Guide to ITAR Rules in the Compliance Center

This table defines the ITAR rules covered in FileCloud's Compliance Center, explains what steps you must take to be in compliance, and describes how FileCloud validates each rule.

Rule (click to see text)DescriptionSteps for complyingValidation
120.6Identify which documents are defense articles.

In the Compliance Center, click the Edit button for the rule, and select a metadata set with a tag that identifies defense articles.

(To carry out compliance, you must use smart classification to apply the metadata tag to defense articles.)

If the metadata set exists and is enabled, status is OK; if not, status is Issues.
120.10Identify which files contain technical data.

In the Compliance Center, click the Edit button for the rule, and select a metadata set with a tag that identifies technical data.

(To carry out compliance, you must use smart classification to apply the metadata tag to technical data.)

If the metadata set exists and is enabled, status is OK; If not, status is Issues.
120.13Only allow access to the system from within the US.In the Compliance Center, click the Edit button for the rule, and select a DLP rule that blocks users from logging in from outside locations. Only DLP rules for the LOGIN action are available for selection.If the DLP rule exists and is enabled, status is OK; if not, or if modifications to the rule allow log in from outside the US, status is Issues.
120.15Only allow US residents to access the system.Enabling the rule to confirm that your system checks if all users are US residents is all that is necessary to pass the compliance check.None
120.17Do not permit public sharing.
  1. In the Compliance Center, click the Edit button for the rule, and select a DLP rule that blocks public shares. Only DLP rules for the SHARE action are available for selection.
  2. Change any existing public shares to private.
If the DLP rule exists and is enabled and there are no existing public shares, status is OK; if not, or if modifications to the rule allow public shares, status is Issues.
120.25Allow at least one user access to the Compliance system.

To enable at least one user to manage the Compliance Center:

  1. Go to Admins and create a role with Compliance access to the Compliance Center.
  2. In Admins, add at least one user to the role with access to the Compliance Center.

If one or more Admin users have access to the Compliance Center, status is OK; if not, status is Issues.

120.50Prevent unauthorized access to data by non-US residents.Install FileCloud with an enterprise license or a license that includes a Digital Rights Management (DRM) component.
If a proper license is installed, status is OK; if not, status is Issues.
120.54(2)(3)Prevent data from being shared with non-US entities. Remove any existing public shares or change them to private.If any public shares exist, status is Issues.
120.54(5)Confirm that data is only transferred between US entities.
  1. In the Admin portal, go to Settings > Server > Server URL. Use HTTPS for the Server URL.
  2. Configure storage encryption. See Setting up Managed Storage Encryption.
  3. Go to Settings > Storage > MyFiles and enable Encryption.
  4. Encrypt all existing files.
If HTTPS is not used, storage is not fully encrypted, or any existing files are not fully encrypted, status is Issues.
120.55Keep decryption methods secure.Enabling the rule to confirm that decryption keys are kept confidential in your system is all that is necessary to pass the compliance check.None.
123.1Ensure that proper permission is given if data is shared with non-US entities
  1. In the Admin portal, go to Settings > Policies > General > Share Mode, and for Set Share Mode in all policies choose either Allow Private Shares Only or Shares Not Allowed.
  2. Remove any existing public shares or change them to private.

If Set Share Mode is Allow All Shares or any public shares exist, status is Issues.

123.26Maintain records of all data shared with non-US entitiesIn the Admin portal, go to Settings > Admin and set the Audit Logging Level to FULL.If Audit Logging Level is set to OFF or REQUEST, status is Issues.
126.1Deny access to the system by prohibited countries

In the row for the rule in the Compliance Center, click the Edit button and select a DLP rule that blocks users from logging in from those countries.


Only DLP rules for the LOGIN action are available for selection.
If the DLP rule exists and is enabled, status is OK; if not, or if modifications to the rule allow log in from those countries, status is Issues.
127.1Confirm that reports of violations of compliance rules can be exported.Enabling the rule to confirm that there is functionality to export reports of compliance rule violations from this page is all that is necessary to pass the compliance check.None