US International Traffic in Arms Regulations (ITAR)
The AWS GovCloud (US) Region supports compliance with United States International Traffic in Arms Regulations (ITAR). As a part of managing a comprehensive ITAR compliance program, companies that are subject to ITAR export regulations must control unintended exports by restricting access to protected data to US Persons, and by restricting physical location of protected data to the US. AWS GovCloud (US) provides an environment that is physically located in the US, and access by AWS personnel is limited to US Persons, thereby allowing qualified companies to use AWS to transmit, process, and store protected articles and data subject to ITAR restrictions. The AWS GovCloud (US) environment has been audited by an independent third-party assessment organization (3PAO) to validate that proper controls are in place to support customer export compliance programs.
What is ITAR?
International Traffic in Arms Regulations (ITAR) controls the export from the US of defense-related articles, and the regulations state that no non-US person can have physical or logical access to the articles stored in the ITAR environment.
Articles that are covered by the ITAR United States Munitions List (USML) include equipment, components, materials, software, and technical information that can only be shared with US Persons unless under special authorization or exemption. US Persons are individuals who are US Green Card (Permanent Resident Card) holders or US citizens.
How do ITAR requirements apply in the cloud?
ITAR compliance in the cloud focuses on ensuring that information considered technical data is not inadvertently distributed to foreign persons or foreign nations. In order for data to be subject to ITAR, an IT workload or type of data has to be deemed an export according to the US Munitions List (USML).
How does AWS support customers who are subject to ITAR export regulations?
AWS provides customers with the option to store their data in AWS GovCloud (US), which is managed solely by US Persons in US locations. AWS GovCloud (US) is Amazon’s isolated cloud environment where accounts are only granted to US Persons working for US organizations.
Because AWS does not have any visibility into what customers are uploading onto our network, including whether or not that data is deemed subject to ITAR regulations, all customer data within the GovCloud region is treated as ITAR data.
How does AWS GovCloud (US) provide assurance to customers that it meets ITAR requirements?
There is no formal ITAR certification. AWS GovCloud (US) is continuously audited by an accredited Federal Risk Authorization Management Program (FedRAMP) independent third-party assessment organization (3PAO) and has been issued a FedRAMP Provisional Authority to Operate (P-ATO) from the Joint Authorization Board (JAB) at the High Baseline. The Chief Information Officers (CIO) from the US Department of Defense, Department of Homeland Security, and General Services Administration represent the JAB. For more information, see Achieve FedRAMP High Compliance in the AWS GovCloud (US) Region.
How does the AWS Shared Responsibility apply when customers transmit, process, and store ITAR data in AWS?
AWS is responsible for the logical and physical compliance of the cloud infrastructure and core services we offer. Customers are responsible for their own on-premises IT infrastructure, applications, and systems. The AWS GovCloud FedRAMP Provisional Authority to Operate (P-ATO) from the Joint Authorization Board (JAB) at the High Baseline attests to the controls in place within AWS GovCloud (US). AWS supports customers who are building ITAR-compliant systems in AWS. The following are some examples of AWS services that help customers manage their own security compliance obligations:
Safeguard Sensitive Data: Customers can protect sensitive unclassified data with server-side encryption in Amazon S3; store and manage security keys with AWS CloudHSM or use our one-click AWS Key Management Service (KMS).
Improve Cloud Visibility: Customers can audit access and use of sensitive data with Amazon CloudTrail, our API logging service, which is managed and operated by US Persons.
Strengthen Identity Management:Customers can limit access to sensitive data by individual, time, and location. To restrict which API calls users are able to make, you can use identity federation, easy key rotation, and other powerful access control testing tools that are available in AWS.