Unit 1: Security fundamentals
Information Security and Cyber Law notes · PTU syllabus (PGCA1932)
On this page
Unit summary
Information security protects the confidentiality, integrity and availability of information and the systems that hold it. This unit covers information system classification and components, the CIA triad, security functional requirements, authentication methods, access control models, and database security and encryption.
After this unit you can
- Classify information systems and their components
- Explain the CIA triad and security functional requirements
- Compare password, token, biometric and remote authentication
- Apply DAC, RBAC and file access control; secure databases
PTU syllabus topics
- Information system classification and components
- CIA triad
- security functional requirements
- authentication methods (password, token, biometric, remote user)
- access control principles (discretionary, role-based, file access control)
- database security and encryption
DAC
The owner of the resource
File permissions set by the user
MAC
System-wide security labels
Military classification levels
RBAC
The user's role
HR role sees salary data
Topic 1
Classification of information systems
- Top secret or restricted
Disclosure would cause grave damage — strategic plans, encryption keys
- Secret or confidential
Serious damage — customer data, salaries, exam papers
- Internal use only
Minor damage — internal circulars, phone lists
- Public
No damage — brochures, website content
- Process: identify information assets, assign an owner, classify by value and sensitivity, label, apply controls (encryption, access rights), and review periodically. Government uses top secret, secret, confidential, restricted; businesses use confidential, internal and public.
Topic 2
Components of an information system
- Software
- Applications, operating systems, utilities — often vulnerable to bugs
- Hardware
- Computers and devices — can be stolen or damaged
- Data
- The most valuable asset and main target
- People
- Users and administrators — the weakest link through errors and social engineering
- Procedures
- Written instructions — leaked procedures help attackers
- Networks
- Connect systems and expose them to outside threats
Topic 3
The CIA triad and related principles
Confidentiality
Only authorised people can read — encryption, access control
Integrity
Data is accurate and unaltered — hashing, checksums
Availability
Systems and data accessible when needed — backups, redundancy, DDoS protection
Authentication, authorisation and non-repudiation
Verify identity, grant rights, prevent denial of actions — passwords, roles, digital signatures
- Other principles: accountability (actions traced through logs), least privilege, defence in depth, separation of duties, fail-safe defaults.
Topic 4
Security functional requirements
- Access control
- Limit access to authorised users
- Awareness and training
- Users know their responsibilities
- Audit and accountability
- Logs traceable to users
- Configuration management
- Baselines and change control
- Identification and authentication
- Verify users and devices
- Incident response
- Detect, contain, recover
- Maintenance and media protection
- Safe repair and disposal
- Physical and environmental protection
- Locks, power, fire
- Contingency planning
- Backups, disaster recovery
- System and communications protection
- Encryption, boundary defence
- Risk assessment
- Identify and rate risks
Topic 5
User authentication methods
Password (something you know)
Secret compared with a salted hash
Guessing, phishing, reuse
Token (something you have)
Smart card, OTP device, phone app
Loss, theft, cloning
Biometric (something you are)
Fingerprint, face, iris, voice
False accept and reject rates, cannot be changed if stolen
Remote user
Challenge–response over a network so the secret never travels in clear
Replay and man-in-the-middle attacks
- Multi-factor authentication combines two or more factors (password + OTP, as in UPI and net banking).
FAR = false accepts / impostor attempts
False acceptance rate
FRR = false rejects / genuine attempts
False rejection rate
EER = point where FAR = FRR
Lower is better
Topic 6
Access control principles
Discretionary (DAC)
Owner grants rights to others
Unix permissions, Windows ACLs
Mandatory (MAC)
System-enforced labels (Top Secret, Secret)
Military systems, SELinux
Role-based (RBAC)
Permissions attached to roles; users assigned roles
Clerk, manager, auditor in a bank
Attribute-based (ABAC)
Rules on user, resource and environment attributes
"Doctors may read records of their own patients during shifts"
- Access matrix
- Subjects × objects with rights
- Access control list
- Per-object list of subjects and rights
- Capability list
- Per-subject list of objects and rights
bashchmod 750 report.sh # owner rwx, group r-x, others none
chown alice:finance report.shTopic 7
Database security and encryption
- Threats: SQL injection, excessive privileges, weak authentication, unencrypted backups, inference attacks on statistical databases.
- Controls: authentication, GRANT and REVOKE privileges, views to hide sensitive columns, encryption (TDE), auditing, data masking, regular patching and backups.
Key terms
- CIA triad
- Confidentiality, integrity and availability
- Multi-factor authentication
- Using two or more independent factors
- RBAC
- Role-based access control
- ACL
- Access control list attached to an object
- FAR
- False acceptance rate of a biometric system
Quick revision
- Information classification; components of an information system.
- CIA triad plus authenticity and accountability; FIPS 200 requirement areas.
- Password, token, biometric, remote authentication; MFA; FAR, FRR.
- DAC, MAC, RBAC, ABAC; access matrix, ACL, capabilities; database security.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is the CIA triad?
- Q2.Name three security functional requirements.
- Q3.What is two-factor authentication?
- Q4.Define FAR and FRR.
- Q5.Distinguish DAC and RBAC.
- Q6.What is an access control list?
Long-answer questions
- Q1.Explain the components of an information system and the CIA triad.
- Q2.Compare user authentication methods.
- Q3.Explain access control models with examples.
- Q4.Explain database security and encryption.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.
