Unit 3: Security management and laws
Information Security notes · PTU syllabus (BSIT501)
On this page
Unit summary
Security must be managed, audited and backed by law. This unit covers access control and intrusion detection, identification and authorisation, intrusion detection and prevention systems, security procedures and best practices, security laws, intellectual property rights, international security standards, security audit, and SSE-CMM and COBIT.
After this unit you can
- Explain identification, authentication and authorisation
- Explain IDS and IPS
- Describe security laws and IPR
- Explain standards, audit, SSE-CMM and COBIT
PTU syllabus topics
- Access control and intrusion detection
- identification and authorization
- intrusion detection and prevention systems
- security procedures and best practices
- security laws
- IPR
- international security standards
- security audit
- SSE-CMM/COBIT
Full form
Intrusion detection system
Intrusion prevention system
Action
Detects and alerts
Detects and blocks
Placement
Monitors a copy of traffic
Inline with traffic
Risk
Attack may get through
False positives may block good traffic
Topic 1
Access control, identification and authorisation
- 1Identification
User claims an identity — user ID
- 2Authentication
Proves it — password, OTP, fingerprint
- 3Authorisation
System grants rights — read, write, execute
- 4Accountability
Actions logged and audited
- Something you know
- Password, PIN, security question
- Something you have
- Smart card, OTP token, mobile phone
- Something you are
- Fingerprint, face, iris
- Somewhere you are or something you do
- Location, typing rhythm
- Multi-factor authentication combines two or more different factors. Biometric errors: false acceptance rate (FAR) and false rejection rate (FRR); the crossover error rate (CER) compares devices.
Topic 2
Intrusion detection and prevention systems
- Personal firewall: software on an individual device (Windows Defender Firewall) controlling its incoming and outgoing connections — important for remote workers.
- Intrusion detection system (IDS): monitors traffic or hosts for suspicious activity and alerts administrators; intrusion prevention system (IPS) also blocks it.
Method
Matches known attack patterns
Flags deviations from normal behaviour
Strength
Accurate for known attacks
Can detect new attacks
Weakness
Misses new attacks
More false alarms
- Types: network-based (NIDS) and host-based (HIDS); modern security operations centres use SIEM tools to correlate alerts.
- IDS response: passive (alert, log) or active (block IP, reset connection — IPS). Honeypots lure attackers to study their methods.
Topic 3
Security procedures and best practices
- Risk assessment
- Identify assets, threats, vulnerabilities and controls
- Patch management
- Apply updates promptly
- Least privilege and separation of duties
- Limit and split powers
- Backups
- 3-2-1 rule: 3 copies, 2 media, 1 offsite
- Awareness training
- Phishing drills, policies
- Incident response
- Prepare, detect, contain, eradicate, recover, learn
- Logging and monitoring
- SIEM and regular review
Topic 4
Security laws
- Information Technology Act, 2000 (amended 2008)
- Legal recognition of electronic records and signatures; cyber offences
- Section 43
- Compensation for unauthorised access, downloading or damage
- Section 43A
- Compensation for failure to protect sensitive personal data — being replaced by the DPDP Act regime
- Section 66, 66C, 66D
- Hacking, identity theft, cheating by impersonation
- Section 66F
- Cyber terrorism
- Section 72A
- Disclosure of information in breach of contract
- CERT-In directions 2022
- Report cyber incidents within six hours
- Digital Personal Data Protection Act, 2023
- Consent-based processing and duties of data fiduciaries, phased in through the DPDP Rules, 2025
- International: GDPR (European Union) for personal data; US laws such as HIPAA (health) and the Computer Fraud and Abuse Act.
Topic 5
Intellectual property rights
Copyright
Original works of expression
Source code, documentation
Patent
Novel, non-obvious inventions
Technical inventions with software (limited in India under Section 3(k))
Trademark
Names, logos and marks
Product brand names
Trade secret
Confidential business information
Algorithms kept secret, protected by NDAs
Industrial design
Visual appearance
Device design
- Software piracy and licence violations breach copyright; open-source licences (GPL, MIT) grant rights under conditions.
Topic 6
International security standards
- ISO/IEC 27001
- Requirements for an information security management system (ISMS) — certifiable
- ISO/IEC 27002
- Code of practice: security controls
- PCI DSS
- Card payment data security
- NIST Cybersecurity Framework
- Identify, protect, detect, respond, recover
- Common Criteria (ISO/IEC 15408)
- Evaluating security of IT products
Topic 7
Security audit
- 1
Plan
Scope, objectives, criteria
- 2
Collect evidence
Policies, configurations, logs, interviews
- 3
Test
Vulnerability scans, penetration tests, control testing
- 4
Analyse
Compare with standards; rate risks
- 5
Report
Findings and recommendations
- 6
Follow up
Verify corrective actions
- Types: internal and external audits; compliance audits (ISO 27001, RBI guidelines for banks); IT general controls review.
Topic 8
SSE-CMM and COBIT
- SSE-CMM (Systems Security Engineering Capability Maturity Model, ISO/IEC 21827): measures the maturity of an organisation's security engineering processes across security, project and organisational process areas.
- 1Level 1
Performed informally
- 2Level 2
Planned and tracked
- 3Level 3
Well defined
- 4Level 4
Quantitatively controlled
- 5Level 5
Continuously improving
- COBIT (Control Objectives for Information and Related Technologies, ISACA): a framework for governance and management of enterprise IT, linking IT goals with business goals; COBIT 2019 defines governance and management objectives such as Evaluate, Direct and Monitor (EDM) and Align, Plan and Organise (APO), Build, Acquire and Implement (BAI), Deliver, Service and Support (DSS), and Monitor, Evaluate and Assess (MEA).
Key terms
- Authentication
- Verifying a claimed identity
- Authorisation
- Granting rights to an authenticated user
- IPS
- System that detects and blocks attacks
- ISO/IEC 27001
- Standard for information security management systems
- COBIT
- Framework for IT governance and management
Quick revision
- Identification → authentication → authorisation → accountability; factors; MFA; FAR, FRR.
- IDS vs IPS; signature vs anomaly; NIDS, HIDS; honeypots.
- Best practices; incident response.
- IT Act sections; CERT-In; DPDP Act 2023; IPR forms.
- ISO 27001/27002, PCI DSS, NIST CSF; audit process; SSE-CMM levels; COBIT domains.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.Distinguish identification and authentication.
- Q2.What is multi-factor authentication?
- Q3.Distinguish IDS and IPS.
- Q4.Which section of the IT Act deals with identity theft?
- Q5.What is ISO/IEC 27001?
- Q6.Expand COBIT.
Long-answer questions
- Q1.Explain access control, identification and authorisation.
- Q2.Explain intrusion detection and prevention systems.
- Q3.Explain security laws and intellectual property rights.
- Q4.Explain security audit, international standards, SSE-CMM and COBIT.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security, or to ask about studying B.Sc IT at Synetic.
