Unit 1 of 4 · B.Sc IT Sem 5

Unit 1: Information security concepts

Information Security notes · PTU syllabus (BSIT501)

3 min read9 topics10 exam questions
On this page
  1. Unit summary
  2. Security overview and background
  3. Principles of security
  4. Information classification
  5. Policy framework
  6. Role-based security
  7. Components of an information system
  8. Balancing security and access
  9. Approaches to security implementation
  10. Security systems development life cycle
  11. Key terms
  12. Quick revision
  13. Important questions

Unit summary

Information security protects information and the systems that hold it. This unit covers the background of security, its principles, information classification, the policy framework, role-based security, the components of information systems, balancing security and access, approaches to implementation and the security systems development life cycle.

After this unit you can

  • Explain the principles of information security
  • Classify information and frame security policies
  • Describe role-based security and components of an information system
  • Explain implementation approaches and the SecSDLC

PTU syllabus topics

  • Security overview and background
  • principles of security
  • information classification
  • policy framework
  • role-based security
  • components of information systems
  • balancing security and access
  • security implementation approaches
  • security systems development life cycle
ClassificationThe CIA triad
Information security
  • Confidentiality

    Only authorised people can see data

  • Integrity

    Data is not altered improperly

  • Availability

    Data and systems are there when needed

1

Topic 1

Security overview and background

  • Information security: protecting information and its critical elements — systems and hardware that use, store and transmit it — from unauthorised access, use, disclosure, disruption, modification or destruction.
  • Background: early security was physical (guarding mainframes, 1960s); ARPANET in the 1970s raised network security issues; the 1990s internet boom, and later cloud, mobile and ransomware, made security a board-level concern. In India, the IT Act 2000, CERT-In and the Digital Personal Data Protection Act 2023 shape the framework.
ClassificationLayers of security
Security
  • Physical

    Buildings, locks, guards

  • Personnel

    Background checks, training

  • Operations

    Procedures and continuity

  • Communications

    Protecting media and messages

  • Network

    Firewalls, IDS, VPN

  • Information

    Data at rest and in transit

2

Topic 2

Principles of security

FrameworkCIA triad and more
  • Confidentiality

    Only authorised people can read — encryption, access control

  • Integrity

    Data is accurate and unaltered — hashing, checksums

  • Availability

    Systems and data accessible when needed — backups, redundancy, DDoS protection

  • Authentication, authorisation and non-repudiation

    Verify identity, grant rights, prevent denial of actions — passwords, roles, digital signatures

  • Other principles: accountability (actions traced through logs), least privilege, defence in depth, separation of duties, fail-safe defaults.
3

Topic 3

Information classification

HierarchyClassification levels
  1. Top secret or restricted

    Disclosure would cause grave damage — strategic plans, encryption keys

  2. Secret or confidential

    Serious damage — customer data, salaries, exam papers

  3. Internal use only

    Minor damage — internal circulars, phone lists

  4. Public

    No damage — brochures, website content

  • Process: identify information assets, assign an owner, classify by value and sensitivity, label, apply controls (encryption, access rights), and review periodically. Government uses top secret, secret, confidential, restricted; businesses use confidential, internal and public.
4

Topic 4

Policy framework

ClassificationSecurity policy framework
Policies
  • Enterprise information security policy (EISP)

    Overall direction and scope, set by top management

  • Issue-specific policies (ISSP)

    Email, internet use, BYOD, passwords

  • System-specific policies (SysSP)

    Firewall rules, access control lists for a system

  • Standards, guidelines and procedures

    Detailed mandatory rules, advice and step-by-step instructions

  • Good policy: written, approved by management, communicated, understood and agreed by users, enforced uniformly and reviewed regularly.
5

Topic 5

Role-based security

  • Role-based access control (RBAC): permissions are assigned to roles, and users are assigned to roles — a user gets exactly the rights needed for the job.
ComparisonAccess control models
Who decides
Example

Discretionary (DAC)

Owner of the resource

File owner grants read access to a colleague

Mandatory (MAC)

System, based on labels and clearances

Military classified documents

Role-based (RBAC)

Administrator, by job role

Faculty role can enter marks; student role can only view

Attribute-based (ABAC)

Policies on user, resource and context attributes

Access only from the campus network during office hours

Example

College ERP roles: Admin (all modules), Accounts (fees), Faculty (attendance and marks), Student (view own records). When a teacher changes duties, only the role assignment changes.

6

Topic 6

Components of an information system

Key termsComponents of an information system
Software
Applications, operating systems, utilities — often vulnerable to bugs
Hardware
Computers and devices — can be stolen or damaged
Data
The most valuable asset and main target
People
Users and administrators — the weakest link through errors and social engineering
Procedures
Written instructions — leaked procedures help attackers
Networks
Connect systems and expose them to outside threats
7

Topic 7

Balancing security and access

  • Perfect security is impossible; security should be balanced against usability and cost.
ComparisonSecurity vs access
Too much security
Too much access

Effect on users

Frustration, workarounds, lost productivity

Easy to use

Risk

Low but unusable

High exposure to attack

Example

Password change every week with 20 characters

Shared admin password for all staff

  • Balance: risk assessment decides controls proportionate to asset value; multi-factor authentication and single sign-on improve both.
8

Topic 8

Approaches to security implementation

ComparisonImplementation approaches
Bottom-up
Top-down

Initiated by

System administrators and technical staff

Senior management

Strengths

Technical expertise

Management support, budget, clear policy, accountability

Weaknesses

Lacks authority, funding and coordination

Needs champions and planning

Success rate

Low

High — preferred approach

9

Topic 9

Security systems development life cycle

CycleSecurity SDLC (SecSDLC)
Security SDLC (SecSDLC)
1Investigation
2Analysis
3Logical design
4Physical design
5Implementation
6Maintenance and change
  1. 1. Investigation: Management defines goals, scope and budget
  2. 2. Analysis: Study threats, existing controls, legal issues, risk
  3. 3. Logical design: Security blueprint, policies, continuity plans
  4. 4. Physical design: Select technologies, evaluate options
  5. 5. Implementation: Acquire, test, install, train
  6. 6. Maintenance and change: Monitor, test, update against new threats

Key terms

Information security
Protection of information and systems from harm
CIA triad
Confidentiality, integrity and availability
Information classification
Labelling information by sensitivity
RBAC
Access granted according to job role
SecSDLC
Life cycle for developing security systems

Quick revision

  • Security history; layers of security.
  • CIA, authentication, non-repudiation; least privilege, defence in depth.
  • Classification levels; EISP, ISSP, SysSP.
  • DAC, MAC, RBAC, ABAC; IS components.
  • Security vs access; bottom-up vs top-down; SecSDLC phases.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.Define information security.
  2. Q2.State the CIA triad.
  3. Q3.What is information classification?
  4. Q4.Distinguish EISP and ISSP.
  5. Q5.What is role-based access control?
  6. Q6.Why is the top-down approach preferred?

Long-answer questions

  1. Q1.Explain the principles of information security.
  2. Q2.Explain information classification and the security policy framework.
  3. Q3.Explain role-based security and the components of an information system.
  4. Q4.Explain the security systems development life cycle.

Stuck on this unit?

Message SBS on WhatsApp for help with Information Security, or to ask about studying B.Sc IT at Synetic.

WhatsApp us