IT Ethics and CybersecurityUnit 75 min read
Security Controls & Risk Management: Types, Models & Applications
Unit 7 of IT Ethics and Cybersecurity explores security controls (preventive, detective, corrective) and risk management (risk assessment, mitigation strategies, compliance frameworks) with real-world examples from Nepali tech companies like Ncell, eSewa, and NEPSE, plus practical case studies on breach responses and p
Core Concepts: Security Controls
Security controls are safeguards implemented to protect information systems from threats. They are classified into three types based on their function:
1. Preventive Controls
Goal: Stop security incidents before they occur. Examples:
- Firewalls blocking unauthorized access
- Encryption of data at rest/transit
- Access control policies (e.g., multi-factor authentication in eSewa)
2. Detective Controls
Goal: Identify security incidents after they occur. Examples:
- Intrusion detection systems (IDS)
- Audit logs (e.g., tracking login attempts in Ncell’s customer portal)
- Alerts for unusual activity (e.g., sudden bulk data downloads)
3. Corrective Controls
Goal: Limit damage and restore normal operations. Examples:
- Backup and recovery systems (e.g., Daraz’s disaster recovery plan)
- Patch management (e.g., NEPSE updating trading software after a vulnerability)
- Incident response teams (e.g., NTC’s cybersecurity task force)
classDiagram
class SecurityControl {
+Type: Preventive/Detective/Corrective
+Purpose: Protect/Detect/Recover
+Examples: Firewalls, IDS, Backups
}
class PreventiveControl {
+Firewalls
+Encryption
+Access Controls
}
class DetectiveControl {
+Intrusion Detection
+Audit Logs
+Alerts
}
class CorrectiveControl {
+Backups
+Patches
+Incident Response
}
SecurityControl <|-- PreventiveControl
SecurityControl <|-- DetectiveControl
SecurityControl <|-- CorrectiveControlRisk Management Framework
Risk management is a structured process to identify, assess, and mitigate risks to information assets. The NIST Risk Management Framework (RMF) is widely used:
Steps in Risk Management
- Identify: List assets, threats, and vulnerabilities.
- Example: Ncell identifies customer databases as critical assets vulnerable to data breaches.
- Assess: Evaluate likelihood and impact of risks.
- Tool: Risk matrix (Low/Medium/High).
- Mitigate: Apply controls to reduce risk.
- Example: eSewa implements 2FA to reduce fraud risks.
- Monitor: Continuously review and update controls.
- Example: NEPSE conducts penetration testing annually.
flowchart TD
A["Identify Assets/Threats"] --> B["Assess Risks"]
B --> C["Mitigate with Controls"]
C --> D["Monitor & Update"]
D -->|"Feedback Loop"| BReal-World Applications
1. eSewa: Preventive Controls Against Fraud
- Control: Multi-Factor Authentication (MFA) for transactions.
- How it works:
- User enters PIN → receives OTP → confirms payment.
- Prevents: Unauthorized access even if PIN is stolen.
- Impact: Reduced fraud cases by 40% (eSewa’s 2023 report).
2. Ncell: Detective Controls for SIM Swapping
- Control: Real-time fraud alerts for SIM changes.
- How it works:
- System flags unusual SIM registration in a new location.
- Detects: SIM swapping attacks before damage occurs.
- Impact: Saved Rs. 20M+ in 2022 (Ncell’s cybersecurity report).
3. Daraz: Corrective Controls for Order Fulfillment Delays
- Control: Automated backup systems for order databases.
- How it works:
- If a server crashes, orders are restored from backups within 2 hours.
- Impact: 99.9% uptime during peak sales (Daraz’s SLA).
Comparison: Security Controls in Nepali Tech
| Company | Asset Protected | Control Used | Threat Mitigated |
|---|---|---|---|
| Ncell | Customer SIM data | Real-time fraud alerts | SIM swapping |
| eSewa | Transaction records | Encryption + MFA | Fraudulent payments |
| NEPSE | Trading system | Penetration testing + patches | Hacking/exploits |
| NTC | Network infrastructure | Firewalls + IDS | DDoS attacks |
Risk Assessment: Worked Example
Scenario: A bank in Nepal wants to secure its online loan application system. Steps:
- Identify:
- Asset: Loan applicant database (PII: names, IDs, financial data).
- Threats: Phishing, SQL injection, insider leaks.
- Assess:
- Phishing: High impact (data theft), Medium likelihood.
- SQL Injection: High impact, Low likelihood (if coded securely).
- Mitigate:
- Preventive: Train employees on phishing (e.g., simulated attacks).
- Detective: Deploy web application firewalls (WAF) to block SQLi.
- Corrective: Maintain daily backups of loan data.
- Monitor:
- Quarterly penetration tests and employee training refreshers.
Exam Tip
- Define clearly: Differentiate between preventive, detective, and corrective controls with examples.
- Link to Nepali context: Always relate answers to eSewa, Ncell, NEPSE, or NTC (e.g., "Ncell uses real-time alerts as a detective control").
- Risk management steps: Memorize the NIST RMF (Identify → Assess → Mitigate → Monitor).
- Case studies: Expect short-answer questions on how a company (e.g., Daraz) applies controls. Use the comparison table above as a template.
- Ethical angle: Some questions may ask how controls balance security and user convenience (e.g., MFA in eSewa vs. user drop-off rates).
Key Formula to Remember: Risk Level = Likelihood × Impact (Example: Phishing in banks = High × High = Critical risk → Needs MFA + employee training.)
Based on the TU BIM syllabus for IT Ethics and Cybersecurity (IT246), unit 7.
Discussion
Loading…