(b) “Employee or officer” means a person who performs labor or services for a public employer in exchange for salary, wages, or other remuneration.
(c) “Foreign country of concern” means the People’s Republic of China, the Russian Federation, the Islamic Republic of Iran, the Democratic People’s Republic of Korea, the Republic of Cuba, the Venezuelan regime of Nicolás Maduro, or the Syrian Arab Republic, including any agency of or any other entity under significant control of such foreign country of concern.
(d) “Foreign principal” means:
2. A political party or a member of a political party or any subdivision of a political party in a foreign country of concern;
3. A partnership, an association, a corporation, an organization, or another combination of persons organized under the laws of or having its principal place of business in a foreign country of concern, or an affiliate or a subsidiary thereof; or
4. Any person who is domiciled in a foreign country of concern and is not a citizen or a lawful permanent resident of the United States.
(f) “Prohibited application” means an application that meets the following criteria:
b. Compromising e-mail and acting as a vector for ransomware deployment;
c. Conducting cyber-espionage against a public employer;
d. Conducting surveillance and tracking of individual users; or
e. Using algorithmic modifications to conduct disinformation or misinformation campaigns; or
2. Restrict access to any prohibited application on a government-issued device.
3. Retain the ability to remotely wipe and uninstall any prohibited application from a government-issued device that is believed to have been adversely impacted, either intentionally or unintentionally, by a prohibited application.
2. A public employer may request a waiver from the department to allow designated employees or officers to download or access a prohibited application on a government-issued device.
(b) Establish procedures for granting or denying requests for waivers pursuant to subparagraph (2)(b)2. The request for a waiver must include all of the following:
2. The maximum number of government-issued devices and employees or officers to which the waiver will apply.
3. The length of time necessary for the waiver. Any waiver granted pursuant to subparagraph (2)(b)2. must be limited to a timeframe of no more than 1 year, but the department may approve an extension.
4. Risk mitigation actions that will be taken to prevent access to sensitive data, including methods to ensure that the activity does not connect to a state system, network, or server.
5. A description of the circumstances under which the waiver applies.
(b) The department shall adopt rules necessary to administer this section.