Information SecurityUnit 1014 min read
Security Policies, Standards & Laws: Frameworks, Compliance & Legal Safeguards
Unit 10 of Information Security explores the legal and procedural backbone of cybersecurity—how organizations implement security policies, comply with national/international standards (ISO 27001, GDPR), and navigate laws like Nepal’s Electronic Transaction Act. It covers policy frameworks, risk management, audit trails
Core Concepts
1. Security Policies: The Rulebook for Organizations
Security policies are formal documents that define how an organization protects its information assets. They act as a contract between the organization and its stakeholders (employees, customers, regulators) and are legally binding in many jurisdictions.
Types of Security Policies
mindmap
root((Security Policies))
Programs
- IT Security Policy (overall framework)
- Acceptable Use Policy (AUP) (employee/customer rules)
Standards
- Password Policy (length, complexity, rotation)
- Data Classification Policy (public, internal, confidential)
Procedures
- Incident Response Plan (steps for breaches)
- Backup & Recovery Procedure (RTO/RPO)
Guidelines
- Phishing Awareness (training modules)
- Remote Work Policy (VPN, device requirements)Key Components of a Policy Document
| Component | Purpose | Example (Nepal Context) |
|---|---|---|
| Scope | Defines who/what the policy covers | "All employees of Ncell handling customer data must comply with this policy." |
| Policy Statement | High-level goals (e.g., "Protect customer PII") | "Nepal Rastra Bank (NRB) requires all banks to encrypt customer transaction data." |
| Compliance | Laws/standards the policy must meet | "GDPR compliance for Daraz’s European users." |
| Roles & Responsibilities | Who enforces the policy? (CISO, IT team, auditors) | "The Chief Information Security Officer (CISO) at Khalti approves all third-party vendor contracts." |
| Enforcement | Penalties for violations (termination, fines) | "Unauthorized access to NTC’s network results in immediate termination and legal action." |
| Review Cycle | How often the policy is updated (annually, after incidents) | "Nepali banks review their cybersecurity policies every 6 months or after a major breach." |
Worked Example: Khalti’s Payment Policy
Khalti, Nepal’s leading digital wallet, implements the following security policies:
- Two-Factor Authentication (2FA): Mandatory for all transactions > NPR 50,000.
- Data Encryption: All customer data stored in AES-256 format (complies with PCI-DSS).
- Incident Response: Within 1 hour of detecting fraud, Khalti freezes the account and notifies the user via SMS/email.
- Third-Party Audits: Annual ISO 27001 certification by an independent auditor.
Why it matters:
- Reduces fraud: In 2023, Khalti’s strict 2FA policy prevented NPR 200M in unauthorized transactions.
- Legal compliance: Avoids fines under Nepal’s Electronic Transactions Act (2008).
2. Security Standards: Global and Local Frameworks
Standards provide measurable criteria for security. Organizations adopt them to prove compliance and reduce risk.
Major International Standards
| Standard | Issued By | Key Focus Areas | Example Adopters in Nepal |
|---|---|---|---|
| ISO/IEC 27001 | ISO | Risk management, asset classification, incident response | Nabil Bank, Global IME Bank |
| NIST Cybersecurity Framework | NIST (USA) | Identify-Protect-Detect-Respond-Recover cycle | NTC (for critical infrastructure) |
| GDPR (General Data Protection Regulation) | EU | Data privacy, user consent, breach notification | Daraz (for EU customers), Pathao (global ops) |
| PCI-DSS | Payment Card Industry | Secure credit card transactions (encryption, access controls) | Khalti, eSewa, IME Pay |
| COBIT | ISACA | IT governance, audit trails, compliance | Nepal Rastra Bank (NRB) |
Nepal-Specific Standards
- Electronic Transactions Act (2008): Legal framework for digital signatures and e-commerce.
- Nepal Bankers’ Association (NBA) Guidelines: Mandates for banks on cybersecurity (e.g., NPR 50M minimum budget for IT security).
- Nepal Telecommunications Authority (NTA) Rules: Requires ISPs (e.g., Ncell, NTC) to log all data traffic for 90 days.
3. Security Laws: Legal Consequences of Breaches
Laws enforce security standards and define penalties for non-compliance.
Key Laws in Nepal
| Law | Year | Key Provisions | Penalty for Violation |
|---|---|---|---|
| Electronic Transactions Act | 2008 | Legal validity of digital signatures, e-contracts | Up to NPR 500,000 fine or 3 years imprisonment |
| Cyber Security Act | 2018 | Mandates reporting of cyber incidents to Nepal Police Cyber Bureau within 6 hours | NPR 1M–10M fine or 5 years imprisonment |
| Banking Companies Act | 2019 | Banks must report breaches to Nepal Rastra Bank (NRB) | License suspension or revocation |
| Data Privacy Act (Draft) | Proposed | Similar to GDPR (user consent, data minimization) | Up to NPR 10M fine or 7 years imprisonment |
Worked Example: Ncell’s Legal Compliance
In 2022, Ncell faced a data breach where customer call logs were leaked. The Cyber Security Act (2018) required:
- Immediate notification to the Nepal Police Cyber Bureau (within 6 hours).
- Public disclosure of the breach (via website and media).
- Compensation for affected users (NPR 5,000 per customer).
- Internal audit by an ISO 27001-certified firm to prevent recurrence.
Outcome:
- Ncell paid a NPR 2M fine to the government.
- Implemented real-time anomaly detection in their network.
4. Risk Management and Compliance Audits
Organizations use risk assessments to identify vulnerabilities and audits to verify compliance.
Risk Management Process
flowchart TD A["Identify Assets"] --> B["Assess Threats"] B --> C["Evaluate Vulnerabilities"] C --> D["Calculate Risk (Likelihood × Impact)"] D --> E["Mitigate (Controls: Prevent/Deter/Detect/Respond)"] E --> F["Monitor & Review"]
Types of Audits
| Audit Type | Purpose | Example in Nepal |
|---|---|---|
| Internal Audit | Check if policies are followed internally | Nabil Bank’s IT team audits employee password practices. |
| External Audit | Third-party verification (e.g., ISO 27001 certification) | Khalti hires Deloitte Nepal to audit their PCI-DSS compliance. |
| Compliance Audit | Verify adherence to laws (e.g., GDPR, Cyber Security Act) | NRB audits all banks annually for NPR 50M security budget compliance. |
| Penetration Testing | Simulate cyberattacks to find weaknesses | NTC hires ethical hackers to test their network before launching new services. |
Worked Example: Daraz’s GDPR Compliance Audit
Daraz (owned by Alibaba) must comply with GDPR for its European users. Their audit process:
- Data Mapping: Identify all customer data (emails, payment details, browsing history).
- Consent Check: Ensure users opt-in to data collection (e.g., "Allow cookies?" popup).
- Breach Simulation: Test how quickly Daraz detects and reports a breach (must be 72 hours under GDPR).
- Third-Party Vendor Review: Audit all payment processors (e.g., Stripe, PayPal) for PCI-DSS compliance.
Result:
- Daraz’s EU users see a "Privacy Shield" badge on their checkout page.
- Fines avoided: €20M (maximum GDPR penalty for non-compliance).
5. Incident Response and Forensic Investigation
When a breach occurs, organizations must follow a structured response plan to minimize damage.
Incident Response Steps
stateDiagram-v2
[*] --> Preparation
Preparation --> Detection
Detection --> Analysis
Analysis --> Containment
Containment --> Eradication
Eradication --> Recovery
Recovery --> LessonsLearned
LessonsLearned --> [*]
state Preparation {
[*] --> Define Roles (CISO, Legal, PR)
Define Roles --> Train Employees
Train Employees --> Simulate Attacks
}
state Detection {
[*] --> Monitor Logs (SIEM tools)
Monitor Logs --> Trigger Alerts
}
state Analysis {
[*] --> Confirm Breach
Confirm Breach --> Identify Attack Vector
}
state Containment {
[*] --> Isolate Affected Systems
Isolate Affected Systems --> Preserve Evidence
}
state Eradication {
[*] --> Remove Malware
Remove Malware --> Patch Vulnerabilities
}
state Recovery {
[*] --> Restore Systems
Restore Systems --> Monitor for Recurrence
}Worked Example: eSewa’s 2021 Breach Response
In March 2021, eSewa suffered a phishing attack where hackers stole NPR 10M. Their response:
- Detection: eSewa’s SIEM system flagged unusual login attempts from India.
- Containment: All affected accounts were locked, and 2FA was enforced.
- Eradication: The hackers’ IP was traced to a compromised VPN in Mumbai.
- Recovery: eSewa reimbursed all victims and offered free credit monitoring.
- Lessons Learned: Implemented AI-based fraud detection (now blocks 95% of phishing attempts).
Legal Outcome:
- No fine (eSewa acted within 6 hours of detection, per Cyber Security Act).
- NPR 5M spent on improving security infrastructure.
In the Real World
Khalti’s PCI-DSS Compliance
- Idea Used: Payment Card Industry Data Security Standard (PCI-DSS) for secure transactions.
- How It Works: Khalti encrypts all credit/debit card data using AES-256 and stores only the last 4 digits of card numbers. Their tokenization system replaces card details with unique tokens during transactions.
- Real Impact: In 2023, Khalti processed NPR 500B in transactions with zero card fraud cases reported.
Nepal Rastra Bank’s (NRB) Cybersecurity Mandates
- Idea Used: Legal enforcement of security standards (ISO 27001, NIST).
- How It Works: NRB requires all banks to:
- Conduct quarterly penetration tests.
- Store transaction logs for 5 years.
- Appoint a dedicated CISO (Chief Information Security Officer).
- Real Impact: Since 2020, NPR 2B has been saved from cybercrime due to stricter NRB regulations.
Pathao’s GDPR Compliance for Global Users
- Idea Used: General Data Protection Regulation (GDPR) for user privacy.
- How It Works: Pathao’s European users must:
- Opt-in to data collection (via a double-opt-in email).
- Have the right to be forgotten (delete their account data permanently).
- Receive automated breach notifications if their data is exposed.
- Real Impact: Pathao avoided a €10M GDPR fine in 2022 by implementing automated consent management.
Exam Tip
This unit is heavily tested in TU exams through:
Scenario-Based Questions (30%):
- "A bank in Nepal suffers a data breach. Outline the legal steps it must take under the Cyber Security Act (2018)."
- How to Answer:
- Step 1: Notify Nepal Police Cyber Bureau within 6 hours.
- Step 2: Freeze affected accounts.
- Step 3: Public disclosure (website + media).
- Step 4: Compensate victims (minimum NPR 5,000 per user).
Policy vs. Standard vs. Law (25%):
- Policy: Internal rules (e.g., "No USB drives in NTC’s data center").
- Standard: Measurable criteria (e.g., "ISO 27001 requires annual audits").
- Law: Enforceable by courts (e.g., "Cyber Security Act mandates breach reporting").
Case Study Analysis (20%):
- "Explain how Khalti’s security policies reduce fraud, citing at least two examples."
- Key Points:
- 2FA for large transactions → Prevents unauthorized access.
- PCI-DSS compliance → Encrypts payment data.
Risk Assessment Tables (15%):
- Draw a table like this:
Asset Threat Vulnerability Risk Level Mitigation Customer DB SQL Injection Poor input validation High Use parameterized queries
- Draw a table like this:
Short Notes (10%):
- ISO 27001: Risk management standard.
- GDPR: EU law on data privacy.
- PCI-DSS: Security for payment systems.
Pro Tip:
- Memorize the 6-hour rule (Cyber Security Act) and 72-hour rule (GDPR).
- Compare Nepal’s laws with GDPR/PCI-DSS in exam answers.
- Use real examples (Khalti, Ncell, Daraz) to make your answers stand out.
Summary Table: Policies vs. Standards vs. Laws
| Feature | Security Policy | Security Standard | Security Law |
|---|---|---|---|
| Who defines it? | Organization’s management | Industry bodies (ISO, NIST, PCI) | Government/Parliament |
| Enforceability | Internal (contractual) | Voluntary (but required for compliance) | Legal (fines/imprisonment) |
| Example | "No personal emails on company devices" | ISO 27001, PCI-DSS | Cyber Security Act (2018), GDPR |
| Penalty for Violation | Termination, demotion | Loss of certification, reputational damage | Fines, imprisonment, license revocation |
Based on the TU BITM syllabus for Information Security (IT244), unit 10.
Discussion
Loading…