MIS And E-BusinessUnit 918 min read
E-Commerce Website Design: Criteria, Models, Security & Development
Unit 9 of MIS And E-Business covers the principles of designing secure, user-friendly e-commerce websites, including structural models (H2C, B2B, C2C), security requirements (authentication, authorization, availability), and development best practices for online stores. Learn with real-world examples from Daraz, eSewa,
TAKEAWAYS:
- Website design criteria (usability, security, scalability) are non-negotiable for e-commerce success—Daraz’s checkout flow reduces cart abandonment by 40%.
- H2C (Hybrid-to-Consumer) models (like eSewa’s payment gateway) blend offline trust with online convenience, critical for Nepal’s semi-digital economy.
- Security layers (authentication via OTPs, authorization via role-based access, availability via CDNs) protect against both technical (SQL injection) and non-technical (social engineering) attacks.
- Development frameworks (Shopify, WooCommerce) vs. custom solutions (Nabil Bank’s secure portal) trade off cost, flexibility, and compliance.
- Mobile-first design (e.g., Pathao’s one-tap ordering) is mandatory—60% of Nepali e-commerce traffic comes from smartphones.
- Supply chain integration (like Daraz’s warehouse management system) directly impacts website performance and customer trust.
Core Concepts: What Makes an E-Commerce Website Work?
1. Defining E-Commerce Website Design
An e-commerce website is a digital storefront that enables online transactions between buyers and sellers. Unlike static websites, it must:
- Process payments securely (PCI-DSS compliance).
- Manage inventory dynamically (real-time stock updates).
- Handle user data ethically (GDPR/PDPA compliance in Nepal).
- Optimize for conversions (e.g., Daraz’s "Buy Now, Pay Later" feature).
2. Key Website Design Criteria
Designing an e-commerce site isn’t just about aesthetics—it’s about functionality, security, and scalability. Here’s what examiners expect you to know:
| Criteria | Why It Matters | Example from Nepal |
|---|---|---|
| Usability | Reduces bounce rates (e.g., mobile-friendly menus). | Daraz’s "Quick Add to Cart" button increases conversions by 25%. |
| Security | Protects against fraud (e.g., SSL certificates, two-factor authentication). | eSewa uses 3D Secure for credit card transactions. |
| Performance | Fast load times (Google ranks sites by speed). | NTC’s e-commerce portal uses CDN (Content Delivery Network) for nationwide speed. |
| Scalability | Handles traffic spikes (e.g., Diwali sales). | Pathao’s backend scales to 10x orders during festivals. |
| Accessibility | Complies with laws (e.g., screen readers for visually impaired users). | Nabil Bank’s website supports Nepali Unicode and high-contrast modes. |
| SEO-Friendliness | Drives organic traffic (e.g., keyword-rich product descriptions). | Himalayan Java’s blog ranks for "best coffee Nepal" due to meta tags and backlinks. |
WORKED EXAMPLE: Daraz’s Checkout Flow
- Step 1: Product Selection → User adds items to cart (session stored via cookies).
- Step 2: Payment Gateway → Redirects to eSewa/Khalti (PCI-compliant).
- Step 3: Order Confirmation → Email/SMS with tracking (integrated with Nepal Post API).
- Step 4: Post-Purchase → Review request (boosts SEO) and loyalty points (retention).
Why it works:
- Reduced cart abandonment: Only 12% (vs. global avg. of 70%) due to one-click checkout.
- Trust signals: SSL badge, customer reviews, and Nepal Police Cyber Bureau certification.
3. E-Commerce Models and Their Website Structures
Not all e-commerce sites are created equal. The model dictates the website structure, security needs, and revenue streams.
A. Classification of E-Commerce Models
mindmap
root((E-Commerce Models))
B2C["B2C: Business → Consumer (e.g., Daraz, Amazon)"]
Pros["Low overhead, global reach"]
Cons["High competition, marketing costs"]
B2B["B2B: Business → Business (e.g., TradeKey, Alibaba)"]
Pros["Bulk orders, long-term contracts"]
Cons["Complex negotiations, longer sales cycles"]
C2C["C2C: Consumer → Consumer (e.g., Swoopo, OLX)"]
Pros["Community-driven, low startup cost"]
Cons["Trust issues, dispute resolution needed"]
C2B["C2B: Consumer → Business (e.g., Freelancer.com)"]
Pros["Access to niche talent"]
Cons["Quality control challenges"]
H2C["H2C: Hybrid → Consumer (e.g., eSewa, Nabil Bank Online)"]
Pros["Blends offline trust with digital convenience"]
Cons["Requires physical + digital infrastructure"]KEY DIFFERENCE: Pure vs. Partial E-Commerce
| Aspect | Pure E-Commerce | Partial E-Commerce |
|---|---|---|
| Example | Amazon, Daraz | Nabil Bank (online + physical branches) |
| Revenue Model | 100% digital (ads, commissions, subscriptions) | Mixed (ATM fees, loan interest, online services) |
| Customer Trust | Built via reviews, ratings, and guarantees | Leverages offline brand reputation |
| Tech Stack | Cloud-native (AWS, Shopify) | Legacy + modern (core banking system + API) |
REAL-WORLD APPLICATION: eSewa’s H2C Model
- Problem: Nepalis distrust online payments (only 30% of adults had bank accounts in 2020).
- Solution: eSewa integrated with physical agents (like local shops) for cash deposits/withdrawals.
- Website Design Impact:
- Agent locator map (Google Maps API).
- OTP-based authentication (reduces fraud).
- Multi-language support (Nepali, English, Hindi).
B. Website Structure Types
Every e-commerce site follows one of these architectural patterns:
WORKED EXAMPLE: NEPSE’s Monolithic Structure
- Why monolithic?
- Low trading volume → no need for microservices.
- Regulatory compliance requires centralized data.
- Security Risks:
- Single vulnerability (e.g., SQL injection) can expose entire database.
- Mitigation: Firewall, WAF, and daily backups.
4. Security in E-Commerce Website Design
Security isn’t an afterthought—it’s the foundation. Here’s how to enforce the AAA triad:
A. Authentication, Authorization, and Availability (AAA)
| Security Layer | How It Works | Nepali Example |
|---|---|---|
| Authentication | Proves identity (username + password + OTP). | Khalti uses biometric login (fingerprint + PIN). |
| Authorization | Grants access (e.g., admin vs. customer). | Nabil Bank’s portal restricts loan officers from viewing savings accounts. |
| Availability | Ensures uptime (CDNs, load balancers). | Daraz uses AWS CloudFront to handle 1M+ daily visitors. |
B. Common Threats and Mitigations
| Threat | Type | Example Attack | Mitigation |
|---|---|---|---|
| SQL Injection | Technical | '; DROP TABLE users; -- in login form |
Use prepared statements, input validation. |
| Phishing | Non-Technical | Fake "eSewa verification" email | DMARC, SPF records, user education. |
| DDoS Attacks | Technical | Overloading Daraz’s server during sales | Cloudflare, rate limiting, anycast routing. |
| Man-in-the-Middle | Technical | Intercepting Khalti transactions | HTTPS (TLS 1.3), HSTS headers. |
| Insider Threats | Non-Technical | Employee selling customer data | Role-based access, audit logs, least privilege principle. |
CASE STUDY: Ncell’s Security Breach (2021)
- Attack: Credential stuffing (reused passwords from other sites).
- Impact: 50,000+ accounts compromised.
- Lessons for Website Design:
- Enforce multi-factor authentication (MFA).
- Monitor failed login attempts (block after 5 tries).
- Educate users (Ncell sent SMS: "Your password was exposed—change it now").
5. Development Frameworks and Tools
Choosing the right tech stack depends on budget, scalability, and compliance.
A. Comparison of E-Commerce Platforms
| Platform | Type | Best For | Nepali Example | Security Features |
|---|---|---|---|---|
| Shopify | SaaS (Hosted) | Small businesses, quick setup | Local coffee shops using Shopify | PCI-compliant, free SSL, Shopify Payments (built-in fraud detection). |
| WooCommerce | Open-Source (Self-Hosted) | Customizable stores | Himalayan Java | Requires manual PCI compliance, plugins like Wordfence for security. |
| Magento | Enterprise | Large-scale (B2B/B2C) | Hypothetical: Chaudhary Group | Advanced role-based permissions, two-factor auth, DDoS protection. |
| Custom (Node.js/Python) | Bespoke | Unique business logic (banks, fintech) | Nabil Bank’s secure portal | Zero-trust architecture, blockchain for transactions, AI-based fraud detection. |
WORKED EXAMPLE: Building a Secure Online Store for a Nepali Spice Exporter
- Platform: WooCommerce (self-hosted on Nepal Data Centers for low latency).
- Security:
- Plugin: WP Cerber (firewall + malware scanner).
- Payment: Khalti API (with 3D Secure).
- Database: MySQL with encryption.
- SEO: Yoast SEO for Nepali keywords (e.g., "मसला निर्यात गर्ने कम्पनी").
- Mobile: AMP (Accelerated Mobile Pages) for fast loading.
Cost Breakdown:
| Item | Cost (NPR) |
|---|---|
| Domain + Hosting | 15,000/year |
| WooCommerce License | Free |
| Security Plugins | 10,000/year |
| Khalti Integration | 5,000 (one-time) |
| Total | 30,000/year |
B. Key Development Steps
flowchart LR A["1. Requirements Gathering"] --> B["2. Wireframing (UI/UX)"] B --> C["3. Choose Tech Stack"] C --> D["4. Develop Frontend (HTML/CSS/JS)"] D --> E["5. Build Backend (APIs, Database)"] E --> F["6. Integrate Payment Gateway"] F --> G["7. Test Security (Penetration Testing)"] G --> H["8. Deploy (CDN, Load Balancer)"] H --> I["9. Monitor & Optimize (Analytics)"]
REAL-WORLD TOOLS USED IN NEPAL:
- Design: Figma, Adobe XD (used by Digital Nepal for government portals).
- Development: WordPress (60% of Nepali blogs), React.js (for dynamic UIs like Pathao’s app).
- Security: Nepal Police Cyber Bureau’s recommended tools (e.g., ClamAV for malware scanning).
6. Emerging Trends in E-Commerce Website Design
What’s next? AI, voice commerce, and sustainability are reshaping e-commerce.
| Trend | How It’s Used | Nepali Example |
|---|---|---|
| AI Chatbots | 24/7 customer support (e.g., Daraz’s "Ask Daraz" bot). | Ncell’s "Ncell Bot" answers billing queries in Nepali. |
| Voice Commerce | Order via Alexa/Google Assistant (e.g., "Alexa, order Himalayan Java coffee"). | Not yet mainstream, but Google Assistant supports Nepali voice searches. |
| Sustainable Packaging | Eco-friendly options (e.g., biodegradable bags). | Himalayan Java offers compostable packaging for online orders. |
| Blockchain for Supply Chain | Transparent tracking (e.g., organic spices). | Nepal Food Hub uses blockchain to verify organic certification. |
In the Real World
eSewa’s Hybrid (H2C) Model
- Idea Used: Hybrid-to-Consumer (H2C) e-commerce, blending offline trust with digital payments.
- How It Works:
- Users can deposit cash at physical agents (kirana shops) and pay online.
- Website integrates agent locator maps, OTP verification, and multi-language support.
- Impact: 5M+ transactions/month, 80% of Nepali digital payments.
Daraz’s Microservices Architecture
- Idea Used: Scalable microservices for handling 1M+ daily visitors.
- How It Works:
- Separate services for cart, payments, reviews, and inventory.
- CDN (Cloudflare) for fast global delivery.
- Impact: 99.9% uptime, even during Diwali sales.
Nabil Bank’s Secure Online Portal
- Idea Used: Zero-trust security model for financial transactions.
- How It Works:
- Biometric login (fingerprint + OTP).
- Real-time fraud detection (AI flags unusual transactions).
- Impact: Zero reported breaches in 2023.
Exam Tip
What Examiners Want to See
For definitions:
- AAA (Authentication, Authorization, Availability): Always explain how each is enforced (e.g., "Authorization is enforced via role-based access control (RBAC) in Nabil Bank’s portal").
- E-Commerce Models: Give Nepali examples (e.g., "H2C is used by eSewa because...").
For comparisons:
- Use tables (like the one above for Pure vs. Partial E-Commerce).
- Highlight one key difference with a real-world tie-in (e.g., "Unlike Amazon (pure), Nabil Bank (partial) requires physical KYC").
For security questions:
- Structure your answer like this:
1. Define the threat (e.g., "SQL injection exploits input fields"). 2. Give a Nepali example (e.g., "In 2022, a local spice exporter’s site was hacked via SQLi"). 3. Explain the mitigation (e.g., "Use **prepared statements** and **WAF like Cloudflare**").
- Structure your answer like this:
For design criteria:
- Pick 3-4 criteria and link each to a Nepali site:
- Usability → Daraz’s one-click checkout.
- Security → eSewa’s OTP + biometric login.
- Performance → NTC’s CDN for nationwide speed.
- Pick 3-4 criteria and link each to a Nepali site:
For case studies:
- Always end with a lesson:
- "Ncell’s breach teaches us that MFA is non-negotiable for financial sites."
- "Daraz’s success shows that mobile-first design is critical in Nepal."
- Always end with a lesson:
Common Mistakes to Avoid
- ❌ Generic answers: Don’t say "e-commerce is important"—say "eSewa’s H2C model reduced cash dependency by 40% in rural Nepal."
- ❌ Ignoring Nepal context: Examiners love local examples (e.g., Nepal Police Cyber Bureau’s guidelines).
- ❌ Skipping security: Always mention AAA or PCI-DSS when discussing payments.
- ❌ Overcomplicating: Stick to 3-4 key points per question. Use bullet lists for clarity.
Final Checklist Before the Exam
| Topic | Must-Know Points |
|---|---|
| Website Design Criteria | Usability, security, performance, scalability, accessibility, SEO. |
| E-Commerce Models | B2C, B2B, C2C, H2C (with Nepali examples). |
| Security (AAA) | Authentication (OTP, biometrics), Authorization (RBAC), Availability (CDN, WAF). |
| Threats & Mitigations | SQLi, phishing, DDoS, MitM (with Nepali case studies). |
| Development Tools | Shopify, WooCommerce, Magento, custom (with cost vs. security trade-offs). |
| Emerging Trends | AI chatbots, voice commerce, blockchain, sustainability. |
Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 9.
Discussion
Loading…