Russia ramps up COVID-19 disinformation, the C-C-P-A spring clean, and a CISO muses on transitioning to a remote workforce. These stories and more, and this week's ISMG Security Report. Hello, I'm Nick Honda. The coronavirus pandemic can almost universally be described as a life-changing event for pretty much everyone.
We're a collectively in a state of voluntary or involuntary lockdown to various degrees, discovering that so many of the things we took for granted are now significantly curtailed. However, the world of nation-state attacks and disinformation stops for no one, or no thing, not even pandemics. And the episode of this particular outbreak is a familiar one, Russia. This week, I have some executive editor, Detective Richard Daine Europe, Matthew Schwartz, explores the spate of recent COVID-19 fiction emanating from the Kremlin.
Here's his report. As the COVID-19 pandemic continues, public health officials are also having to battle another challenge, disinformation. The EU's anti-disinformation unit says that since January, it's logged more than 110 cases involving misinformation about the disease. Many of these messages, it says, appear to follow the Kremlin's well-homed practice of using disinformation to amplify divisions, so distrust in chaos, and exacerbate crisis situations and issues of public concern.
So, says the EU's European External Action Service in a new report. Peter Stano is the European Commission's chief spokesman on foreign and security policy. When we are speaking about this informational means or false information circulating about coronavirus or COVID-19, we are always stressing that the source is either in Russia or can be tracked down to an outlet which is obviously and has been exposed in the past as programming. Kremlin-aligned messaging focuses most on promulgating a lie that the virus that causes COVID-19 was man-made, the EU says.
For a Russian domestic audience, such messaging describes the virus as a form of foreign aggression, but messaging aimed at international audiences focuses primarily on conspiracy theories about global elites, deliberately weaponizing or exploiting the virus for their own ends. Such information, the EU says, is getting disseminated in multiple languages, including Arabic, English, French, Italian, and Spanish, as well as via multiple channels. Oftentimes, via Russia's state-sponsored television and online network RT, formerly known as Russia, today. Multiple disinformation campaigns, likely tied to Moscow, are being targeted at various governments.
In Europe, one campaign, targeting Lithuania, against false claims that the US soldiers with COVID-19 had been taken to one of the country's hospitals. In Slovakia, officials said there were false reports that the country's prime minister had contracted the virus at a February summit in Brussels, and one Washington think tank says it's extremely likely that Kremlin also started rumors in Ukraine last month concerning evacuees being transported back to the country from the Wuhan region of China where the outbreak began, saying these evacuees were suffering from COVID-19. The rumors triggered protests last month in five Ukrainian towns, and led to the resignation of Ukrainian governor. Beyond Moscow, however, multiple governments appeared to be attempting to turn the chaos caused by COVID-19 to their advantage.
For example, Chinese language, pro-Beijing propaganda, has been lauding the Chinese president's handling of the crisis, and presenting the Chinese Communist Party's response to the pandemic as being strong and successful. The campaign also claims that the virus didn't originate in China but rather abroad, most likely in the United States. In Iran, a pro-teron disinformation campaign also claims that the US created the virus as a biological weapon, given the prevalence of disinformation around COVID-19, and the very real public health risk that this poses. The EU's stand-o has urged all governments and individuals to take no claims about the disease or who might be spreading it at face value.
What is very important is also to inform the public and to be aware about this, because whoever, I mean, it's not only coming from Russia, this is not the only source of disinformation, but whoever is spreading that this information is essentially playing with people's lives. And every responsible social media or media user should be aware of this, that there is a lot of misinformation circulating around and double-check, triple-check, go to a media you really trust and look at the sources. For information security media group, I'm Nati Schwartz. You're listening to the ISMG Security Report on ISMG Radio, ISMG, your number one source for information security news.
Remember, CCPA? Amidst the COVID-19 pandemic, California's Attorney General at March 11th raised the second modification of the proposed regulations to implement the California Consumer Protection Act, or CCPA. Subscurity information, governance and privacy attorney treatment, Sanders, Saudi Amuzah, explains what's included in this spring cleaning. We refer to it as a spring cleaning, because there's been a few versions of the draft regulations that have been released prior to the March 11th version, which is the article I referring to.
There was a version released early in February, I think around the 10th. The March 11th version, it really was just more of a light dusting to regulations. There wasn't many substantive changes. There are a couple of good things, but I think for the most part, now I think not why most people are probably looking for at this point, given how close the enforcement deadline is.
A couple of things that we noticed in this version of the draft regulations, and you know some good things, Adrian really did clean up the Notice That Collection requirement, so I'm not sure how familiar you are with it, but the CCPA does require businesses to give a Notice That Collection, right? We under certain circumstances, the types of personal information, businesses are collecting, and how it's being used for the purposes of the collection, and that notice is supposed to be given before or at the time of collection. And so if you follow the history of like the CCPA and the draft regulation, there's always this issue of our businesses who don't have a direct relationship with consumers. The question cannot well, if we don't have a direct relationship, how are we supposed to give that notice?
It took a couple of times to get this right, at various stages, at first the agent came out and the draft drives and said, okay, if you don't have a direct relationship, you don't need to provide the notice, but if you sell it, then you need to give some type of notice. While I'm sorry, sure, we got to a point in this version of the draft regulations, I've said, look, you don't have a direct relationship with your consumers that you're collecting PI from, and you're also not selling the information, then you don't need to give the notice. There's another carve out specific to data brokers, which is defined in the law where they would also be sent from the notice on a collection requirement. That was a good change we saw.
We also cleaned up some other areas, so for example the Notice That collection you have to give to employees. Before the CCK, I used to say, you need to include, in the notice, there needs to be a link to a privacy policy. I just left a bunch of people wondering, well, what, are we linking it back to our consumer privacy policy? The AG came out in the middle and said, okay, no, link it to your employee privacy policy.
Many businesses don't have a specific link for an employee privacy policy, so that didn't make sense. And so eventually they just came out in this version, said, okay, forget the link, you don't need a privacy policy, I know that that's a collection. What else? There was, they removed the very infamous off-down button.
In this one, it made me laugh at my seat in the draft regulation, because they had, so what the CCK says right now is, you need to include a link on your website, you're selling information, that says, do not sell my personal information, and that's what's the link to a Notice of Right Top now. Then the draft regulation say, hey, everyone, here's an optional button to put next to your Notice of Right Top now. I was like, why would any business want to put this optional button? Anyway, they got struck, so that was not a good thing we saw.
In terms of, you know, we always feel like that, saying, then we said, look, you missed some spots, because notably absent from almost every version of the draft regulation has been any clarification around why is it fail? And I'm sure, you know, that's been one of the biggest issues under the CCK. In a time directly to when you have to give consumers a right to offer, they have been notably silent on providing any clarification around this, so I think a lot of organizations have gone, you know, they weren't thrilled by fact that they're not getting any clarification, but I really believe that that's what people are most struggling with at this point. For many of us, this is week two of working remotely, we're just into a new normal, we're sharing an office space with children, pets, and elderly relatives, many of which don't fully grasp the concept of a professional working environment.
High for one, a fighting for attention, with a rather disobedient four-year-old Labrador Retriever, who is overjoyed and is now far less nomadic, and rather excited to notify me whenever there's a squirrel near the bird feeder. For those in the outside of security field that are used to running cohesive teams in a sock or another environment, the changes of working remote are significant. And this week, ICEM's SVP of editorial Tom Field spoke with Jim Rath, CSOC at Massimutual, about he has adjusted his team to working from a remote office environment. Here he is.
Well, I think first and foremost, the CSOC kind of has to look at this from a people leadership perspective and recognize that the new normal of working at home has a whole bunch of implications to that. So, you know, part of it is that I have a lot more tolerance for dog barking on web conferences. I have a lot more tolerance and, frankly, empathy for kids screaming about, you know, they want this toy of that toy and that sort of thing in the background. That's just part of the new normal of what it's like.
And I think all of us have to recognize that there's some adjustments that we're making. And there are a lot of people that have accountability and responsibilities and dependencies for family members, both elderly and young, that are impacting their ability to work in a, you know, in a quiet, serene kind of environment. Just that's not the way we live and it's not the way we work any longer. So, so those adjustments that are kind of right out of the gate.
The second is that the bandwidth, you know, technology infrastructure necessary to support everybody working at home at the same time simultaneously with a rich, medium kind of interface is not what enterprises are set up to do. They've always had that capability for a small slice or subset of the population that works at home at any one time, but to not only be able to support that where everybody's working at all at the same time, but everybody starts meetings on the hour. So, you've got this influx of capability that has to be in place from a capacity standpoint. And of course, security plays a role in deciding, well, how are we going to do split tunneling?
So, our VPN doesn't get totally overwhelmed and we can allow this kind of rich media experience. And so, the trade-offs on what network traffic to split and what network traffic is going to remain encrypted is a security decision. And so, two things have to be in place. One is you have to agree and decide that how you're going to do split tunneling.
The second is you go decide who decides when you change that because it's a, it's a configuration change that's made based on capacity information at any point in time. We worked through that actually relatively well largely because we did a little bit of prep beforehand where we knew it was coming. So, we've had a pretty good or pretty, you know, reasonable experience for most people at working at home to do that. So, that's been really useful.
And I think the security kind of engaged early made a big difference there. So, that was helpful. Then we have to think about, okay, what about the work at home construct for the third party or the third-party service provider? And that's kind of the next generation is basically taking care of your third-party service providers that have the same shelter at place, you know, restrictions regardless of where they might be around the world and giving them that capability to work at home under the, you know, extending the same kind of controls to do that.
So, we're at the mode where we've got that pretty much set, although some of our operations, we decided not to allow a work at home extension for third and fourth parties because of the sensitivity of the information. So, we're actually looking for additive capacity building up a capability onshore to be able to do that. And those are just some of the trade-offs for making based on the sensitivity of the information. So, we're at the third and fourth channel now where we're working on, you know, dealing with the work at home phenomena relatively mature and well down the pike.
And so far, you know, the companies have been very reasonable and, you know, and responsive in a, you know, in a short time frame. So, so far, it's working pretty well. That's it for this week's Ice and Security Report. Thing news is why you think audio?
I'm Nick Collins. Catch you next time.