Dictionary domainTrack D
Research security
NSPM-33, foreign component, DURC, dual-use research.
For implementers
Operational deployment checklist for Research security: prerequisites, five deploy steps, integration notes for Pure, Symplectic Elements, Worktribe, DSpace, and more, plus the pitfalls that recur in the field.
Terms in this domain
54 terms
Commerce Control List (CCL)
The Commerce Control List (CCL) is the master list of 'dual-use' items -- goods, software, and technology with both civilian and military, terrorism, or weapons-of-mass-destruction-related applications -- that are subject to the Export Administration Regulations (EAR, 15 CFR Parts 730-774) and administered by the Department of Commerce's Bureau of Industry and Security (BIS). The CCL is organized into ten numbered categories (0-9) and, within each category, five lettered product groups (A-E); an item that matches a specific CCL entry is assigned an Export Control Classification Number (ECCN), while an item that is subject to the EAR but matches no CCL entry falls into the residual EAR99 classification.
Research Security
<p>Research security is the set of institutional and federal policies, disclosures, and safeguards designed to protect the U.S. federally funded research enterprise against foreign government interference, undisclosed foreign support, and the misappropriation of research and development. The controlling federal definition comes from <a href='/dictionary/term/nspm-33'>National Security Presidential Memorandum 33 (NSPM-33)</a> (issued January 2021) and its implementing guidance from the National Science and Technology Council (NSTC): research security means <em>"safeguarding the research enterprise against the misappropriation of research and development to the detriment of national or economic security, related violations of research integrity, and foreign government interference."</em></p><p>An activity, disclosure, or policy is an instance of research security -- as distinct from general information security, export control, or <a href='/dictionary/term/research-integrity'>research integrity</a> -- when it satisfies three conditions together: (1) it concerns federally funded or federally regulated research; (2) it addresses a risk tied to foreign government interference, undisclosed foreign talent recruitment, or misuse of research outputs for national/economic security ends; and (3) it maps to one of the concrete compliance mechanisms federal research agencies now require -- disclosure of foreign financial support and affiliations, foreign travel security, research security training, export control training, and cybersecurity controls for federally funded R&D. Under NSPM-33's implementation, research organizations that receive more than $50 million per year in federal research funding must certify they operate a research security program covering four elements: cybersecurity, foreign travel security, research security training, and export control training.</p>
DARPA Countering Foreign Influence Program (CFIP)
A DARPA-specific risk-review process, applied to proposed awards, in which senior/key personnel disclosures are screened against a qualitative risk rubric covering participation in foreign talent programs, affiliation with denied or restricted entities, funding or in-kind support from foreign government sources, and affiliation with designated high-risk foreign institutions, generally over the preceding four years, with results assigned a risk level from low to very high that informs (but does not automatically decide) award negotiation.
Export Control and AI (EAR/ITAR Applied to AI Models and Systems)
Export control and AI refers to how the US Export Administration Regulations (EAR, 15 CFR Parts 730-774, administered by the Commerce Department's Bureau of Industry and Security, or BIS) and the International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120-130, administered by the State Department) apply to artificial intelligence and machine learning software, trained models, model weights, training datasets, and the underlying computing hardware used in research. An AI-related item, dataset, or system is subject to export control analysis if it is US-origin, meets an EAR or ITAR jurisdictional trigger, and either physically leaves the United States, is transmitted electronically to a destination abroad, or is released ('deemed exported') to a foreign national inside the United States who is not a US citizen, lawful permanent resident, or protected individual.
Section 117 Foreign Gift and Contract Reporting
An institution triggers Section 117 of the Higher Education Act (20 U.S.C. § 1011f) reporting when it is a covered institution — offering a bachelor's degree or higher (or an at-least-two-year transfer program toward one), accredited by a nationally recognized accrediting agency, and receiving federal financial assistance — and it receives a gift from, or enters a contract with, a foreign source valued at $250,000 or more, either alone or cumulatively with all other gifts and contracts from that same foreign source, within a calendar year. Institutions owned or controlled by a foreign source must separately disclose that relationship, with no dollar threshold. Covered institutions report semiannually to the U.S. Department of Education (historically due January 31 and July 31, for the preceding six-month period); as of January 2026, filings go through ED's new foreignfundinghighered.gov reporting portal.
Research Security Officer (RSO)
The Research Security Officer (RSO) is the institutional official or office that coordinates a research institution's research security program under NSPM-33 and the CHIPS and Science Act of 2022 -- owning export control review, foreign-influence and foreign talent recruitment program disclosure, cybersecurity coordination for federally funded research, insider-threat and travel-security policy, training rollout, and certification to funding agencies that the required program is in place. "Research Security Officer" is not a title NSPM-33 itself mandates verbatim -- it is the role most covered institutions have created to hold that accountability.
DOE AI Policy
"DOE AI policy" most precisely refers to the U.S. Department of Energy's Generative Artificial Intelligence Policy (DOE P 2031, "Use of Generative Artificial Intelligence," issued December 29, 2025) -- a departmental directive governing how DOE's own federal workforce and National Laboratory staff may adopt, deploy, and use generative AI tools in their work. It sits inside DOE's broader 200-series management directives and was written to align with the October 2023 White House Executive Order on AI and the March 2024 OMB Memorandum M-24-10 on federal agency AI governance. It is an internal governance instrument, not an applicant-facing submission requirement: it does not create a DOE-wide rule that external grant applicants, proposers, or awardees must disclose generative AI use when submitting a funding opportunity announcement (FOA) response. Where DOE's policy does touch research practice directly is inside the agency: when generative AI contributes to an idea, approach, or invention developed at DOE or a National Laboratory, DOE staff are expected to identify that specific contribution and cite the GenAI tool as part of the research methodology, consistent with the department's broader research-integrity and record-keeping expectations. Research administrators should not assume this term is interchangeable with the applicant-facing generative AI disclosure notices published by other funders -- see NSF AI Policy and Nature Portfolio AI Policy for that different category of policy -- and should always check the specific DOE FOA's own instructions and applicable acquisition regulations for any submission-level AI-disclosure requirement, since DOE has not, as of this writing, published a separate proposer-facing AI-disclosure notice comparable to NSF's.
Biosafety in Microbiological and Biomedical Laboratories (BMBL)
Biosafety in Microbiological and Biomedical Laboratories (BMBL) is the primary US reference manual for laboratory biosafety practice, jointly produced by the CDC and the NIH and now in its 6th edition (2020). It defines the four Biosafety Level (BSL-1 through BSL-4) containment tiers, the risk-group classification system for infectious agents, and the standard and special microbiological practices, safety equipment, and facility design requirements associated with each tier. BMBL is an advisory best-practice document rather than a standalone binding federal regulation, but it carries practical regulatory force because it is incorporated by reference into binding frameworks, including the NIH Guidelines for Research Involving Recombinant or Synthetic Nucleic Acid Molecules and the Federal Select Agent Program.
Category A Bioterrorism Agents
Category A is the highest-priority tier of CDC's three-tier (A/B/C) bioterrorism-agent classification, used for public-health emergency-preparedness planning rather than as a compliance roster. An agent qualifies as Category A if it can be easily disseminated or transmitted person-to-person, causes high mortality with potential for major public-health impact, might cause public panic and social disruption, and requires special action for public health preparedness (e.g., stockpiling, enhanced surveillance, and public-communication planning). CDC groups six agents/diseases under Category A: anthrax (Bacillus anthracis), botulism (Clostridium botulinum toxin), plague (Yersinia pestis), smallpox (variola major), tularemia (Francisella tularensis), and viral hemorrhagic fevers caused by filoviruses (e.g., Ebola, Marburg) and arenaviruses (e.g., Lassa, Machupo). This is distinct from, though heavily overlapping with, the Federal Select Agent Program's regulated roster: Category A is a preparedness-prioritization label with no independent registration or compliance obligation attached to it directly, while the Select Agent List is the specific set of agents and toxins an entity must register to legally possess, use, or transfer.
USDA Research Security Training Requirement
The USDA Research Security Training Requirement is the U.S. Department of Agriculture's implementation of the government-wide research-security training mandate created by Section 10634 of the CHIPS and Science Act of 2022 (42 U.S.C. Section 19234) and directed by NSPM-33 — the same policy family behind the parallel DOE and NASA requirements. Multiple institutional sponsored-programs offices report that USDA introduced the requirement via Secretary's Memorandum SM 1078-014 (dated July 8, 2025) and folded it into USDA's General Terms and Conditions for financial assistance awards, effective December 31, 2025: named 'covered individuals' on a USDA-funded application or award must complete an approved research-security training course, with completion certified to USDA as part of the award's terms and conditions. CASRAI could not independently confirm this text against a primary usda.gov source at the time of writing (the USDA PDF did not load during verification); treat the SM 1078-014 number and December 31, 2025 effective date as reported-tier pending direct confirmation against USDA's own published memorandum and General Terms and Conditions before relying on them for a compliance deadline.
NASA Research Security Training (GIC 26-02)
NASA's research security training requirement, established under Grant Information Circular (GIC) 26-02 (issued February 2026), requires every 'covered individual' -- a Principal Investigator or Co-PI on a NASA grant or cooperative agreement at any level of effort, or a Co-Investigator committing 10% or more effort annually -- to certify completion of qualifying research security training. The requirement takes effect for proposals and annual progress reports due on or after August 5, 2026, and is evidenced through updated NASA Biographical Sketch and Current and Pending (Other) Support forms rather than a separate standalone certificate.
DOE Research Security Training Requirement
DOE's research security training requirement, announced via Policy Flash PF 2025-04 (Financial Assistance Letter FAL 2025-02) under Section 10634 of the CHIPS and Science Act of 2022 (42 U.S.C. Section 19234) and NSPM-33, requires that 'covered individuals' named on a DOE R&D financial-assistance application complete research security training -- addressing cybersecurity, international collaboration/travel, foreign interference, and rules on proper use of funds, disclosure, conflict of commitment, and conflict of interest -- within the 12 months prior to submitting that application. The applicant organization certifies completion for all listed covered individuals via Current and Pending Support disclosure certification; DOE does not require use of any specific pre-approved training course.
Section 889 (Covered Telecommunications Equipment Ban)
A federal restriction, originating in Section 889 of the FY2019 NDAA and implemented for grant recipients at 2 CFR 200.216 (effective August 13, 2020), that prohibits an institution from using federal award funds to procure, obtain, extend, or renew a contract for telecommunications or video surveillance equipment or services produced by Huawei, ZTE, Hytera, Hikvision, or Dahua (or their subsidiaries/affiliates, or other PRC-government-connected entities so designated), when that equipment or service is a substantial or essential component of a system or constitutes critical technology. It attaches to the federal funding stream used for a specific procurement, not to an institution's equipment inventory generally.
Biosafety and Biosecurity
Biosafety and biosecurity are the two complementary risk-management frameworks that together govern institutional work with biological materials capable of causing harm. Biosafety is the set of containment practices, equipment, and facility design (see Biosafety Level (BSL)) intended to prevent accidental exposure of personnel or unintended release of a biological agent into the environment. Biosecurity is the set of physical security, access control, personnel-reliability, and material-accountability measures intended to prevent deliberate misuse, theft, loss, or diversion of biological agents or toxins -- the concern is an intentional bad actor, not an accident. A given institutional program is a biosafety-and-biosecurity program only when it addresses both halves: containment/exposure-prevention controls administered through an Institutional Biosafety Committee (IBC) under the NIH Guidelines and the CDC/NIH Biosafety in Microbiological and Biomedical Laboratories (BMBL) manual, and security/accountability controls administered through the Federal Select Agent Program (jointly run by CDC and USDA-APHIS) for any select agent or toxin on the HHS/USDA Select Agent List, plus Dual-Use Research of Concern (DURC) review where applicable. A program that only locks containment (biosafety) without inventory control and personnel vetting for regulated agents is not biosecure; a program with strict access control but inadequate containment practice is not biosafe. The two are reviewed together but are not interchangeable and are not satisfied by the same control.
15 CFR Part 734 (EAR — Scope and Definitions)
15 CFR Part 734, titled “Scope of the Export Administration Regulations,” is the part of the Export Administration Regulations (EAR) -- the dual-use export control regime administered by the US Department of Commerce's Bureau of Industry and Security (BIS) -- that establishes what the EAR applies to at all and supplies the controlling definitions used throughout the rest of the regulation (15 CFR Parts 730-774). Part 734 does not itself list controlled items -- that is the Commerce Control List, Supplement No. 1 to 15 CFR Part 774 -- instead it defines what is 'subject to the EAR' (15 CFR 734.2-734.3), sets the de minimis US-content threshold for foreign-made items (734.4), and supplies the definitions of 'export' (734.13), 'reexport' (734.14), 'release' (734.15), and 'transfer (in-country)' (734.16), including the deemed-export and deemed-reexport concepts built into those definitions and into the dedicated carve-outs at 734.18 and 734.20. It also states the fundamental research exclusion (734.8): technology or software that arises during, or results from, fundamental research and is intended for publication falls outside the EAR's scope entirely, not merely under a license exception. Because these definitions determine whether the EAR applies to a given item, transaction, or disclosure at all, a research institution's export-control determination almost always starts with a Part 734 definition rather than with a Commerce Control List entry.
International Confidentiality Agreement
A confidentiality agreement (NDA) between parties in different countries, which requires provisions a purely domestic NDA does not: export-control screening of the disclosed information for deemed-export risk, a deliberately chosen governing-law/jurisdiction/dispute-resolution clause that will actually be enforceable across the relevant borders, and, when the confidential information includes personal data, transfer safeguards that satisfy the data-protection law of the disclosing party's jurisdiction (most commonly GDPR Chapter V).
22 CFR Part 120 (ITAR — Purpose and Definitions)
22 CFR Part 120 is the opening part of the International Traffic in Arms Regulations (ITAR), the body of US federal regulations administered by the Department of State's Directorate of Defense Trade Controls (DDTC) that controls the export and temporary import of defense articles and defense services on the US Munitions List (USML). Part 120 does not itself list controlled items -- that is Part 121 (the USML) -- instead it states ITAR's statutory basis and purpose (Subpart A) and, in Subpart C (22 CFR 120.30-120.69), supplies the controlling definitions used throughout the rest of ITAR (22 CFR Parts 121-130), including 'defense article,' 'defense service,' 'technical data,' 'export,' 'US person,' and 'foreign person.' Because these definitions govern how every other ITAR part is read, a research institution's export-control determination for a given item, collaboration, or foreign national almost always traces back to a Part 120 definition rather than to a substantive control provision elsewhere in ITAR.
Dual-Use Research of Concern (DURC)
Research is DURC only when it meets a two-part US Government test: it involves one of 15 enumerated select agents/toxins, AND it is reasonably anticipated to produce an outcome in one of seven defined categories of experimental concern (e.g., enhancing transmissibility/virulence, conferring resistance to countermeasures). DURC review by an institution's Institutional Review Entity/IBC is complementary to, not a substitute for, routine biosafety containment review.
NIST SP 800-171
<p><strong>NIST SP 800-171</strong> ("Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations") is a U.S. National Institute of Standards and Technology special publication that specifies the security requirements a <strong>nonfederal</strong> organization — including a university, hospital, or independent research institute — must implement to protect <a href='/dictionary/term/controlled-unclassified-information-cui'>Controlled Unclassified Information (CUI)</a> when that information resides in, or flows through, the organization's own IT systems rather than a federal government system. A document, dataset, or research record is 'in scope' for 800-171 when it (a) meets the definition of CUI under the NARA CUI Registry categories — commonly Export Controlled, Controlled Technical Information, or Privacy — and (b) is created, received, stored, or transmitted by a nonfederal entity under a federal contract, grant, or agreement that designates it as CUI. The most widely deployed version, Revision 2, organizes <strong>110 security requirements</strong> into <strong>14 requirement families</strong>: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each family groups related controls (e.g., multi-factor authentication and least-privilege access sit under Access Control) rather than prescribing a single monolithic checklist.</p>
Secure Data Enclave
A controlled-access computing environment in which approved researchers analyze restricted or sensitive data in place, without the ability to download, copy, or otherwise export the raw underlying records. Access is typically granted only after training, credentialing, and a signed data use agreement, computation happens on infrastructure the data steward controls (an on-site terminal room, a remote-access session, or an isolated cloud workspace), and only aggregate or disclosure-reviewed outputs — tables, statistics, model results — are allowed to leave the environment. The defining feature is not where the data sits but that raw data never crosses the boundary; only vetted outputs do.
ECCN Determination Process
The process by which a specific item, technology, or piece of software is assigned an Export Control Classification Number (ECCN) under the US Export Administration Regulations (EAR, 15 CFR 730-774), determining whether and how it is controlled for export under the Commerce Control List (CCL) administered by the Department of Commerce's Bureau of Industry and Security (BIS). An item is either classified against a specific ECCN entry on the CCL, or, if it is subject to the EAR but matches no CCL entry, falls into the residual 'EAR99' catch-all category. Determination can be done in-house by self-classification against the CCL, or by requesting a formal, binding Commodity Classification from BIS (a Commodity Classification Automated Tracking System, or CCATS, determination). In a university research setting, the outcome of this determination is a prerequisite input to fundamental research exclusion analysis: the exclusion (rooted in NSDD-189, 1985) can remove a project's published *results* from EAR/ITAR control, but it does not retroactively declassify a controlled *item, software, or technical data set* used to get there -- so export control offices classify the underlying technology first, independent of whether the surrounding research is intended for open publication.
NNN Agreement (Non-Disclosure, Non-Use, Non-Circumvention Agreement)
A hybrid contract -- combining non-disclosure, non-use, and non-circumvention clauses -- used when a research institution or inventor discloses confidential technical information to a prospective foreign manufacturing or licensing partner, most commonly a China-based manufacturer, where a standalone confidentiality (NDA) clause is often difficult to enforce or insufficient in scope.
NIH Research Security Training (RST)
NIH's Research Security Training (RST) requirement, established under NIH Guide Notice NOT-OD-26-017, requires every 'covered individual' -- meaning every senior/key person listed on an NIH grant application -- to complete research security training within the 12 months before the application's due date. Compliance is evidenced through a dual certification: an institutional certification by the Authorized Organizational Representative (AOR) on the SF424 R&R face page, and an individual certification captured through the person's NIH Biographical Sketch in SciENcv. It applies to applications with due dates on or after May 25, 2026.
Select Agent List
The Select Agent List is the HHS/USDA-maintained roster (42 CFR Part 73, 7 CFR Part 331, 9 CFR Part 121) of specific biological agents and toxins determined to pose a severe threat to human, animal, or plant health. Any entity possessing, using, or transferring a listed agent above regulatory exclusion thresholds must register with the Federal Select Agent Program (jointly run by CDC and USDA/APHIS), designate a Responsible Official, and ensure every individual with access clears an FBI Security Risk Assessment; a smaller Tier 1 subset carries additional security and suitability-monitoring requirements.
Software export controls
The application of US export control regulations, principally the Export Administration Regulations (EAR, 15 CFR 730-774), to software source code, object code, and related technical data, addressing three issues distinct from general item/equipment export control: (1) whether the software qualifies as 'published' and therefore outside EAR jurisdiction under 15 CFR 734.7 (or fundamental-research-excluded under 734.8), based on whether it was released without restriction on further dissemination; (2) whether the software has cryptographic functionality subject to the separate Category 5 Part 2 encryption controls (ECCNs 5A002/5D002/5E002) and associated License Exception ENC or self-classification requirements; and (3) whether granting a foreign national visual, electronic, or repository access to controlled, non-published source code constitutes a deemed export under 15 CFR 734.13, independent of whether any file is physically transmitted abroad.
Consolidated Screening List (CSL)
A single, merged database published by the US Department of Commerce (trade.gov) that consolidates the restricted- and denied-party lists maintained separately by the Departments of Commerce (BIS: Denied Persons List, Entity List, Unverified List, Military End-User List), State (AECA Debarred List, Nonproliferation Sanctions list), and Treasury (OFAC's Specially Designated Nationals List and related sanctions lists). Institutions screen a party's name against the CSL once to check for a match on any contributing list, then trace a hit back to the underlying regulation (EAR, ITAR, or an OFAC sanctions program) it falls under. Source lists are updated daily.
OFAC List (SDN List)
The "OFAC list" ordinarily refers to the Specially Designated Nationals and Blocked Persons List (SDN List) maintained by the US Department of the Treasury's Office of Foreign Assets Control (OFAC). OFAC administers and enforces economic and trade sanctions based on US foreign policy and national security goals, targeting foreign countries, regimes, terrorists, international narcotics traffickers, weapons-of-mass-destruction proliferators, and other threats. The SDN List names individuals, companies, research institutions, non-profits, vessels, and aircraft with which US persons -- including US universities and their employees -- are generally prohibited from dealing at all: their property and interests in property that come within US jurisdiction are "blocked" (frozen), and virtually all transactions between them and a US person are prohibited absent a specific OFAC license or applicable general license. OFAC also maintains a broader Consolidated Sanctions List (which folds in several narrower sectoral and program-specific lists) and country-based comprehensive sanctions programs (for example, on Cuba, Iran, North Korea, Syria, and the Russia-related programs); an entity or person can be sanctioned by inclusion in one of those programs without appearing on the SDN List specifically. For research institutions, "checking the OFAC list" is shorthand for restricted-party screening: running a prospective international collaborator, visiting scholar, subrecipient, vendor, or payment counterparty through OFAC's Sanctions List Search tool (which uses fuzzy-name matching) before entering into the relationship or releasing funds or controlled items.
CFIUS (Committee on Foreign Investment in US)
CFIUS (the Committee on Foreign Investment in the United States) is the US federal interagency committee, chaired by the Secretary of the Treasury and acting under Section 721 of the Defense Production Act of 1950 (as amended by FIRRMA in 2018) and its implementing regulations at 31 CFR Part 800, that reviews “covered transactions” — foreign acquisitions of control of a US business, and, since FIRRMA, certain non-controlling foreign investments granting governance or information rights in a critical-technology, critical-infrastructure, or sensitive-personal-data US business (a “TID US business”) — for national security risk.
NSF Biosketch (SciENcv)
The Biographical Sketch that a proposer submits for NSF senior/key personnel counts as an NSF Biosketch (SciENcv) only when it is generated inside SciENcv using NSF's Biographical Sketch module and follows the NSPM-33 Common Form structure (Identifying Information, Organization and Location, Professional Preparation, Appointments and Positions, Products, Certification) -- a hand-typed PDF built outside SciENcv is no longer an accepted substitute for proposals subject to the current PAPPG.
Data Breach Response Plan
A data breach response plan for research data is a documented, pre-established procedure -- distinct from a generic enterprise IT incident response plan -- specifying how an institution or research team will detect, contain, assess the impact of, and report a security incident involving research data, with particular attention to data subject to a specific regulatory, contractual, or funder obligation: HIPAA-covered protected health information (PHI), data obtained under a signed Data Use Agreement or a controlled-access repository's data use certification (e.g., NIH's dbGaP), export-controlled technical data (EAR/ITAR), or identifiable human-subjects data subject to IRB oversight. What distinguishes it from a general IT incident response plan is not the detection/containment mechanics -- those follow the same ISO/IEC 27001 Annex A.5.24-A.5.28 discipline any organization uses -- but an explicit notification-routing step naming, for each data type, which additional party (an IRB, a funding agency, a repository's Data Access Committee, an export control office) must be notified, and on what timeline, on top of whatever an institution's central IT security office already does for any security incident.
Technology Control Plan (TCP)
An institutional document, developed and implemented by a research institution (typically coordinated by the export control office or research security office together with the Principal Investigator), that specifies the physical, IT, and administrative safeguards used to prevent unauthorized access to a specific set of ITAR- or EAR-controlled technology, technical data, software, or equipment. A TCP is required whenever controlled technology is present in a project or lab and no exclusion (fundamental research exclusion) or license exception/exemption fully removes the access restriction — most commonly because a foreign national who is not a US person, per 22 CFR 120.62 and 15 CFR 772.1, will otherwise have physical, visual, electronic, or oral access to the controlled item or data. Its defining feature is that it names the specific controlled technology, identifies by name and citizenship every individual authorized to access it, and sets out concrete, auditable controls — not general policy language — covering access restriction, physical and IT security, personnel screening, and training.
ITAR and EAR
The two primary US federal regimes restricting the export of controlled items, software, technology, and technical data to foreign persons or destinations. The International Traffic in Arms Regulations (ITAR, 22 CFR 120-130) are administered by the State Department's Directorate of Defense Trade Controls (DDTC) and cover defense articles, services, and technical data on the US Munitions List (USML). The Export Administration Regulations (EAR, 15 CFR 730-774) are administered by the Commerce Department's Bureau of Industry and Security (BIS) and cover dual-use items (civil plus military/WMD-related applications) on the Commerce Control List (CCL), classified by an Export Control Classification Number (ECCN). A given controlled item or technical data set falls under one regime or the other, determined by its classification, not by the institution's general research posture.
Open vs closed research
The distinction between research conducted with the intent to disseminate findings broadly through publication and other open channels, and research subject to restrictions on dissemination, foreign-national access, or publication imposed by sponsor, classification, or contractual terms.
Five Eyes alliance (research context)
The intelligence-sharing partnership between Australia, Canada, New Zealand, the United Kingdom, and the United States, increasingly invoked as a coordinating channel for aligned research security policies among the five countries.
JASON Report on research security
A 2019 report by the JASON advisory group, commissioned by the US National Science Foundation, analysing risks to fundamental research from foreign government influence and recommending a transparency-and-disclosure-based response rather than restrictive measures.
CHIPS and Science Act
A 2022 United States federal statute that authorises substantial public investment in semiconductor manufacturing and scientific research, and incorporates significant research security provisions affecting federally-funded researchers and institutions.
Trusted research framework (UK)
The United Kingdom guidance and supporting tools developed by the Centre for the Protection of National Infrastructure (now NPSA) in collaboration with UKRI and university bodies, providing practical advice to researchers and institutions on managing risks of international research collaboration.
Joint appointment (foreign)
A formal appointment in which a researcher holds simultaneous positions at their primary institution and a foreign institution, each with defined roles, time commitments, and supervisory relationships.
Visiting scholar agreement
A written agreement between a host institution and a visiting researcher (and frequently their home institution) defining the terms, duration, access, intellectual property, and compliance expectations of the visit.
Deemed export
The release of controlled US technology or source code to a foreign national, even within the United States, that is treated under export control regulations as an export to the foreign national's country of nationality.
Fundamental research exemption
A provision in US export control regulations exempting basic and applied research, conducted at accredited institutions of higher education, the results of which are ordinarily published and shared broadly within the scientific community, from many export licensing requirements. Rooted in NSDD-189, it is lost when publication, foreign-national access, or dissemination is contractually restricted.
Export-controlled research
Research subject to government regulations restricting the transfer of certain items, software, technologies, or technical data to foreign persons, foreign destinations, or end uses, regardless of whether transfer occurs domestically or internationally.
Controlled unclassified information (CUI)
United States government information that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy, but is not classified under Executive Order 13526 or the Atomic Energy Act.
Sensitive technology
A technology area designated by national authorities as having potential national security, economic security, or strategic significance, warranting heightened due diligence and protective measures in research and innovation activities.
Undue foreign influence
The exertion of pressure, control, or hidden incentives by a foreign government or its proxies that distorts research conduct, integrity, or outputs to advance the interests of that foreign state at the expense of the funding country, host institution, or scientific community.
Foreign talent recruitment programme
A formal or informal arrangement sponsored, organised, or supported by a foreign state, instrumentality, or affiliated entity to recruit researchers based abroad, typically offering compensation, resources, or other benefits in exchange for affiliations, research outputs, or services.
In-kind contribution disclosure
The disclosure of non-monetary support provided in support of research, including access to laboratories, equipment, materials, personnel, data, or computational resources, regardless of whether a financial transaction occurs.
Pending grants disclosure
The disclosure of all research proposals submitted but not yet awarded or declined at the time of application, including those under review and those awaiting submission decision.
Active grants disclosure
The disclosure of all research grants currently providing financial or in-kind support to an investigator at the time of application or progress report.
Other support (NIH format)
The NIH-specific disclosure document listing all resources made available to a researcher in support of their research endeavours, including financial support and in-kind contributions, regardless of relevance to the NIH-funded project.
Current and pending support
A standardised disclosure of all current, pending, and in-kind sources of research support available to an investigator, regardless of monetary value, funding source, or relationship to the proposed work.
Foreign component disclosure
The disclosure of any significant scientific element or segment of a federally-funded research project performed outside the awardee country, including collaborators, resources, or activities conducted abroad.
Research security policy
An institutional or governmental policy framework that establishes safeguards, disclosures, and review processes intended to protect research integrity, intellectual property, sensitive data, and national interests from undue foreign influence or unauthorised transfer.
NSPM-33
United States National Security Presidential Memorandum 33, issued January 2021, directing federal research agencies to standardise disclosure requirements for researchers receiving federal funding and to strengthen protections against foreign government interference in the US research enterprise.







