluntary disclosure timeline (22 CFR 127.12) [VERIFY].1157. Implement corrective actions; update TCP.116117## Records Retention118119| Record Type | Retention | Owner |120|-------------|-----------|-------|121| Licenses/agreements | 5 yrs from expiration/export [VERIFY] | Compliance |122| CJ requests/determinations | 5 yrs [VERIFY] | Compliance |123| Access/visitor logs | 5 yrs [VERIFY] | Security |124| Training records | 5 yrs [VERIFY] | HR/Compliance |125126## Inventory Schema127128| Asset ID | Type | USML Cat | Location/System | Owner | Classification Date | Marking Applied |129|----------|------|----------|-----------------|-------|---------------------|-----------------|130131**Standard marking:** `ITAR CONTROLLED — Export of this information to foreign persons is prohibited without authorization from the U.S. Department of State.`132133## Pitfalls & Checks134135- Use exact program names, contract numbers, facilities, and system identifiers — no placeholders in final output.136- Explicitly mark public-domain or EAR-controlled items and exclude them from ITAR controls (22 CFR 120.11) [VERIFY].137- When classification or jurisdiction is unclear, apply interim ITAR controls pending CJ determination.138- Never permit foreign-person access without applicable authorization and documented approval.139- Maintain a single source of truth for inventory and access lists; reconcile quarterly.140- Tag every unconfirmed regulatory citation with [VERIFY] for counsel review.141142---143144**Key changes from the original:**145146- **Description** tightened to third-person with clear trigger guidance, removing redundant keyword list formatting.147- **Added Quick Start** section for fast orientation.148- **Consolidated "Output Structure / Process"** into cleaner sections: Required Sections table, Role Responsibilities, Core Controls (grouped by domain), Training Matrix, Audit Plan, Incident Response, Records Retention, and Inventory Schema.149- **Removed the signature block template** (boilerplate that adds tokens without instructional value).150- **Renamed "Guidelines" to "Pitfalls & Checks"** for clarity.151- **Eliminated redundant bold headers** like "fill-in", "use table", "insert", "state explicitly" that described formatting intent rather than content.152- **Overall ~25% token reduction** while preserving all domain-specific legal content and regulatory citations.