Unit 4: Internet security protocols and cyber law
Information Security and Cyber Law notes · PTU syllabus (PGCA1932)
On this page
- Unit summary
- SSL, TLS and HTTPS
- IPv4 and IPv6 security
- Information security policy
- ISO and international standards
- Introduction to cyberspace and Indian cyber law
- The IT Act 2000 and related laws
- Electronic records and e-governance
- Classification of cyber crimes
- Certifying authorities and digital signatures
- Patents, copyright and IPR in cyberspace
- Key terms
- Quick revision
- Important questions
Unit summary
Secure internet protocols protect data in transit, and cyber law gives digital actions legal force. This unit covers SSL, TLS, HTTPS and IP security, security policy and ISO standards, Indian cyber law and the IT Act 2000, e-governance, cyber crimes, certifying authorities, IPR and digital signatures.
After this unit you can
- Explain SSL, TLS, HTTPS and IPsec
- Describe security policy and ISO 27001
- Explain the IT Act 2000, e-records, e-governance and certifying authorities
- Classify cyber crimes and explain digital signatures and IPR
PTU syllabus topics
- SSL
- TLS
- HTTPS
- IPv4/IPv6 security protocols
- information security policy concepts
- ISO standards
- Indian cyber laws
- IT Act 2000
- electronic records and e-governance
- classification of cyber crimes
- certifying authority regulation
- patents
- copyright
- digital signatures
- introduction to cyberspace
Section 43
Unauthorised access and damage: compensation
Section 66
Computer-related offences
Section 66C
Identity theft
Section 66D
Cheating by impersonation
Section 66E
Violation of privacy
Section 67
Obscene material online
Topic 1
SSL, TLS and HTTPS
- HTTP transfers web pages in plain text; HTTPS adds TLS (successor of SSL) to encrypt traffic and authenticate the server.
- 1Client hello
Supported versions and ciphers
- 2Server hello and certificate
- 3Client verifies certificate with a trusted CA
- 4Key exchange
Session key agreed
- 5Encrypted session
Symmetric encryption of data
- The browser padlock shows a valid certificate; TLS 1.2 and 1.3 are current versions.
- SSL protocol stack: SSL Record Protocol (fragment, compress, MAC, encrypt) with Handshake, Change Cipher Spec and Alert protocols above it. SSL is obsolete; TLS 1.2 and 1.3 are used today.
- SET (Secure Electronic Transaction): a protocol by Visa and MasterCard (1996) to secure card payments using certificates for cardholder, merchant and payment gateway. Its dual signature links the order information (seen by the merchant) and payment information (seen by the bank) so neither sees the other's details. SET was too complex and was replaced by TLS-based payment gateways and 3-D Secure.
- Web attacks: SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF); defended by input validation, prepared statements, output encoding and CSRF tokens.
Topic 2
IPv4 and IPv6 security
- IPsec secures traffic at the network layer — mandatory to support in IPv6, optional in IPv4.
Provides
Integrity and origin authentication
Confidentiality plus integrity
Use
Rare today
Most VPNs
Protects
Payload only
Whole original packet wrapped in a new one
Use
Host-to-host
Site-to-site VPNs
- IKE negotiates keys and security associations.
Topic 3
Information security policy
Enterprise information security policy (EISP)
Overall direction and scope, set by top management
Issue-specific policies (ISSP)
Email, internet use, BYOD, passwords
System-specific policies (SysSP)
Firewall rules, access control lists for a system
Standards, guidelines and procedures
Detailed mandatory rules, advice and step-by-step instructions
- Good policy: written, approved by management, communicated, understood and agreed by users, enforced uniformly and reviewed regularly.
Topic 4
ISO and international standards
- ISO/IEC 27001
- Requirements for an information security management system (ISMS) — certifiable
- ISO/IEC 27002
- Code of practice: security controls
- PCI DSS
- Card payment data security
- NIST Cybersecurity Framework
- Identify, protect, detect, respond, recover
- Common Criteria (ISO/IEC 15408)
- Evaluating security of IT products
Topic 5
Introduction to cyberspace and Indian cyber law
- Cyberspace: the virtual world of networks, data and online interactions; cyber law governs conduct, transactions and crimes within it.
Topic 6
The IT Act 2000 and related laws
- Information Technology Act, 2000 (amended 2008)
- Legal recognition of electronic records and signatures; cyber offences
- Section 43
- Compensation for unauthorised access, downloading or damage
- Section 43A
- Compensation for failure to protect sensitive personal data — being replaced by the DPDP Act regime
- Section 66, 66C, 66D
- Hacking, identity theft, cheating by impersonation
- Section 66F
- Cyber terrorism
- Section 72A
- Disclosure of information in breach of contract
- CERT-In directions 2022
- Report cyber incidents within six hours
- Digital Personal Data Protection Act, 2023
- Consent-based processing and duties of data fiduciaries, phased in through the DPDP Rules, 2025
- International: GDPR (European Union) for personal data; US laws such as HIPAA (health) and the Computer Fraud and Abuse Act.
Topic 7
Electronic records and e-governance
- Section 4
- Legal recognition of electronic records
- Section 5
- Legal recognition of electronic signatures
- Section 6
- Use of electronic records in government (filing, licences, payments)
- Section 7
- Retention of electronic records
- Section 10A
- Validity of contracts formed electronically
- E-governance examples: DigiLocker, UMANG, e-filing of income tax, GeM, Aadhaar-based e-sign.
Topic 8
Classification of cyber crimes
Against property
Hacking, credit card fraud, IPR theft, ransomware
Against organisations
Data breach, DoS, insider sabotage
Against society and nation
Cyber terrorism, child abuse material, fake news inciting violence
Topic 9
Certifying authorities and digital signatures
- 1Sender hashes the message
- 2Hash encrypted with sender's private key → signature
- 3Message + signature + certificate sent
- 4Receiver decrypts signature with sender's public key
- 5Compares with own hash — match proves authenticity and integrity
- Controller of Certifying Authorities (CCA)
- Licenses and regulates CAs (Sections 17–34)
- Certifying Authority
- Issues Digital Signature Certificates (e.g., eMudhra)
- DSC
- Binds a public key to an identity; classes used for e-filing and tenders
- Root CA of India
- Top of the trust chain
Topic 10
Patents, copyright and IPR in cyberspace
Copyright
Original works of expression
Source code, documentation
Patent
Novel, non-obvious inventions
Technical inventions with software (limited in India under Section 3(k))
Trademark
Names, logos and marks
Product brand names
Trade secret
Confidential business information
Algorithms kept secret, protected by NDAs
Industrial design
Visual appearance
Device design
- Software piracy and licence violations breach copyright; open-source licences (GPL, MIT) grant rights under conditions.
Key terms
- TLS
- Transport Layer Security protecting web traffic
- IPsec ESP
- IPsec protocol providing encryption
- ISO 27001
- Standard for information security management systems
- CCA
- Controller of Certifying Authorities
- Digital signature
- Hash encrypted with the sender's private key
Quick revision
- TLS handshake; HTTPS; IPsec AH and ESP, transport and tunnel modes.
- Security policy; ISO 27001 and 27002.
- IT Act sections; e-records; e-governance.
- Crimes against individuals, property, organisations, nation.
- CCA, CA, DSC; signing and verification; copyright and patents.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What does HTTPS add to HTTP?
- Q2.Distinguish AH and ESP.
- Q3.What is ISO 27001?
- Q4.What does Section 4 of the IT Act provide?
- Q5.Who regulates certifying authorities in India?
- Q6.How is a digital signature verified?
Long-answer questions
- Q1.Explain SSL/TLS and IPsec.
- Q2.Explain the main provisions of the IT Act 2000.
- Q3.Classify cyber crimes with examples.
- Q4.Explain digital signatures and the role of certifying authorities.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.
