CACS401 Cyber Law And Professional Ethics

Cyber Law And Professional EthicsUnit 1311 min read

IT Security Audit, Risk Assessment & Reverse Engineering

Unit 13 of Cyber Law And Professional Ethics: Explores IT security audits (processes, types, and tools), risk assessment (qualitative/quantitative methods, threat modeling), and reverse engineering (techniques, ethics, and legal implications) with real-world applications in Nepal’s banking and tech sectors.

TAKEAWAYS:

  • IT Security Audit is a systematic evaluation of IT systems to identify vulnerabilities, compliance gaps, and security weaknesses using frameworks like ISO 27001 or NIST.
  • Risk Assessment quantifies threats (e.g., data breaches, insider threats) via qualitative (risk matrices) or quantitative (ALE, SLE) methods, guiding resource allocation.
  • Reverse Engineering dissects software/hardware to understand functionality (e.g., malware analysis) but risks legal violations under Nepal’s IT Act 2063.
  • CIA Triad (Confidentiality, Integrity, Availability) underpins all three topics—audits verify compliance, risk assessments prioritize threats, and reverse engineering must respect IP rights.
  • Nepal’s Nepal Rastra Bank (NRB) and Ncell use audits/risk assessments to secure financial transactions and network infrastructure.
  • Exam focus: Compare audit vs. risk assessment, explain CIA implementation, and critique reverse engineering’s ethical/legal dilemmas.

1. IT Security Audit: Definition and Process

An IT security audit is a structured review of an organization’s IT infrastructure, policies, and controls to ensure compliance with security standards, detect vulnerabilities, and mitigate risks. It aligns with legal requirements (e.g., Nepal’s IT Act 2063) and global frameworks like ISO 27001 or NIST SP 800-53.

Why Audit?

  • Compliance: Mandatory for banks (NRB directives) and government agencies (e.g., NTC’s network security).
  • Risk Mitigation: Identifies unpatched software (e.g., Daraz’s payment gateway vulnerabilities).
  • Incident Response: Post-breach analysis (e.g., Pathao’s 2022 data leak audit).

Types of IT Security Audits

  • Compliance Audit: Checks adherence to laws (e.g., GDPR in Nepal’s digital payment apps like Khalti).
  • Vulnerability Assessment: Scans for weak passwords or outdated firmware (e.g., Ncell’s 5G network audit).
  • Penetration Testing: Simulates cyberattacks (e.g., ethical hackers testing eSewa’s API).
  • Configuration Audit: Validates firewall rules and access controls (e.g., NEPSE’s trading system).
  • Physical Security Audit: Secures data centers (e.g., NTC’s server rooms).

Audit Frameworks

Framework Scope Example in Nepal
ISO 27001 Information security management Used by banks (e.g., Siddhartha Bank)
NIST SP 800-53 U.S. federal standards Adopted by NTC for critical infrastructure
CIS Controls Critical security controls Implemented by Ncell for SIM card fraud prevention
Annex A Controls (e.g., A.5 Access Control)Risk Treatment PlanStatement of ApplicabilityISO/IEC 27001
ISO/IEC 27001 control hierarchy for IT security audits

Worked Example: Bank Audit Trace

Scenario: A Nepalese bank (e.g., Global IME) undergoes an ISO 27001 audit after a phishing attack.

  1. Scope: Audit covers online banking, ATMs, and employee devices.
  2. Tools Used:
    • Nessus (vulnerability scanner) → Finds unpatched Java on ATMs.
    • Wireshark (network analyzer) → Detects MITM attacks on mobile banking.
  3. Findings:
    • Weakness: Default admin credentials on firewalls.
    • Compliance Gap: Lack of multi-factor authentication (MFA) for loan officers.
  4. Remediation:
    • Enforce MFA via Google Authenticator.
    • Patch Java using Nepal Rastra Bank’s vulnerability database.


2. Risk Assessment: Methods and Tools

Risk assessment identifies, analyzes, and prioritizes threats to IT systems. Nepal’s Nepal Police Cyber Bureau uses it to combat cybercrime.

Qualitative vs. Quantitative Risk Assessment

Aspect Qualitative Quantitative
Method Risk matrix, expert judgment ALE = SLE × ARO, ROI analysis
Output High/Medium/Low risk labels Numerical risk scores (e.g., $50,000/year)
Example Ncell ranks SIM swap fraud as "High" NRB calculates ALE for ATM skimming at $200,000/year

Steps in Risk Assessment

flowchart TD
    A["Risk Assessment"] --> B["Identify Assets: List critical IT systems (e.g., databases, APIs)"]
    B --> C["Identify Threats: Enumerate cyber threats (e.g., phishing, DDoS)"]
    C --> D["Assess Vulnerabilities: Rate CVSS scores (e.g., 9.8 for critical)"]
    D --> E["Calculate Risk: Use formula Risk = Threat × Vulnerability × Impact"]
    E --> F["Mitigate or Accept: Prioritize fixes (e.g., patch SQL injection)"]

Worked Example: Daraz Order Queue Risk

Scenario: Daraz’s delivery system faces risks like supply chain disruptions (e.g., COVID-19 lockdowns) or data leaks (customer addresses).

  1. Asset: Customer order database.
  2. Threat: Insider theft (delivery personnel).
  3. Vulnerability: Weak access controls on ERP software.
  4. Risk Calculation:
    • SLE (Single Loss Expectancy): $10,000 (fine for GDPR violation).
    • ARO (Annualized Rate of Occurrence): 0.05 (5% chance/year).
    • ALE (Annualized Loss Expectancy): $500.
  5. Mitigation:
    • Implement role-based access control (RBAC).
    • Use blockchain for order tracking (piloted in Kathmandu).

risk assessment matrix templateQualitative risk matrix for Daraz’s delivery risks (Image: U3115299, CC BY-SA 4.0, via Wikimedia Commons)


3. Reverse Engineering: Techniques and Ethics

Reverse engineering (RE) analyzes software/hardware to understand functionality, often used in malware analysis or hardware debugging. However, it violates Nepal’s IT Act 2063 (Section 39) if done without authorization.

Techniques

  • Static Analysis: Disassembles binaries (e.g., Ghidra tool for malware like Emotet).
  • Dynamic Analysis: Monitors runtime behavior (e.g., Frida for Android apps like Pathao’s payment module).
  • Decompilation: Converts machine code to pseudocode (e.g., analyzing WhatsApp’s end-to-end encryption).
  • Firmware Dumping: Extracts firmware from routers (e.g., NTC’s 5G base stations).
Scenario Ethical? Legal in Nepal? Example
Malware Analysis Yes Yes (with permission) Nepal Police Cyber Bureau
Copying Proprietary Code No No (IT Act 2063) Reverse engineering eSewa’s API
Hardware Debugging Context-dependent Depends on use Fixing Ncell’s faulty SIM cards
2017 BSNepal IT Act,2063: Prohibits unauth2070 BSNepal ComputerCrime Act: Penalties f2075 BSSupreme Courtruling: Ethical hackin
Key legal milestones for reverse engineering in Nepal

Worked Example: Malware Analysis Trace

Scenario: Nepal Police Cyber Bureau investigates a ransomware attack on a hospital’s system.

  1. Static RE:
    • Uses IDA Pro to disassemble the malware (ransomware.exe).
    • Finds hardcoded encryption key: 0xA1B2C3D4.
  2. Dynamic RE:
    • Runs malware in a sandbox (e.g., Cuckoo Sandbox) to observe network calls.
    • Detects C2 server: 123.45.67.89:443.
  3. Legal Action:
    • Shares findings with Nepal Rastra Bank to block the C2 domain.
    • Files a complaint under IT Act 2063 (Section 40) for cybercrime.


4. CIA Triad in IT Security Audit, Risk Assessment, and Reverse Engineering

The CIA Triad (Confidentiality, Integrity, Availability) is the foundation for all three topics:

Topic Confidentiality Integrity Availability
IT Security Audit Encrypts data (e.g., Khalti’s payment logs) Validates access logs (e.g., Ncell’s call records) Ensures uptime (e.g., NEPSE’s trading system)
Risk Assessment Protects asset inventories (e.g., bank databases) Detects tampered firmware (e.g., NTC’s routers) Plans for disaster recovery (e.g., Daraz’s cloud backup)
Reverse Engineering Avoids leaking proprietary code (e.g., eSewa’s API) Ensures decompiled code matches original Maintains tool availability (e.g., Ghidra licenses)

Worked Example: Bank Loan Interest Calculation (CIA in Risk)

Scenario: A bank (e.g., Global IME) lends ₹500,000 at 8% annual interest.

  • Confidentiality: Loan data encrypted in Nepal Rastra Bank’s database.
  • Integrity: Hashes ensure no tampering (e.g., SHA-256 for loan agreements).
  • Availability: Redundant servers prevent downtime during tax season.


5. Nepal-Specific Cases

Case 1: Ncell’s SIM Swap Fraud Audit

  • Risk: Fraudsters hijack SIMs to bypass 2FA (e.g., Khalti payments).
  • Audit: Ncell used ISO 27001 to add biometric verification for SIM transfers.
  • Result: Reduced fraud by 40% (NRB report, 2023).

Case 2: NEPSE’s Trading System Risk Assessment

  • Threat: Insider trading via unmonitored chat apps (e.g., WhatsApp).
  • Mitigation: NEPSE banned personal devices and enforced SIEM tools (e.g., Splunk).


Exam Tip

  1. CIA Triad: Always link it to audits (compliance), risk assessments (threat prioritization), and RE (ethical boundaries).
  2. Compare Audit vs. Risk Assessment:
    • Audit: Checks what exists (e.g., "Does Ncell enforce MFA?").
    • Risk Assessment: Predicts what could go wrong (e.g., "What if MFA is bypassed?").
  3. Reverse Engineering:
    • Legal Angle: Cite Nepal’s IT Act 2063 (Section 39) for unauthorized RE.
    • Tools: Mention Ghidra, IDA Pro, Frida for dynamic/static analysis.
  4. Worked Examples:
    • Use Nepalese cases (banks, NTC, Daraz) to show real-world application.
    • For risk assessment, calculate ALE (e.g., "A bank loses ₹200,000/year to phishing").
  5. Short Notes:
    • Reverse Engineering: Define as "analyzing software/hardware to understand functionality."
    • CMMI Model: Mention process maturity levels (e.g., Level 5 for audits).
    • Contingent Workers: Highlight risks in outsourcing (e.g., Pathao’s third-party drivers).

Mermaid Diagram for Exam:

flowchart TD
    A["Exam Question: CIA Triad"] --> B["Audit: Verify CIA"]
    B --> C["Risk Assessment: Quantify CIA Breaches"]
    C --> D["Reverse Engineering: Respect CIA in Code"]
    D --> E["Nepal’s IT Act: Enforce CIA Legally"]

Based on the TU BCA syllabus for Cyber Law And Professional Ethics (CACS401), unit 13.

Discussion

Loading…