Unit 2: Security in digital transformation
Managing Digital Innovation and Transformation notes · PTU syllabus (MBA 944-18)
On this page
Unit summary
Security is the foundation of trust in digital business. This unit covers an overview of security, digital threats, encryption and cryptography fundamentals, and securing e-commerce networks through HTTP and SSL, firewalls, personal firewalls, intrusion detection systems, VPNs and public key infrastructure.
After this unit you can
- Explain security goals and digital threats
- Explain encryption and cryptography fundamentals
- Explain HTTP, SSL/TLS, firewalls and IDS
- Explain VPNs and public key infrastructure
PTU syllabus topics
- Security overview
- digital threats
- encryption and cryptography fundamentals
- securing e-commerce networks — HTTP
- SSL
- firewalls
- personal firewalls
- IDS
- VPNs
- Public Key Infrastructure
Encryption
Protect data in transit and at rest
SSL/TLS and HTTPS
Secure web traffic
Firewalls and IDS
Filter and detect
VPN
Secure remote access
PKI
Certificates and trust
Topic 1
Security overview
Confidentiality
Only intended recipients can read (encryption)
Integrity
Message not altered (hashing)
Authentication
Sender is who they claim (certificates, passwords)
Non-repudiation
Sender cannot deny sending (digital signatures)
- Access controls: identification and authentication, authorisation (role-based access), accounting (logs).
Topic 2
Digital threats
Malware
Viruses, worms, trojans, spyware, ransomware
Phishing and social engineering
Fake emails, sites and calls stealing credentials
Denial of service
Flooding systems to make them unavailable (DDoS)
Data breaches
Unauthorised access to customer data
Insider threats
Malicious or careless employees
Man-in-the-middle
Intercepting communications
Supply-chain attacks
Compromising vendors or software updates
- India: CERT-In coordinates incident response; reporting of cyber incidents within six hours is mandatory for organisations.
Topic 3
Encryption and cryptography fundamentals
Keys
One shared secret key
Pair — public key and private key
Speed
Fast
Slower
Key distribution
Difficult — key must be shared securely
Easy — public key can be published
Examples
AES, DES, 3DES
RSA, ECC
Use
Bulk data encryption
Key exchange, digital signatures
- Hybrid approach (SSL/TLS): asymmetric encryption to exchange a session key, then symmetric encryption for data.
- Public/private key pair: what one key encrypts only the other can decrypt — encrypt with the receiver's public key for confidentiality; sign with the sender's private key for authentication.
- Hash functions (SHA-256) produce fixed-length digests for integrity checks; AES is the common symmetric standard; RSA and elliptic-curve cryptography are common asymmetric methods.
Topic 4
HTTP and SSL/TLS
- HTTP transfers web pages in plain text; HTTPS adds TLS (successor of SSL) to encrypt traffic and authenticate the server.
- 1Client hello
Supported versions and ciphers
- 2Server hello and certificate
- 3Client verifies certificate with a trusted CA
- 4Key exchange
Session key agreed
- 5Encrypted session
Symmetric encryption of data
- The browser padlock shows a valid certificate; TLS 1.2 and 1.3 are current versions.
Topic 5
Firewalls
A firewall is a hardware or software system that monitors and controls incoming and outgoing network traffic based on security rules, separating trusted internal networks from untrusted ones.
Packet-filtering router
Checks IP addresses, ports, protocols
Stateful inspection
Tracks connection states
Application (proxy) gateway
Inspects application-level traffic
Circuit-level gateway
Validates TCP sessions
Next-generation firewall
Deep packet inspection, intrusion prevention, application awareness
DMZ (screened subnet)
Hosts public servers between two firewalls
- Functionality: access control, logging and auditing, NAT (hiding internal addresses), VPN support, content filtering, alerts.
- Design factors: security policy (default deny), network architecture (DMZ), performance and scalability, redundancy, ease of management, cost, regular updating and monitoring; firewalls do not stop insider threats or malware in permitted traffic — layered security is needed.
Topic 6
Personal firewalls and intrusion detection systems
- Personal firewall: software on an individual device (Windows Defender Firewall) controlling its incoming and outgoing connections — important for remote workers.
- Intrusion detection system (IDS): monitors traffic or hosts for suspicious activity and alerts administrators; intrusion prevention system (IPS) also blocks it.
Method
Matches known attack patterns
Flags deviations from normal behaviour
Strength
Accurate for known attacks
Can detect new attacks
Weakness
Misses new attacks
More false alarms
- Types: network-based (NIDS) and host-based (HIDS); modern security operations centres use SIEM tools to correlate alerts.
Topic 7
Virtual private networks
- VPN: creates an encrypted tunnel over the public internet so remote users or branches can access a private network securely.
- Types: remote-access VPN and site-to-site VPN; protocols — IPsec, SSL/TLS VPNs, WireGuard.
- Zero-trust networking increasingly complements VPNs — verify every user and device for every access.
Topic 8
Public key infrastructure and authentication
- 1
Sender hashes the message
SHA-256 digest
- 2
Sender encrypts the hash with private key
Digital signature
- 3
Message + signature sent
- 4
Receiver decrypts signature with sender's public key
- 5
Receiver hashes the message
- 6
Hashes match → authentic and unaltered
- Digital certificates: issued by Certifying Authorities (PKI) binding a public key to an identity; India — Controller of Certifying Authorities under the IT Act.
- Additional authentication methods: passwords and PINs, OTP, two-factor and multi-factor authentication, biometrics (Aadhaar fingerprint/face), smart cards and tokens, Kerberos.
- Non-repudiation methods: digital signatures, time-stamping services, audit logs, trusted third parties.
Certifying authority (CA)
Issues and revokes certificates
Registration authority
Verifies identity before issue
Digital certificates
Bind public keys to identities (X.509)
Certificate revocation lists and OCSP
Check validity
Repository
Stores certificates and policies
Key terms
- Ransomware
- Malware that encrypts data and demands payment
- TLS
- Protocol securing data in transit on the web
- IDS
- System detecting suspicious network or host activity
- VPN
- Encrypted tunnel over a public network
- PKI
- System of CAs, certificates and keys enabling trust
Quick revision
- Security goals: confidentiality, integrity, availability, authentication, non-repudiation.
- Threats: malware, phishing, DDoS, breaches, insiders, MITM, supply chain; CERT-In.
- Symmetric vs asymmetric; hashing; AES, RSA.
- HTTPS and TLS handshake; firewalls; personal firewalls; IDS and IPS.
- VPN types; zero trust; PKI components.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.Name the five security goals.
- Q2.What is ransomware?
- Q3.Distinguish symmetric and asymmetric encryption.
- Q4.What is the role of TLS?
- Q5.Distinguish IDS and IPS.
- Q6.Name the components of PKI.
Long-answer questions
- Q1.Explain the major digital threats to organisations.
- Q2.Explain encryption and cryptography fundamentals.
- Q3.Explain how HTTPS, firewalls and IDS secure e-commerce networks.
- Q4.Explain VPNs and public key infrastructure.
Stuck on this unit?
Message SBS on WhatsApp for help with Managing Digital Innovation and Transformation, or to ask about studying MBA at Synetic.
