skills/legal/itar-technology-control-plan/SKILL.md
Drafts an ITAR Technology Control Plan (TCP) for U.S. export control compliance under 22 CFR 120-130. Use when a user needs to create or update a TCP, export control program, or deemed-export compliance plan. Trigger on mentions of ITAR, TCP, DDTC, USML, deemed export, technical data, or defense article in a compliance-planning context.
npx skillsauth add casemark/skills itar-technology-control-planInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces an organization-specific, auditable TCP covering USML scoping, technical data controls, U.S. person screening, deemed-export safeguards, cybersecurity, training, audits, and incident response.
Collect before drafting:
| # | Section | Key Content | |---|---------|-------------| | 1 | Purpose & Authority | TCP applicability; cite ITAR 22 CFR 120-130 [VERIFY]. | | 2 | Definitions | Defense article, technical data, export, U.S. person, deemed export — with citations [VERIFY]. | | 3 | Scope | Programs/contracts, USML categories (22 CFR 121.1) [VERIFY], facilities, remote-work boundaries. | | 4 | Roles & Governance | Empowered official, compliance officer, IT/security, HR, program owners. | | 5 | Classification & Inventory | USML mapping, CJ workflow (22 CFR 120.4) [VERIFY], marking, version control. | | 6 | Access Controls | U.S. person verification, badge logic, visitor escorts, need-to-know. | | 7 | IT & Cybersecurity | Segmentation, MFA, encryption, logging, device/media restrictions. | | 8 | Handling & Transmission | Storage rules, secure transfer, travel, remote-access constraints. | | 9 | Training | Initial + annual; role-based modules; completion records. | | 10 | Audits & Monitoring | Annual audits, trigger-based reviews, corrective actions. | | 11 | Incident Response | Containment, investigation, voluntary disclosure (22 CFR 127.12) [VERIFY]. | | 12 | Records & Retention | 5-year retention (22 CFR 122.5) [VERIFY]; record types, custody. | | 13 | Revision Control | Versioning, approvals, distribution, acknowledgment. | | — | Appendices | Forms, checklists, logs, access roster, facility maps. |
| Role | Key TCP Duties | |------|---------------| | Empowered Official | Approves TCP; oversees disclosures and licensing. | | Export Compliance Officer | Maintains TCP; coordinates audits/training; classification oversight. | | IT/Security | Implements segmentation, logging, encryption. | | HR | U.S. person verification; onboarding/offboarding workflow. | | Program Manager | Enforces scope, need-to-know, reporting. |
| Audience | Frequency | Topics | |----------|-----------|--------| | All with access | Initial + annual | ITAR basics, deemed export, TCP rules, reporting. | | Empowered Official | Annual + updates | Licensing, disclosures, penalties. | | IT/Security | Annual + updates | Segmentation, logging, incident response. | | HR | Annual + updates | U.S. person screening, onboarding/offboarding. |
| Record Type | Retention | Owner | |-------------|-----------|-------| | Licenses/agreements | 5 yrs from expiration/export [VERIFY] | Compliance | | CJ requests/determinations | 5 yrs [VERIFY] | Compliance | | Access/visitor logs | 5 yrs [VERIFY] | Security | | Training records | 5 yrs [VERIFY] | HR/Compliance |
| Asset ID | Type | USML Cat | Location/System | Owner | Classification Date | Marking Applied | |----------|------|----------|-----------------|-------|---------------------|-----------------|
Standard marking: ITAR CONTROLLED — Export of this information to foreign persons is prohibited without authorization from the U.S. Department of State.
Key changes from the original:
development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.