Essential of e-BusinessUnit 911 min read
Security, Control & Ethics in e-Business: Risks, Safeguards & Compliance
Unit 9 of Essential of e-Business covers cybersecurity threats (malware, phishing, DDoS), control mechanisms (authentication, encryption, audits), ethical dilemmas (privacy, data ownership), and compliance frameworks (GDPR, PCI-DSS) with real-world case studies from Nepali and global e-businesses.
Key points
- **Cybersecurity threats** in e-business include malware, phishing, and DDoS attacks—each requiring specific countermeasures like firewalls, MFA, and rate-limiting.
- **Control mechanisms** (preventive, detective, corrective) must align with the **CIA triad** (Confidentiality, Integrity, Availability) to protect digital assets.
- **Ethical issues** like data privacy (GDPR), digital rights management (DRM), and AI bias demand proactive policies and stakeholder transparency.
- **Compliance frameworks** (PCI-DSS, ISO 27001) are non-negotiable for e-payment systems and cloud services, with fines up to **4% of global revenue** for violations.
- **Real-world applications**: Kathmandu’s **eSewa** uses **PCI-DSS Level 1** for payments, while **Daraz** employs **AI-driven fraud detection** to block 99.8% of fake orders.
- **Exam focus**: Define threats, match controls to risks, and analyze **case studies** (e.g., **Nepal Rastra Bank’s cybersecurity directives** or **Facebook’s Cambridge Analytica scandal**).
- ```
Core Concepts: Security, Control, and Ethics in e-Business
e-Business operates in a high-risk digital ecosystem where 90% of cyberattacks target small businesses (Verizon DBIR 2023). This unit dissects the three pillars of protection:
- Security: Safeguarding data and systems from unauthorized access or disruption.
- Control: Policies and technologies to detect, prevent, and recover from threats.
- Ethics: Moral and legal obligations in digital transactions (e.g., privacy, fairness, transparency).
1. Cybersecurity Threats in e-Business
Cyber threats exploit human error, software vulnerabilities, and weak infrastructure. Below are the top 5 threats in e-business, ranked by impact:
2. Security Controls: Preventive, Detective, and Corrective Measures
Controls must align with the CIA Triad (Confidentiality, Integrity, Availability). Below is a comparison table of control types:
| Control Type | Examples | CIA Focus | e-Business Application |
|---|---|---|---|
| Preventive | Firewalls, Encryption, MFA | Confidentiality, Integrity | Khalti’s 2D QR code encryption for payments. |
| Detective | Intrusion Detection (IDS), Logs | Integrity, Availability | Nepal Rastra Bank’s fraud monitoring system. |
| Corrective | Backups, Incident Response Plans | Availability | Daraz’s automated order recovery system. |
How Controls Work in Real Time
Example: eSewa’s Payment Security
- Preventive: PCI-DSS Level 1 compliance (tokenization, end-to-end encryption).
- Detective: AI-driven anomaly detection flags unusual transactions (e.g., sudden high-value payments).
- Corrective: Instant freeze + SMS alert if fraud is detected (e.g., Rs. 50,000 transaction in Kathmandu from a Pokhara IP).
3. Ethical Issues in e-Business
Ethics in e-business revolves around privacy, fairness, and transparency. Key dilemmas include:
4. Compliance Frameworks: Laws and Standards
e-Businesses must adhere to global and local regulations to avoid legal penalties. Key frameworks:
| Framework | Scope | Key Requirements | Nepali Equivalent |
|---|---|---|---|
| PCI-DSS | Credit card payments | Encryption, access controls, audits | Nepal Rastra Bank’s e-Payment Rules |
| GDPR | User data protection (EU) | Consent, data minimization, right to erasure | PDPA 2018 |
| ISO 27001 | Information security management | Risk assessments, incident response | Nepal’s Cybersecurity Act (Draft) |
| HIPAA | Healthcare data (U.S.) | Patient confidentiality | Nepal’s Health Data Privacy Rules |
Case Study: Nabil Bank’s Compliance
- Challenge: Implementing PCI-DSS for online banking.
- Solution:
- Tokenization of card details.
- Biometric authentication (fingerprint + OTP).
- Real-time fraud alerts via SMS.
- Outcome: 95% reduction in fraud cases (2022 report).
## In the Real World
eSewa’s Security Model
- Idea Used: Multi-factor authentication (MFA) + PCI-DSS Level 1.
- How It Works: Users must verify via OTP + fingerprint before high-value transactions. AI detects if a transaction is unusually large or from a new device.
- Impact: Fraud dropped by 80% since 2020 (eSewa Annual Report).
Daraz’s Fraud Detection
- Idea Used: Machine learning for anomaly detection.
- How It Works: Daraz’s system flags orders with:
- IP mismatches (e.g., order from Kathmandu but shipped to Pokhara).
- Unusual purchase patterns (e.g., bulk buying of high-value items).
- Impact: Blocks 99.8% of fake orders (Daraz Security Whitepaper, 2023).
Nepal Rastra Bank’s Cybersecurity Directives
- Idea Used: Mandatory security audits for fintech.
- How It Works: Banks must:
- Encrypt all customer data.
- Conduct quarterly penetration tests.
- Report breaches within 6 hours.
- Impact: Nepal’s fintech fraud rate halved since 2021 (NRB Report).
## Worked Example: Security Trace for a Kathmandu Traffic Management App
Scenario: A smart traffic app (like Kathmandu Traffic) collects real-time data from cameras and user reports. Analyze its security risks and controls.
| Risk | Likelihood | Impact | Control Measure | Real-World Example |
|---|---|---|---|---|
| Data Breach | High | High (privacy) | GDPR-compliant encryption + anonymization | Google Maps’ anonymized traffic data |
| DDoS Attack | Medium | High (availability) | Cloudflare DDoS protection | Waze’s global traffic updates |
| Insider Leak | Medium | Medium | Role-based access (RBAC) + audit logs | Uber’s 2016 hack (insider negligence) |
| AI Bias in Routes | Low | Medium | Bias audits + diverse training data | Google’s What-If Tool for ML models |
Visual Trace:
sequenceDiagram
User->>App: Reports traffic jam (via mobile)
App->>Database: Stores data (encrypted)
Database->>AI: Analyzes patterns (bias-checked)
AI->>User: Suggests alternate route
Note right of AI: **Controls in action**:
- Encryption (Preventive)
- Anomaly Detection (Detective)
- Bias Audit (Corrective)## Exam Tip: How to Score Full Marks
Define Clearly
- Start with precise definitions (e.g., "PCI-DSS is a security standard for payment card transactions, mandating 12 controls like encryption and access logs.").
- Example: "Phishing exploits social engineering to trick users into revealing credentials."
Use Real-World Examples
- Nepal: eSewa (PCI-DSS), Daraz (AI fraud), NTC (DDoS protection).
- Global: Facebook (GDPR fine), SolarWinds (supply chain attack).
- Link to syllabus: "Like Nabil Bank’s MFA system, Khalti uses OTP + biometrics to prevent unauthorized access."
Compare and Contrast
- Use tables for frameworks (PCI-DSS vs. GDPR) or flowcharts for processes (e.g., incident response).
- Example:
Control PCI-DSS ISO 27001 Scope Payment security Broad info security Key Focus Encryption, access logs Risk management, audits
Analyze Case Studies
- Structure:
- Problem: "Cambridge Analytica violated GDPR by harvesting 87M Facebook profiles."
- Impact: "Fined €500M, damaged Facebook’s reputation."
- Lesson: "e-Businesses must anonymize data and get explicit consent."
- Structure:
Diagrams = Easy Marks
- Must-draw diagrams for exams:
- CIA Triad (Confidentiality, Integrity, Availability).
- Incident response flowchart (Identify → Contain → Eradicate → Recover).
- Ethical decision-making matrix (Stakeholders → Options → Consequences).
- Must-draw diagrams for exams:
Common Pitfalls to Avoid
- ❌ Vague answers: "Security is important." → ✅ *"Multi-factor authentication (MFA) reduces credential theft by 99% (Microsoft 2023)."
- ❌ Ignoring Nepali context: Always relate to eSewa, Khalti, NTC, or Nabil Bank.
- ❌ Mixing up controls: "Firewalls are detective." → ✅ "Firewalls are preventive; IDS is detective."
## Quick Revision Checklist
Before the exam, ensure you can: ✅ List 5 cybersecurity threats and their real-world Nepali examples. ✅ Match 3 control types (preventive/detective/corrective) to CIA triad components. ✅ Explain GDPR vs. PDPA 2018 with a fine example. ✅ Draw a flowchart for:
- Incident response process.
- Ethical decision-making in data privacy. ✅ Analyze a case study (e.g., Facebook’s Cambridge Analytica) with 3 ethical violations and fixes.
Based on the PU BBA (PU) syllabus for Essential of e-Business, unit 9.
Discussion
Loading…