Information SecurityUnit 19 min read

InfoSec Basics: CIA Triad, Threats, Risks & Security Models

Unit 1 of Information Security introduces core concepts like the CIA triad (Confidentiality, Integrity, Availability), security threats, risk management, and foundational security models (layered, defense-in-depth). It explains how organizations protect data, why security is critical in digital systems, and real-world

1. What is Information Security?

Information Security (InfoSec) is the practice of protecting information from unauthorized access, disclosure, alteration, or destruction. It ensures that data remains confidential, integrity is maintained, and availability is guaranteed—collectively known as the CIA Triad.

1.1 Why is InfoSec Important?

  • Data breaches (e.g., stolen customer records) can destroy trust.
  • Financial loss (e.g., fraud, ransomware attacks).
  • Legal consequences (e.g., GDPR violations in Europe, Nepal’s Electronic Transactions Act).
  • Operational disruptions (e.g., a hospital’s system being locked by malware).

2. The CIA Triad: Core Principles

The CIA Triad is the foundation of InfoSec. Each pillar addresses a different security goal:

Confidentiality (33%)Integrity (33%)Availability (34%)
CIA Triad proportions in eSewa’s security policy (approximate weights based on real-world emphasis)
Pillar Definition Example in Nepal
Confidentiality Ensures data is accessible only to authorized users. eSewa encrypts user transactions so only the sender/receiver can see them.
Integrity Ensures data is accurate and unaltered. Ncell’s billing system prevents tampering with call records.
Availability Ensures systems and data are accessible when needed. NTC’s fiber network must stay up to avoid internet outages during exams.

Worked Example:

  • eSewa’s Confidentiality: When you send money via eSewa, the app uses TLS encryption (like HTTPS) so hackers can’t read your transaction details.
  • Ncell’s Integrity: If a hacker tries to change your call duration records, Ncell’s digital signatures detect the tampering.

3. Security Threats and Vulnerabilities

Threats are potential dangers to information, while vulnerabilities are weaknesses that can be exploited.

3.1 Types of Threats

Accidental DeletionMisconfigurationHuman ErrorsHackingPhishingRansomwareMalicious AttacksFloodsPower OutagesNatural DisastersOutdated SoftwareWeak PasswordsStructural WeaknessesSecurity Threats
Hierarchical classification of security threats (Nepal context: e.g., power outages affect eSewa transactions)
sequenceDiagram
    participant User
    participant Attacker
    participant eSewaServer
    User->>eSewaServer: Sends money (Phishing Link)
    Attacker->>User: Fake eSewa SMS
    User->>Attacker: Clicks malicious link
    Attacker->>eSewaServer: Steals session cookies
    eSewaServer-->>Attacker: Unauthorized access
    Note right of Attacker: **Phishing → Session Hijacking**
Phishing attack flow targeting eSewa users (real-world example: 2023 scam waves)

Real-World Example:

  • Pathao’s Vulnerability: In 2022, Pathao faced a DDoS attack (overloading servers) during peak hours, making the app unavailable.
  • Nepal Rastra Bank’s Threat: Weak ATM PIN policies (e.g., allowing simple PINs like "1234") led to skimming attacks.

4. Risk Management: Identifying and Mitigating Risks

Risk = Threat × Vulnerability × Impact Organizations use Risk Assessment to prioritize security measures.

4.1 Risk Assessment Steps

  1. Identify assets (e.g., customer databases, financial records).
  2. Identify threats (e.g., hackers, insiders, natural disasters).
  3. Assess vulnerabilities (e.g., weak firewalls, unpatched software).
  4. Determine impact (e.g., financial loss, reputational damage).
  5. Mitigate risks (e.g., encryption, access controls, backups).

Worked Example: Daraz’s Risk Management

  • Threat: Credit card fraud during online payments.
  • Vulnerability: Weak PCI-DSS compliance (payment security standards).
  • Mitigation:
    • Tokenization (replacing card details with tokens).
    • Two-factor authentication (2FA) for logins.

5. Security Models: Layered Defense

Security is not a single solution but a multi-layered approach.

Physical SecurityBiometrics, CCTVNetwork SecurityFirewalls, IDS/IPSSystem SecurityOS Hardening, Patch ManagementApplication SecurityEncryption, Access ControlData SecurityBackup, Redundancy
Defense-in-Depth Model for eSewa: Layers protecting transactions (Nepal’s most-used digital payment system)

5.1 Defense-in-Depth Model

Real-World Example: Nepal’s Banking Security

  • Outer Layer: ATMs have biometric scanners (fingerprint + PIN).
  • Middle Layer: Banks use firewalls to block DDoS attacks.
  • Inner Layer: End-to-end encryption secures online fund transfers.

6. Common Security Policies and Standards

Organizations follow standards to ensure security best practices.

Standard Description Used By
ISO 27001 International standard for information security management. Banks, Ncell, NTC
PCI-DSS Payment Card Industry Data Security Standard. eSewa, Khalti, Daraz
GDPR General Data Protection Regulation (EU, but influences Nepal’s data laws). Global companies operating in Nepal
Nepal’s IT Act Legal framework for cybersecurity in Nepal. All government and private sectors

Worked Example: NTC’s Compliance

  • NTC follows ISO 27001 to protect its fiber optic network from sabotage.
  • Physical Security: Guarded data centers with biometric access.
  • Network Security: VPNs for remote workers to prevent data leaks.

7. Real-World Applications in Nepal

HTTPSEncryptedPCI-DSS ComplianteSewa ServerUser DeviceDatabasePayment Gateway
Simplified eSewa transaction flow with security controls (Nepal’s most critical digital payment system)

Case 1: eSewa’s Security Measures

  • Confidentiality: Uses AES-256 encryption for transactions.
  • Integrity: Digital signatures verify sender identity.
  • Availability: Redundant servers prevent downtime.

Case 2: Ncell’s SIM Registration Security

  • Threat: SIM cloning (fraudsters duplicate SIMs to steal calls/data).
  • Solution:
    • Biometric verification (fingerprint + photo ID).
    • One-time passwords (OTP) for new SIM activations.

Case 3: NEPSE’s Market Security

  • Threat: Insider trading (traders manipulating stock prices).
  • Solution:
    • Audit logs track all trades.
    • Two-factor authentication for broker logins.

8. Common Mistakes to Avoid

  • Weak passwords (e.g., "password123").
  • Ignoring software updates (unpatched systems are easy targets).
  • Not backing up data (ransomware can wipe everything).
  • Skipping multi-factor authentication (MFA).

Exam Tip

What Examiners Look For:

✅ Define CIA Triad clearly (don’t just list—explain with examples). ✅ Compare threats vs. vulnerabilities (e.g., "A hacker is a threat; an unpatched server is a vulnerability"). ✅ Apply concepts to real Nepalese cases (e.g., "How does eSewa ensure confidentiality?"). ✅ Draw diagrams (CIA triad, defense-in-depth layers, risk assessment flowcharts). ❌ Avoid vague answers like "Security is important" without details.

High-Scoring Answers Include:

  • Examples from Nepal (eSewa, Ncell, banks, NTC).
  • Step-by-step risk assessments.
  • Diagrams (CIA triad, layered security, threat classifications).
  • Comparisons (e.g., "Symmetric vs. asymmetric encryption in eSewa").

Summary Checklist

Before the exam, ensure you can: ✔ Explain the CIA Triad with Nepalese examples. ✔ Differentiate between threats, vulnerabilities, and risks. ✔ Describe defense-in-depth using a layered model. ✔ List 3 security standards (ISO 27001, PCI-DSS, GDPR) and where they apply. ✔ Analyze a real-world case (eSewa, Ncell, Daraz) using InfoSec principles.

Based on the TU BIM syllabus for Information Security (IT244), unit 1.

Discussion

Loading…