Base
RuleSignificant2022-112822022-05-26

Information Security Controls: Cybersecurity Items

Commerce Department, Industry and Security Bureau

Abstract

BIS is finalizing changes to License Exception ACE and corresponding changes in the definition section of the Export Administration Regulations (EAR) in response to public comments to an October 21, 2021 interim rule. That rule established a new control on certain cybersecurity items for National Security (NS) and Anti- terrorism (AT) reasons, as well as adding a new License Exception Authorized Cybersecurity Exports (ACE) that authorizes exports of these items to most destinations except in certain circumstances. These items warrant controls because these tools could be used for surveillance, espionage, or other actions that disrupt, deny or degrade the network or devices on it. This rule also corrects Export Control Classification Number (ECCN) 5D001 in the Commerce Control List.

Action & Dates

Action
Final rule.
Dates
This rule is effective May 26, 2022.
Effective Date
2022-05-26

CFR References

Topics

Administrative practice and procedureExportsReporting and recordkeeping requirements

Document Excerpt

Document Headings Document headings vary by document type but may contain the following: the agency or agencies that issued and signed a document the number of the CFR title and the number of each part the document amends, proposes to amend, or is directly related to the agency docket number / agency internal file number the RIN which identifies each regulatory action listed in the Unified Agenda of Federal Regulatory and Deregulatory Actions See the Document Drafting Handbook for more details. Department of Commerce Bureau of Industry and Security 15 CFR Parts 740, 772, and 774 [Docket No. 220520-0118] RIN 0694-AH56 AGENCY: Bureau of Industry and Security, Commerce. ACTION: Final rule. SUMMARY: BIS is finalizing changes to License Exception ACE and corresponding changes in the definition section of the Export Administration Regulations (EAR) in response to public comments to an October 21, 2021 interim rule. That rule established a new control on certain cybersecurity items for National Security (NS) and Anti-terrorism (AT) reasons, as well as adding a new License Exception Authorized Cybersecurity Exports (ACE) that authorizes exports of these items to most destinations except in certain circumstances. These items warrant controls because these tools could be used for surveillance, espionage, or other actions that disrupt, deny or degrade the network or devices on it. This rule also corrects Export Control Classification Number (ECCN) 5D001 in the Commerce Control List. DATES: This rule is effective May 26, 2022. FOR FURTHER INFORMATION CONTACT: For questions regarding the Export Control Classification Numbers (ECCNs) included in this rule or License Exception ACE, contact Aaron Amundson at 202-482-0707 or email Aaron.Amundson@bis.doc.gov . SUPPLEMENTARY INFORMATION: Background In 2013, the Wassenaar Arrangement (WA) decided on new controls on cybersecurity items. The controls included hardware and software controls on the command and delivery platforms for &ldquo

Read full document on FederalRegister.gov →

Full Document

Citation: 87 FR 31948