Sec. 6308. Cyber protection support for personnel of the Department of State in positions highly vulnerable to cyber attack
406 words·~2 min read·
/bill/118/s/2226/es/section-6308A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
In this section: The term at-risk personnel means personnel of the Department— whom the Secretary determines to be highly vulnerable to cyber attacks and hostile information collection activities because of their positions in the Department; and whose personal technology devices or personal accounts are highly vulnerable to cyber attacks and hostile information collection activities. The term personal accounts means accounts for online and telecommunications services, including telephone, residential internet access, email, text and multimedia messaging, cloud computing, social media, health care, and financial services, used by personnel of the Department outside of the scope of their employment with the Department.
The term personal technology devices means technology devices used by personnel of the Department outside of the scope of their employment with the Department, including networks to which such devices connect. The Secretary, in consultation with the Secretary of Homeland Security and the Director of National Intelligence, as appropriate— shall offer cyber protection support for the personal technology devices and personal accounts of at-risk personnel; and may provide the support described in paragraph
(1)to any Department personnel who request such support. Subject to the availability of resources, the cyber protection support provided to personnel pursuant to subsection
(b)may include training, advice, assistance, and other services relating to protection against cyber attacks and hostile information collection activities. The Department is prohibited pursuant to this section from accessing or retrieving any information from any personal technology device or personal account of Department employees unless— access or information retrieval is necessary for carrying out the cyber protection support specified in this section; and the Department has received explicit consent from the employee to access a personal technology device or personal account prior to each time such device or account is accessed. Nothing in this section may be construed— to encourage Department personnel to use personal technology devices for official business; or to authorize cyber protection support for senior Department personnel using personal devices, networks, and personal accounts in an official capacity. Not later than 180 days after the date of the enactment of this Act, the Secretary shall submit a report to the appropriate congressional committees regarding the provision of cyber protection support pursuant to subsection (b), which shall include— a description of the methodology used to make the determination under subsection (a)(1); and guidance for the use of cyber protection support and tracking of support requests for personnel receiving cyber protection support pursuant to subsection (b).