IT244 Information Security
Information Security notes
10 chapter notes, in syllabus order. Each starts with the key points.
Unit 1
InfoSec Basics: CIA Triad, Threats, Risks & Security ModelsUnit 1 of Information Security introduces core concepts like the CIA triad (Confidentiality, Integrity, Availability), security threats, risk management, and foundational security models (layered, defense-in-depth). It explains how organizations protect data, why security is critical in digital systems, and real-world 9 min readUnit 2
Security Threats & Attacks: Types, Tactics & Real-World ImpactsUnit 2 of Information Security explores the taxonomy of cyber threats (passive/active, insider/outsider), attack vectors (malware, phishing, DoS), and real-world case studies like Ncell SIM-swapping frauds and eSewa payment hacks, with visual attack trees and timeline diagrams to trace how breaches unfold.11 min readUnit 3
Classical Cryptography: Ciphers, Codes & SteganographyUnit 3 of Information Security explores the foundations of cryptography—substitution ciphers (Caesar, Vigenère), transposition methods, steganography, and their mathematical underpinnings—with real-world examples from eSewa’s transaction logs and Ncell’s SMS-based authentication.13 min readUnit 4
Symmetric Key Cryptography: Algorithms, Modes, Attacks & ApplicationsUnit 4 of Information Security explores symmetric key cryptography, covering core algorithms (DES, AES), encryption modes (ECB, CBC, CFB), key management, performance trade-offs, and real-world vulnerabilities like differential cryptanalysis. Students learn how symmetric encryption secures data in transit and at rest, 13 min readUnit 5
Public Key Cryptography: RSA, ECC, Diffie-Hellman, Digital SignaturesUnit 5 of Information Security explores public key cryptography, covering RSA and ECC algorithms, key exchange protocols (Diffie-Hellman), digital signatures, and their applications in secure communication, authentication, and e-commerce.15 min readUnit 6
Hash Functions & Digital Signatures: How Data Integrity & Signatures WorkUnit 6 of Information Security explores hash functions (SHA-256, MD5), their collision resistance, and digital signatures (RSA, ECDSA), including how they secure data integrity, authentication, and non-repudiation in real-world systems like eSewa and NEPSE.10 min readUnit 7
Authentication & Access Control: Methods, Protocols & SecurityUnit 7 of Information Security explores authentication mechanisms (passwords, biometrics, tokens), access control models (MAC, DAC, RBAC), and real-world implementations like multi-factor authentication in eSewa and role-based permissions in Ncell’s internal systems. It covers vulnerabilities, best practices, and legal11 min readUnit 8
Network & Web Security: Protocols, Attacks & DefensesUnit 8 of Information Security explores how data travels securely over networks and the web, covering protocols (HTTP/HTTPS, TLS, DNS), common attacks (MITM, DDoS, SQLi), and defenses (firewalls, VPNs, WAFs), with real-world examples from Nepalese platforms like eSewa and Ncell.13 min readUnit 9
Malware Types, Attacks & Intrusion Detection SystemsUnit 9 of Information Security explores malware (viruses, worms, ransomware, spyware) and intrusion detection systems (IDS), covering how they work, their real-world impact, and detection methods like signature-based and anomaly-based analysis.9 min readUnit 10
Security Policies, Standards & Laws: Frameworks, Compliance & Legal SafeguardsUnit 10 of Information Security explores how organizations enforce security through policies, standards, and laws—covering frameworks like ISO 27001, GDPR, HIPAA, and Nepal’s IT Act, their implementation steps, real-world compliance challenges, and legal consequences of non-compliance, with case studies from Nepali ban14 min read