Federal · Title 22 — Foreign Relations and Intercourse
22 U.S.C. § 10308: Cyber protection support for personnel of the Department of State in positions highly vulnerable to cyber attack
Read the full statutory text
whom the Secretary determines to be highly vulnerable to cyber attacks and hostile information collection activities because of their positions in the Department; and whose personal technology devices or personal accounts are highly vulnerable to cyber attacks and hostile information collection activities. The term “personal accounts” means accounts for online and telecommunications services, including telephone, residential internet access, email, text and multimedia messaging, cloud computing, social media, health care, and financial services, used by Department personnel outside of the scope of their employment with the Department. The term “personal technology devices” means technology devices used by personnel of the Department outside of the scope of their employment with the Department, including networks to which such devices connect. shall offer cyber protection support for the personal technology devices and personal accounts of at-risk personnel; and may provide the support described in paragraph (1) to any Department personnel who request such support. Subject to the availability of resources, the cyber protection support provided to personnel pursuant to subsection (b) may include training, advice, assistance, and other services relating to protection against cyber attacks and hostile information collection activities. access or information retrieval is necessary for carrying out the cyber protection support specified in this section; and the Department has received explicit consent from the employee to access a personal technology device or personal account prior to each time such device or account is accessed. to encourage Department personnel to use personal technology devices for official business; or to authorize cyber protection support for senior Department personnel using personal devices, networks, and personal accounts in an official capacity. a description of the methodology used to make the determination under subsection (a)(1); and guidance for the use of cyber protection support and tracking of support requests for personnel receiving cyber protection support pursuant to subsection (b). the appropriate congressional committees; the Select Committee on Intelligence and the Committee on Homeland Security and Governmental Affairs of the Senate; and the Permanent Select Committee on Intelligence and the Committee on Oversight and Accountability of the House of Representatives. the Committee on Foreign Relations, the Select Committee on Intelligence, the Committee on Homeland Security and Governmental Affairs, and the Committee on Armed Services of the Senate; and the Committee on Foreign Affairs, the Permanent Select Committee on Intelligence, the Committee on Homeland Security, and the Committee on Armed Services of the House of Representatives. The term ‘covered device’ means any electronic mobile device, including smartphones, tablet computing devices, or laptop computing device, that is issued by the Department for official use. The terms ‘foreign commercial spyware’ and ‘spyware’ have the meanings given those terms in section 1102A of the National Security Act of 1947 ( 50 U.S.C. 3232a ). issue standards, guidance, best practices, and policies for Department [of State] and USAID [United States Agency for International Development] personnel to protect covered devices from being compromised by foreign commercial spyware; survey the processes used by the Department and USAID to identify and catalog instances where a covered device was compromised by foreign commercial spyware over the prior 2 years and it is reasonably expected to have resulted in an unauthorized disclosure of sensitive information; and submit to the appropriate committees of Congress a report on the measures in place to identify and catalog instances of such compromises for covered devices by foreign commercial spyware, which may be submitted in classified form. the location of the personnel whose covered device was compromised; the number of covered devices compromised; an assessment by the Secretary of the damage to the national security of the United States resulting from any loss of data or sensitive information; and an assessment by the Secretary of any foreign government or foreign organization or entity, and, to the extent possible, the foreign individuals, who directed and benefitted from any information acquired from the compromise. Not later than one year after the date of the enactment of this Act, and annually thereafter for 5 years, the Secretary, in coordination with relevant agencies, shall submit to the appropriate committees of Congress, the Committee on the Judiciary of the Senate, and the Committee on the Judiciary of the House of Representatives a report regarding any covered device that was compromised by foreign commercial spyware, including the information described in subparagraphs (A) through (D) of paragraph (2).”
Verify at the official source: Federal legislative text
Facing this? Know exactly what happens next.
MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.
This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.