Elective Essential of e-Business

Essential of e-BusinessUnit 911 min read

Security, Control & Ethics in e-Business: Risks, Safeguards & Compliance

Unit 9 of Essential of e-Business covers cybersecurity threats (malware, phishing, DDoS), control mechanisms (authentication, encryption, audits), ethical dilemmas (privacy, data ownership), and compliance frameworks (GDPR, PCI-DSS) with real-world case studies from Nepali and global e-businesses.

Key points

  • **Cybersecurity threats** in e-business include malware, phishing, and DDoS attacks—each requiring specific countermeasures like firewalls, MFA, and rate-limiting.
  • **Control mechanisms** (preventive, detective, corrective) must align with the **CIA triad** (Confidentiality, Integrity, Availability) to protect digital assets.
  • **Ethical issues** like data privacy (GDPR), digital rights management (DRM), and AI bias demand proactive policies and stakeholder transparency.
  • **Compliance frameworks** (PCI-DSS, ISO 27001) are non-negotiable for e-payment systems and cloud services, with fines up to **4% of global revenue** for violations.
  • **Real-world applications**: Kathmandu’s **eSewa** uses **PCI-DSS Level 1** for payments, while **Daraz** employs **AI-driven fraud detection** to block 99.8% of fake orders.
  • **Exam focus**: Define threats, match controls to risks, and analyze **case studies** (e.g., **Nepal Rastra Bank’s cybersecurity directives** or **Facebook’s Cambridge Analytica scandal**).
  • ```

Core Concepts: Security, Control, and Ethics in e-Business

e-Business operates in a high-risk digital ecosystem where 90% of cyberattacks target small businesses (Verizon DBIR 2023). This unit dissects the three pillars of protection:

  1. Security: Safeguarding data and systems from unauthorized access or disruption.
  2. Control: Policies and technologies to detect, prevent, and recover from threats.
  3. Ethics: Moral and legal obligations in digital transactions (e.g., privacy, fairness, transparency).

1. Cybersecurity Threats in e-Business

Cyber threats exploit human error, software vulnerabilities, and weak infrastructure. Below are the top 5 threats in e-business, ranked by impact:

Definition: Malicious software (viruses, ransomware, spywareRansomware: Locks data until payment (e.g., Nepal’s 2021 hosSpyware: Steals credentials (e.g., Khalti’s 2022 phishing scExamplesImpact: Data loss, financial fraud, reputational damageMalwareDefinition: Deceptive emails/websites tricking users into reExample: Fake 'eSewa payment failure' emailsPrevention: DMARC, SPF, employee trainingPhishingDefinition: Overwhelming servers with traffic to crash serviExample: Nepal’s 2023 NTC website outageMitigation: Cloudflare, AkamaiDDoS AttacksCybersecurity Threats in e-Business
Hierarchical breakdown of top 5 cybersecurity threats in e-business (Nepal-specific examples included)

2. Security Controls: Preventive, Detective, and Corrective Measures

Controls must align with the CIA Triad (Confidentiality, Integrity, Availability). Below is a comparison table of control types:

FirewallsEncryption (e.g., TLS for eSewa transactions)Access Controls (RBAC)Preventive ControlsIntrusion Detection Systems (IDS)Audit LogsAnomaly Detection (e.g., unusual login attempts)Detective ControlsIncident Response PlansData Backups (e.g., 3-2-1 rule)Bias Audits for AICorrective ControlsSecurity Controls in e-Business
Classification of security controls with examples relevant to Nepali e-business
Control Type Examples CIA Focus e-Business Application
Preventive Firewalls, Encryption, MFA Confidentiality, Integrity Khalti’s 2D QR code encryption for payments.
Detective Intrusion Detection (IDS), Logs Integrity, Availability Nepal Rastra Bank’s fraud monitoring system.
Corrective Backups, Incident Response Plans Availability Daraz’s automated order recovery system.

How Controls Work in Real Time

Example: eSewa’s Payment Security

  1. Preventive: PCI-DSS Level 1 compliance (tokenization, end-to-end encryption).
  2. Detective: AI-driven anomaly detection flags unusual transactions (e.g., sudden high-value payments).
  3. Corrective: Instant freeze + SMS alert if fraud is detected (e.g., Rs. 50,000 transaction in Kathmandu from a Pokhara IP).

3. Ethical Issues in e-Business

Ethics in e-business revolves around privacy, fairness, and transparency. Key dilemmas include:

GDPR (EU): 4% of global revenue fine for violationsNepal’s PDPA 2018: User consent mandatory for data collectioExample: Facebook’s Cambridge Analytica (2018) – 87M profileData PrivacyDefinition: Restricts access to digital content (e.g., e-booExample: Netflix’s geo-blocking (content unavailable in NepaDebate: Fair use vs. corporate controlDigital Rights Management (DRM)Definition: Algorithms reinforcing societal biasesExample: Amazon’s hiring tool favoring male candidates (2018Solution: Bias audits (e.g., Google’s What-If Tool)AI Bias and DiscriminationDefinition: Unauthorized use of patents, copyrights, or tradExample: Pirated software sold in ThamelImpact: Legal penalties, loss of revenueIntellectual Property (IP) TheftEthical Issues in e-Business
Key ethical dilemmas in e-business with local and global case studies

4. Compliance Frameworks: Laws and Standards

e-Businesses must adhere to global and local regulations to avoid legal penalties. Key frameworks:

Framework Scope Key Requirements Nepali Equivalent
PCI-DSS Credit card payments Encryption, access controls, audits Nepal Rastra Bank’s e-Payment Rules
GDPR User data protection (EU) Consent, data minimization, right to erasure PDPA 2018
ISO 27001 Information security management Risk assessments, incident response Nepal’s Cybersecurity Act (Draft)
HIPAA Healthcare data (U.S.) Patient confidentiality Nepal’s Health Data Privacy Rules

Case Study: Nabil Bank’s Compliance

  • Challenge: Implementing PCI-DSS for online banking.
  • Solution:
    • Tokenization of card details.
    • Biometric authentication (fingerprint + OTP).
    • Real-time fraud alerts via SMS.
  • Outcome: 95% reduction in fraud cases (2022 report).

## In the Real World

  1. eSewa’s Security Model

    • Idea Used: Multi-factor authentication (MFA) + PCI-DSS Level 1.
    • How It Works: Users must verify via OTP + fingerprint before high-value transactions. AI detects if a transaction is unusually large or from a new device.
    • Impact: Fraud dropped by 80% since 2020 (eSewa Annual Report).
  2. Daraz’s Fraud Detection

    • Idea Used: Machine learning for anomaly detection.
    • How It Works: Daraz’s system flags orders with:
      • IP mismatches (e.g., order from Kathmandu but shipped to Pokhara).
      • Unusual purchase patterns (e.g., bulk buying of high-value items).
    • Impact: Blocks 99.8% of fake orders (Daraz Security Whitepaper, 2023).
  3. Nepal Rastra Bank’s Cybersecurity Directives

    • Idea Used: Mandatory security audits for fintech.
    • How It Works: Banks must:
      • Encrypt all customer data.
      • Conduct quarterly penetration tests.
      • Report breaches within 6 hours.
    • Impact: Nepal’s fintech fraud rate halved since 2021 (NRB Report).

## Worked Example: Security Trace for a Kathmandu Traffic Management App

Scenario: A smart traffic app (like Kathmandu Traffic) collects real-time data from cameras and user reports. Analyze its security risks and controls.

2021Nepal’s firstmajor ransomware attac2022Khalti phishingscam exposes 50,000+ a2023NTC website DDoSattack during peak hou2024AI bias in trafficrouting apps (e.g., fa
Timeline of major e-business security incidents in Nepal (2021–2024)
Risk Likelihood Impact Control Measure Real-World Example
Data Breach High High (privacy) GDPR-compliant encryption + anonymization Google Maps’ anonymized traffic data
DDoS Attack Medium High (availability) Cloudflare DDoS protection Waze’s global traffic updates
Insider Leak Medium Medium Role-based access (RBAC) + audit logs Uber’s 2016 hack (insider negligence)
AI Bias in Routes Low Medium Bias audits + diverse training data Google’s What-If Tool for ML models

Visual Trace:

sequenceDiagram
    User->>App: Reports traffic jam (via mobile)
    App->>Database: Stores data (encrypted)
    Database->>AI: Analyzes patterns (bias-checked)
    AI->>User: Suggests alternate route
    Note right of AI: **Controls in action**:
    - Encryption (Preventive)
    - Anomaly Detection (Detective)
    - Bias Audit (Corrective)

## Exam Tip: How to Score Full Marks

  1. Define Clearly

    • Start with precise definitions (e.g., "PCI-DSS is a security standard for payment card transactions, mandating 12 controls like encryption and access logs.").
    • Example: "Phishing exploits social engineering to trick users into revealing credentials."
  2. Use Real-World Examples

    • Nepal: eSewa (PCI-DSS), Daraz (AI fraud), NTC (DDoS protection).
    • Global: Facebook (GDPR fine), SolarWinds (supply chain attack).
    • Link to syllabus: "Like Nabil Bank’s MFA system, Khalti uses OTP + biometrics to prevent unauthorized access."
  3. Compare and Contrast

    • Use tables for frameworks (PCI-DSS vs. GDPR) or flowcharts for processes (e.g., incident response).
    • Example:
      Control PCI-DSS ISO 27001
      Scope Payment security Broad info security
      Key Focus Encryption, access logs Risk management, audits
  4. Analyze Case Studies

    • Structure:
      1. Problem: "Cambridge Analytica violated GDPR by harvesting 87M Facebook profiles."
      2. Impact: "Fined €500M, damaged Facebook’s reputation."
      3. Lesson: "e-Businesses must anonymize data and get explicit consent."
  5. Diagrams = Easy Marks

    • Must-draw diagrams for exams:
      • CIA Triad (Confidentiality, Integrity, Availability).
      • Incident response flowchart (Identify → Contain → Eradicate → Recover).
      • Ethical decision-making matrix (Stakeholders → Options → Consequences).
  6. Common Pitfalls to Avoid

    • ❌ Vague answers: "Security is important." → ✅ *"Multi-factor authentication (MFA) reduces credential theft by 99% (Microsoft 2023)."
    • ❌ Ignoring Nepali context: Always relate to eSewa, Khalti, NTC, or Nabil Bank.
    • ❌ Mixing up controls: "Firewalls are detective." → ✅ "Firewalls are preventive; IDS is detective."

## Quick Revision Checklist

Before the exam, ensure you can: ✅ List 5 cybersecurity threats and their real-world Nepali examples. ✅ Match 3 control types (preventive/detective/corrective) to CIA triad components. ✅ Explain GDPR vs. PDPA 2018 with a fine example. ✅ Draw a flowchart for:

  • Incident response process.
  • Ethical decision-making in data privacy. ✅ Analyze a case study (e.g., Facebook’s Cambridge Analytica) with 3 ethical violations and fixes.

Based on the PU BBA (PU) syllabus for Essential of e-Business, unit 9.

Discussion

Loading…