IT Ethics and CybersecurityUnit 77 min read
Security Controls & Risk Management: Types, Models, and Real-World Applications
Unit 7 of IT Ethics and Cybersecurity explores security controls (preventive, detective, corrective) and risk management (identification, assessment, mitigation) in IT systems, with real-world examples from Nepali and global tech companies, legal frameworks, and everyday cybersecurity challenges.
Core Concepts
1. What Are Security Controls?
Security controls are mechanisms, policies, or procedures designed to protect IT systems and data from threats. They are categorized based on their function:
How They Work
- Preventive Controls block unauthorized access (e.g., firewalls, passwords).
- Detective Controls monitor for suspicious activity (e.g., logs, SIEM tools).
- Corrective Controls fix issues post-breach (e.g., restoring from backups).
Worked Example: Ncell’s SIM Registration System Ncell uses preventive controls (biometric verification + OTP) to stop SIM fraud. If a breach occurs (detected via logs), they correct it by blocking the compromised SIM and issuing a new one.
2. Risk Management Process
Risk management is a structured approach to identifying, assessing, and mitigating risks. The steps are:
flowchart TD
A["Risk Identification"] --> B["Risk Assessment"]
B --> C["Risk Mitigation"]
C --> D["Monitoring & Review"]Step-by-Step Breakdown
| Step | Action | Example in Nepal |
|---|---|---|
| Identification | List potential threats (e.g., malware, insider attacks). | Daraz identifies risks like payment fraud or data leaks. |
| Assessment | Evaluate likelihood and impact (qualitative/quantitative). | NTC assesses risks of DDoS attacks on its network. |
| Mitigation | Apply controls to reduce risk (avoid, transfer, mitigate, accept). | Banks use encryption (mitigate) and insurance (transfer) for fraud risks. |
| Monitoring | Continuously review and update risk strategies. | eSewa updates two-factor authentication after new phishing attacks emerge. |
Risk Treatment Options
| Option | Definition | When to Use | Example |
|---|---|---|---|
| Avoid | Eliminate the risk entirely. | High-risk, non-critical systems. | NEPSE avoids public Wi-Fi for trading to prevent hacking. |
| Transfer | Shift risk to a third party (e.g., insurance). | Financial risks. | Pathao uses fraud insurance for rider payouts. |
| Mitigate | Reduce risk via controls. | Most common approach. | Khalti uses tokenization to protect card details. |
| Accept | Acknowledge and monitor. | Low-impact risks. | Small blogs accept comment spam as a minor nuisance. |
3. Security Control Models
Two key models help implement security controls:
A. CIA Triad (Confidentiality, Integrity, Availability)
- Confidentiality: Only authorized users access data (e.g., bank vaults, encrypted emails).
- Integrity: Data is accurate and unaltered (e.g., blockchain, hash functions).
- Availability: Systems are operational when needed (e.g., cloud backups, redundant servers).
B. Defense-in-Depth (Layered Security)
graph TD
A["User"] --> B["Firewall"]
B --> C["Antivirus"]
C --> D["IDS/IPS"]
D --> E["Encryption"]
E --> F["Data"]Example: Kathmandu Traffic Management System
- Layer 1: Firewall (blocks unauthorized access to traffic cameras).
- Layer 2: Biometric authentication (for traffic police portals).
- Layer 3: Encrypted data transmission (prevents hacking of real-time traffic data).
4. Risk Assessment Methods
Two common techniques:
A. Qualitative Risk Assessment
- Uses subjective scoring (High/Medium/Low).
- Example: A small business rates the risk of email phishing as "High" due to employee training gaps.
B. Quantitative Risk Assessment
- Uses numerical values (e.g., SLE × ARO = ALE).
- SLE (Single Loss Expectancy): Cost per incident (e.g., ₹50,000 for a data breach).
- ARO (Annualized Rate of Occurrence): How often it happens (e.g., 1 breach/year).
- ALE (Annualized Loss Expectancy): SLE × ARO = ₹50,000 × 1 = ₹50,000/year.
Worked Example: Daraz’s Risk Calculation
- SLE: ₹200,000 (cost of a single fraudulent order).
- ARO: 2 incidents/year (based on past data).
- ALE: ₹200,000 × 2 = ₹400,000/year → Daraz invests in AI fraud detection to reduce ARO.
In the Real World
Khalti’s Two-Factor Authentication (2FA)
- Idea Used: Preventive Control (Multi-Factor Authentication)
- How: Khalti requires OTP + fingerprint for transactions, reducing fraud by 90% (per their 2023 report).
NTC’s DDoS Protection
- Idea Used: Detective + Corrective Controls (Firewalls + Traffic Analysis)
- How: NTC uses cloud-based DDoS mitigation (from Akamai) to detect and block attacks on its 4G/5G networks.
Nepal Rastra Bank’s Cybersecurity Framework
- Idea Used: Risk Management (ISO 27001 Compliance)
- How: Banks must identify risks (e.g., insider threats), assess impact, and mitigate via encryption + audits.
Exam Tip
Define Key Terms Precisely
- Example:
"Security controls are safeguards implemented to protect IT assets from threats, categorized into preventive, detective, and corrective types."
- Example:
Compare CIA Triad with Real Scenarios
- Question: "How does Ncell ensure availability of its network?"
- Answer:
"Ncell uses redundant servers (CIA: Availability) and SMS alerts (CIA: Integrity) to ensure data accuracy and uptime."
Calculate ALE in Exam Questions
- Given:
- SLE = ₹100,000
- ARO = 0.5/year
- Answer:
"ALE = SLE × ARO = ₹100,000 × 0.5 = ₹50,000/year."
- Given:
Link Theory to Nepali Companies
- Question: "Explain defense-in-depth using Pathao’s security."
- Answer:
*"Pathao uses multiple layers:
- Firewall (blocks unauthorized API access),
- Tokenization (protects rider data),
- Incident response team (corrects breaches)."*
Memorize Risk Treatment Options
- Avoid/Transfer/Mitigate/Accept are high-yield for short-answer questions.
Final Note: Always relate controls to real-world examples (eSewa, banks, NTC) and use formulas (ALE) where applicable. Visuals (CIA triad, risk flowchart) fetch extra marks!
Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 7.
Discussion
Loading…