IT246 IT Ethics and Cybersecurity

IT Ethics and CybersecurityUnit 77 min read

Security Controls & Risk Management: Types, Models, and Real-World Applications

Unit 7 of IT Ethics and Cybersecurity explores security controls (preventive, detective, corrective) and risk management (identification, assessment, mitigation) in IT systems, with real-world examples from Nepali and global tech companies, legal frameworks, and everyday cybersecurity challenges.

Core Concepts

1. What Are Security Controls?

Security controls are mechanisms, policies, or procedures designed to protect IT systems and data from threats. They are categorized based on their function:

FirewallsAccess ControlsEncryptionPreventive ControlsIntrusion Detection Systems (IDS)LogsAuditsDetective ControlsBackupsIncident Response PlansPatchingCorrective ControlsSecurity Controls
Hierarchy of security controls by function and examples

How They Work

  • Preventive Controls block unauthorized access (e.g., firewalls, passwords).
  • Detective Controls monitor for suspicious activity (e.g., logs, SIEM tools).
  • Corrective Controls fix issues post-breach (e.g., restoring from backups).

Worked Example: Ncell’s SIM Registration System Ncell uses preventive controls (biometric verification + OTP) to stop SIM fraud. If a breach occurs (detected via logs), they correct it by blocking the compromised SIM and issuing a new one.


2. Risk Management Process

Risk management is a structured approach to identifying, assessing, and mitigating risks. The steps are:

flowchart TD
    A["Risk Identification"] --> B["Risk Assessment"]
    B --> C["Risk Mitigation"]
    C --> D["Monitoring & Review"]

Step-by-Step Breakdown

Step Action Example in Nepal
Identification List potential threats (e.g., malware, insider attacks). Daraz identifies risks like payment fraud or data leaks.
Assessment Evaluate likelihood and impact (qualitative/quantitative). NTC assesses risks of DDoS attacks on its network.
Mitigation Apply controls to reduce risk (avoid, transfer, mitigate, accept). Banks use encryption (mitigate) and insurance (transfer) for fraud risks.
Monitoring Continuously review and update risk strategies. eSewa updates two-factor authentication after new phishing attacks emerge.

Risk Treatment Options

Option Definition When to Use Example
Avoid Eliminate the risk entirely. High-risk, non-critical systems. NEPSE avoids public Wi-Fi for trading to prevent hacking.
Transfer Shift risk to a third party (e.g., insurance). Financial risks. Pathao uses fraud insurance for rider payouts.
Mitigate Reduce risk via controls. Most common approach. Khalti uses tokenization to protect card details.
Accept Acknowledge and monitor. Low-impact risks. Small blogs accept comment spam as a minor nuisance.

3. Security Control Models

Two key models help implement security controls:

A. CIA Triad (Confidentiality, Integrity, Availability)

Confidentiality (33%)Integrity (33%)Availability (34%)
CIA Triad proportions (hypothetical distribution for illustration)
  • Confidentiality: Only authorized users access data (e.g., bank vaults, encrypted emails).
  • Integrity: Data is accurate and unaltered (e.g., blockchain, hash functions).
  • Availability: Systems are operational when needed (e.g., cloud backups, redundant servers).

B. Defense-in-Depth (Layered Security)

graph TD
    A["User"] --> B["Firewall"]
    B --> C["Antivirus"]
    C --> D["IDS/IPS"]
    D --> E["Encryption"]
    E --> F["Data"]

Example: Kathmandu Traffic Management System

  • Layer 1: Firewall (blocks unauthorized access to traffic cameras).
  • Layer 2: Biometric authentication (for traffic police portals).
  • Layer 3: Encrypted data transmission (prevents hacking of real-time traffic data).

4. Risk Assessment Methods

Two common techniques:

2023 BSQualitativeassessment (expert jud2024 BSQuantitativeassessment (financial 2025 BSHybrid approach(combining both method
Evolution of risk assessment methodologies over time

A. Qualitative Risk Assessment

  • Uses subjective scoring (High/Medium/Low).
  • Example: A small business rates the risk of email phishing as "High" due to employee training gaps.

B. Quantitative Risk Assessment

  • Uses numerical values (e.g., SLE × ARO = ALE).
    • SLE (Single Loss Expectancy): Cost per incident (e.g., ₹50,000 for a data breach).
    • ARO (Annualized Rate of Occurrence): How often it happens (e.g., 1 breach/year).
    • ALE (Annualized Loss Expectancy): SLE × ARO = ₹50,000 × 1 = ₹50,000/year.

Worked Example: Daraz’s Risk Calculation

  • SLE: ₹200,000 (cost of a single fraudulent order).
  • ARO: 2 incidents/year (based on past data).
  • ALE: ₹200,000 × 2 = ₹400,000/year → Daraz invests in AI fraud detection to reduce ARO.

In the Real World

  1. Khalti’s Two-Factor Authentication (2FA)

    • Idea Used: Preventive Control (Multi-Factor Authentication)
    • How: Khalti requires OTP + fingerprint for transactions, reducing fraud by 90% (per their 2023 report).
  2. NTC’s DDoS Protection

    • Idea Used: Detective + Corrective Controls (Firewalls + Traffic Analysis)
    • How: NTC uses cloud-based DDoS mitigation (from Akamai) to detect and block attacks on its 4G/5G networks.
  3. Nepal Rastra Bank’s Cybersecurity Framework

    • Idea Used: Risk Management (ISO 27001 Compliance)
    • How: Banks must identify risks (e.g., insider threats), assess impact, and mitigate via encryption + audits.

Exam Tip

  1. Define Key Terms Precisely

    • Example:

      "Security controls are safeguards implemented to protect IT assets from threats, categorized into preventive, detective, and corrective types."

  2. Compare CIA Triad with Real Scenarios

    • Question: "How does Ncell ensure availability of its network?"
    • Answer:

      "Ncell uses redundant servers (CIA: Availability) and SMS alerts (CIA: Integrity) to ensure data accuracy and uptime."

  3. Calculate ALE in Exam Questions

    • Given:
      • SLE = ₹100,000
      • ARO = 0.5/year
    • Answer:

      "ALE = SLE × ARO = ₹100,000 × 0.5 = ₹50,000/year."

  4. Link Theory to Nepali Companies

    • Question: "Explain defense-in-depth using Pathao’s security."
    • Answer:

      *"Pathao uses multiple layers:

      • Firewall (blocks unauthorized API access),
      • Tokenization (protects rider data),
      • Incident response team (corrects breaches)."*
  5. Memorize Risk Treatment Options

    • Avoid/Transfer/Mitigate/Accept are high-yield for short-answer questions.

Final Note: Always relate controls to real-world examples (eSewa, banks, NTC) and use formulas (ALE) where applicable. Visuals (CIA triad, risk flowchart) fetch extra marks!

Based on the TU BITM syllabus for IT Ethics and Cybersecurity (IT246), unit 7.

Discussion

Loading…