Information SecurityUnit 19 min read
InfoSec Basics: CIA Triad, Threats, Risks & Security Models
Unit 1 of Information Security introduces core concepts like the CIA triad (Confidentiality, Integrity, Availability), security threats, risk management, and foundational security models (layered, defense-in-depth). It explains how organizations protect data, why security is critical in digital systems, and real-world
1. What is Information Security?
Information Security (InfoSec) is the practice of protecting information from unauthorized access, disclosure, alteration, or destruction. It ensures that data remains confidential, integrity is maintained, and availability is guaranteed—collectively known as the CIA Triad.
1.1 Why is InfoSec Important?
- Data breaches (e.g., stolen customer records) can destroy trust.
- Financial loss (e.g., fraud, ransomware attacks).
- Legal consequences (e.g., GDPR violations in Europe, Nepal’s Electronic Transactions Act).
- Operational disruptions (e.g., a hospital’s system being locked by malware).
2. The CIA Triad: Core Principles
The CIA Triad is the foundation of InfoSec. Each pillar addresses a different security goal:
| Pillar | Definition | Example in Nepal |
|---|---|---|
| Confidentiality | Ensures data is accessible only to authorized users. | eSewa encrypts user transactions so only the sender/receiver can see them. |
| Integrity | Ensures data is accurate and unaltered. | Ncell’s billing system prevents tampering with call records. |
| Availability | Ensures systems and data are accessible when needed. | NTC’s fiber network must stay up to avoid internet outages during exams. |
Worked Example:
- eSewa’s Confidentiality: When you send money via eSewa, the app uses TLS encryption (like HTTPS) so hackers can’t read your transaction details.
- Ncell’s Integrity: If a hacker tries to change your call duration records, Ncell’s digital signatures detect the tampering.
3. Security Threats and Vulnerabilities
Threats are potential dangers to information, while vulnerabilities are weaknesses that can be exploited.
3.1 Types of Threats
sequenceDiagram
participant User
participant Attacker
participant eSewaServer
User->>eSewaServer: Sends money (Phishing Link)
Attacker->>User: Fake eSewa SMS
User->>Attacker: Clicks malicious link
Attacker->>eSewaServer: Steals session cookies
eSewaServer-->>Attacker: Unauthorized access
Note right of Attacker: **Phishing → Session Hijacking**Phishing attack flow targeting eSewa users (real-world example: 2023 scam waves)Real-World Example:
- Pathao’s Vulnerability: In 2022, Pathao faced a DDoS attack (overloading servers) during peak hours, making the app unavailable.
- Nepal Rastra Bank’s Threat: Weak ATM PIN policies (e.g., allowing simple PINs like "1234") led to skimming attacks.
4. Risk Management: Identifying and Mitigating Risks
Risk = Threat × Vulnerability × Impact Organizations use Risk Assessment to prioritize security measures.
4.1 Risk Assessment Steps
- Identify assets (e.g., customer databases, financial records).
- Identify threats (e.g., hackers, insiders, natural disasters).
- Assess vulnerabilities (e.g., weak firewalls, unpatched software).
- Determine impact (e.g., financial loss, reputational damage).
- Mitigate risks (e.g., encryption, access controls, backups).
Worked Example: Daraz’s Risk Management
- Threat: Credit card fraud during online payments.
- Vulnerability: Weak PCI-DSS compliance (payment security standards).
- Mitigation:
- Tokenization (replacing card details with tokens).
- Two-factor authentication (2FA) for logins.
5. Security Models: Layered Defense
Security is not a single solution but a multi-layered approach.
5.1 Defense-in-Depth Model
Real-World Example: Nepal’s Banking Security
- Outer Layer: ATMs have biometric scanners (fingerprint + PIN).
- Middle Layer: Banks use firewalls to block DDoS attacks.
- Inner Layer: End-to-end encryption secures online fund transfers.
6. Common Security Policies and Standards
Organizations follow standards to ensure security best practices.
| Standard | Description | Used By |
|---|---|---|
| ISO 27001 | International standard for information security management. | Banks, Ncell, NTC |
| PCI-DSS | Payment Card Industry Data Security Standard. | eSewa, Khalti, Daraz |
| GDPR | General Data Protection Regulation (EU, but influences Nepal’s data laws). | Global companies operating in Nepal |
| Nepal’s IT Act | Legal framework for cybersecurity in Nepal. | All government and private sectors |
Worked Example: NTC’s Compliance
- NTC follows ISO 27001 to protect its fiber optic network from sabotage.
- Physical Security: Guarded data centers with biometric access.
- Network Security: VPNs for remote workers to prevent data leaks.
7. Real-World Applications in Nepal
Case 1: eSewa’s Security Measures
- Confidentiality: Uses AES-256 encryption for transactions.
- Integrity: Digital signatures verify sender identity.
- Availability: Redundant servers prevent downtime.
Case 2: Ncell’s SIM Registration Security
- Threat: SIM cloning (fraudsters duplicate SIMs to steal calls/data).
- Solution:
- Biometric verification (fingerprint + photo ID).
- One-time passwords (OTP) for new SIM activations.
Case 3: NEPSE’s Market Security
- Threat: Insider trading (traders manipulating stock prices).
- Solution:
- Audit logs track all trades.
- Two-factor authentication for broker logins.
8. Common Mistakes to Avoid
- Weak passwords (e.g., "password123").
- Ignoring software updates (unpatched systems are easy targets).
- Not backing up data (ransomware can wipe everything).
- Skipping multi-factor authentication (MFA).
Exam Tip
What Examiners Look For:
✅ Define CIA Triad clearly (don’t just list—explain with examples). ✅ Compare threats vs. vulnerabilities (e.g., "A hacker is a threat; an unpatched server is a vulnerability"). ✅ Apply concepts to real Nepalese cases (e.g., "How does eSewa ensure confidentiality?"). ✅ Draw diagrams (CIA triad, defense-in-depth layers, risk assessment flowcharts). ❌ Avoid vague answers like "Security is important" without details.
High-Scoring Answers Include:
- Examples from Nepal (eSewa, Ncell, banks, NTC).
- Step-by-step risk assessments.
- Diagrams (CIA triad, layered security, threat classifications).
- Comparisons (e.g., "Symmetric vs. asymmetric encryption in eSewa").
Summary Checklist
Before the exam, ensure you can: ✔ Explain the CIA Triad with Nepalese examples. ✔ Differentiate between threats, vulnerabilities, and risks. ✔ Describe defense-in-depth using a layered model. ✔ List 3 security standards (ISO 27001, PCI-DSS, GDPR) and where they apply. ✔ Analyze a real-world case (eSewa, Ncell, Daraz) using InfoSec principles.
Based on the TU BIM syllabus for Information Security (IT244), unit 1.
Discussion
Loading…