research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
ITAR-specific compliance assessment for defense articles
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/itar-assessContext preview
What this command does when you run it.
ITAR-specific compliance assessment for defense articles
description: ITAR-specific compliance assessment for defense articles
> **Engineering guidance only. Not legal advice.** DDTC determines ITAR applicability and jurisdiction, not this toolkit. Citations worth reading alongside this command: [22 CFR 120.54](https://www.ecfr.gov/current/title-22/chapter-I/subchapter-M/part-120) (encrypted-technical-data carve-out), [22 CFR 122.5](https://www.ecfr.gov/current/title-22/chapter-I/subchapter-M/part-122) (recordkeeping scope). Work with export-control counsel before adopting any of the postures below.
Deep dive assessment for International Traffic in Arms Regulations (ITAR) compliance. Focuses on defense articles, technical data, and defense services under the US Munitions List (USML).
**Requirement**: Only "US persons" as defined in [22 CFR 120.62](https://www.ecfr.gov/current/title-22/chapter-I/subchapter-M/part-120/subpart-C/section-120.62) may access ITAR-controlled technical data. That definition is broader than citizens and green-card holders. It also includes "protected individuals" under 8 USC 1324b(a)(3) (certain refugees, asylees, and specific visa holders) and US-incorporated entities / US governmental agencies for entity-level access. Access policies that narrow to "citizens or LPRs only" over-restrict and can trigger employment-law exposure. Use the full 120.62 definition.
**Assessment Questions**:
**Cloud Verification**:
**Posture summary**: ITAR technical data is stored in US-located systems by default. 22 CFR 120.54 carves out end-to-end-encrypted technical data from the release definition, so properly-encrypted-in-transit-and-at-rest deployment patterns have room that a strict "US regions only" rule doesn't capture. Default to US-located regions; raise the encryption-carve-out question with counsel before relying on it.
**Assessment Questions**:
**Recommended Regions**:
**Requirement**: All ITAR data must be encrypted with FIPS 140-2 validated cryptographic modules.
**Assessment Questions**:
**Verification**:
**Requirement summary**: 22 CFR 122.5 requires ITAR-registered exporters to retain *specific record categories* (manufacturing, export transactions, broker records) for 5 years. It is not a blanket "retain every cloud log for 5 years" rule. Map which of your cloud logs actually carry those record categories, and set 5-year retention on *those*. General security/audit logs that fall outside 122.5 can have shorter retention set by your own policy or other applicable frameworks.
**Assessment Questions**:
**Requirement**: ITAR systems should be isolated from non-ITAR systems.
**Assessment Questions**:
**Requirement**: ITAR data must be marked with appropriate export control notices.
**Assessment Questions**:
**Requirement**: Control access by cloud service providers and third parties.
**Assessment Questions**:
**Requirement**: Most organizations handling ITAR data must register with DDTC.
**Annual Fee**: $3,000 per year **Form**: DS-2032 (Statement of Registration) **Renewal**: Annual before expiration
| Platform | Recommendation | Notes | |----------|---------------|-------| | **AWS GovCloud** | Highly Recommended | FedRAMP High, US-located, US persons only | | **Azure Government** | Highly Recommended | FedRAMP High, screened personnel | | **GCP Assured Workloads** | Recommended | With ITAR configuration, data residency controls | | **AWS Commercial** | Limited Use | US regions only, additional c
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.