Import and Export Controls

Import and export controls require navigating international agreements and complying with national laws to regulate the cross-border flow of sensitive data, software, and technology.

4 slides · 3 min read · Domain 1

Slide 1

Importing and exporting goods between countries has been done for thousands of years, dating at least as far back as ancient Egypt and the Roman Empire. Import and export have various limitations and taxes imposed on both sides by local governments. When discussing import and export controls and limitations in the cybersecurity world, most limitations are on how the technology can be used. Specific treaties exist between countries to ensure that technologies imported and exported between countries do not change the force balance between nations.

An example of such a control is the Wassenaar Arrangement. Originally signed in 1996 by 33 countries, there are 42 countries that now participate in the agreement that restricts import and export of conventional weapons, as well as dual-use goods and technologies such as encryption. The arrangement maintains effective export controls between the parties that uphold the agreement. In the U.S., the Militarily Critical Technologies List (MCTL) details many products, components, and technologies that require special export permissions (such as heavy transport vehicles capable of being modified into roadmobile rocket launchers). The MCTL has had an on-again, off-again set of restrictions on many encryptions, cyber forensics, and other information security tools. Russia, China, Ukraine, and North Korea top the list of countries having the most restrictive import policies regarding encryption.

The United States, the European Union (EU), and other nations also can rapidly impose trade sanctions that can limit or ban the export of certain goods (including technology goods) to a country, a set of businesses within a country, or even to by-name individuals, as part of a variety of foreign policy objectives.

Countries such as Russia, China, and the Democratic People's Republic of Korea place severe restrictions on the use of cryptography by their citizens, which can complicate exporting even the most benign smart contract process or Bitcoin-powered app (both of which use encryption) to such countries. (Bringing such devices into such countries as a traveler could be fraught with legal perils.)

As security professionals, we must be aware whether our organization falls under the directive of import and export control agreements, since this can affect what technologies we can use, create, sell, or purchase.

For example, consider the use of encryption in providing and enhancing privacy protection for personal data. Import and export controls for encryption may prevent such privacy-enhancing services and products from being sold or marketed in each jurisdiction or may place onerous restrictions on their use. The COVID-19 pandemic focused attention on the need to take seemingly private data and make it more public as part of contact tracing, disease transmission vector analysis, and assessment of the effectiveness of different public and private health policies, treatments, and measures. Some countries pursued these technologies with very stringent protections for privacy in mind; others, such as Indonesia, have chosen to implement their contact tracing technologies in ways that routinely make information about an individual's movements available to law enforcement— even their movements within private spaces

Test this domain