Unit 4 of 4 · M.Sc IT Sem 4

Unit 4: Internet security protocols and cyber law

Information Security and Cyber Law notes · PTU syllabus (PGCA1932)

3 min read10 topics10 exam questions
On this page
  1. Unit summary
  2. SSL, TLS and HTTPS
  3. IPv4 and IPv6 security
  4. Information security policy
  5. ISO and international standards
  6. Introduction to cyberspace and Indian cyber law
  7. The IT Act 2000 and related laws
  8. Electronic records and e-governance
  9. Classification of cyber crimes
  10. Certifying authorities and digital signatures
  11. Patents, copyright and IPR in cyberspace
  12. Key terms
  13. Quick revision
  14. Important questions

Unit summary

Secure internet protocols protect data in transit, and cyber law gives digital actions legal force. This unit covers SSL, TLS, HTTPS and IP security, security policy and ISO standards, Indian cyber law and the IT Act 2000, e-governance, cyber crimes, certifying authorities, IPR and digital signatures.

After this unit you can

  • Explain SSL, TLS, HTTPS and IPsec
  • Describe security policy and ISO 27001
  • Explain the IT Act 2000, e-records, e-governance and certifying authorities
  • Classify cyber crimes and explain digital signatures and IPR

PTU syllabus topics

  • SSL
  • TLS
  • HTTPS
  • IPv4/IPv6 security protocols
  • information security policy concepts
  • ISO standards
  • Indian cyber laws
  • IT Act 2000
  • electronic records and e-governance
  • classification of cyber crimes
  • certifying authority regulation
  • patents
  • copyright
  • digital signatures
  • introduction to cyberspace
ClassificationIT Act 2000: key cyber offences
Cyber crimes
  • Section 43

    Unauthorised access and damage: compensation

  • Section 66

    Computer-related offences

  • Section 66C

    Identity theft

  • Section 66D

    Cheating by impersonation

  • Section 66E

    Violation of privacy

  • Section 67

    Obscene material online

1

Topic 1

SSL, TLS and HTTPS

  • HTTP transfers web pages in plain text; HTTPS adds TLS (successor of SSL) to encrypt traffic and authenticate the server.
ProcessTLS handshake (simplified)
  1. 1Client hello

    Supported versions and ciphers

  2. 2Server hello and certificate
  3. 3Client verifies certificate with a trusted CA
  4. 4Key exchange

    Session key agreed

  5. 5Encrypted session

    Symmetric encryption of data

  • The browser padlock shows a valid certificate; TLS 1.2 and 1.3 are current versions.
  • SSL protocol stack: SSL Record Protocol (fragment, compress, MAC, encrypt) with Handshake, Change Cipher Spec and Alert protocols above it. SSL is obsolete; TLS 1.2 and 1.3 are used today.
  • SET (Secure Electronic Transaction): a protocol by Visa and MasterCard (1996) to secure card payments using certificates for cardholder, merchant and payment gateway. Its dual signature links the order information (seen by the merchant) and payment information (seen by the bank) so neither sees the other's details. SET was too complex and was replaced by TLS-based payment gateways and 3-D Secure.
  • Web attacks: SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF); defended by input validation, prepared statements, output encoding and CSRF tokens.
2

Topic 2

IPv4 and IPv6 security

  • IPsec secures traffic at the network layer — mandatory to support in IPv6, optional in IPv4.
ComparisonIPsec
Authentication Header (AH)
Encapsulating Security Payload (ESP)

Provides

Integrity and origin authentication

Confidentiality plus integrity

Use

Rare today

Most VPNs

ComparisonIPsec modes
Transport
Tunnel

Protects

Payload only

Whole original packet wrapped in a new one

Use

Host-to-host

Site-to-site VPNs

  • IKE negotiates keys and security associations.
3

Topic 3

Information security policy

ClassificationSecurity policy framework
Policies
  • Enterprise information security policy (EISP)

    Overall direction and scope, set by top management

  • Issue-specific policies (ISSP)

    Email, internet use, BYOD, passwords

  • System-specific policies (SysSP)

    Firewall rules, access control lists for a system

  • Standards, guidelines and procedures

    Detailed mandatory rules, advice and step-by-step instructions

  • Good policy: written, approved by management, communicated, understood and agreed by users, enforced uniformly and reviewed regularly.
4

Topic 4

ISO and international standards

Key termsSecurity standards
ISO/IEC 27001
Requirements for an information security management system (ISMS) — certifiable
ISO/IEC 27002
Code of practice: security controls
PCI DSS
Card payment data security
NIST Cybersecurity Framework
Identify, protect, detect, respond, recover
Common Criteria (ISO/IEC 15408)
Evaluating security of IT products
5

Topic 5

Introduction to cyberspace and Indian cyber law

  • Cyberspace: the virtual world of networks, data and online interactions; cyber law governs conduct, transactions and crimes within it.
6

Topic 6

The IT Act 2000 and related laws

Key termsIndian cyber laws
Information Technology Act, 2000 (amended 2008)
Legal recognition of electronic records and signatures; cyber offences
Section 43
Compensation for unauthorised access, downloading or damage
Section 43A
Compensation for failure to protect sensitive personal data — being replaced by the DPDP Act regime
Section 66, 66C, 66D
Hacking, identity theft, cheating by impersonation
Section 66F
Cyber terrorism
Section 72A
Disclosure of information in breach of contract
CERT-In directions 2022
Report cyber incidents within six hours
Digital Personal Data Protection Act, 2023
Consent-based processing and duties of data fiduciaries, phased in through the DPDP Rules, 2025
  • International: GDPR (European Union) for personal data; US laws such as HIPAA (health) and the Computer Fraud and Abuse Act.
7

Topic 7

Electronic records and e-governance

Key termsIT Act provisions
Section 4
Legal recognition of electronic records
Section 5
Legal recognition of electronic signatures
Section 6
Use of electronic records in government (filing, licences, payments)
Section 7
Retention of electronic records
Section 10A
Validity of contracts formed electronically
  • E-governance examples: DigiLocker, UMANG, e-filing of income tax, GeM, Aadhaar-based e-sign.
8

Topic 8

Classification of cyber crimes

ClassificationCyber crimes
Against individuals|Cyber stalking, harassment, identity theft, sextortion
  • Against property

    Hacking, credit card fraud, IPR theft, ransomware

  • Against organisations

    Data breach, DoS, insider sabotage

  • Against society and nation

    Cyber terrorism, child abuse material, fake news inciting violence

9

Topic 9

Certifying authorities and digital signatures

ProcessDigital signature
  1. 1Sender hashes the message
  2. 2Hash encrypted with sender's private key → signature
  3. 3Message + signature + certificate sent
  4. 4Receiver decrypts signature with sender's public key
  5. 5Compares with own hash — match proves authenticity and integrity
Key termsRegulation of certifying authorities
Controller of Certifying Authorities (CCA)
Licenses and regulates CAs (Sections 17–34)
Certifying Authority
Issues Digital Signature Certificates (e.g., eMudhra)
DSC
Binds a public key to an identity; classes used for e-filing and tenders
Root CA of India
Top of the trust chain
10

Topic 10

Patents, copyright and IPR in cyberspace

ComparisonForms of IPR
Protects
Software example

Copyright

Original works of expression

Source code, documentation

Patent

Novel, non-obvious inventions

Technical inventions with software (limited in India under Section 3(k))

Trademark

Names, logos and marks

Product brand names

Trade secret

Confidential business information

Algorithms kept secret, protected by NDAs

Industrial design

Visual appearance

Device design

  • Software piracy and licence violations breach copyright; open-source licences (GPL, MIT) grant rights under conditions.

Key terms

TLS
Transport Layer Security protecting web traffic
IPsec ESP
IPsec protocol providing encryption
ISO 27001
Standard for information security management systems
CCA
Controller of Certifying Authorities
Digital signature
Hash encrypted with the sender's private key

Quick revision

  • TLS handshake; HTTPS; IPsec AH and ESP, transport and tunnel modes.
  • Security policy; ISO 27001 and 27002.
  • IT Act sections; e-records; e-governance.
  • Crimes against individuals, property, organisations, nation.
  • CCA, CA, DSC; signing and verification; copyright and patents.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.What does HTTPS add to HTTP?
  2. Q2.Distinguish AH and ESP.
  3. Q3.What is ISO 27001?
  4. Q4.What does Section 4 of the IT Act provide?
  5. Q5.Who regulates certifying authorities in India?
  6. Q6.How is a digital signature verified?

Long-answer questions

  1. Q1.Explain SSL/TLS and IPsec.
  2. Q2.Explain the main provisions of the IT Act 2000.
  3. Q3.Classify cyber crimes with examples.
  4. Q4.Explain digital signatures and the role of certifying authorities.

Stuck on this unit?

Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.

WhatsApp us