FEDERAL · 22 U.S.C. · Chapter 110

Cyber protection support for personnel of the Department of State in positions highly vulnerable to cyber attack

22 U.S.C. § 10308
Title22Foreign Relations and Intercourse
Chapter110 — INFORMATION SECURITY AND CYBER DIPLOMACY

This text of 22 U.S.C. § 10308 (Cyber protection support for personnel of the Department of State in positions highly vulnerable to cyber attack) is published on Counsel Stack Legal Research, covering United States primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
22 U.S.C. § 10308.

Text

(a)Definitions In this section: The term "at-risk personnel" means personnel of the Department—
(A)whom the Secretary determines to be highly vulnerable to cyber attacks and hostile information collection activities because of their positions in the Department; and
(B)whose personal technology devices or personal accounts are highly vulnerable to cyber attacks and hostile information collection activities. The term "personal accounts" means accounts for online and telecommunications services, including telephone, residential internet access, email, text and multimedia messaging, cloud computing, social media, health care, and financial services, used by Department personnel outside of the scope of their employment with the Department. The term "personal technology devices" means technol

Free access — add to your briefcase to read the full text and ask questions with AI

Source Credit

History

(Pub. L. 118–31, div. F, title LXIII, §6308, Dec. 22, 2023, 137 Stat. 993.)

Editorial Notes

Statutory Notes and Related Subsidiaries

Measures To Protect Department Devices From the Proliferation and Use of Foreign Commercial Spyware
Pub. L. 118–159, div. G, title LXXIII, §7302, Dec. 23, 2024, 138 Stat. 2541, provided that:
"(a) Definitions.—In this section:
"(1) Appropriate committees of congress.—The term 'appropriate committees of Congress' means—
"(A) the Committee on Foreign Relations, the Select Committee on Intelligence, the Committee on Homeland Security and Governmental Affairs, and the Committee on Armed Services of the Senate; and
"(B) the Committee on Foreign Affairs, the Permanent Select Committee on Intelligence, the Committee on Homeland Security, and the Committee on Armed Services of the House of Representatives.
"(2) Covered device.—The term 'covered device' means any electronic mobile device, including smartphones, tablet computing devices, or laptop computing device, that is issued by the Department for official use.
"(3) Foreign commercial spyware; spyware.—The terms 'foreign commercial spyware' and 'spyware' have the meanings given those terms in section 1102A of the National Security Act of 1947 (50 U.S.C. 3232a).
"(b) Protection of Covered Devices.—
"(1) Requirement.—Not later than 120 days after the date of the enactment of this Act [Dec. 23, 2024], the Secretary [of State] shall, in consultation with the relevant agencies—
"(A) issue standards, guidance, best practices, and policies for Department [of State] and USAID [United States Agency for International Development] personnel to protect covered devices from being compromised by foreign commercial spyware;
"(B) survey the processes used by the Department and USAID to identify and catalog instances where a covered device was compromised by foreign commercial spyware over the prior 2 years and it is reasonably expected to have resulted in an unauthorized disclosure of sensitive information; and
"(C) submit to the appropriate committees of Congress a report on the measures in place to identify and catalog instances of such compromises for covered devices by foreign commercial spyware, which may be submitted in classified form.
"(2) Notifications.—Not later than 60 days after the date on which the Department becomes aware that a covered device was seriously compromised by foreign commercial spyware, the Secretary, in coordination with relevant agencies, shall notify the appropriate committees of Congress of the facts concerning such targeting or compromise, including—
"(A) the location of the personnel whose covered device was compromised;
"(B) the number of covered devices compromised;
"(C) an assessment by the Secretary of the damage to the national security of the United States resulting from any loss of data or sensitive information; and
"(D) an assessment by the Secretary of any foreign government or foreign organization or entity, and, to the extent possible, the foreign individuals, who directed and benefitted from any information acquired from the compromise.
"(3) Annual report.—Not later than one year after the date of the enactment of this Act, and annually thereafter for 5 years, the Secretary, in coordination with relevant agencies, shall submit to the appropriate committees of Congress, the Committee on the Judiciary of the Senate, and the Committee on the Judiciary of the House of Representatives a report regarding any covered device that was compromised by foreign commercial spyware, including the information described in subparagraphs (A) through (D) of paragraph (2)."

Definitions
For definitions of "Department", "Secretary", and "appropriate congressional committees" as used in this section, see section 6002 of Pub. L. 118–31, set out as a note under section 2651 of this title.

Cite This Page — Counsel Stack

Bluebook (online)
22 U.S.C. § 10308, Counsel Stack Legal Research, https://law.counselstack.com/usc/22/10308.