IT Ethics and CybersecurityUnit 68 min read
Cybersecurity Fundamentals: CIA Triad, Threats, Controls & Real-World Defense
Unit 6 of IT Ethics and Cybersecurity explores the core principles of cybersecurity—confidentiality, integrity, and availability (CIA Triad)—common threats like malware and phishing, and practical security controls (preventive, detective, corrective). It connects theory to Nepal’s digital ecosystem (eSewa, Ncell, banks
Core Concepts: The CIA Triad
Cybersecurity revolves around three pillars: Confidentiality, Integrity, and Availability (CIA Triad). These principles form the foundation for protecting information systems.
1. Confidentiality
Definition: Ensuring that data is accessible only to authorized users, processes, or systems. How it works:
- Uses encryption (e.g., AES, RSA), access controls (passwords, biometrics), and authentication (OAuth, MFA).
- Example: When you log into eSewa, your transaction details are encrypted to prevent unauthorized access.
Real-World Application:
- Ncell’s Mobile Banking: Uses end-to-end encryption to protect SMS-based transactions from interception.
- Google Accounts: Implements two-factor authentication (2FA) to ensure only you can access your data.
2. Integrity
Definition: Ensuring data remains accurate, consistent, and unaltered during transmission or storage. How it works:
- Uses hash functions (SHA-256), digital signatures, and checksums.
- Example: When you download a file from Daraz, the website verifies its integrity using a checksum to ensure it hasn’t been tampered with.
Real-World Application:
- Nepal Rastra Bank’s Digital Payments: Uses blockchain-like ledgers to track and verify transactions, preventing fraud.
- WhatsApp Messages: Uses SHA-256 hashing to detect if messages are altered during transmission.
3. Availability
Definition: Ensuring systems and data are accessible to authorized users when needed. How it works:
- Uses redundancy (backup servers), DDoS protection, and load balancing.
- Example: NTC’s fiber-optic network uses redundant routes to ensure internet availability even if one path fails.
Real-World Application:
- Pathao’s Ride-Hailing System: Uses cloud-based redundancy to keep the app running during peak traffic (e.g., Dashain).
- YouTube’s CDN: Distributes content across servers worldwide to ensure videos load quickly, even during high demand.
Visual: The CIA Triad in Action
pie
title Cybersecurity CIA Triad
"Confidentiality" : 33
"Integrity" : 33
"Availability" : 33
"Overlap (All 3)" : 1How the CIA Triad protects a single transaction in eSewa:
- Confidentiality: Encrypted data (AES-256).
- Integrity: Digital signature (RSA) to verify sender.
- Availability: Redundant servers to prevent downtime.
Common Cyber Threats
Cybersecurity threats can be categorized into active (malicious attacks) and passive (eavesdropping). Below are key threats with real-world examples:
| Threat Type | Description | Nepal Example | Global Example |
|---|---|---|---|
| Malware | Software designed to harm systems (viruses, ransomware). | Nepal Police’s 2021 ransomware attack (data locked until payment). | WannaCry (2017) attacked NHS hospitals. |
| Phishing | Tricking users into revealing sensitive data. | Fake "Ncell Recharge" SMS leading to fake websites. | Google Docs Phishing Scam (2017). |
| Denial-of-Service (DoS/DDoS) | Overloading systems to crash them. | Nepal’s 2020 internet shutdowns during protests. | Mirai Botnet (2016) took down Twitter, Netflix. |
| Man-in-the-Middle (MitM) | Intercepting communications between two parties. | Unsecured Wi-Fi in cafes stealing login credentials. | Firesheep (2010) hijacked Facebook sessions. |
| Insider Threats | Employees or contractors misusing access. | Bank employee leaking customer data in Kathmandu. | Edward Snowden (NSA leaks, 2013). |
Security Controls: Preventing, Detecting, and Correcting Threats
Security controls are categorized into three types:
1. Preventive Controls
Goal: Stop threats before they occur. Examples:
- Firewalls (block unauthorized access).
- Antivirus Software (scans for malware).
- Password Policies (enforce strong passwords).
Real-World Example:
- Nepal’s Online Transaction Act (2020) mandates firewalls and encryption for all financial institutions.
2. Detective Controls
Goal: Identify threats after they occur. Examples:
- Intrusion Detection Systems (IDS).
- Audit Logs (track user activity).
- Anomaly Detection (AI-based monitoring).
Real-World Example:
- Ncell’s Fraud Detection System flags unusual call patterns (e.g., sudden international calls from a local SIM).
3. Corrective Controls
Goal: Fix damage caused by threats. Examples:
- Backup and Recovery (restore data after ransomware).
- Incident Response Teams (handle breaches).
- Patch Management (update software to fix vulnerabilities).
Real-World Example:
- Daraz’s 2022 Data Breach Response: Isolated affected systems and notified users within 24 hours.
Visual: Security Control Lifecycle
flowchart TD
A["Threat Occurs"] -->|"Preventive"| B["Firewall Blocks Attack"]
A -->|"Detective"| C["IDS Alerts Security Team"]
A -->|"Corrective"| D["Backup Restores Data"]
B --> E["Threat Avoided"]
C --> F["Investigation & Patch"]
D --> G["System Recovered"]Real-World Applications in Nepal
eSewa’s Security Model
- Confidentiality: AES-256 encryption for all transactions.
- Integrity: Digital signatures for payment verification.
- Availability: Cloud-based redundancy to prevent downtime.
- Threat Mitigation: Two-factor authentication (2FA) for logins.
Ncell’s Fraud Prevention
- Uses AI-driven anomaly detection to flag suspicious calls (e.g., sudden roaming activation).
- Preventive Control: SIM Binding to link SIMs to national IDs.
Nepal Stock Exchange (NEPSE) Security
- Integrity: Blockchain-based trading logs to prevent tampering.
- Availability: Multiple data centers to avoid single points of failure.
Exam Tip: How to Score Full Marks
Define CIA Triad Clearly
- Always explain confidentiality, integrity, and availability with one real-world example each (e.g., eSewa, Ncell, Daraz).
- Example Answer:
"Confidentiality in Ncell’s mobile banking is ensured through end-to-end encryption, preventing unauthorized access to transaction details."
Compare Threats with Controls
- Question: "How would you mitigate a phishing attack on eSewa?"
- Answer:
*"Phishing can be mitigated using:
- Preventive: Multi-factor authentication (MFA) and user training.
- Detective: Email filtering to block suspicious links.
- Corrective: Incident response team to reset compromised accounts."*
Use Diagrams in Exams
- Draw CIA Triad, security control flowcharts, or threat matrices to visually explain concepts.
- Example:
pie title Security Controls for eSewa "Preventive (Firewall, MFA)" : 40 "Detective (IDS, Logs)" : 30 "Corrective (Backups, Patching)" : 30
Relate to Nepal’s Digital Laws
- Mention Electronic Transactions Act (2020) or Cybersecurity Strategy (2021) when discussing compliance.
- Example:
"Under Nepal’s Cybersecurity Strategy, financial institutions must implement encryption and audit logs to comply with confidentiality and integrity requirements."
Avoid Generic Answers
- Bad: "Cybersecurity is important."
- Good: "Nepal Rastra Bank’s 2023 audit found that 30% of banks lacked proper encryption, exposing them to man-in-the-middle attacks during online transfers."
Key Takeaways
- The CIA Triad (Confidentiality, Integrity, Availability) is the core framework for cybersecurity.
- Real-world threats like phishing (eSewa scams) and DDoS (NTC outages) require preventive, detective, and corrective controls.
- Nepal’s digital platforms (eSewa, Ncell, NEPSE) rely on encryption, MFA, and redundancy to stay secure.
- Exam success depends on linking theory to Nepal’s tech landscape and using visuals (diagrams, tables) to explain concepts.
Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 6.
Discussion
Loading…