Foundation Of Information TechnologyUnit 910 min read
Information Security & Ethical IT Issues
Unit 9 of Foundation Of Information Technology: Explores cybersecurity principles (confidentiality, integrity, availability), ethical dilemmas in IT, legal frameworks (Nepal’s IT Act), and real-world threats (malware, phishing) with case studies from eSewa, NTC, and global tech giants.
TAKEAWAYS:
- Information security is built on CIA triad (Confidentiality, Integrity, Availability) and authentication (biometrics, passwords, tokens).
- Ethical IT balances privacy (GDPR, Nepal’s IT Act) with innovation, requiring transparency in data use (e.g., Daraz’s customer tracking).
- Malware (viruses, ransomware) exploits vulnerabilities like weak passwords or unpatched systems (seen in NTC’s 2022 breach).
- Social engineering (phishing, pretexting) targets human error—e.g., WhatsApp scams tricking users into sharing OTPs.
- Legal compliance (Nepal’s IT Act 2075) mandates data protection but lacks teeth; global firms like Google face stricter GDPR fines.
- Emerging threats (AI-driven attacks, IoT vulnerabilities) demand proactive defenses (e.g., Ncell’s SIM swap fraud prevention).
1. Defining Information Security
Information security protects data from unauthorized access, disclosure, alteration, or destruction. It relies on three core principles:
mindmap
root((Information Security))
CIA((CIA Triad))
Confidentiality((Keep data private))
- Encryption (AES, RSA)
- Access controls (RBAC, MAC)
Integrity((Prevent unauthorized changes))
- Hashing (SHA-256)
- Digital signatures
Availability((Ensure access when needed))
- Redundancy (RAID, cloud backups)
- DDoS protection
Authentication((Verify identity))
- Something you know (passwords)
- Something you have (smart cards)
- Something you are (fingerprint, iris)
Non-repudiation((Prove actions))
- Logs + digital signaturesWorked Example: eSewa’s Security eSewa uses multi-factor authentication (MFA) to prevent unauthorized transactions. When a user logs in, they must:
- Enter password (something you know).
- Scan fingerprint (something you are).
- Approve via SMS OTP (time-based one-time password). This combines confidentiality (passwords), authentication (biometrics), and non-repudiation (logs).
2. Types of Information Security Threats
Threats exploit weaknesses in systems. Classify them as:
| Category | Example | Impact | Real-World Case |
|---|---|---|---|
| Malware | Ransomware (Locky) | Encrypts files; demands payment | NTC’s 2022 data breach (ransomware) |
| Phishing | Fake login pages | Steals credentials | WhatsApp OTP scams (2023) |
| Social Engineering | Pretexting (fake support) | Manipulates users into disclosing data | Pathao driver scams (fake "manager") |
| Insider Threats | Disgruntled employees | Sabotage or data leaks | Google’s 2018 insider leak (100M emails) |
| Denial-of-Service | DDoS attacks | Crashes services | Daraz’s 2021 Black Friday outage |
| Hardware Tampering | Skimming devices | Steals card data | ATM skimmers in Kathmandu banks |
3. Ethical Issues in IT
Ethics governs moral principles in IT use. Key dilemmas include:
A. Privacy vs. Surveillance
- Privacy: Right to control personal data (e.g., eSewa’s transaction history).
- Surveillance: Government/marketers tracking data (e.g., NTC’s user location logs).
- Example: Nepal’s IT Act 2075 requires user consent for data collection but lacks enforcement. Compare to GDPR (EU), which fines companies up to 4% of global revenue for violations.
B. Intellectual Property (IP) Theft
- Plagiarism: Copying code (e.g., students submitting others’ projects).
- Software Piracy: Unauthorized use of licensed software (e.g., running cracked Windows in offices).
- Worked Example: Daraz’s Copyright Battle
Daraz sued a local seller for selling counterfeit Nike shoes via its platform. The case highlighted:
- Ethical duty: Daraz must moderate listings to prevent IP theft.
- Legal recourse: Nepal’s Copyright Act 2063 allows takedown requests.
C. Bias in AI/Algorithms
- Example: Pathao’s surge pricing algorithm may penalize low-income riders during peak hours, creating ethical concerns.
- Mitigation: Transparent algorithms and diversity in training data.
4. Legal Frameworks
A. Nepal’s IT Act 2075
- Key Provisions:
- Mandates data localization (sensitive data must stay in Nepal).
- Defines cybercrimes (e.g., hacking, identity theft) with penalties up to 10 years in prison.
- Requires user consent for data collection (but lacks enforcement mechanisms).
- Gap: No data protection authority to investigate breaches (unlike GDPR’s EDPB).
B. Global Standards (GDPR, CCPA)
| Law | Region | Key Requirement | Fine Example |
|---|---|---|---|
| GDPR | EU | Right to erasure; strict consent rules | Google fined €50M (2019) |
| CCPA | California | Right to opt-out of data sales | Facebook fined $5B (2023) |
| Nepal IT Act | Nepal | Data localization; vague enforcement | No major fines recorded yet |
5. Secure Coding Practices
Preventing vulnerabilities starts at the code level:
flowchart TD
A["Secure Coding Practices"] --> B["Input Validation"]
A --> C["Use Prepared Statements"]
A --> D["Encrypt Data"]
A --> E["Follow Principle of Least Privilege"]
A --> F["Regular Updates"]
B --> B1["Sanitize user input"]
B1 --> B1a["Prevent SQL injection"]
C --> C1["Parameterized queries"]
D --> D1["AES-256 for passwords"]
D --> D2["Hashing for sensitive data"]
E --> E1["Grant only required permissions"]
F --> F1["Patch vulnerabilities"]
F --> F2["Update libraries"]Worked Example: SQL Injection Vulnerability Unsafe Code (Nepalese bank’s old login system):
SELECT * FROM users WHERE username = '$_POST[username]' AND password = '$_POST[password]';
Attack: User enters admin' -- → Bypasses password check.
Secure Fix: Use prepared statements (PHP PDO):
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = ? AND password = ?");
$stmt->execute([$username, $password]);
6. Incident Response Plan
When a breach occurs, follow this NIST-recommended process:
sequenceDiagram
participant User
participant System
participant SOC
participant Legal
User->>System: Detect anomaly (e.g., unusual login)
System->>SOC: Trigger alert (SIEM tool)
SOC->>SOC: Isolate affected system
SOC->>Legal: Report to authorities (if cybercrime)
Legal->>Police: File complaint under IT Act 2075
SOC->>User: Notify stakeholders (if data exposed)Real-World Case: NTC’s 2022 Breach
- Incident: Ransomware encrypted NTC’s internal systems.
- Response:
- Containment: Isolated infected machines.
- Eradication: Reinstalled OS and patched vulnerabilities.
- Recovery: Restored from backups (no data loss).
- Lessons: Lack of automated backups delayed recovery.
7. Emerging Threats
A. AI-Driven Attacks
- Deepfake Phishing: AI-generated voice calls impersonating bosses (e.g., "Transfer funds to this account").
- Example: In 2023, a UK energy firm lost £243,000 to a deepfake CEO scam.
B. IoT Vulnerabilities
- Example: Ncell’s smart meters were hacked in 2022 due to default passwords on routers.
- Mitigation:
- Enable two-factor authentication on IoT devices.
- Segment IoT networks from corporate systems.
In the Real World
eSewa’s Two-Factor Authentication
- Idea Used: Multi-factor authentication (MFA) combining passwords, biometrics, and OTPs.
- Why It Matters: Prevents account takeovers during phishing attacks. When a user logs in from a new device, eSewa sends an OTP to their registered phone, enforcing availability (only authorized users access funds).
NTC’s SIM Swap Fraud Prevention
- Idea Used: Biometric verification for SIM registrations.
- Why It Matters: In 2021, Nepal saw 10,000+ SIM swap frauds where attackers hijacked users’ phone numbers. NTC now requires fingerprint verification during registration, addressing the authentication gap in the CIA triad.
Daraz’s Copyright Moderation
- Idea Used: Automated IP detection + human review.
- Why It Matters: Daraz uses hash-matching algorithms to flag counterfeit products (e.g., fake Nike shoes). This balances integrity (protecting brands) with availability (keeping the marketplace functional).
Exam Tip
- Focus on the CIA Triad: Always link security measures (e.g., encryption, firewalls) to confidentiality, integrity, or availability.
- Compare Legal Frameworks: Nepal’s IT Act is vague; contrast it with GDPR or CCPA for full marks.
- Worked Examples: Expect 1–2 questions with real-world scenarios (e.g., "How would you secure a bank’s ATM network?").
- Ethics Over Theory: Prioritize practical dilemmas (e.g., "Is it ethical for Pathao to track rider locations for ads?") over abstract definitions.
- Malware Types: Memorize ransomware, phishing, and social engineering—these appear in short-answer questions.
Sample Question Breakdown:
- Define: "Explain the CIA triad." → 1 mark each for confidentiality, integrity, availability.
- Apply: "How would you secure eSewa’s mobile app?" → 3 marks:
- MFA (2 marks).
- Encryption (1 mark).
- Regular audits (0.5 marks).
- Compare: "Differentiate GDPR and Nepal’s IT Act." → Table format (2 marks for 2 clear differences).
Based on the TU BITM syllabus for Foundation Of Information Technology (IT231), unit 9.
Discussion
Loading…