CSC323 Society and Ethics in Information Technology

Society and Ethics in Information TechnologyUnit 1212 min read

Risk Assessment & Management in IT: Threats, Mitigation & Real-World Cases

Unit 12 of Society and Ethics in Information Technology explores how IT risks are identified, evaluated, and mitigated—from cybersecurity threats to software failures—using frameworks like ISO 27001, COBIT, and NIST, with case studies from Nepal’s NTC, Daraz, and global tech giants like Google.

TAKEAWAYS

  • Risk assessment in IT is the structured process of identifying, analyzing, and prioritizing threats (e.g., data breaches, system crashes) using frameworks like NIST SP 800-30 or ISO 31000.
  • Software risks (e.g., bugs, poor design) are quantified using qualitative (expert judgment) or quantitative (probability × impact) methods, with tools like FAIR or MEGA Risk Manager.
  • Mitigation strategies include technical controls (firewalls, encryption), organizational policies (access controls), and operational procedures (regular audits).
  • Nepal’s NTC and Ncell use risk management to secure telecom networks, while Daraz applies it to prevent supply chain disruptions during peak sales (e.g., Dashain).
  • Real-world failures (e.g., eSewa’s 2020 payment outage, Google’s 2013 Gmail downtime) highlight how unmanaged risks erode trust and revenue.
  • Legal and ethical risks (e.g., GDPR violations, copyright infringement) require compliance frameworks like Nepal’s Data Protection Act (2022) or DMCA for digital ownership.

1. Definitions: Risk, Threat, and Vulnerability

Risk in IT is the potential for harm when a threat exploits a vulnerability in a system. To manage it, we need clear definitions:

flowchart TD
    A["Risk"] -->|"= Threat × Vulnerability × Impact"| B["Risk Level"]
    A --> C["Risk = Probability × Severity"]
    C --> D["Low: Green<br/>Medium: Yellow<br/>High: Red"]
    B --> E["Risk Matrix"]
  • Threat: An intentional or unintentional event that could harm assets (e.g., hackers, natural disasters).
  • Vulnerability: A weakness in systems, processes, or human behavior (e.g., weak passwords, outdated software).
  • Impact: The consequences of a realized risk (financial loss, reputational damage, legal penalties).

Worked Example: Nepal’s NTC faces risks from:

  • Threat: Cyberattacks on its fiber-optic network (e.g., DDoS attacks).
  • Vulnerability: Legacy systems without end-to-end encryption.
  • Impact: Service outages during exams or emergencies (e.g., 2021 monsoon floods). Mitigation: NTC uses ISO 27001-certified firewalls and regular penetration testing.

2. Risk Assessment Frameworks

Risk assessment is not guesswork—it follows standardized frameworks. Here are the top three:

Framework Scope Key Tools/Methods Used by
NIST SP 800-30 U.S. government/enterprise Risk assessment guide, risk scoring NASA, DoD, Nepal’s Nepal Police Cyber Unit
ISO 31000 Global standard Risk management principles Google, Ncell, Daraz
COBIT IT governance & control IT control objectives (ITCO) Banks (NMB, Siddhartha Bank)
FAIR Quantitative risk analysis Probability × Loss Event Frequency Insurance firms (NIC Asia)

How ISO 31000 Works (Step-by-Step):

  1. Establish context: Define scope (e.g., "Ncell’s 5G network").
  2. Risk identification: Brainstorm threats (e.g., SIM swapping, tower sabotage).
  3. Risk analysis: Score threats using a risk matrix (probability vs. impact).
  4. Risk evaluation: Decide if risk is acceptable or needs treatment.
  5. Risk treatment: Apply controls (e.g., 2FA for Ncell accounts).
  6. Monitor & review: Audit risks quarterly (e.g., Nepal Rastra Bank’s cyber drills).

Worked Example: Daraz’s Risk Assessment for Dashain Sales

  • Threat: Server overload during peak sales (like Amazon Prime Day).
  • Vulnerability: Inadequate load balancing.
  • Impact: Slow checkout → lost sales (~₹500M/year).
  • Mitigation:
    • Technical: Scaled AWS servers (like Google’s auto-scaling).
    • Operational: Pre-sales alerts to users (like WhatsApp’s "Save for Later").
    • Contingency: Partnered with Ncell for SMS-based order confirmations.

3. Types of IT Risks

Risks fall into four categories, each requiring different mitigation:

mindmap
  root((IT Risks))
    Technical Risks
      - Malware (ransomware, spyware)
      - Hardware failure (server crashes)
      - Network outages (DDoS)
    Operational Risks
      - Human error (misconfigured firewalls)
      - Process failures (poor backup policies)
    Legal & Compliance Risks
      - GDPR violations (eSewa’s 2020 data leak)
      - Copyright infringement (unlicensed software)
    Strategic Risks
      - Market competition (Pathao vs. Uber)
      - Reputation damage (NTC’s 2021 outage)

Real-World Cases:

  • Technical Risk: Google’s 2013 Gmail outage (DNS misconfiguration) cost $500K/minute.
  • Operational Risk: Nepal’s eSewa lost ₹100M in 2020 when its backup server failed during a power cut.
  • Legal Risk: YouTube’s copyright strikes (automated Content ID system) led to false takedowns.
  • Strategic Risk: WhatsApp’s end-to-end encryption (2016) backfired when users feared privacy violations.

4. Risk Assessment Methods

Assessing risk requires data-driven or expert-based approaches:

Method Description Example
Qualitative Uses expert judgment (e.g., risk matrices). NTC’s cybersecurity team rates threats as Low/Medium/High.
Quantitative Uses numbers (probability × impact). FAIR model: A hacker attack has 80% probability and ₹20M impact → ₹16M risk.
Scenario Analysis "What if?" exercises (e.g., "What if Ncell’s towers go dark?"). Nepal Telecom’s disaster recovery plan.
SWOT Analysis Strengths, Weaknesses, Opportunities, Threats. Pathao’s SWOT: Weakness = reliance on third-party drivers.

Worked Example: Quantifying Ncell’s Risk of SIM Swapping

  1. Probability: 1 in 500 users targeted annually (based on Nepal Police data).
  2. Impact: ₹10,000 loss per victim (average fraud amount).
  3. Risk: (1/500) × ₹10,000 = ₹20 per user.
  4. Mitigation: 2FA + biometric verification (like Khalti’s transaction limits).

5. Risk Mitigation Strategies

Once risks are identified, reduce, transfer, accept, or avoid them:

flowchart TD
    A["Risk"] --> B{"Mitigation Strategy?"}
    B -->|"Reduce"| C["Technical: Firewalls, Encryption<br/>Organizational: Policies, Training"]
    B -->|"Transfer"| D["Insurance, Outsourcing (e.g., NTC’s cloud backup with AWS)"]
    B -->|"Accept"| E["Low-impact risks (e.g., minor software bugs)"]
    B -->|"Avoid"| F["Stop high-risk activities (e.g., no unencrypted databases)"]

Mitigation Techniques by Risk Type:

Risk Type Mitigation Example Real-World Use
Cybersecurity Zero-trust architecture (e.g., Google BeyondCorp). Nepal Police’s secure email system.
Data Loss 3-2-1 backup rule (3 copies, 2 media, 1 offsite). Daraz’s cloud backups in AWS + local servers.
Human Error Phishing simulations (like WhatsApp’s security tips). Ncell’s employee training programs.
Compliance GDPR/DMA compliance tools (e.g., OneTrust). eSewa’s data anonymization.

Worked Example: Pathao’s Risk Mitigation for Driver Safety

  • Risk: Drivers facing harassment or accidents.
  • Mitigation:
    • Technical: GPS tracking + emergency SOS button (like Uber’s safety features).
    • Organizational: Driver training on conflict resolution.
    • Contingency: Insurance partnerships with NIC Asia.

6. Risk Management in Nepal’s IT Sector

Nepal’s IT risks are unique due to:

  • Infrastructure gaps (e.g., NTC’s fiber cuts during landslides).
  • Regulatory gaps (e.g., no strict cybersecurity laws before 2022).
  • Human factor (e.g., eSewa users sharing OTPs).

Case Study: Ncell’s Risk Management for 5G Rollout

Risk Assessment Mitigation
Signal interference Probability: High (urban congestion). Deployed self-healing networks.
Fraud (SIM swapping) Probability: Medium. Biometric + PIN verification.
Vendor lock-in Probability: Low. Multi-vendor contracts (Huawei + Ericsson).

Risk management isn’t just technical—it’s ethical and legal:

  • GDPR/Nepal’s Data Protection Act: Fines for unauthorized data collection (e.g., eSewa’s 2020 breach).
  • Copyright Infringement: Downloading pirated software (e.g., unlicensed Adobe Suite in Nepali colleges).
  • Reputation Risk: Data leaks (e.g., Nepal Police’s 2021 cyberattack).

Worked Example: NEPSE’s Risk of Market Manipulation

  • Risk: Insider trading in stocks.
  • Mitigation:
    • Legal: Stricter SEBON (Securities Exchange Board of Nepal) rules.
    • Technical: Blockchain-based audit trails (like Nasdaq’s Linq).

8. Risk Assessment Tools

Tool Purpose Used by
Mega Risk Manager Enterprise risk management. Banks, NTC.
Qualys Vulnerability scanning. Google, Daraz.
Splunk Security information & event management (SIEM). Nepal Police Cyber Unit.
RiskWatch ISO 27001 compliance. Ncell, Siddhartha Bank.

In the Real World

  1. NTC’s Risk Management for Monsoon Outages

    • Idea Used: Disaster recovery planning (ISO 22301).
    • How: NTC uses automated failover systems to switch to backup towers when fiber is cut (e.g., during 2021’s heavy rains). This is similar to Google’s multi-region data centers.
  2. Daraz’s Risk Mitigation for Peak Sales

    • Idea Used: Load balancing and scenario analysis.
    • How: Before Dashain, Daraz runs simulated traffic tests (like Amazon’s Prime Day prep) to ensure servers handle 10x normal traffic. They also partner with Ncell for SMS-based order confirmations to avoid app crashes.
  3. eSewa’s Risk of Payment Failures

    • Idea Used: Redundant payment gateways.
    • How: eSewa routes payments through multiple banks (SBI, NMB, Global IME) to prevent outages (e.g., if one bank’s server crashes). This is like PayPal’s multi-currency support.

Exam Tip

This unit is highly exam-focused—expect short-answer questions (SAQs) on definitions and long-answer questions (LAQs) on case studies. Here’s how to score full marks:

  1. For SAQs (10-15 marks):

    • Risk assessment: Define risk = Threat × Vulnerability × Impact.
    • Frameworks: Mention NIST, ISO 31000, or COBIT with 1 example.
    • Mitigation: List 4 strategies (reduce, transfer, accept, avoid) with 1 real-world example.
  2. For LAQs (20-30 marks):

    • Structure: Use the risk management cycle (identify → analyze → treat → monitor).
    • Case study: Pick NTC, Daraz, or eSewa and apply quantitative/qualitative risk assessment.
    • Ethical angle: Always link risks to legal compliance (e.g., GDPR, Nepal’s Data Protection Act).

Example LAQ Answer Structure:

"Explain how Ncell can assess and mitigate risks in its 5G rollout. Step 1: Risk Identification

  • Threats: Signal interference, SIM swapping, vendor lock-in.
  • Vulnerabilities: Urban congestion, weak authentication.

Step 2: Risk Assessment (Quantitative)

  • SIM swapping: Probability = 0.15, Impact = ₹10,000 → ₹1,500 risk per user.
  • Mitigation: Biometric + 2FA (cost: ₹500/user).

Step 3: Risk Treatment

  • Reduce: Deploy self-healing networks (cost: ₹20M).
  • Transfer: Insurance policy for natural disasters.
  • Monitor: Quarterly penetration testing (like Google’s bug bounty program).

Ethical/Legal: Comply with Nepal’s Telecom Regulatory Authority (NTRA) guidelines to avoid fines."*

Key Exam Tips:

  • Use real Nepalese examples (NTC, Daraz, eSewa) to stand out.
  • Diagrams help: Draw a risk matrix or risk treatment flowchart for LAQs.
  • Avoid vague answers: Always quantify risks (e.g., "₹X impact") or cite frameworks (e.g., "ISO 27001").

Based on the TU BSc CSIT syllabus for Society and Ethics in Information Technology (CSC323), unit 12.

Discussion

Loading…