Foundation of Information TechnologyUnit 97 min read
Information Security & Ethical Issues – Core Concepts & Practices
Unit 9 of Foundation of Information Technology: an in‑depth exploration of the CIA triad, cryptographic primitives, authentication & authorization mechanisms, security controls, incident response, and the ethical and legal frameworks that govern responsible use of information technology.
Key points
- Information security protects data through confidentiality, integrity, and availability (CIA).
- Cryptography provides confidentiality (encryption), integrity (hashing), and authenticity (digital signatures).
- Authentication verifies identity; authorization determines access rights.
- Security controls are preventive, detective, and corrective, forming a layered defense.
- Ethical issues such as privacy, data protection, and responsible disclosure shape professional conduct.
1. Foundations of Information Security
Information security is the discipline that safeguards information assets against unauthorized access, disclosure, modification, or destruction. The CIA triad is the foundational model:
flowchart TD "Confidentiality" --> "Integrity" "Integrity" --> "Availability" "Availability" --> "Confidentiality"
| Element | Definition | Typical Controls |
|---|---|---|
| Confidentiality | Ensuring that information is accessible only to authorized parties. | Encryption, access control lists (ACLs), authentication. |
| Integrity | Guaranteeing that data is accurate and unaltered. | Hash functions, checksums, digital signatures. |
| Availability | Ensuring timely and reliable access to information. | Redundancy, load balancing, disaster recovery. |
2. Threat Landscape
| Threat | Description | Example |
|---|---|---|
| Malware | Software designed to disrupt or gain unauthorized access. | Ransomware encrypting user files. |
| Phishing | Deceptive emails or sites to steal credentials. | Fake eSewa login page. |
| Denial‑of‑Service (DoS) | Overloading resources to deny legitimate use. | 2023 Ncell DDoS attack. |
| Insider Threat | Malicious or careless actions by authorized users. | Employee leaking customer data. |
| Social Engineering | Manipulating humans to bypass security. | Caller claiming to be IT support. |
3. Security Controls
3.1 Preventive Controls
- Firewalls: Block unauthorized traffic.
- Encryption: Protect data at rest and in transit.
- Access Control: Role‑based (RBAC) or attribute‑based (ABAC).
3.2 Detective Controls
- Intrusion Detection Systems (IDS): Monitor network for malicious activity.
flowchart TD "Network Traffic" --> "IDS Sensor" "IDS Sensor" --> "Alert Engine" "Alert Engine" --> "Security Operations Center"
3.3 Corrective Controls
- Patch Management: Fix vulnerabilities.
- Backup & Recovery: Restore data after loss.
4. Cryptographic Primitives
4.1 Symmetric Encryption
- Same key for encryption/decryption.
- Fast, suitable for bulk data.
Worked Example – AES‑128
A 128‑bit key encrypts a 128‑bit plaintext block to ciphertext using 10 rounds of substitution, permutation, and key mixing. The decryption process reverses these steps with the same key .
4.2 Asymmetric Encryption
- Public key for encryption, private key for decryption.
- Enables secure key exchange and digital signatures.
4.3 Hash Functions
- One‑way mapping from arbitrary input to fixed‑length output.
- Collision resistance ensures uniqueness.
flowchart TD "Message M" --> "Hash Function H" "H(M)" --> "Hash Value"
Worked Example – SHA‑256
Input: "Hello World"
Output: a591a6d40bf420404a011733cfb7b190d62c65bf0bcda32b...
Changing one character yields a completely different hash.
4.4 Digital Signatures
- Signer uses private key to sign a hash; verifier uses public key.
5. Authentication & Authorization
5.1 Authentication Methods
| Method | Strength | Example |
|---|---|---|
| Passwords | Low (guessable) | eSewa login |
| Biometrics | High (unique) | Fingerprint on Ncell device |
| Tokens | Medium (physical) | Hardware token for 2FA |
| Multi‑Factor Authentication (MFA) | Highest | 2FA on Pathao driver app |
flowchart TD "User" --> "Login Page" "Login Page" --> "Password Verification" "Login Page" --> "Token Verification" "Password Verification" --> "Access Granted" "Token Verification" --> "Access Granted"
5.2 Authorization Models
| Model | Description | Typical Use |
|---|---|---|
| ACL | List of permissions per object | File system permissions |
| RBAC | Permissions assigned to roles | Corporate network access |
| ABAC | Permissions based on attributes | Cloud resource access |
6. Security Policies & Standards
- ISO/IEC 27001: Information security management system.
- NIST SP 800‑53: Security controls for federal information systems.
- NEPSE IT Act: Regulations for electronic transactions in Nepal.
Policies define acceptable use, data classification, incident response, and compliance requirements.
7. Incident Response Lifecycle
flowchart TD "Detection" --> "Analysis" "Analysis" --> "Containment" "Containment" --> "Eradication" "Eradication" --> "Recovery" "Recovery" --> "Lessons Learned"
Example – Ransomware Attack on a Small Enterprise
- Detection: IDS alerts on unusual outbound traffic.
- Analysis: Identify infected hosts.
- Containment: Isolate affected machines.
- Eradication: Remove malware, patch vulnerabilities.
- Recovery: Restore from backups, verify integrity.
- Lessons Learned: Update policies, conduct training.
8. Ethical & Legal Considerations
| Issue | Ethical Concern | Legal Framework |
|---|---|---|
| Privacy | Respecting personal data | Nepal IT Act, GDPR |
| Intellectual Property | Copyright, patents | Copyright Act, Patent Act |
| Cybercrime | Unauthorized access, defamation | Cybercrime Act |
| Responsible Disclosure | Timely reporting of vulnerabilities | NIST guidelines |
Case Study – Ethical Hacking
A security researcher discovers a vulnerability in a banking app. Ethical practice requires responsible disclosure to the vendor, giving them time to patch before public release. Failure to do so may lead to legal action under the Cybercrime Act.
9. In the real world
| Product | Idea Used | How It Works |
|---|---|---|
| eSewa | End‑to‑end encryption | Payment data is encrypted with AES‑256 before transmission to the server, ensuring confidentiality. |
| Pathao Driver App | Two‑factor authentication | Drivers log in using a password and a hardware token that generates a time‑based OTP, preventing unauthorized access. |
| Ncell VPN | Virtual Private Network | All corporate traffic is routed through an IPSec tunnel, providing confidentiality and integrity across public networks. |
Worked Real‑World Example – Daraz Order Queue
Daraz uses a message queue (Kafka) to handle order placement. Each order message is signed with a digital signature to guarantee authenticity. If a malicious actor attempts to inject a fake order, the signature verification fails, and the order is discarded, preserving data integrity.
10. Exam tip
- Multiple‑choice questions often test definitions and basic concepts (e.g., CIA triad).
- Short answer may ask for explanations of cryptographic primitives or security controls.
- Case studies require applying knowledge to real scenarios (e.g., incident response steps).
- Diagram labeling: Be familiar with labeling a firewall, IDS, or encryption process.
- Practice tracing: Work through encryption/decryption or authentication flows to solidify understanding.
Based on the TU BIM syllabus for Foundation of Information Technology (IT231), unit 9.
Discussion
Loading…