Welcome to Baker McKenzie Stockholm Fifth Annual Trade Day. 7 November 2017

Similar documents
iclass SE multiclass SE 125kHz, 13.56MHz 125kHz, 13.56MHz

Patent Portfolio Overview May The data in this presentation is current as of this date.

Overcoming the Compliance Challenges of VAT Remittance. 12 April :55 to 16:30 (CEST)

Spoka Meet Audio Calls Rates Dial-In UK

Cisco Aironet In-Building Wireless Solutions International Power Compliance Chart

EventBuilder.com. International Audio Conferencing Access Guide. This guide contains: :: International Toll-Free Access Dialing Instructions

MANUAL VOICE/DATA SIMCARD CANADA

For: Ministry of Education From Date: 19 November 18-2 December 18 Venue: M1 Shops

VOICE/DATA SIMCARD USA UNLIMITED

Digital EAGLEs. Outlook and perspectives

END-OF-SALE AND END-OF-LIFE ANNOUNCEMENT FOR THE CISCO MEDIA CONVERGENCE SERVER 7845H-2400

International Business Mail Rate Card

Carrier Services. Intelligent telephony. for over COUNTRIES DID NUMBERS. All IP

Quintiles vdesk Welcome Guide

International Packets

Patent Portfolio Overview July The data in this presentation is current as of this date.

Items exceeding one or more of the maximum weight and dimensions of a flat. For maximum dimensions please see the service user guide.

Purchasing. Operations 3% Marketing 3% HR. Production 1%

Cisco HCS Country Dial Plans

No Purchase needed

Global entertainment and media outlook Explore the content and tools

Payphone Origination Service Charge Rate Per Min. Mobile Origination Service Charge. MLB Switched Rate Per Min. MLB Dedicated Rate Per Min

International Roaming Critical Information Summaries JULY 2017

EE Pay Monthly Add-Ons & Commitment Packs. Version

Dashboard. Feb 18, Feb 18, 2008 Comparing to: Site. 13,318 Visits 28,414 Pageviews 2.13 Pages/Visit

Traffic Offload. Cisco 7200/Cisco 7500 APPLICATION NOTE

CUSTOMER GUIDE Interoute One Bridge Outlook Plugin Meeting Invite Example Guide

Power Analyzer Firmware Update Utility Version Software Release Notes

PLEASE NOTE: firms may submit one set of research questionnaires covering both China and Hong Kong or separate sets for each jurisdiction

International Business Parcels Rate card

Service withdrawal: Selected IBM ServicePac offerings

AN POST SCHEDULE OF CHARGES

Cisco CallManager 4.0-PBX Interoperability: Lucent/Avaya Definity G3 MV1.3 PBX using 6608-T1 PRI NI2 with MGCP

Dataliner Message Displays Using DL50 Slaves with a DL40 Master

Enterprise price plan guide Vodafone One Net Business

Cisco Voice Services Provisioning Tool 2.6(1)

Allianz SE Reinsurance Branch Asia Pacific Systems Requirements & Developments. Dr. Lutz Füllgraf

CISCO IP PHONE 7970G NEW! CISCO IP PHONE 7905G AND 7912G XML

GW-WN150M 11b/g/n USB Wireless User Manual

DataKom Vodafone Mobile Tariff Minimum 30 day end of month notice cancellation - Subject to contract. DataKom O2 Mobile Tariff. All prices exclude VAT

Access Code and Phone Number

Cisco Extensible Provisioning and Operations Manager 4.5

Instructions. (For 6180 Industrial Computers) Applications. Overview & Safety

STANDARD BROADBAND & FIBRE BROADBAND PLANS

Common European Submission Portal

Field Terminal Assembly (FTA)

STANDARD BROADBAND & FIBRE BROADBAND PLANS

Automation DriveServer

ENHANCED INTERIOR GATEWAY ROUTING PROTOCOL STUB ROUTER FUNCTIONALITY

Instructions. (For 6180 Industrial Computers) Installing a Processor Upgrade

NEW CISCO IOS SOFTWARE RELEASE 12.2(25)EY FOR CISCO CATALYST 3750 METRO SERIES SWITCHES

RT-AX95U Wireless-AX11000 Tri Band Gigabit Router

The Role of SANAS in Support of South African Regulatory Objectives. Mr. Mpho Phaloane South African National Accreditation System

MORE THAN JUST A PRODUCT, CABLOFIL IS A GLOBAL SOLUTION. Safer, more economic economic and more performant and A SYSTEM AN EXPERTISE A SERVICE

IBM offers Software Maintenance for additional Licensed Program Products

STANDARD BROADBAND & FIBRE BROADBAND PLANS

Enterprise price plan guide Vodafone One Net Business

CISCO 7304 SERIES ROUTER PORT ADAPTER CARRIER CARD

Moving Professionals Forward. World Leader In Competence Based Certification

E-Seminar. Voice over IP. Internet Technical Solution Seminar

NEW METHOD FOR ORDERING CISCO 1700 SERIES MODULAR ACCESS ROUTERS AND CISCO 1800 SERIES INTEGRATED SERVICES ROUTERS SOFTWARE SPARE IMAGES

Turquoise Terminal Returns User Guide for Creating & Uploading a Turquoise Terminal Return

Beckhoff short profile

Digital Context Pacific Alliance

Vodafone Usage Manager R2.0

Appendix G. Percentiles and Standard Deviations of Science Achievement TIMSS 2011 INTERNATIONAL RESULTS IN SCIENCE APPENDIX G 495

THE POWER OF A STRONG PARTNERSHIP.

Shell Global Helpline - Telephone Numbers

Out of Bundle Vodafone

Safety. Introduction

ICT Connectivity for Trade & Development

Cisco Catalyst 2950 Series Software Feature Comparison Standard Image (SI) and Enhanced Image (EI) Feature Comparison

Step 1: New Portal User User ID Created Using IdentityIQ (IIQ)

Cisco 2651XM Gateway - PBX Interoperability: Avaya Definity G3 PBX using Analog FXO Interfaces to an H.323 Gateway

Customers want to transform their datacenter 80% 28% global IT budgets spent on maintenance. time spent on administrative tasks

Configuring DHCP for ShoreTel IP Phones

The IECEE CB Scheme facilitates Global trade of Information Technology products.

CONFIGURING EPOLICY ORCHESTRATOR 3.0 AND MCAFEE 8.0i WITH CISCO CALLMANAGER

L-force Controller 3200 C. Control and visualisation compactly combined

Cisco 3745 Gateway - PBX Interoperability: Avaya Definity G3 PBX using Q.931 PRI Network Side Interfaces to an H.323 Gateway

NEW JERSEY S HIGHER EDUCATION NETWORK (NJEDGE.NET), AN IP-VPN CASE STUDY

PAY MONTHLY ADDITIONAL SERVICES TERMS AND CONDITIONS

Reference Interconnect Offer Fix and Mobile (RIO F&M)

MINUTES AND TEXTS CUSTOMER MOBILE BOLT-ON GUIDE JUNE 2018 BOLT-ON WILL KEEP YOU IN CONTROL OF YOUR COSTS. INTERNATIONAL NUMBERS FROM YOUR MOBILE, THIS

A Guide to our Tariffs

Alternative phone number: Credit card/debit card number Expiry date: / / DD MM YYYY

IGEL-Briefing March Managed Software and Hardware Thin Clients

DATA APPENDIX. Real Exchange Rate Movements and the Relative Price of Nontraded Goods Caroline M. Betts and Timothy J. Kehoe

icims Browser & Version Support Policy

PIRLS 2016 INTERNATIONAL RESULTS IN READING

8510 AC Spindle Drive Hardware/Firmware Replacement

Rights and Responsibilities in. Benjamin Edelman Harvard Business School

CISCO FAX SERVER. Figure 1. Example Deployment Scenario. The Cisco Fax Server solution consists of the following components:

ANNOUNCING NEW PRODUCT OFFERINGS FOR THE CISCO CATALYST 6500 SERIES

COCAINE (unless otherwise noted) amongst young people (ordered alphabetically by regions)

Cisco Unified CallConnector for Microsoft Office Quick Reference Guide 1

PRIVACY NOTICE WHO WILL PROCESS YOUR PERSONAL INFORMATION? WHY IS YOUR PERSONAL INFORMATION REQUIRED?

A Guide to our Tariffs

E-Seminar. Wireless LAN. Internet Technical Solution Seminar

MULTI-VRF AND IP MULTICAST

Transcription:

Welcome to Baker McKenzie Stockholm Fifth Annual Trade Day 7 November 2017

Software Classification and Security Alison Stafford Powell and Olof König 3

4 Alison J. Stafford Powell Partner Baker McKenzie Palo Alto CA +1 650 856 5531 alison.stafford-powell@bakermckenzie.com Olof König Senior Associate Baker McKenzie Stockholm +46 (0) 8 566 177 44 olof.konig@bakermckenzie.com

Software Security Encryption is used everywhere and is the flip side of cyber security threat It is important to understand and control/own the encryption functionality used by you company Note that there is a revised structure in the new Dual use list which restructure Category 5 Part 2 into a more positive control list. Note 4 (decontrol note to Category 5, Part 2) has been removed, and is now incorporated into 5A002.a. This session will focus on encryption functionality. Note that the new proposed General Export Authorisation ( GEA ) for encryption and the proposed GEA for intra group transfers will take time before it is implemented 5

Regulators, Banks and Cryptography Crypto controls for electronic transfers Increased use of FinTech Regulators' focus on banks Increasing security and use of cryptography Export control rules apply to transfer of software / hardware using encryption Previously not a priority for banks, increased attention in last 1-2 years Regulatory audits by Export Control Organizations Other side of the coin for cyber risk 6

Encryption functionality 5A002 "Information security" systems, equipment and components, as follows: Designed or modified to use 'cryptography for data confidentiality using: a) A "symmetric algorithm" employing a key length in excess of 56 bits. or; b) An "asymmetric algorithm" where the security of the algorithm is based on any of the following: 1. Factorisation of integers in excess of 512 bits (e.g., RSA); 2. Computation of discrete logarithms in a multiplicative group of a finite field of size greater than 512 bits; or 3. Discrete logarithms in a group other than mentioned in paragraph b.2. in excess of 112 bits. 7

Decontrols and Exemptions What is the primary function of the product and its encryption functionality; Cryptographic activation" Decontrol parameters and easy routes: Banking use, authentication only, ancillary cryptography, OAM, and mass market Is the product available for free or sold to the general public? Presenting reasons to persuade ISP to want to treat an application as decontrolled 8

How to Achieve Compliance Key Aspects of Process Dedicated Team Minimising impact on operations Classification How does client get it right? Audit Licensing Record Keeping 9

EU Import Controls on Cryptography No EU-wide import control requirements on cryptography. Some exceptions: Bulgaria (registration requirements for imports from outside the EU) France (registration requirements, plus reporting requirements for exports) Latvia (import licensing requirements for certain goods) Poland (reporting requirements) Croatia 10

Encryption Requirements by Country* Country Import Export Argentina No Yes Australia No Yes Austria No Yes Belgium No Yes Belarus Yes Yes Brazil No No Bulgaria Yes Yes Canada No Yes Chile No No China Yes Yes Croatia Yes Yes Cyprus No Yes Czech Republic No Yes Denmark No Yes Egypt Yes No Estonia No Yes Finland No Yes France Yes Yes Germany No Yes Greece No Yes 11 Country Import Export Hong Kong Yes Yes Hungary No Yes India Yes Yes Ireland No Yes Israel Yes Yes Italy No Yes Japan No Yes Kazakhstan Yes Yes Latvia Yes Yes Lithuania No Yes Luxembourg No Yes Malaysia No Yes Malta No Yes Mexico No Yes Netherlands No Yes New Zealand No Yes Norway No Yes Poland Yes Yes Portugal No Yes *Baker & McKenzie Survey March 2012

Encryption Requirements by Country* (2) Country Import Export Romania No Yes Russia Yes Yes Singapore No Yes Slovakia No Yes Slovenia No Yes South Africa Yes Yes South Korea Yes Yes Spain No Yes Switzerland No Yes Taiwan No Yes Thailand No No Turkey Yes Yes United Arab Emirates Yes Yes United Kingdom No Yes Ukraine Yes Yes United States No Yes Venezuela No No Vietnam No Yes *Baker & McKenzie survey March 2012 12

US Origin Content

EAR De Minimis Rule Basic Rule Foreign made items incorporating or bundled with certain US origin content are subject to US jurisdiction and may require licenses even without any US involvement Compare apples to apples ; oranges to oranges Bundled the US software is re-exported together with a foreign item and is " configured for" that item (even if not necessarily physically integrated into it); and the " bundled" US software content is either classified EAR99 or controlled for " AT" (antiterrorism) reasons only on the US Commerce Control List in the EAR treat only bundled portion of software as part of overall hardware

De Minimis Value Thresholds > 10%: Iran, North Korea, Sudan, Syria > 25%: Other countries (inc. Crimea and Cuba) 0%: 600 series/9x515 content and certain others ( see through carve-out) Special encryption de minimis rules Must meet value thresholds and be notified/classified under encryption rules in EAR Encryption carve-out foreign products produced/developed from US encryption items not previously subject to review under License Exception ENC subject to EAR

De Minimis Rule Controlled Content What is controlled content? Cuba, North Korea, Syria, Crimea: Anything (inc. EAR99) Iran/Sudan: non-ear99 items Others: Depends on ECCN and Reason for Control on CCL Decision Tool: https://www.bis.doc.gov/index.php/de-minimis-directproduct-rules-decision-tool

De Minimis Caution on bundling for Iran! EAR (BIS) General rule: no commingling of values as between hardware/software/technology ( apples to apples ) Exception - Bundling Rule: Certain controlled software can be counted against the value of foreign hardware ( apples to oranges ) if: bundled (configured for item) and EAR99 or AT controlled only Threshold: over 10% ITSR (OFAC) Must be below threshold on both non-commingled basis and bundled basis (cumulative): Must meet value tests for each of the following: 1) hardware-hardware 2) software-software 3) technology-technology 4) AND for complex products compare software to entire foreign item Threshold: 10% or more

www.bakermckenzie.com Baker & McKenzie Advokatbyrå KB is a member firm of Baker & McKenzie International, a Swiss Verein with member law firms around the world. In accordance with the common terminology used in professional service organisations, reference to a "partner" means a person who is a partner, or equivalent, in such a law firm. Similarly, reference to an "office" means an office of any such law firm. This may qualify as Attorney Advertising requiring notice in some jurisdictions. Prior results do not guarantee a similar outcome.