U.S Code last checked for updates: Nov 22, 2024
§ 10308.
Cyber protection support for personnel of the Department of State in positions highly vulnerable to cyber attack
(a)
Definitions
In this section:
(1)
At-risk personnel
The term “at-risk personnel” means personnel of the Department—
(A)
whom the Secretary determines to be highly vulnerable to cyber attacks and hostile information collection activities because of their positions in the Department; and
(B)
whose personal technology devices or personal accounts are highly vulnerable to cyber attacks and hostile information collection activities.
(2)
Personal accounts
(3)
Personal technology devices
(b)
Requirement to provide cyber protection support
The Secretary, in consultation with the Secretary of Homeland Security and the Director of National Intelligence, as appropriate—
(1)
shall offer cyber protection support for the personal technology devices and personal accounts of at-risk personnel; and
(2)
may provide the support described in paragraph (1) to any Department personnel who request such support.
(c)
Nature of cyber protection support
(d)
Privacy protections for personal devices
The Department is prohibited pursuant to this section from accessing or retrieving any information from any personal technology device or personal account of Department employees unless—
(1)
access or information retrieval is necessary for carrying out the cyber protection support specified in this section; and
(2)
the Department has received explicit consent from the employee to access a personal technology device or personal account prior to each time such device or account is accessed.
(e)
Rule of construction
Nothing in this section may be construed—
(1)
to encourage Department personnel to use personal technology devices for official business; or
(2)
to authorize cyber protection support for senior Department personnel using personal devices, networks, and personal accounts in an official capacity.
(f)
Report
(1)
In general
Not later than 180 days after December 22, 2023, the Secretary shall submit to the appropriate committees of Congress a report regarding the provision of cyber protection support pursuant to subsection (b), which shall include—
(A)
a description of the methodology used to make the determination under subsection (a)(1); and
(B)
guidance for the use of cyber protection support and tracking of support requests for personnel receiving cyber protection support pursuant to subsection (b).
(2)
Appropriate committees of Congress defined
In this subsection, the term “appropriate committees of Congress” means—
(A)
the appropriate congressional committees;
(B)
the Select Committee on Intelligence and the Committee on Homeland Security and Governmental Affairs of the Senate; and
(C)
the Permanent Select Committee on Intelligence and the Committee on Oversight and Accountability of the House of Representatives.
(Pub. L. 118–31, div. F, title LXIII, § 6308, Dec. 22, 2023, 137 Stat. 993.)
cite as: 22 USC 10308