Unit 1 of 4 · M.Sc IT Sem 4

Unit 1: Security fundamentals

Information Security and Cyber Law notes · PTU syllabus (PGCA1932)

3 min read7 topics10 exam questions
On this page
  1. Unit summary
  2. Classification of information systems
  3. Components of an information system
  4. The CIA triad and related principles
  5. Security functional requirements
  6. User authentication methods
  7. Access control principles
  8. Database security and encryption
  9. Key terms
  10. Quick revision
  11. Important questions

Unit summary

Information security protects the confidentiality, integrity and availability of information and the systems that hold it. This unit covers information system classification and components, the CIA triad, security functional requirements, authentication methods, access control models, and database security and encryption.

After this unit you can

  • Classify information systems and their components
  • Explain the CIA triad and security functional requirements
  • Compare password, token, biometric and remote authentication
  • Apply DAC, RBAC and file access control; secure databases

PTU syllabus topics

  • Information system classification and components
  • CIA triad
  • security functional requirements
  • authentication methods (password, token, biometric, remote user)
  • access control principles (discretionary, role-based, file access control)
  • database security and encryption
ComparisonAccess control models
Who decides access
Example

DAC

The owner of the resource

File permissions set by the user

MAC

System-wide security labels

Military classification levels

RBAC

The user's role

HR role sees salary data

1

Topic 1

Classification of information systems

HierarchyClassification levels
  1. Top secret or restricted

    Disclosure would cause grave damage — strategic plans, encryption keys

  2. Secret or confidential

    Serious damage — customer data, salaries, exam papers

  3. Internal use only

    Minor damage — internal circulars, phone lists

  4. Public

    No damage — brochures, website content

  • Process: identify information assets, assign an owner, classify by value and sensitivity, label, apply controls (encryption, access rights), and review periodically. Government uses top secret, secret, confidential, restricted; businesses use confidential, internal and public.
2

Topic 2

Components of an information system

Key termsComponents of an information system
Software
Applications, operating systems, utilities — often vulnerable to bugs
Hardware
Computers and devices — can be stolen or damaged
Data
The most valuable asset and main target
People
Users and administrators — the weakest link through errors and social engineering
Procedures
Written instructions — leaked procedures help attackers
Networks
Connect systems and expose them to outside threats
3

Topic 3

The CIA triad and related principles

FrameworkCIA triad and more
  • Confidentiality

    Only authorised people can read — encryption, access control

  • Integrity

    Data is accurate and unaltered — hashing, checksums

  • Availability

    Systems and data accessible when needed — backups, redundancy, DDoS protection

  • Authentication, authorisation and non-repudiation

    Verify identity, grant rights, prevent denial of actions — passwords, roles, digital signatures

  • Other principles: accountability (actions traced through logs), least privilege, defence in depth, separation of duties, fail-safe defaults.
4

Topic 4

Security functional requirements

Key termsRequirement areas (FIPS 200)
Access control
Limit access to authorised users
Awareness and training
Users know their responsibilities
Audit and accountability
Logs traceable to users
Configuration management
Baselines and change control
Identification and authentication
Verify users and devices
Incident response
Detect, contain, recover
Maintenance and media protection
Safe repair and disposal
Physical and environmental protection
Locks, power, fire
Contingency planning
Backups, disaster recovery
System and communications protection
Encryption, boundary defence
Risk assessment
Identify and rate risks
5

Topic 5

User authentication methods

ComparisonAuthentication factors
How it works
Weaknesses

Password (something you know)

Secret compared with a salted hash

Guessing, phishing, reuse

Token (something you have)

Smart card, OTP device, phone app

Loss, theft, cloning

Biometric (something you are)

Fingerprint, face, iris, voice

False accept and reject rates, cannot be changed if stolen

Remote user

Challenge–response over a network so the secret never travels in clear

Replay and man-in-the-middle attacks

  • Multi-factor authentication combines two or more factors (password + OTP, as in UPI and net banking).
Key formulasBiometric accuracy
  • FAR = false accepts / impostor attempts

    False acceptance rate

  • FRR = false rejects / genuine attempts

    False rejection rate

  • EER = point where FAR = FRR

    Lower is better

6

Topic 6

Access control principles

ComparisonAccess control models
Basis
Example

Discretionary (DAC)

Owner grants rights to others

Unix permissions, Windows ACLs

Mandatory (MAC)

System-enforced labels (Top Secret, Secret)

Military systems, SELinux

Role-based (RBAC)

Permissions attached to roles; users assigned roles

Clerk, manager, auditor in a bank

Attribute-based (ABAC)

Rules on user, resource and environment attributes

"Doctors may read records of their own patients during shifts"

Key termsAccess control structures
Access matrix
Subjects × objects with rights
Access control list
Per-object list of subjects and rights
Capability list
Per-subject list of objects and rights
bashchmod 750 report.sh        # owner rwx, group r-x, others none
chown alice:finance report.sh
7

Topic 7

Database security and encryption

  • Threats: SQL injection, excessive privileges, weak authentication, unencrypted backups, inference attacks on statistical databases.
  • Controls: authentication, GRANT and REVOKE privileges, views to hide sensitive columns, encryption (TDE), auditing, data masking, regular patching and backups.

Key terms

CIA triad
Confidentiality, integrity and availability
Multi-factor authentication
Using two or more independent factors
RBAC
Role-based access control
ACL
Access control list attached to an object
FAR
False acceptance rate of a biometric system

Quick revision

  • Information classification; components of an information system.
  • CIA triad plus authenticity and accountability; FIPS 200 requirement areas.
  • Password, token, biometric, remote authentication; MFA; FAR, FRR.
  • DAC, MAC, RBAC, ABAC; access matrix, ACL, capabilities; database security.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.What is the CIA triad?
  2. Q2.Name three security functional requirements.
  3. Q3.What is two-factor authentication?
  4. Q4.Define FAR and FRR.
  5. Q5.Distinguish DAC and RBAC.
  6. Q6.What is an access control list?

Long-answer questions

  1. Q1.Explain the components of an information system and the CIA triad.
  2. Q2.Compare user authentication methods.
  3. Q3.Explain access control models with examples.
  4. Q4.Explain database security and encryption.

Stuck on this unit?

Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.

WhatsApp us