Information SecurityUnit 110 min read
InfoSec Basics: CIA Triad, Threats, Risks & Security Models
Unit 1 of Information Security introduces core concepts like the CIA triad (Confidentiality, Integrity, Availability), security threats, risk management, and foundational security models (Bell-LaPadula, Biba, Clark-Wilson). It explains how organizations protect data, classify assets, and implement security policies in
What is Information Security?
Information Security (InfoSec) is the practice of protecting information (data, software, hardware) from unauthorized access, disclosure, alteration, or destruction. It ensures that systems and data remain confidential, integral, and available (CIA triad) while supporting business operations.
Why is InfoSec Important?
- Data breaches (e.g., stolen customer records) can cost millions (e.g., Nepal’s Ncell data leak in 2021 exposed 10M+ users).
- Financial loss: Fraud, ransomware (e.g., Daraz suppliers hit by malware).
- Reputation damage: Trust is lost if users’ data is compromised (e.g., eSewa hack in 2022).
- Legal compliance: Laws like Nepal’s Electronic Transactions Act (2008) mandate data protection.
The CIA Triad: Core Principles
The CIA triad defines the three pillars of InfoSec:
| Principle | Definition | Example in Nepal |
|---|---|---|
| Confidentiality | Ensures data is accessible only to authorized users. | Ncell encrypts customer call logs so only authorized staff can access them. |
| Integrity | Ensures data is accurate and unaltered. | Nepal Stock Exchange (NEPSE) uses digital signatures to prevent tampering with trade records. |
| Availability | Ensures systems and data are accessible when needed. | eSewa has backup servers to prevent downtime during peak transactions (e.g., Dashain). |
Worked Example:
- Scenario: A Khalti user reports that their transaction history was changed.
- Confidentiality violated? No (only the user could see it).
- Integrity violated? Yes (data was altered).
- Availability violated? No (data was still accessible).
Security Threats and Vulnerabilities
Threats exploit vulnerabilities in systems. Common threats include:
1. Types of Threats
mindmap
root((Security Threats))
Human Errors
Phishing["Emails like 'Your Khalti account is locked'"]
Misconfiguration["Weak passwords in Daraz supplier dashboards"]
Malicious Attacks
Cyberattacks["DDoS on NTC website during exams"]
Insider Threats["Employee stealing Ncell customer data"]
Natural Disasters
Floods["Data center in Kathmandu submerged in 2022"]
Fires["Server room fire at a Nepalese bank"]2. Vulnerabilities vs. Threats vs. Risks
| Term | Definition | Example |
|---|---|---|
| Vulnerability | Weakness in a system (e.g., unpatched software). | Old Windows OS on a bank’s server with no updates. |
| Threat | Potential danger (e.g., hackers, viruses). | Ransomware targeting Pathao’s delivery partner app. |
| Risk | Likelihood × Impact of a threat exploiting a vulnerability. | High risk: If Pathao’s app is hacked, delivery routes and customer data are exposed. |
Worked Example:
- Threat: A hacker tries to brute-force a Daraz seller’s login.
- Vulnerability: The seller uses
password123. - Risk: If successful, the hacker could change shipping addresses for fraud.
Risk Management Process
Organizations use a structured approach to manage risks:
flowchart TD A["Identify Assets"] --> B["Identify Threats & Vulnerabilities"] B --> C["Assess Risks"] C --> D["Mitigate Risks"] D --> E["Monitor & Review"]
Steps Explained
- Identify Assets
- What needs protection? (e.g., NEPSE’s trading data, Ncell’s customer database).
- Identify Threats & Vulnerabilities
- Example: SQL injection in a bank’s login page.
- Assess Risks
- Likelihood: High (many users).
- Impact: Critical (financial loss).
- Mitigate Risks
- Controls:
- Preventive: Firewalls, encryption.
- Detective: Intrusion detection systems (IDS).
- Corrective: Backup systems.
- Controls:
- Monitor & Review
- Regular audits (e.g., Nepal Rastra Bank’s financial security checks).
Security Models and Policies
Security models define how access is controlled. Three key models:
1. Bell-LaPadula Model (Confidentiality)
- Rule: No read-up, no write-down.
- Use Case: Military/Government systems (e.g., Nepal Army’s classified data).
- Example:
- A Classified file can only be read by Secret or Classified users.
- A Secret user cannot write to a Top Secret file.
2. Biba Model (Integrity)
- Rule: No read-down, no write-up.
- Use Case: Database systems (e.g., NEPSE’s trade records).
- Example:
- A Low-integrity user cannot read High-integrity data.
- Prevents Trojan horses from corrupting critical data.
3. Clark-Wilson Model (Commercial Integrity)
- Rule: Separation of duties + well-formed transactions.
- Use Case: Banking systems (e.g., Nabil Bank’s loan processing).
- Example:
- Two people must approve a loan (prevents fraud).
Comparison Table:
| Model | Focus | Key Rule | Example Use Case |
|---|---|---|---|
| Bell-LaPadula | Confidentiality | No read-up, no write-down | Government databases |
| Biba | Integrity | No read-down, no write-up | Financial transaction logs |
| Clark-Wilson | Commercial Integrity | Separation of duties | Bank loan approval systems |
Security Policies and Standards
Organizations follow policies and standards to enforce security:
1. Types of Security Policies
mindmap
root((Security Policies))
Program-Level["High-level goals (e.g., 'Protect customer data')"]
Issue-Specific["Handles a single issue (e.g., 'Password policy')"]
System-Specific["Covers a system (e.g., 'Ncell network security')"]
Organization-Defining["Overall security framework (e.g., 'Nepal Rastra Bank’s IT policy')"]2. Common Standards
| Standard | Description | Example in Nepal |
|---|---|---|
| ISO 27001 | International security management standard. | Nepal’s banks follow this for cybersecurity. |
| NIST Framework | Risk management guidelines. | NTC’s network security planning. |
| PCI DSS | Payment Card Industry security standard. | eSewa & Khalti comply for online payments. |
In the Real World
eSewa’s Two-Factor Authentication (2FA)
- Idea Used: Authentication (CIA Triad’s Confidentiality)
- How? After entering a password, users get a one-time SMS code (prevents unauthorized access even if password is stolen).
Ncell’s Encrypted Call Logs
- Idea Used: Confidentiality (Bell-LaPadula Model)
- How? Customer call data is encrypted at rest and in transit, so only authorized staff can decrypt it (following Nepal Telecom Authority’s regulations).
NEPSE’s Digital Signatures for Trades
- Idea Used: Integrity (Biba Model)
- How? Traders must digitally sign orders to prevent fake trades (e.g., someone altering a buy/sell order).
Pathao’s Driver Verification System
- Idea Used: Access Control (Clark-Wilson Model)
- How? Two checks are required:
- Background verification (prevents fraudulent drivers).
- GPS-based location checks (ensures drivers are where they claim to be).
Exam Tip
What Examiners Look For
✅ CIA Triad: Always explain all three principles in answers (e.g., "A DDoS attack violates Availability"). ✅ Threats vs. Vulnerabilities vs. Risks: Define clearly and give real-world examples (e.g., "Weak passwords are a vulnerability; brute-force attacks are a threat"). ✅ Security Models: Know Bell-LaPadula (confidentiality), Biba (integrity), and Clark-Wilson (commercial integrity). Compare them in tables. ✅ Risk Management Steps: Memorize the 5-step process (Identify → Assess → Mitigate → Monitor). ✅ Policies & Standards: Link ISO 27001 to banks, PCI DSS to eSewa/Khalti, and NIST to NTC.
Common Mistakes to Avoid
❌ Mixing up confidentiality and integrity (e.g., saying "encryption ensures integrity" – wrong! Encryption ensures confidentiality). ❌ Ignoring real-world examples – Always tie answers to Nepalese companies (e.g., Ncell, eSewa, NEPSE). ❌ Overlooking the CIA triad in case studies – If a question describes a breach, ask: Which CIA principle was violated?
Practice Question (TU-style)
Question: "A hacker gains access to a bank’s database by exploiting a misconfigured firewall. Identify the threat, vulnerability, and risk. Which CIA principle is violated? Suggest two security controls to prevent this."
Model Answer:
- Threat: Unauthorized access (cyberattack).
- Vulnerability: Misconfigured firewall (weak security setting).
- Risk: High (financial data exposure, fraud).
- CIA Principle Violated: Confidentiality (data accessed by unauthorized users).
- Security Controls:
- Firewall hardening (block unnecessary ports).
- Intrusion Detection System (IDS) to detect and alert on suspicious activity.
How NEPSE traders sign orders digitally. (Image: Wikisosh, CC BY-SA 4.0, via Wikimedia Commons)
Based on the TU BITM syllabus for Information Security (IT244), unit 1.
Discussion
Loading…