Topic Title
Export Control as part of operational compliance
Topic Overview
Tracking of export control assessments for individual artifacts is crucial for an overarching evaluation of export control for an aggregated product.
Scaling, context, trust and validation are crucial factors for the topics, that require end-to-end process integration.
Problem Statement or Opportunity
A manufacturer develops and distributes a product that incorporates multiple internal software components, third-party libraries and open-source dependencies. If the manufacturer intends to distribute this product across multiple jurisdictions they must ensure compliance with applicable export control regulations.
Individual export control classification may be required for distinct product artifacts. These classifications must be linked to the assessed artifacts and propagated through project context, enabling downstream stakeholders (e.g., distribution, legal, customers) to determine whether export restrictions apply.
Organizations require processes and data management at scale to fulfill their obligations.
Assessments may be repeated across multiple jurisdictions, resulting in parallel classification based on distribution context.
Data validity is crucial, as assessment results can only be relied upon when shared among trusted entities.
Potential Outcomes
Best practice guidance
Topic Maturity
Requires Community Discussion
Topic Champion
@umm0
References
Implemented in SPDX 3 Operations Profile: https://github.com/spdx/spdx-3-model/blob/develop/model/Operations/Classes/ExportControlClassification.md
Topic Title
Export Control as part of operational compliance
Topic Overview
Tracking of export control assessments for individual artifacts is crucial for an overarching evaluation of export control for an aggregated product.
Scaling, context, trust and validation are crucial factors for the topics, that require end-to-end process integration.
Problem Statement or Opportunity
A manufacturer develops and distributes a product that incorporates multiple internal software components, third-party libraries and open-source dependencies. If the manufacturer intends to distribute this product across multiple jurisdictions they must ensure compliance with applicable export control regulations.
Individual export control classification may be required for distinct product artifacts. These classifications must be linked to the assessed artifacts and propagated through project context, enabling downstream stakeholders (e.g., distribution, legal, customers) to determine whether export restrictions apply.
Organizations require processes and data management at scale to fulfill their obligations.
Assessments may be repeated across multiple jurisdictions, resulting in parallel classification based on distribution context.
Data validity is crucial, as assessment results can only be relied upon when shared among trusted entities.
Potential Outcomes
Best practice guidance
Topic Maturity
Requires Community Discussion
Topic Champion
@umm0
References
Implemented in SPDX 3 Operations Profile: https://github.com/spdx/spdx-3-model/blob/develop/model/Operations/Classes/ExportControlClassification.md