Information Security notes

10 chapter notes, in syllabus order. Each starts with the key points.

Unit 1

InfoSec Basics: CIA Triad, Threats, Risks & Security ModelsUnit 1 of Information Security introduces core concepts like the CIA triad (Confidentiality, Integrity, Availability), security threats, risk management, and foundational security models (Bell-LaPadula, Biba, Clark-Wilson). It explains how organizations protect data, classify assets, and implement security policies in 10 min read

Unit 2

Security Threats & Attacks: Types, Methods & Real-World ImpactsUnit 2 of Information Security explores the classification of security threats (passive/active, internal/external), common attack methods (phishing, DoS, MITM, malware), their mechanisms and impacts, and real-world case studies from Nepalese and global systems. Learn how attackers exploit vulnerabilities in networks, a8 min read

Unit 3

Classical Cryptography: Ciphers, Caesar, Vigenère, Playfair, and Frequency AnalysisUnit 3 of Information Security explores the foundations of cryptography, covering substitution and transposition ciphers, classical algorithms like Caesar and Vigenère, and their vulnerabilities to frequency analysis. It also introduces the Playfair cipher and compares classical methods with modern cryptography.14 min read

Unit 4

Symmetric Key Cryptography: Algorithms, Modes & ApplicationsUnit 4 of Information Security explores symmetric key cryptography—how identical keys encrypt/decrypt data, core algorithms (DES, AES), modes of operation (ECB, CBC), and real-world uses in banking, e-commerce, and secure messaging. Learn key exchange challenges, performance trade-offs, and why symmetric ciphers domina15 min read

Unit 5

Public Key Cryptography: Algorithms, RSA, Diffie-Hellman, Digital SignaturesUnit 5 of Information Security explores public key cryptography, covering asymmetric encryption, RSA algorithm, Diffie-Hellman key exchange, digital signatures, and their real-world applications in secure communications, e-commerce, and authentication systems.10 min read

Unit 6

Hash Functions & Digital Signatures: How Data Integrity & Authenticity WorkUnit 6 of Information Security explores hash functions (one-way hashing, collision resistance, cryptographic vs. non-cryptographic hashes) and digital signatures (RSA-based, DSA, ECDSA), their mathematical foundations, real-world applications in blockchain and secure communications, and how they prevent tampering and v17 min read

Unit 7

Authentication & Access Control: Methods, Protocols & Security ModelsUnit 7 of Information Security explores how systems verify identities (authentication) and restrict access (authorization), covering biometrics, tokens, multi-factor schemes, role-based models, and real-world attacks like credential stuffing—essential for securing digital assets in Nepal’s banking, e-commerce, and gove12 min read

Unit 8

Network & Web Security: Protocols, Attacks, Defenses, HTTPS, FirewallsUnit 8 of Information Security explores how data travels securely over networks and the web, covering protocols (TCP/IP, HTTPS), common attacks (MITM, DDoS, SQLi), defense mechanisms (firewalls, VPNs, IDS), and real-world implementations like eSewa’s encrypted transactions and Ncell’s secure mobile banking. Includes ha10 min read

Unit 9

Malware Types, Intrusion Detection & ResponseUnit 9 of Information Security explores malware (viruses, worms, ransomware, spyware, trojans) and intrusion detection systems (IDS/IPS), their mechanisms, real-world impacts, and countermeasures—essential for protecting digital assets in Nepal’s growing tech ecosystem.12 min read

Unit 10

Security Policies, Standards & Laws: Frameworks, Compliance & Legal SafeguardsUnit 10 of Information Security explores the legal and procedural backbone of cybersecurity—how organizations implement security policies, comply with national/international standards (ISO 27001, GDPR), and navigate laws like Nepal’s Electronic Transaction Act. It covers policy frameworks, risk management, audit trails14 min read