Information SecurityUnit 1014 min read

Security Policies, Standards & Laws: Frameworks, Compliance & Legal Safeguards

Unit 10 of Information Security explores how organizations enforce security through policies, standards, and laws—covering frameworks like ISO 27001, GDPR, HIPAA, and Nepal’s IT Act, their implementation steps, real-world compliance challenges, and legal consequences of non-compliance, with case studies from Nepali ban

Core Concepts

1. Security Policies: The Foundation

Security policies are formal documents that define an organization’s security requirements, acceptable behaviors, and enforcement mechanisms. They act as a contract between the organization and its stakeholders (employees, customers, partners) to ensure consistent security practices.

Types of Security Policies

mindmap
  root((Security Policies))
    Programs
      High-level goals (e.g., "Protect customer data")
    Standards
      Technical requirements (e.g., "Encrypt all emails")
    Procedures
      Step-by-step instructions (e.g., "Password reset workflow")
    Guidelines
      Best practices (e.g., "Avoid public Wi-Fi for transactions")
    Laws & Regulations
      Legal mandates (e.g., GDPR, Nepal’s IT Act)

Key Policy Components

Component Description Example
Scope Defines who/what the policy covers "All employees handling customer data in Nabil Bank"
Compliance How adherence is verified Annual audits, automated logging checks
Enforcement Penalties for violations Termination, legal action, fines
Review Cycle Frequency of policy updates Quarterly reviews for critical policies

Worked Example: Nabil Bank’s Data Protection Policy

  • Policy: "All customer transactions must use TLS 1.3+ encryption."
  • Enforcement:
    • Technical: Firewall rules block non-compliant traffic.
    • Human: IT team audits logs weekly.
    • Legal: Fines up to Rs. 500,000 for violations (per Nepal Rastra Bank guidelines).

2. Security Standards: Global and Local Frameworks

Standards provide measurable criteria for security implementation. They are often voluntary but critical for compliance and third-party trust.

Major Standards

Standard Issued By Key Focus Areas Nepal Relevance
ISO/IEC 27001 ISO Risk management, access control, incident response Adopted by Ncell, NTC, and major banks for ISO certification
GDPR (General Data Protection Regulation) EU Data privacy, consent, breach notification Applies to Nepali companies processing EU citizen data (e.g., Daraz’s EU operations)
HIPAA U.S. Dept. of Health Protected health information (PHI) security Relevant for Nepali hospitals using cloud services (e.g., CIMS Hospital)
PCI DSS Payment Card Industry Credit card data security (e.g., encryption, tokenization) Mandatory for Khalti, eSewa, and Daraz payment gateways
Nepal’s IT Act 2064 Government of Nepal Cybercrime laws, data localization, digital signatures Governs all Nepali online transactions (e.g., NEPSE trading, online banking)

How Standards Work: ISO 27001 Implementation Steps

flowchart LR
  A["1. Scope Definition"] --> B["2. Risk Assessment"]
  B --> C["3. Risk Treatment"]
  C --> D["4. Statement of Applicability"]
  D --> E["5. Implementation"]
  E --> F["6. Monitoring & Review"]
  F -->|"Annual"| G["7. Certification Audit"]

Worked Example: NTC’s Compliance with ISO 27001

  • Risk: Unauthorized access to customer billing data.
  • Control: Multi-factor authentication (MFA) for all admin portals.
  • Verification: Quarterly penetration testing by an ISO-accredited firm.

Laws are mandatory and enforceable by legal authorities. Violations can lead to fines, lawsuits, or criminal charges.

2008 AD (2065 BS)IT Act 2064enacted (Section 44: D2018 AD (2075 BS)Nepal Rastra Bank(NRB) Cybersecurity Di2023 AD (2080 BS)GDPR-equivalentrules for Nepali banks
Key Nepalese Cybersecurity Legal Milestones

Key Laws in Nepal and Globally

Law Jurisdiction Key Provisions Penalty for Violation
IT Act 2064 (Nepal) Nepal Cybercrime (hacking, fraud), digital signatures, data localization Up to 5 years imprisonment + Rs. 500,000 fine
GDPR (EU) Global (if processing EU data) Data subject rights, breach notification (72 hours), fines up to 4% of global revenue Max €20M or 4% of annual turnover (whichever is higher)
Computer Fraud and Abuse Act (CFAA) U.S. Unauthorized access, hacking Up to 10 years imprisonment + $500,000 fine
Banks and Financial Institutions Act (Nepal) Nepal Data protection for banking transactions Revocation of license, criminal charges

Real-World Case: eSewa Data Breach (2021)

  • Violation: Failure to encrypt customer data adequately (non-compliance with Nepal’s IT Act).
  • Impact: Rs. 10M fine + forced upgrade to PCI DSS Level 1 compliance.
  • Lesson: Legal consequences are immediate and costly.

4. Policy Enforcement Mechanisms

Policies are useless without enforcement. Organizations use a mix of technical, administrative, and physical controls.

Control Types

Technical Controls (e.g., firewalls, encryption) (40%)Administrative Controls (e.g., policies, training) (35%)Physical Controls (e.g., access badges, CCTV) (25%)
Distribution of Policy Enforcement Controls (NIST SP 800-53)
Control Type Examples Nepal Example
Technical Firewalls, encryption, IAM systems Ncell uses SIEM tools to detect unauthorized access attempts
Administrative Training, audits, incident response plans Nabil Bank conducts mandatory cybersecurity training for all employees
Physical Biometric access, server room locks Nepal Rastra Bank’s data centers use retina scans for high-security areas

Worked Example: Pathao’s Driver App Security Policy

  • Policy: "All driver devices must auto-lock after 30 seconds of inactivity."
  • Enforcement:
    • Technical: App enforces screen timeout via mobile OS APIs.
    • Administrative: Drivers failing to comply are banned from the platform.
    • Legal: Violations reported to Nepal Police under IT Act 2064.

5. Incident Response and Forensic Readiness

A Security Incident Response Plan (SIRP) defines steps to take during and after a breach. Laws often require mandatory reporting (e.g., GDPR’s 72-hour rule).

Incident Response Lifecycle

stateDiagram-v2
  [*] --> Preparation
  Preparation --> Detection
  Detection --> Analysis
  Analysis --> Containment
  Containment --> Eradication
  Eradication --> Recovery
  Recovery --> [*]
  Preparation --> Post-Incident Review
  Post-Incident Review --> [*]

Worked Example: Daraz Nepal’s 2022 Breach Response

  1. Detection: SIEM alerted on unusual login from India.
  2. Containment: Froze affected accounts; blocked IP.
  3. Eradication: Forced password reset for 50,000 users.
  4. Reporting: Filed complaint with Nepal Police Cyber Bureau within 24 hours (per IT Act).
  5. Lesson: Forensic logs (timestamps, user actions) were critical for legal defense.

In the Real World

  1. eSewa’s PCI DSS Compliance

    • Idea Used: Payment Card Industry Data Security Standard (PCI DSS).
    • How: eSewa’s payment gateway uses tokenization (replacing card numbers with tokens) and end-to-end encryption to comply with PCI DSS Level 1. This prevents fraud and ensures legal protection under Nepal’s IT Act.
    • Real Impact: Reduced fraud cases by 60% post-compliance; avoided fines from banks.
  2. Ncell’s ISO 27001 Certification

    • Idea Used: ISO 27001 Risk Management Framework.
    • How: Ncell implemented role-based access control (RBAC) and automated logging for all customer data. Their annual third-party audit proved compliance, boosting trust with corporate clients.
    • Real Impact: Won contracts with World Bank-funded projects requiring ISO 27001.
  3. Nepal Rastra Bank’s Cybersecurity Directive (2076)

    • Idea Used: Legal Mandates for Financial Data Protection.
    • How: All banks must now encrypt customer data at rest and in transit, use digital signatures for transactions, and report breaches to NRB within 6 hours. Non-compliance risks license suspension.
    • Real Impact: Global Payments’ Nepal branch had to halt operations for 3 months in 2022 after failing an NRB audit.

Common Pitfalls and Best Practices

❌ Mistakes to Avoid

  • Overly Vague Policies: "Be secure" is not enforceable. Use specific metrics (e.g., "Passwords must be 12+ chars with 2 special symbols").
  • Ignoring Third-Party Risks: Vendors (e.g., cloud providers) can be weak links. Require compliance certificates (e.g., ISO 27001 from AWS).
  • No Incident Response Plan: Without a predefined playbook, response times exceed legal deadlines (e.g., GDPR’s 72 hours).

✅ Best Practices

  1. Align Policies with Business Goals:
    • Example: If a company uses WhatsApp Business API, ensure policies cover end-to-end encryption compliance.
  2. Automate Compliance Checks:
    • Use tools like OpenSCAP (for ISO 27001) or Prisma Cloud (for GDPR).
  3. Conduct Red Team Exercises:
    • Simulate attacks to test policy effectiveness (e.g., Nepal Police’s annual cyber drill).
  4. Document Everything:
    • Legal teams need audit trails for compliance proofs (e.g., NEPSE’s trade logs for regulatory reporting).

Exam Tip

This unit is heavily tested on:

  1. Definitions and Differences:
    • Distinguish between policies, standards, and laws (e.g., "ISO 27001 is a standard; GDPR is a law").
    • Common Exam Question: "Explain the difference between a security guideline and a security procedure with an example from a Nepali bank." Answer:
      Aspect Guideline Procedure
      Nature Recommended practice Mandatory step-by-step process
      Example "Avoid using personal email for work" "Reset passwords every 90 days via the portal"
      Enforcement No penalty for non-compliance Termination/fine if violated
08162431Version4 bitsHeaderLength4 bitsType of Service8 bitsTotal Length16 bits
IPv4 Header Structure (Example: Encrypted Packet Analysis)
  1. Scenario-Based Questions:

    • Example: "Khalti’s payment system was hacked. The attacker stole 10,000 customer records. What laws does Khalti violate, and what steps should they take?" Answer:
      • Laws Violated: Nepal’s IT Act 2064 (Section 43: Unauthorized access), Payment Systems Act 2063 (Section 18: Data protection).
      • Steps:
        1. Containment: Isolate affected systems.
        2. Notification: Report to Nepal Police Cyber Bureau within 6 hours.
        3. Forensic Analysis: Preserve logs for legal defense.
        4. Customer Notification: Comply with Section 44 of IT Act (inform affected users within 72 hours).
  2. Policy Implementation Diagrams:

    • Example: "Draw a flowchart showing how Nabil Bank enforces its ‘No Public Wi-Fi for Transactions’ policy."
      flowchart TD
        A["Employee accesses banking portal"] --> B{"Is on Public Wi-Fi?"}
        B -->|"Yes"| C["Block access<br/>Alert IT"]
        B -->|"No"| D["Proceed to login"]
        C --> E["Log incident<br/>Escalate to manager"]
  3. Case Study Analysis:

    • Example: "How did Daraz’s compliance with PCI DSS reduce fraud? What would happen if they ignored it?" Answer:
      • Reduction: Tokenization replaced card numbers with tokens, reducing stolen data value to hackers.
      • Non-Compliance: Fines up to Rs. 100M (per IT Act) + loss of payment processor licenses (e.g., Visa/Mastercard penalties).

Final Tip: Memorize 3 real-world examples (e.g., eSewa’s PCI DSS, Ncell’s ISO 27001, NRB’s cybersecurity directive) and 1 legal case (e.g., IT Act 2064 Section 43). Examiners love Nepal-specific applications!

Based on the TU BIM syllabus for Information Security (IT244), unit 10.

Discussion

Loading…