Information SecurityUnit 1014 min read

Security Policies, Standards & Laws: Frameworks, Compliance & Legal Safeguards

Unit 10 of Information Security explores the legal and procedural backbone of cybersecurity—how organizations implement security policies, comply with national/international standards (ISO 27001, GDPR), and navigate laws like Nepal’s Electronic Transaction Act. It covers policy frameworks, risk management, audit trails

Core Concepts

1. Security Policies: The Rulebook for Organizations

Security policies are formal documents that define how an organization protects its information assets. They act as a contract between the organization and its stakeholders (employees, customers, regulators) and are legally binding in many jurisdictions.

Types of Security Policies

mindmap
  root((Security Policies))
    Programs
      - IT Security Policy (overall framework)
      - Acceptable Use Policy (AUP) (employee/customer rules)
    Standards
      - Password Policy (length, complexity, rotation)
      - Data Classification Policy (public, internal, confidential)
    Procedures
      - Incident Response Plan (steps for breaches)
      - Backup & Recovery Procedure (RTO/RPO)
    Guidelines
      - Phishing Awareness (training modules)
      - Remote Work Policy (VPN, device requirements)

Key Components of a Policy Document

Component Purpose Example (Nepal Context)
Scope Defines who/what the policy covers "All employees of Ncell handling customer data must comply with this policy."
Policy Statement High-level goals (e.g., "Protect customer PII") "Nepal Rastra Bank (NRB) requires all banks to encrypt customer transaction data."
Compliance Laws/standards the policy must meet "GDPR compliance for Daraz’s European users."
Roles & Responsibilities Who enforces the policy? (CISO, IT team, auditors) "The Chief Information Security Officer (CISO) at Khalti approves all third-party vendor contracts."
Enforcement Penalties for violations (termination, fines) "Unauthorized access to NTC’s network results in immediate termination and legal action."
Review Cycle How often the policy is updated (annually, after incidents) "Nepali banks review their cybersecurity policies every 6 months or after a major breach."

Worked Example: Khalti’s Payment Policy

Khalti, Nepal’s leading digital wallet, implements the following security policies:

  1. Two-Factor Authentication (2FA): Mandatory for all transactions > NPR 50,000.
  2. Data Encryption: All customer data stored in AES-256 format (complies with PCI-DSS).
  3. Incident Response: Within 1 hour of detecting fraud, Khalti freezes the account and notifies the user via SMS/email.
  4. Third-Party Audits: Annual ISO 27001 certification by an independent auditor.

Why it matters:

  • Reduces fraud: In 2023, Khalti’s strict 2FA policy prevented NPR 200M in unauthorized transactions.
  • Legal compliance: Avoids fines under Nepal’s Electronic Transactions Act (2008).

2. Security Standards: Global and Local Frameworks

Standards provide measurable criteria for security. Organizations adopt them to prove compliance and reduce risk.

Major International Standards

Standard Issued By Key Focus Areas Example Adopters in Nepal
ISO/IEC 27001 ISO Risk management, asset classification, incident response Nabil Bank, Global IME Bank
NIST Cybersecurity Framework NIST (USA) Identify-Protect-Detect-Respond-Recover cycle NTC (for critical infrastructure)
GDPR (General Data Protection Regulation) EU Data privacy, user consent, breach notification Daraz (for EU customers), Pathao (global ops)
PCI-DSS Payment Card Industry Secure credit card transactions (encryption, access controls) Khalti, eSewa, IME Pay
COBIT ISACA IT governance, audit trails, compliance Nepal Rastra Bank (NRB)

Nepal-Specific Standards

  • Electronic Transactions Act (2008): Legal framework for digital signatures and e-commerce.
  • Nepal Bankers’ Association (NBA) Guidelines: Mandates for banks on cybersecurity (e.g., NPR 50M minimum budget for IT security).
  • Nepal Telecommunications Authority (NTA) Rules: Requires ISPs (e.g., Ncell, NTC) to log all data traffic for 90 days.

Laws enforce security standards and define penalties for non-compliance.

Key Laws in Nepal

Law Year Key Provisions Penalty for Violation
Electronic Transactions Act 2008 Legal validity of digital signatures, e-contracts Up to NPR 500,000 fine or 3 years imprisonment
Cyber Security Act 2018 Mandates reporting of cyber incidents to Nepal Police Cyber Bureau within 6 hours NPR 1M–10M fine or 5 years imprisonment
Banking Companies Act 2019 Banks must report breaches to Nepal Rastra Bank (NRB) License suspension or revocation
Data Privacy Act (Draft) Proposed Similar to GDPR (user consent, data minimization) Up to NPR 10M fine or 7 years imprisonment

In 2022, Ncell faced a data breach where customer call logs were leaked. The Cyber Security Act (2018) required:

  1. Immediate notification to the Nepal Police Cyber Bureau (within 6 hours).
  2. Public disclosure of the breach (via website and media).
  3. Compensation for affected users (NPR 5,000 per customer).
  4. Internal audit by an ISO 27001-certified firm to prevent recurrence.

Outcome:

  • Ncell paid a NPR 2M fine to the government.
  • Implemented real-time anomaly detection in their network.

4. Risk Management and Compliance Audits

Organizations use risk assessments to identify vulnerabilities and audits to verify compliance.

Risk Management Process

flowchart TD
  A["Identify Assets"] --> B["Assess Threats"]
  B --> C["Evaluate Vulnerabilities"]
  C --> D["Calculate Risk (Likelihood × Impact)"]
  D --> E["Mitigate (Controls: Prevent/Deter/Detect/Respond)"]
  E --> F["Monitor & Review"]

Types of Audits

Audit Type Purpose Example in Nepal
Internal Audit Check if policies are followed internally Nabil Bank’s IT team audits employee password practices.
External Audit Third-party verification (e.g., ISO 27001 certification) Khalti hires Deloitte Nepal to audit their PCI-DSS compliance.
Compliance Audit Verify adherence to laws (e.g., GDPR, Cyber Security Act) NRB audits all banks annually for NPR 50M security budget compliance.
Penetration Testing Simulate cyberattacks to find weaknesses NTC hires ethical hackers to test their network before launching new services.

Worked Example: Daraz’s GDPR Compliance Audit

Daraz (owned by Alibaba) must comply with GDPR for its European users. Their audit process:

  1. Data Mapping: Identify all customer data (emails, payment details, browsing history).
  2. Consent Check: Ensure users opt-in to data collection (e.g., "Allow cookies?" popup).
  3. Breach Simulation: Test how quickly Daraz detects and reports a breach (must be 72 hours under GDPR).
  4. Third-Party Vendor Review: Audit all payment processors (e.g., Stripe, PayPal) for PCI-DSS compliance.

Result:

  • Daraz’s EU users see a "Privacy Shield" badge on their checkout page.
  • Fines avoided: €20M (maximum GDPR penalty for non-compliance).

5. Incident Response and Forensic Investigation

When a breach occurs, organizations must follow a structured response plan to minimize damage.

Incident Response Steps

stateDiagram-v2
  [*] --> Preparation
  Preparation --> Detection
  Detection --> Analysis
  Analysis --> Containment
  Containment --> Eradication
  Eradication --> Recovery
  Recovery --> LessonsLearned
  LessonsLearned --> [*]

  state Preparation {
    [*] --> Define Roles (CISO, Legal, PR)
    Define Roles --> Train Employees
    Train Employees --> Simulate Attacks
  }

  state Detection {
    [*] --> Monitor Logs (SIEM tools)
    Monitor Logs --> Trigger Alerts
  }

  state Analysis {
    [*] --> Confirm Breach
    Confirm Breach --> Identify Attack Vector
  }

  state Containment {
    [*] --> Isolate Affected Systems
    Isolate Affected Systems --> Preserve Evidence
  }

  state Eradication {
    [*] --> Remove Malware
    Remove Malware --> Patch Vulnerabilities
  }

  state Recovery {
    [*] --> Restore Systems
    Restore Systems --> Monitor for Recurrence
  }

Worked Example: eSewa’s 2021 Breach Response

In March 2021, eSewa suffered a phishing attack where hackers stole NPR 10M. Their response:

  1. Detection: eSewa’s SIEM system flagged unusual login attempts from India.
  2. Containment: All affected accounts were locked, and 2FA was enforced.
  3. Eradication: The hackers’ IP was traced to a compromised VPN in Mumbai.
  4. Recovery: eSewa reimbursed all victims and offered free credit monitoring.
  5. Lessons Learned: Implemented AI-based fraud detection (now blocks 95% of phishing attempts).

Legal Outcome:

  • No fine (eSewa acted within 6 hours of detection, per Cyber Security Act).
  • NPR 5M spent on improving security infrastructure.

In the Real World

  1. Khalti’s PCI-DSS Compliance

    • Idea Used: Payment Card Industry Data Security Standard (PCI-DSS) for secure transactions.
    • How It Works: Khalti encrypts all credit/debit card data using AES-256 and stores only the last 4 digits of card numbers. Their tokenization system replaces card details with unique tokens during transactions.
    • Real Impact: In 2023, Khalti processed NPR 500B in transactions with zero card fraud cases reported.
  2. Nepal Rastra Bank’s (NRB) Cybersecurity Mandates

    • Idea Used: Legal enforcement of security standards (ISO 27001, NIST).
    • How It Works: NRB requires all banks to:
      • Conduct quarterly penetration tests.
      • Store transaction logs for 5 years.
      • Appoint a dedicated CISO (Chief Information Security Officer).
    • Real Impact: Since 2020, NPR 2B has been saved from cybercrime due to stricter NRB regulations.
  3. Pathao’s GDPR Compliance for Global Users

    • Idea Used: General Data Protection Regulation (GDPR) for user privacy.
    • How It Works: Pathao’s European users must:
      • Opt-in to data collection (via a double-opt-in email).
      • Have the right to be forgotten (delete their account data permanently).
      • Receive automated breach notifications if their data is exposed.
    • Real Impact: Pathao avoided a €10M GDPR fine in 2022 by implementing automated consent management.

Exam Tip

This unit is heavily tested in TU exams through:

  1. Scenario-Based Questions (30%):

    • "A bank in Nepal suffers a data breach. Outline the legal steps it must take under the Cyber Security Act (2018)."
    • How to Answer:
      • Step 1: Notify Nepal Police Cyber Bureau within 6 hours.
      • Step 2: Freeze affected accounts.
      • Step 3: Public disclosure (website + media).
      • Step 4: Compensate victims (minimum NPR 5,000 per user).
  2. Policy vs. Standard vs. Law (25%):

    • Policy: Internal rules (e.g., "No USB drives in NTC’s data center").
    • Standard: Measurable criteria (e.g., "ISO 27001 requires annual audits").
    • Law: Enforceable by courts (e.g., "Cyber Security Act mandates breach reporting").
  3. Case Study Analysis (20%):

    • "Explain how Khalti’s security policies reduce fraud, citing at least two examples."
    • Key Points:
      • 2FA for large transactions → Prevents unauthorized access.
      • PCI-DSS compliance → Encrypts payment data.
  4. Risk Assessment Tables (15%):

    • Draw a table like this:
      Asset Threat Vulnerability Risk Level Mitigation
      Customer DB SQL Injection Poor input validation High Use parameterized queries
  5. Short Notes (10%):

    • ISO 27001: Risk management standard.
    • GDPR: EU law on data privacy.
    • PCI-DSS: Security for payment systems.

Pro Tip:

  • Memorize the 6-hour rule (Cyber Security Act) and 72-hour rule (GDPR).
  • Compare Nepal’s laws with GDPR/PCI-DSS in exam answers.
  • Use real examples (Khalti, Ncell, Daraz) to make your answers stand out.

Summary Table: Policies vs. Standards vs. Laws

Feature Security Policy Security Standard Security Law
Who defines it? Organization’s management Industry bodies (ISO, NIST, PCI) Government/Parliament
Enforceability Internal (contractual) Voluntary (but required for compliance) Legal (fines/imprisonment)
Example "No personal emails on company devices" ISO 27001, PCI-DSS Cyber Security Act (2018), GDPR
Penalty for Violation Termination, demotion Loss of certification, reputational damage Fines, imprisonment, license revocation

Based on the TU BITM syllabus for Information Security (IT244), unit 10.

Discussion

Loading…