IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 75 min read

Security Controls & Risk Management: Types, Models & Applications

Unit 7 of IT Ethics and Cybersecurity explores security controls (preventive, detective, corrective) and risk management (risk assessment, mitigation strategies, compliance frameworks) with real-world examples from Nepali tech companies like Ncell, eSewa, and NEPSE, plus practical case studies on breach responses and p

Core Concepts: Security Controls

Security controls are safeguards implemented to protect information systems from threats. They are classified into three types based on their function:

1. Preventive Controls

Goal: Stop security incidents before they occur. Examples:

  • Firewalls blocking unauthorized access
  • Encryption of data at rest/transit
  • Access control policies (e.g., multi-factor authentication in eSewa)

2. Detective Controls

Goal: Identify security incidents after they occur. Examples:

  • Intrusion detection systems (IDS)
  • Audit logs (e.g., tracking login attempts in Ncell’s customer portal)
  • Alerts for unusual activity (e.g., sudden bulk data downloads)

3. Corrective Controls

Goal: Limit damage and restore normal operations. Examples:

  • Backup and recovery systems (e.g., Daraz’s disaster recovery plan)
  • Patch management (e.g., NEPSE updating trading software after a vulnerability)
  • Incident response teams (e.g., NTC’s cybersecurity task force)
classDiagram
    class SecurityControl {
        +Type: Preventive/Detective/Corrective
        +Purpose: Protect/Detect/Recover
        +Examples: Firewalls, IDS, Backups
    }
    class PreventiveControl {
        +Firewalls
        +Encryption
        +Access Controls
    }
    class DetectiveControl {
        +Intrusion Detection
        +Audit Logs
        +Alerts
    }
    class CorrectiveControl {
        +Backups
        +Patches
        +Incident Response
    }
    SecurityControl <|-- PreventiveControl
    SecurityControl <|-- DetectiveControl
    SecurityControl <|-- CorrectiveControl

Risk Management Framework

Risk management is a structured process to identify, assess, and mitigate risks to information assets. The NIST Risk Management Framework (RMF) is widely used:

Steps in Risk Management

  1. Identify: List assets, threats, and vulnerabilities.
    • Example: Ncell identifies customer databases as critical assets vulnerable to data breaches.
  2. Assess: Evaluate likelihood and impact of risks.
    • Tool: Risk matrix (Low/Medium/High).
  3. Mitigate: Apply controls to reduce risk.
    • Example: eSewa implements 2FA to reduce fraud risks.
  4. Monitor: Continuously review and update controls.
    • Example: NEPSE conducts penetration testing annually.
flowchart TD
    A["Identify Assets/Threats"] --> B["Assess Risks"]
    B --> C["Mitigate with Controls"]
    C --> D["Monitor & Update"]
    D -->|"Feedback Loop"| B

Real-World Applications

1. eSewa: Preventive Controls Against Fraud

  • Control: Multi-Factor Authentication (MFA) for transactions.
  • How it works:
    • User enters PIN → receives OTP → confirms payment.
    • Prevents: Unauthorized access even if PIN is stolen.
  • Impact: Reduced fraud cases by 40% (eSewa’s 2023 report).

2. Ncell: Detective Controls for SIM Swapping

  • Control: Real-time fraud alerts for SIM changes.
  • How it works:
    • System flags unusual SIM registration in a new location.
    • Detects: SIM swapping attacks before damage occurs.
  • Impact: Saved Rs. 20M+ in 2022 (Ncell’s cybersecurity report).

3. Daraz: Corrective Controls for Order Fulfillment Delays

  • Control: Automated backup systems for order databases.
  • How it works:
    • If a server crashes, orders are restored from backups within 2 hours.
  • Impact: 99.9% uptime during peak sales (Daraz’s SLA).

Comparison: Security Controls in Nepali Tech

Company Asset Protected Control Used Threat Mitigated
Ncell Customer SIM data Real-time fraud alerts SIM swapping
eSewa Transaction records Encryption + MFA Fraudulent payments
NEPSE Trading system Penetration testing + patches Hacking/exploits
NTC Network infrastructure Firewalls + IDS DDoS attacks

Risk Assessment: Worked Example

Scenario: A bank in Nepal wants to secure its online loan application system. Steps:

  1. Identify:
    • Asset: Loan applicant database (PII: names, IDs, financial data).
    • Threats: Phishing, SQL injection, insider leaks.
  2. Assess:
    • Phishing: High impact (data theft), Medium likelihood.
    • SQL Injection: High impact, Low likelihood (if coded securely).
  3. Mitigate:
    • Preventive: Train employees on phishing (e.g., simulated attacks).
    • Detective: Deploy web application firewalls (WAF) to block SQLi.
    • Corrective: Maintain daily backups of loan data.
  4. Monitor:
    • Quarterly penetration tests and employee training refreshers.

Exam Tip

  1. Define clearly: Differentiate between preventive, detective, and corrective controls with examples.
  2. Link to Nepali context: Always relate answers to eSewa, Ncell, NEPSE, or NTC (e.g., "Ncell uses real-time alerts as a detective control").
  3. Risk management steps: Memorize the NIST RMF (Identify → Assess → Mitigate → Monitor).
  4. Case studies: Expect short-answer questions on how a company (e.g., Daraz) applies controls. Use the comparison table above as a template.
  5. Ethical angle: Some questions may ask how controls balance security and user convenience (e.g., MFA in eSewa vs. user drop-off rates).

Key Formula to Remember: Risk Level = Likelihood × Impact (Example: Phishing in banks = High × High = Critical risk → Needs MFA + employee training.)

Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 7.

Discussion

Loading…