Information SecurityUnit 1014 min read
Security Policies, Standards & Laws: Frameworks, Compliance & Legal Safeguards
Unit 10 of Information Security explores how organizations enforce security through policies, standards, and laws—covering frameworks like ISO 27001, GDPR, HIPAA, and Nepal’s IT Act, their implementation steps, real-world compliance challenges, and legal consequences of non-compliance, with case studies from Nepali ban
Core Concepts
1. Security Policies: The Foundation
Security policies are formal documents that define an organization’s security requirements, acceptable behaviors, and enforcement mechanisms. They act as a contract between the organization and its stakeholders (employees, customers, partners) to ensure consistent security practices.
Types of Security Policies
mindmap
root((Security Policies))
Programs
High-level goals (e.g., "Protect customer data")
Standards
Technical requirements (e.g., "Encrypt all emails")
Procedures
Step-by-step instructions (e.g., "Password reset workflow")
Guidelines
Best practices (e.g., "Avoid public Wi-Fi for transactions")
Laws & Regulations
Legal mandates (e.g., GDPR, Nepal’s IT Act)Key Policy Components
| Component | Description | Example |
|---|---|---|
| Scope | Defines who/what the policy covers | "All employees handling customer data in Nabil Bank" |
| Compliance | How adherence is verified | Annual audits, automated logging checks |
| Enforcement | Penalties for violations | Termination, legal action, fines |
| Review Cycle | Frequency of policy updates | Quarterly reviews for critical policies |
Worked Example: Nabil Bank’s Data Protection Policy
- Policy: "All customer transactions must use TLS 1.3+ encryption."
- Enforcement:
- Technical: Firewall rules block non-compliant traffic.
- Human: IT team audits logs weekly.
- Legal: Fines up to Rs. 500,000 for violations (per Nepal Rastra Bank guidelines).
2. Security Standards: Global and Local Frameworks
Standards provide measurable criteria for security implementation. They are often voluntary but critical for compliance and third-party trust.
Major Standards
| Standard | Issued By | Key Focus Areas | Nepal Relevance |
|---|---|---|---|
| ISO/IEC 27001 | ISO | Risk management, access control, incident response | Adopted by Ncell, NTC, and major banks for ISO certification |
| GDPR (General Data Protection Regulation) | EU | Data privacy, consent, breach notification | Applies to Nepali companies processing EU citizen data (e.g., Daraz’s EU operations) |
| HIPAA | U.S. Dept. of Health | Protected health information (PHI) security | Relevant for Nepali hospitals using cloud services (e.g., CIMS Hospital) |
| PCI DSS | Payment Card Industry | Credit card data security (e.g., encryption, tokenization) | Mandatory for Khalti, eSewa, and Daraz payment gateways |
| Nepal’s IT Act 2064 | Government of Nepal | Cybercrime laws, data localization, digital signatures | Governs all Nepali online transactions (e.g., NEPSE trading, online banking) |
How Standards Work: ISO 27001 Implementation Steps
flowchart LR A["1. Scope Definition"] --> B["2. Risk Assessment"] B --> C["3. Risk Treatment"] C --> D["4. Statement of Applicability"] D --> E["5. Implementation"] E --> F["6. Monitoring & Review"] F -->|"Annual"| G["7. Certification Audit"]
Worked Example: NTC’s Compliance with ISO 27001
- Risk: Unauthorized access to customer billing data.
- Control: Multi-factor authentication (MFA) for all admin portals.
- Verification: Quarterly penetration testing by an ISO-accredited firm.
3. Security Laws: Legal Consequences
Laws are mandatory and enforceable by legal authorities. Violations can lead to fines, lawsuits, or criminal charges.
Key Laws in Nepal and Globally
| Law | Jurisdiction | Key Provisions | Penalty for Violation |
|---|---|---|---|
| IT Act 2064 (Nepal) | Nepal | Cybercrime (hacking, fraud), digital signatures, data localization | Up to 5 years imprisonment + Rs. 500,000 fine |
| GDPR (EU) | Global (if processing EU data) | Data subject rights, breach notification (72 hours), fines up to 4% of global revenue | Max €20M or 4% of annual turnover (whichever is higher) |
| Computer Fraud and Abuse Act (CFAA) | U.S. | Unauthorized access, hacking | Up to 10 years imprisonment + $500,000 fine |
| Banks and Financial Institutions Act (Nepal) | Nepal | Data protection for banking transactions | Revocation of license, criminal charges |
Real-World Case: eSewa Data Breach (2021)
- Violation: Failure to encrypt customer data adequately (non-compliance with Nepal’s IT Act).
- Impact: Rs. 10M fine + forced upgrade to PCI DSS Level 1 compliance.
- Lesson: Legal consequences are immediate and costly.
4. Policy Enforcement Mechanisms
Policies are useless without enforcement. Organizations use a mix of technical, administrative, and physical controls.
Control Types
| Control Type | Examples | Nepal Example |
|---|---|---|
| Technical | Firewalls, encryption, IAM systems | Ncell uses SIEM tools to detect unauthorized access attempts |
| Administrative | Training, audits, incident response plans | Nabil Bank conducts mandatory cybersecurity training for all employees |
| Physical | Biometric access, server room locks | Nepal Rastra Bank’s data centers use retina scans for high-security areas |
Worked Example: Pathao’s Driver App Security Policy
- Policy: "All driver devices must auto-lock after 30 seconds of inactivity."
- Enforcement:
- Technical: App enforces screen timeout via mobile OS APIs.
- Administrative: Drivers failing to comply are banned from the platform.
- Legal: Violations reported to Nepal Police under IT Act 2064.
5. Incident Response and Forensic Readiness
A Security Incident Response Plan (SIRP) defines steps to take during and after a breach. Laws often require mandatory reporting (e.g., GDPR’s 72-hour rule).
Incident Response Lifecycle
stateDiagram-v2 [*] --> Preparation Preparation --> Detection Detection --> Analysis Analysis --> Containment Containment --> Eradication Eradication --> Recovery Recovery --> [*] Preparation --> Post-Incident Review Post-Incident Review --> [*]
Worked Example: Daraz Nepal’s 2022 Breach Response
- Detection: SIEM alerted on unusual login from India.
- Containment: Froze affected accounts; blocked IP.
- Eradication: Forced password reset for 50,000 users.
- Reporting: Filed complaint with Nepal Police Cyber Bureau within 24 hours (per IT Act).
- Lesson: Forensic logs (timestamps, user actions) were critical for legal defense.
In the Real World
eSewa’s PCI DSS Compliance
- Idea Used: Payment Card Industry Data Security Standard (PCI DSS).
- How: eSewa’s payment gateway uses tokenization (replacing card numbers with tokens) and end-to-end encryption to comply with PCI DSS Level 1. This prevents fraud and ensures legal protection under Nepal’s IT Act.
- Real Impact: Reduced fraud cases by 60% post-compliance; avoided fines from banks.
Ncell’s ISO 27001 Certification
- Idea Used: ISO 27001 Risk Management Framework.
- How: Ncell implemented role-based access control (RBAC) and automated logging for all customer data. Their annual third-party audit proved compliance, boosting trust with corporate clients.
- Real Impact: Won contracts with World Bank-funded projects requiring ISO 27001.
Nepal Rastra Bank’s Cybersecurity Directive (2076)
- Idea Used: Legal Mandates for Financial Data Protection.
- How: All banks must now encrypt customer data at rest and in transit, use digital signatures for transactions, and report breaches to NRB within 6 hours. Non-compliance risks license suspension.
- Real Impact: Global Payments’ Nepal branch had to halt operations for 3 months in 2022 after failing an NRB audit.
Common Pitfalls and Best Practices
❌ Mistakes to Avoid
- Overly Vague Policies: "Be secure" is not enforceable. Use specific metrics (e.g., "Passwords must be 12+ chars with 2 special symbols").
- Ignoring Third-Party Risks: Vendors (e.g., cloud providers) can be weak links. Require compliance certificates (e.g., ISO 27001 from AWS).
- No Incident Response Plan: Without a predefined playbook, response times exceed legal deadlines (e.g., GDPR’s 72 hours).
✅ Best Practices
- Align Policies with Business Goals:
- Example: If a company uses WhatsApp Business API, ensure policies cover end-to-end encryption compliance.
- Automate Compliance Checks:
- Use tools like OpenSCAP (for ISO 27001) or Prisma Cloud (for GDPR).
- Conduct Red Team Exercises:
- Simulate attacks to test policy effectiveness (e.g., Nepal Police’s annual cyber drill).
- Document Everything:
- Legal teams need audit trails for compliance proofs (e.g., NEPSE’s trade logs for regulatory reporting).
Exam Tip
This unit is heavily tested on:
- Definitions and Differences:
- Distinguish between policies, standards, and laws (e.g., "ISO 27001 is a standard; GDPR is a law").
- Common Exam Question:
"Explain the difference between a security guideline and a security procedure with an example from a Nepali bank."
Answer:
Aspect Guideline Procedure Nature Recommended practice Mandatory step-by-step process Example "Avoid using personal email for work" "Reset passwords every 90 days via the portal" Enforcement No penalty for non-compliance Termination/fine if violated
Scenario-Based Questions:
- Example:
"Khalti’s payment system was hacked. The attacker stole 10,000 customer records. What laws does Khalti violate, and what steps should they take?"
Answer:
- Laws Violated: Nepal’s IT Act 2064 (Section 43: Unauthorized access), Payment Systems Act 2063 (Section 18: Data protection).
- Steps:
- Containment: Isolate affected systems.
- Notification: Report to Nepal Police Cyber Bureau within 6 hours.
- Forensic Analysis: Preserve logs for legal defense.
- Customer Notification: Comply with Section 44 of IT Act (inform affected users within 72 hours).
- Example:
"Khalti’s payment system was hacked. The attacker stole 10,000 customer records. What laws does Khalti violate, and what steps should they take?"
Answer:
Policy Implementation Diagrams:
- Example:
"Draw a flowchart showing how Nabil Bank enforces its ‘No Public Wi-Fi for Transactions’ policy."
flowchart TD A["Employee accesses banking portal"] --> B{"Is on Public Wi-Fi?"} B -->|"Yes"| C["Block access<br/>Alert IT"] B -->|"No"| D["Proceed to login"] C --> E["Log incident<br/>Escalate to manager"]
- Example:
"Draw a flowchart showing how Nabil Bank enforces its ‘No Public Wi-Fi for Transactions’ policy."
Case Study Analysis:
- Example:
"How did Daraz’s compliance with PCI DSS reduce fraud? What would happen if they ignored it?"
Answer:
- Reduction: Tokenization replaced card numbers with tokens, reducing stolen data value to hackers.
- Non-Compliance: Fines up to Rs. 100M (per IT Act) + loss of payment processor licenses (e.g., Visa/Mastercard penalties).
- Example:
"How did Daraz’s compliance with PCI DSS reduce fraud? What would happen if they ignored it?"
Answer:
Final Tip: Memorize 3 real-world examples (e.g., eSewa’s PCI DSS, Ncell’s ISO 27001, NRB’s cybersecurity directive) and 1 legal case (e.g., IT Act 2064 Section 43). Examiners love Nepal-specific applications!
Based on the TU BIM syllabus for Information Security (IT244), unit 10.
Discussion
Loading…