Federal · Title 22 — Foreign Relations and Intercourse
22 U.S.C. § 10301: United States international cyberspace policy
Read the full statutory text
promotes democracy, the rule of law, and human rights, including freedom of expression; supports the ability to innovate, communicate, and promote economic prosperity; and is designed to protect privacy and guard against deception, malign influence, incitement to violence, harassment and abuse, fraud, and theft; to encourage and aid United States allies and partners in improving their own technological capabilities and resiliency to pursue, defend, and protect shared interests and values, free from coercion and external pressure; and to provide incentives to the private sector to accelerate the development of the technologies referred to in such paragraphs; to modernize and harmonize with allies and partners export controls and investment screening regimes and associated policies and regulations; and to enhance United States leadership in technical standards-setting bodies and avenues for developing norms regarding the use of digital tools. to clarify the applicability of international laws and norms to the use of information and communications technology (referred to in this subsection as “ICT”); to reduce and limit the risk of escalation and retaliation in cyberspace, damage to critical infrastructure, and other malicious cyber activity that impairs the use and operation of critical infrastructure that provides services to the public; to cooperate with like-minded countries that share common values and cyberspace policies with the United States, including respect for human rights, democracy, and the rule of law, to advance such values and policies internationally; to encourage the responsible development of new, innovative technologies and ICT products that strengthen a secure internet architecture that is accessible to all; not to conduct, or knowingly support, cyber-enabled theft of intellectual property, including trade secrets or other confidential business information, with the intent of providing competitive advantages to companies or commercial sectors; to take all appropriate and reasonable efforts to keep their territories clear of intentionally wrongful acts using ICT in violation of international commitments; not to conduct or knowingly support ICT activity that intentionally damages or otherwise impairs the use and operation of critical infrastructure providing services to the public, in violation of international law; to take appropriate measures to protect the country’s critical infrastructure from ICT threats; not to conduct or knowingly support malicious international activity that harms the information systems of authorized international emergency response teams (also known as “computer emergency response teams” or “cybersecurity incident response teams”) of another country or authorize emergency response teams to engage in malicious international activity, in violation of international law; to respond to appropriate requests for assistance to mitigate malicious ICT activity emanating from their territory and aimed at the critical infrastructure of another country; not to restrict cross-border data flows or require local storage or processing of data; and to protect the exercise of human rights and fundamental freedoms on the internet, while recognizing that the human rights that people have offline also need to be protected online; and to advance, encourage, and support the development and adoption of internationally recognized technical standards and best practices. Not later than 180 days after the date of the enactment of this Act [ Dec. 18, 2025 ], the Department [of State] shall issue internal guidelines that authorize and track the use of enclaves deployed in overseas commercial cloud regions for OCONUS systems categorized at the Federal Information Security Modernization Act [of 2014, Pub. L. 113–283 , see Tables for classification] (FISMA) high baseline. The enclave deployments shall be consistent with existing Federal cybersecurity regulations as well as best practices established across National Institute of Standards and Technology standards and ISO 27000 security controls. relevant risk assessments; and any security challenges regarding implementation. the Committee on Foreign Affairs and the Permanent Select Committee on Intelligence of the House of Representatives; and the Committee on Foreign Relations and the Select Committee on Intelligence of the Senate.” the Committee on Foreign Affairs and the Committee on Appropriations of the House of Representatives; and the Committee on Foreign Relations and the Committee on Appropriations of the Senate. artificial intelligence and machine learning systems; cybersecurity modernization tools or platforms; cloud computing services and infrastructure; enterprise data platforms and analytics tools; customer experience platforms for public-facing services; and internal workflow automation or modernization systems. The term ‘technology transformation project’ means any new or significantly modified technology deployed by the Department [of State] with the purpose of improving diplomatic, consular, administrative, or security operations. The term ‘technology transformation project’ does not include a routine software update or version upgrade, a security patch or maintenance of an existing system, a minor configuration change, a business-as-usual information technology operation, a support activity, or a project that costs less than $1,000,000. Not later than 180 days after the date of the enactment of this Act [ Dec. 18, 2025 ], and annually thereafter for five years, the Secretary [of State] shall submit to the appropriate congressional committees a report on all technology transformation projects completed during the preceding two fiscal years. A summary of the objective, scope, and operational context of the project. An identification of the primary technologies and vendors used, including artificial intelligence models, cloud providers, cybersecurity platforms, and major software components. operational efficiency, such as reductions in processing time, staff hours, or error rates; user impact, such as improvements in end-user satisfaction scores and reliability; security posture, such as enhancements in threat detection, incident response time; cost performance, including budgeted costs versus actual costs and projected cost savings or cost avoidance; interoperability and integration, including level of integration achieved with existing systems of the Department; artificial intelligence, if applicable; and an estimate of the percentage of eligible end-users actively using the system within the first three, six, and 12 months of deployment; the proportion of staff trained to use the system; the frequency and duration of use, disaggregated by bureau or geographic region if relevant; summarized user feedback, including pain points and satisfaction ratings; and a description of the status of deprecation or reduction in use of legacy systems, if applicable. A description of key challenges encountered during implementation and any mitigation strategies employed. A summary of contracting or acquisition strategies used, including information on how the vendor or development team supported change management and adoption, including user testing, stakeholder engagement, and phased rollout. A remediation plan with specific steps to improve adoption, including retraining, user experience improvements, or outreach. An assessment of whether rollout should be paused or modified. Any plans for iterative development based on feedback from employees. Not later than 60 days after submitting a report required by paragraph (1) to the appropriate congressional committees, the Secretary shall publish an unclassified summary of the report on the publicly accessible website of the Department, consistent with national security interests. the extent to which the Department has implemented and reported on technology transformation projects in accordance with the requirements under this section; the effectiveness and reliability of the Department’s performance and adoption metrics for such projects; whether such projects have met intended goals related to operational efficiency, security, cost-effectiveness, user adoption, and modernization of legacy systems; and the adequacy of oversight mechanisms in place to ensure the responsible deployment of artificial intelligence and other emerging technologies; and including any recommendations to improve the Department’s management, implementation, or evaluation of technology transformation efforts.” to oppose the misuse of commercial spyware to target individuals, including journalists, defenders of internationally recognized human rights, and members of civil society groups, members of ethnic or religious minority groups, and others for exercising their internationally recognized human rights and fundamental freedoms, or the family members of these targeted individuals; to coordinate with allies and partners to prevent the export of commercial spyware tools to end-users likely to use them for malicious activities; to maintain robust information-sharing with trusted allies and partners on commercial spyware proliferation and misuse, including to better identify and track these tools; to work with private industry to identify and counter the abuse and misuse of commercial spyware technology; and to work with allies and partners to establish robust guardrails to ensure that the use of commercial spyware tools are consistent with respect for internationally recognized human rights, and the rule of law.”
Verify at the official source: Federal legislative text
Facing this? Know exactly what happens next.
MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.
This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.