Unit 1: Information security concepts
Information Security notes · PTU syllabus (BSIT501)
On this page
- Unit summary
- Security overview and background
- Principles of security
- Information classification
- Policy framework
- Role-based security
- Components of an information system
- Balancing security and access
- Approaches to security implementation
- Security systems development life cycle
- Key terms
- Quick revision
- Important questions
Unit summary
Information security protects information and the systems that hold it. This unit covers the background of security, its principles, information classification, the policy framework, role-based security, the components of information systems, balancing security and access, approaches to implementation and the security systems development life cycle.
After this unit you can
- Explain the principles of information security
- Classify information and frame security policies
- Describe role-based security and components of an information system
- Explain implementation approaches and the SecSDLC
PTU syllabus topics
- Security overview and background
- principles of security
- information classification
- policy framework
- role-based security
- components of information systems
- balancing security and access
- security implementation approaches
- security systems development life cycle
Confidentiality
Only authorised people can see data
Integrity
Data is not altered improperly
Availability
Data and systems are there when needed
Topic 1
Security overview and background
- Information security: protecting information and its critical elements — systems and hardware that use, store and transmit it — from unauthorised access, use, disclosure, disruption, modification or destruction.
- Background: early security was physical (guarding mainframes, 1960s); ARPANET in the 1970s raised network security issues; the 1990s internet boom, and later cloud, mobile and ransomware, made security a board-level concern. In India, the IT Act 2000, CERT-In and the Digital Personal Data Protection Act 2023 shape the framework.
Physical
Buildings, locks, guards
Personnel
Background checks, training
Operations
Procedures and continuity
Communications
Protecting media and messages
Network
Firewalls, IDS, VPN
Information
Data at rest and in transit
Topic 2
Principles of security
Confidentiality
Only authorised people can read — encryption, access control
Integrity
Data is accurate and unaltered — hashing, checksums
Availability
Systems and data accessible when needed — backups, redundancy, DDoS protection
Authentication, authorisation and non-repudiation
Verify identity, grant rights, prevent denial of actions — passwords, roles, digital signatures
- Other principles: accountability (actions traced through logs), least privilege, defence in depth, separation of duties, fail-safe defaults.
Topic 3
Information classification
- Top secret or restricted
Disclosure would cause grave damage — strategic plans, encryption keys
- Secret or confidential
Serious damage — customer data, salaries, exam papers
- Internal use only
Minor damage — internal circulars, phone lists
- Public
No damage — brochures, website content
- Process: identify information assets, assign an owner, classify by value and sensitivity, label, apply controls (encryption, access rights), and review periodically. Government uses top secret, secret, confidential, restricted; businesses use confidential, internal and public.
Topic 4
Policy framework
Enterprise information security policy (EISP)
Overall direction and scope, set by top management
Issue-specific policies (ISSP)
Email, internet use, BYOD, passwords
System-specific policies (SysSP)
Firewall rules, access control lists for a system
Standards, guidelines and procedures
Detailed mandatory rules, advice and step-by-step instructions
- Good policy: written, approved by management, communicated, understood and agreed by users, enforced uniformly and reviewed regularly.
Topic 5
Role-based security
- Role-based access control (RBAC): permissions are assigned to roles, and users are assigned to roles — a user gets exactly the rights needed for the job.
Discretionary (DAC)
Owner of the resource
File owner grants read access to a colleague
Mandatory (MAC)
System, based on labels and clearances
Military classified documents
Role-based (RBAC)
Administrator, by job role
Faculty role can enter marks; student role can only view
Attribute-based (ABAC)
Policies on user, resource and context attributes
Access only from the campus network during office hours
Example
College ERP roles: Admin (all modules), Accounts (fees), Faculty (attendance and marks), Student (view own records). When a teacher changes duties, only the role assignment changes.
Topic 6
Components of an information system
- Software
- Applications, operating systems, utilities — often vulnerable to bugs
- Hardware
- Computers and devices — can be stolen or damaged
- Data
- The most valuable asset and main target
- People
- Users and administrators — the weakest link through errors and social engineering
- Procedures
- Written instructions — leaked procedures help attackers
- Networks
- Connect systems and expose them to outside threats
Topic 7
Balancing security and access
- Perfect security is impossible; security should be balanced against usability and cost.
Effect on users
Frustration, workarounds, lost productivity
Easy to use
Risk
Low but unusable
High exposure to attack
Example
Password change every week with 20 characters
Shared admin password for all staff
- Balance: risk assessment decides controls proportionate to asset value; multi-factor authentication and single sign-on improve both.
Topic 8
Approaches to security implementation
Initiated by
System administrators and technical staff
Senior management
Strengths
Technical expertise
Management support, budget, clear policy, accountability
Weaknesses
Lacks authority, funding and coordination
Needs champions and planning
Success rate
Low
High — preferred approach
Topic 9
Security systems development life cycle
- 1. Investigation: Management defines goals, scope and budget
- 2. Analysis: Study threats, existing controls, legal issues, risk
- 3. Logical design: Security blueprint, policies, continuity plans
- 4. Physical design: Select technologies, evaluate options
- 5. Implementation: Acquire, test, install, train
- 6. Maintenance and change: Monitor, test, update against new threats
Key terms
- Information security
- Protection of information and systems from harm
- CIA triad
- Confidentiality, integrity and availability
- Information classification
- Labelling information by sensitivity
- RBAC
- Access granted according to job role
- SecSDLC
- Life cycle for developing security systems
Quick revision
- Security history; layers of security.
- CIA, authentication, non-repudiation; least privilege, defence in depth.
- Classification levels; EISP, ISSP, SysSP.
- DAC, MAC, RBAC, ABAC; IS components.
- Security vs access; bottom-up vs top-down; SecSDLC phases.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.Define information security.
- Q2.State the CIA triad.
- Q3.What is information classification?
- Q4.Distinguish EISP and ISSP.
- Q5.What is role-based access control?
- Q6.Why is the top-down approach preferred?
Long-answer questions
- Q1.Explain the principles of information security.
- Q2.Explain information classification and the security policy framework.
- Q3.Explain role-based security and the components of an information system.
- Q4.Explain the security systems development life cycle.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security, or to ask about studying B.Sc IT at Synetic.
