CACS301 MIS And E-Business

MIS And E-BusinessUnit 918 min read

E-Commerce Website Design: Criteria, Models, Security & Development

Unit 9 of MIS And E-Business covers the principles of designing secure, user-friendly e-commerce websites, including structural models (H2C, B2B, C2C), security requirements (authentication, authorization, availability), and development best practices for online stores. Learn with real-world examples from Daraz, eSewa,

TAKEAWAYS:

  • Website design criteria (usability, security, scalability) are non-negotiable for e-commerce success—Daraz’s checkout flow reduces cart abandonment by 40%.
  • H2C (Hybrid-to-Consumer) models (like eSewa’s payment gateway) blend offline trust with online convenience, critical for Nepal’s semi-digital economy.
  • Security layers (authentication via OTPs, authorization via role-based access, availability via CDNs) protect against both technical (SQL injection) and non-technical (social engineering) attacks.
  • Development frameworks (Shopify, WooCommerce) vs. custom solutions (Nabil Bank’s secure portal) trade off cost, flexibility, and compliance.
  • Mobile-first design (e.g., Pathao’s one-tap ordering) is mandatory—60% of Nepali e-commerce traffic comes from smartphones.
  • Supply chain integration (like Daraz’s warehouse management system) directly impacts website performance and customer trust.

Core Concepts: What Makes an E-Commerce Website Work?

1. Defining E-Commerce Website Design

An e-commerce website is a digital storefront that enables online transactions between buyers and sellers. Unlike static websites, it must:

  • Process payments securely (PCI-DSS compliance).
  • Manage inventory dynamically (real-time stock updates).
  • Handle user data ethically (GDPR/PDPA compliance in Nepal).
  • Optimize for conversions (e.g., Daraz’s "Buy Now, Pay Later" feature).

2. Key Website Design Criteria

Designing an e-commerce site isn’t just about aesthetics—it’s about functionality, security, and scalability. Here’s what examiners expect you to know:

Criteria Why It Matters Example from Nepal
Usability Reduces bounce rates (e.g., mobile-friendly menus). Daraz’s "Quick Add to Cart" button increases conversions by 25%.
Security Protects against fraud (e.g., SSL certificates, two-factor authentication). eSewa uses 3D Secure for credit card transactions.
Performance Fast load times (Google ranks sites by speed). NTC’s e-commerce portal uses CDN (Content Delivery Network) for nationwide speed.
Scalability Handles traffic spikes (e.g., Diwali sales). Pathao’s backend scales to 10x orders during festivals.
Accessibility Complies with laws (e.g., screen readers for visually impaired users). Nabil Bank’s website supports Nepali Unicode and high-contrast modes.
SEO-Friendliness Drives organic traffic (e.g., keyword-rich product descriptions). Himalayan Java’s blog ranks for "best coffee Nepal" due to meta tags and backlinks.

WORKED EXAMPLE: Daraz’s Checkout Flow

  1. Step 1: Product Selection → User adds items to cart (session stored via cookies).
  2. Step 2: Payment Gateway → Redirects to eSewa/Khalti (PCI-compliant).
  3. Step 3: Order Confirmation → Email/SMS with tracking (integrated with Nepal Post API).
  4. Step 4: Post-Purchase → Review request (boosts SEO) and loyalty points (retention).

Why it works:

  • Reduced cart abandonment: Only 12% (vs. global avg. of 70%) due to one-click checkout.
  • Trust signals: SSL badge, customer reviews, and Nepal Police Cyber Bureau certification.

3. E-Commerce Models and Their Website Structures

Not all e-commerce sites are created equal. The model dictates the website structure, security needs, and revenue streams.

A. Classification of E-Commerce Models

mindmap
  root((E-Commerce Models))
    B2C["B2C: Business → Consumer (e.g., Daraz, Amazon)"]
      Pros["Low overhead, global reach"]
      Cons["High competition, marketing costs"]
    B2B["B2B: Business → Business (e.g., TradeKey, Alibaba)"]
      Pros["Bulk orders, long-term contracts"]
      Cons["Complex negotiations, longer sales cycles"]
    C2C["C2C: Consumer → Consumer (e.g., Swoopo, OLX)"]
      Pros["Community-driven, low startup cost"]
      Cons["Trust issues, dispute resolution needed"]
    C2B["C2B: Consumer → Business (e.g., Freelancer.com)"]
      Pros["Access to niche talent"]
      Cons["Quality control challenges"]
    H2C["H2C: Hybrid → Consumer (e.g., eSewa, Nabil Bank Online)"]
      Pros["Blends offline trust with digital convenience"]
      Cons["Requires physical + digital infrastructure"]

KEY DIFFERENCE: Pure vs. Partial E-Commerce

Aspect Pure E-Commerce Partial E-Commerce
Example Amazon, Daraz Nabil Bank (online + physical branches)
Revenue Model 100% digital (ads, commissions, subscriptions) Mixed (ATM fees, loan interest, online services)
Customer Trust Built via reviews, ratings, and guarantees Leverages offline brand reputation
Tech Stack Cloud-native (AWS, Shopify) Legacy + modern (core banking system + API)

REAL-WORLD APPLICATION: eSewa’s H2C Model

  • Problem: Nepalis distrust online payments (only 30% of adults had bank accounts in 2020).
  • Solution: eSewa integrated with physical agents (like local shops) for cash deposits/withdrawals.
  • Website Design Impact:
    • Agent locator map (Google Maps API).
    • OTP-based authentication (reduces fraud).
    • Multi-language support (Nepali, English, Hindi).

B. Website Structure Types

Every e-commerce site follows one of these architectural patterns:

Example: Nepal Stock Exchange (NEPSE) PortalPros: Simple to deploy, tight couplingCons: Hard to scale, single point of failureMonolithicExample: Daraz (modular services: cart, payments, reviews)Pros: Independent scaling, tech flexibilityCons: Complex to manage, inter-service latencyMicroservicesExample: Himalayan Java (content + commerce separated)Pros: Omnichannel content, API-drivenCons: Higher initial cost, developer expertise neededHeadless CMSWebsite Structure Types
Comparison of e-commerce website architecture types with pros/cons

WORKED EXAMPLE: NEPSE’s Monolithic Structure

  • Why monolithic?
    • Low trading volume → no need for microservices.
    • Regulatory compliance requires centralized data.
  • Security Risks:
    • Single vulnerability (e.g., SQL injection) can expose entire database.
    • Mitigation: Firewall, WAF, and daily backups.

4. Security in E-Commerce Website Design

Security isn’t an afterthought—it’s the foundation. Here’s how to enforce the AAA triad:

A. Authentication, Authorization, and Availability (AAA)

Security Layer How It Works Nepali Example
Authentication Proves identity (username + password + OTP). Khalti uses biometric login (fingerprint + PIN).
Authorization Grants access (e.g., admin vs. customer). Nabil Bank’s portal restricts loan officers from viewing savings accounts.
Availability Ensures uptime (CDNs, load balancers). Daraz uses AWS CloudFront to handle 1M+ daily visitors.
Passwords + MFA (e.g., SMS OTP)Biometrics (fingerprint, facial recognition)Social login (Google, Facebook)AuthenticationRole-based access (Admin, Customer, Guest)Attribute-based (e.g., age verification)Permission matrices (e.g., edit/delete)AuthorizationRedundancy (mirror servers)Load balancing (distributed traffic)CDN caching (global delivery)AvailabilityAAA Framework
AAA framework components with common implementation methods

B. Common Threats and Mitigations

Threat Type Example Attack Mitigation
SQL Injection Technical '; DROP TABLE users; -- in login form Use prepared statements, input validation.
Phishing Non-Technical Fake "eSewa verification" email DMARC, SPF records, user education.
DDoS Attacks Technical Overloading Daraz’s server during sales Cloudflare, rate limiting, anycast routing.
Man-in-the-Middle Technical Intercepting Khalti transactions HTTPS (TLS 1.3), HSTS headers.
Insider Threats Non-Technical Employee selling customer data Role-based access, audit logs, least privilege principle.

CASE STUDY: Ncell’s Security Breach (2021)

  • Attack: Credential stuffing (reused passwords from other sites).
  • Impact: 50,000+ accounts compromised.
  • Lessons for Website Design:
    1. Enforce multi-factor authentication (MFA).
    2. Monitor failed login attempts (block after 5 tries).
    3. Educate users (Ncell sent SMS: "Your password was exposed—change it now").

5. Development Frameworks and Tools

Choosing the right tech stack depends on budget, scalability, and compliance.

021.2542.563.7585Shopify85Magento72WooCommerce68PrestaShop55OpenCart42Adoption Rate (%)
Market share of popular e-commerce platforms (2023, % of global sites)

A. Comparison of E-Commerce Platforms

Platform Type Best For Nepali Example Security Features
Shopify SaaS (Hosted) Small businesses, quick setup Local coffee shops using Shopify PCI-compliant, free SSL, Shopify Payments (built-in fraud detection).
WooCommerce Open-Source (Self-Hosted) Customizable stores Himalayan Java Requires manual PCI compliance, plugins like Wordfence for security.
Magento Enterprise Large-scale (B2B/B2C) Hypothetical: Chaudhary Group Advanced role-based permissions, two-factor auth, DDoS protection.
Custom (Node.js/Python) Bespoke Unique business logic (banks, fintech) Nabil Bank’s secure portal Zero-trust architecture, blockchain for transactions, AI-based fraud detection.

WORKED EXAMPLE: Building a Secure Online Store for a Nepali Spice Exporter

  1. Platform: WooCommerce (self-hosted on Nepal Data Centers for low latency).
  2. Security:
    • Plugin: WP Cerber (firewall + malware scanner).
    • Payment: Khalti API (with 3D Secure).
    • Database: MySQL with encryption.
  3. SEO: Yoast SEO for Nepali keywords (e.g., "मसला निर्यात गर्ने कम्पनी").
  4. Mobile: AMP (Accelerated Mobile Pages) for fast loading.

Cost Breakdown:

Item Cost (NPR)
Domain + Hosting 15,000/year
WooCommerce License Free
Security Plugins 10,000/year
Khalti Integration 5,000 (one-time)
Total 30,000/year

B. Key Development Steps

flowchart LR
  A["1. Requirements Gathering"] --> B["2. Wireframing (UI/UX)"]
  B --> C["3. Choose Tech Stack"]
  C --> D["4. Develop Frontend (HTML/CSS/JS)"]
  D --> E["5. Build Backend (APIs, Database)"]
  E --> F["6. Integrate Payment Gateway"]
  F --> G["7. Test Security (Penetration Testing)"]
  G --> H["8. Deploy (CDN, Load Balancer)"]
  H --> I["9. Monitor & Optimize (Analytics)"]

REAL-WORLD TOOLS USED IN NEPAL:

  • Design: Figma, Adobe XD (used by Digital Nepal for government portals).
  • Development: WordPress (60% of Nepali blogs), React.js (for dynamic UIs like Pathao’s app).
  • Security: Nepal Police Cyber Bureau’s recommended tools (e.g., ClamAV for malware scanning).

What’s next? AI, voice commerce, and sustainability are reshaping e-commerce.

Trend How It’s Used Nepali Example
AI Chatbots 24/7 customer support (e.g., Daraz’s "Ask Daraz" bot). Ncell’s "Ncell Bot" answers billing queries in Nepali.
Voice Commerce Order via Alexa/Google Assistant (e.g., "Alexa, order Himalayan Java coffee"). Not yet mainstream, but Google Assistant supports Nepali voice searches.
Sustainable Packaging Eco-friendly options (e.g., biodegradable bags). Himalayan Java offers compostable packaging for online orders.
Blockchain for Supply Chain Transparent tracking (e.g., organic spices). Nepal Food Hub uses blockchain to verify organic certification.

In the Real World

  1. eSewa’s Hybrid (H2C) Model

    • Idea Used: Hybrid-to-Consumer (H2C) e-commerce, blending offline trust with digital payments.
    • How It Works:
      • Users can deposit cash at physical agents (kirana shops) and pay online.
      • Website integrates agent locator maps, OTP verification, and multi-language support.
    • Impact: 5M+ transactions/month, 80% of Nepali digital payments.
  2. Daraz’s Microservices Architecture

    • Idea Used: Scalable microservices for handling 1M+ daily visitors.
    • How It Works:
      • Separate services for cart, payments, reviews, and inventory.
      • CDN (Cloudflare) for fast global delivery.
    • Impact: 99.9% uptime, even during Diwali sales.
  3. Nabil Bank’s Secure Online Portal

    • Idea Used: Zero-trust security model for financial transactions.
    • How It Works:
      • Biometric login (fingerprint + OTP).
      • Real-time fraud detection (AI flags unusual transactions).
    • Impact: Zero reported breaches in 2023.

Exam Tip

What Examiners Want to See

  1. For definitions:

    • AAA (Authentication, Authorization, Availability): Always explain how each is enforced (e.g., "Authorization is enforced via role-based access control (RBAC) in Nabil Bank’s portal").
    • E-Commerce Models: Give Nepali examples (e.g., "H2C is used by eSewa because...").
  2. For comparisons:

    • Use tables (like the one above for Pure vs. Partial E-Commerce).
    • Highlight one key difference with a real-world tie-in (e.g., "Unlike Amazon (pure), Nabil Bank (partial) requires physical KYC").
  3. For security questions:

    • Structure your answer like this:
      1. Define the threat (e.g., "SQL injection exploits input fields").
      2. Give a Nepali example (e.g., "In 2022, a local spice exporter’s site was hacked via SQLi").
      3. Explain the mitigation (e.g., "Use **prepared statements** and **WAF like Cloudflare**").
      
  4. For design criteria:

    • Pick 3-4 criteria and link each to a Nepali site:
      • Usability → Daraz’s one-click checkout.
      • Security → eSewa’s OTP + biometric login.
      • Performance → NTC’s CDN for nationwide speed.
  5. For case studies:

    • Always end with a lesson:
      • "Ncell’s breach teaches us that MFA is non-negotiable for financial sites."
      • "Daraz’s success shows that mobile-first design is critical in Nepal."

Common Mistakes to Avoid

  • ❌ Generic answers: Don’t say "e-commerce is important"—say "eSewa’s H2C model reduced cash dependency by 40% in rural Nepal."
  • ❌ Ignoring Nepal context: Examiners love local examples (e.g., Nepal Police Cyber Bureau’s guidelines).
  • ❌ Skipping security: Always mention AAA or PCI-DSS when discussing payments.
  • ❌ Overcomplicating: Stick to 3-4 key points per question. Use bullet lists for clarity.

Final Checklist Before the Exam

Topic Must-Know Points
Website Design Criteria Usability, security, performance, scalability, accessibility, SEO.
E-Commerce Models B2C, B2B, C2C, H2C (with Nepali examples).
Security (AAA) Authentication (OTP, biometrics), Authorization (RBAC), Availability (CDN, WAF).
Threats & Mitigations SQLi, phishing, DDoS, MitM (with Nepali case studies).
Development Tools Shopify, WooCommerce, Magento, custom (with cost vs. security trade-offs).
Emerging Trends AI chatbots, voice commerce, blockchain, sustainability.

Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 9.

Discussion

Loading…