Unit 3 of 4 · B.Sc IT Sem 5

Unit 3: Security management and laws

Information Security notes · PTU syllabus (BSIT501)

3 min read8 topics10 exam questions
On this page
  1. Unit summary
  2. Access control, identification and authorisation
  3. Intrusion detection and prevention systems
  4. Security procedures and best practices
  5. Security laws
  6. Intellectual property rights
  7. International security standards
  8. Security audit
  9. SSE-CMM and COBIT
  10. Key terms
  11. Quick revision
  12. Important questions

Unit summary

Security must be managed, audited and backed by law. This unit covers access control and intrusion detection, identification and authorisation, intrusion detection and prevention systems, security procedures and best practices, security laws, intellectual property rights, international security standards, security audit, and SSE-CMM and COBIT.

After this unit you can

  • Explain identification, authentication and authorisation
  • Explain IDS and IPS
  • Describe security laws and IPR
  • Explain standards, audit, SSE-CMM and COBIT

PTU syllabus topics

  • Access control and intrusion detection
  • identification and authorization
  • intrusion detection and prevention systems
  • security procedures and best practices
  • security laws
  • IPR
  • international security standards
  • security audit
  • SSE-CMM/COBIT
ComparisonIDS vs IPS
IDS
IPS

Full form

Intrusion detection system

Intrusion prevention system

Action

Detects and alerts

Detects and blocks

Placement

Monitors a copy of traffic

Inline with traffic

Risk

Attack may get through

False positives may block good traffic

1

Topic 1

Access control, identification and authorisation

ProcessAccess control process
  1. 1Identification

    User claims an identity — user ID

  2. 2Authentication

    Proves it — password, OTP, fingerprint

  3. 3Authorisation

    System grants rights — read, write, execute

  4. 4Accountability

    Actions logged and audited

Key termsAuthentication factors
Something you know
Password, PIN, security question
Something you have
Smart card, OTP token, mobile phone
Something you are
Fingerprint, face, iris
Somewhere you are or something you do
Location, typing rhythm
  • Multi-factor authentication combines two or more different factors. Biometric errors: false acceptance rate (FAR) and false rejection rate (FRR); the crossover error rate (CER) compares devices.
2

Topic 2

Intrusion detection and prevention systems

  • Personal firewall: software on an individual device (Windows Defender Firewall) controlling its incoming and outgoing connections — important for remote workers.
  • Intrusion detection system (IDS): monitors traffic or hosts for suspicious activity and alerts administrators; intrusion prevention system (IPS) also blocks it.
ComparisonIDS approaches
Signature-based
Anomaly-based

Method

Matches known attack patterns

Flags deviations from normal behaviour

Strength

Accurate for known attacks

Can detect new attacks

Weakness

Misses new attacks

More false alarms

  • Types: network-based (NIDS) and host-based (HIDS); modern security operations centres use SIEM tools to correlate alerts.
  • IDS response: passive (alert, log) or active (block IP, reset connection — IPS). Honeypots lure attackers to study their methods.
3

Topic 3

Security procedures and best practices

Key termsBest practices
Risk assessment
Identify assets, threats, vulnerabilities and controls
Patch management
Apply updates promptly
Least privilege and separation of duties
Limit and split powers
Backups
3-2-1 rule: 3 copies, 2 media, 1 offsite
Awareness training
Phishing drills, policies
Incident response
Prepare, detect, contain, eradicate, recover, learn
Logging and monitoring
SIEM and regular review
4

Topic 4

Security laws

Key termsIndian cyber laws
Information Technology Act, 2000 (amended 2008)
Legal recognition of electronic records and signatures; cyber offences
Section 43
Compensation for unauthorised access, downloading or damage
Section 43A
Compensation for failure to protect sensitive personal data — being replaced by the DPDP Act regime
Section 66, 66C, 66D
Hacking, identity theft, cheating by impersonation
Section 66F
Cyber terrorism
Section 72A
Disclosure of information in breach of contract
CERT-In directions 2022
Report cyber incidents within six hours
Digital Personal Data Protection Act, 2023
Consent-based processing and duties of data fiduciaries, phased in through the DPDP Rules, 2025
  • International: GDPR (European Union) for personal data; US laws such as HIPAA (health) and the Computer Fraud and Abuse Act.
5

Topic 5

Intellectual property rights

ComparisonForms of IPR
Protects
Software example

Copyright

Original works of expression

Source code, documentation

Patent

Novel, non-obvious inventions

Technical inventions with software (limited in India under Section 3(k))

Trademark

Names, logos and marks

Product brand names

Trade secret

Confidential business information

Algorithms kept secret, protected by NDAs

Industrial design

Visual appearance

Device design

  • Software piracy and licence violations breach copyright; open-source licences (GPL, MIT) grant rights under conditions.
6

Topic 6

International security standards

Key termsSecurity standards
ISO/IEC 27001
Requirements for an information security management system (ISMS) — certifiable
ISO/IEC 27002
Code of practice: security controls
PCI DSS
Card payment data security
NIST Cybersecurity Framework
Identify, protect, detect, respond, recover
Common Criteria (ISO/IEC 15408)
Evaluating security of IT products
7

Topic 7

Security audit

ProcessSecurity audit process
  1. 1

    Plan

    Scope, objectives, criteria

  2. 2

    Collect evidence

    Policies, configurations, logs, interviews

  3. 3

    Test

    Vulnerability scans, penetration tests, control testing

  4. 4

    Analyse

    Compare with standards; rate risks

  5. 5

    Report

    Findings and recommendations

  6. 6

    Follow up

    Verify corrective actions

  • Types: internal and external audits; compliance audits (ISO 27001, RBI guidelines for banks); IT general controls review.
8

Topic 8

SSE-CMM and COBIT

  • SSE-CMM (Systems Security Engineering Capability Maturity Model, ISO/IEC 21827): measures the maturity of an organisation's security engineering processes across security, project and organisational process areas.
ProcessSSE-CMM capability levels
  1. 1Level 1

    Performed informally

  2. 2Level 2

    Planned and tracked

  3. 3Level 3

    Well defined

  4. 4Level 4

    Quantitatively controlled

  5. 5Level 5

    Continuously improving

  • COBIT (Control Objectives for Information and Related Technologies, ISACA): a framework for governance and management of enterprise IT, linking IT goals with business goals; COBIT 2019 defines governance and management objectives such as Evaluate, Direct and Monitor (EDM) and Align, Plan and Organise (APO), Build, Acquire and Implement (BAI), Deliver, Service and Support (DSS), and Monitor, Evaluate and Assess (MEA).

Key terms

Authentication
Verifying a claimed identity
Authorisation
Granting rights to an authenticated user
IPS
System that detects and blocks attacks
ISO/IEC 27001
Standard for information security management systems
COBIT
Framework for IT governance and management

Quick revision

  • Identification → authentication → authorisation → accountability; factors; MFA; FAR, FRR.
  • IDS vs IPS; signature vs anomaly; NIDS, HIDS; honeypots.
  • Best practices; incident response.
  • IT Act sections; CERT-In; DPDP Act 2023; IPR forms.
  • ISO 27001/27002, PCI DSS, NIST CSF; audit process; SSE-CMM levels; COBIT domains.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.Distinguish identification and authentication.
  2. Q2.What is multi-factor authentication?
  3. Q3.Distinguish IDS and IPS.
  4. Q4.Which section of the IT Act deals with identity theft?
  5. Q5.What is ISO/IEC 27001?
  6. Q6.Expand COBIT.

Long-answer questions

  1. Q1.Explain access control, identification and authorisation.
  2. Q2.Explain intrusion detection and prevention systems.
  3. Q3.Explain security laws and intellectual property rights.
  4. Q4.Explain security audit, international standards, SSE-CMM and COBIT.

Stuck on this unit?

Message SBS on WhatsApp for help with Information Security, or to ask about studying B.Sc IT at Synetic.

WhatsApp us