Information Security
Unit:VIII
and Cyber Law
8.1 Digital society and computer ethics
8.2 Concept of Information security
8.3 Concept of Cybercrime
8.4 Malicious software and Spam
8.5 Protection from cybercrime
8.6 IT Policy
8.7 Cyber Laws in Nepal
8.8 Intellectual property rights
8.9 Digital Signature
8.10 Protection from cyber crime
Digital Society and Computer Ethics
Digital Society
We are living in a digital society, in which every aspect of our lives is extremely being affected by
the digitalization of data: how we communicate and socialize; how we work, learn, stay healthy and
participate in politics and the economy. Digitalization promises tremendous benefits for better
health, mobility that is more efficient, efficient energy use, and flourishing companies. Digital
innovations has changed our society, economy,
culture and lifestyle. Application of digital
innovations benefits our society and daily life.
Digitalization process helps to understand the
relationship between digital advancement and its
impact on society. The concept of digital society
reflects the results of the modern society in
adopting and integrating information and
communication technologies at home, work
education and recreation. Mobile and cloud
technologies impacts on the improvement of
citizens’ lives and efficiency to many areas
including health services, transportation, energy, agriculture, manufacturing, retail and public
administration. They can also improve the governing process by helping policy-makers take better
decisions and engage citizens. The Internet has considerable potential to promote democracy,
cultural diversity and human rights like the freedom of expression and freedom to information.
However, we also have to understand how the scale and speed of these changes impact consumers,
users, citizens and workers, including all of these combined into a single ‘digital person’, as well as
how they affect social and private life, education, science, government, democracy and business.
The digital economy is built on a myriad of technologies and products. Key pillars include the
internet, smart phones, broadband and mobile networks, Radio Frequency Identification, sensors (to
detect changes in the environment), and an expanding software universe. Increasingly, users to
communicate with other users or devices do not only use these technologies, but also to enable smart
devices to communicate with each other in what has been coined the ‘Internet of Things’ (IoT).
Computer Ethics
Ethics is a set of moral principles that govern the
behavior of a group or individual. Therefore,
computer ethics is set of moral principles that
regulate the use of computers. Some common
issues of computer ethics include intellectual
property rights such as copyrighted electronic
content, privacy concerns and how computers
affect society.
For example, while it is easy to duplicate
copyrighted digital content, computer ethics
462 Computer Science - XI Approved by CDC, Nepal
would suggest that it is wrong to do so without the author's approval. Moreover, while it may be
possible to access someone's personal information on a computer system, computer ethics would
advise that such an action is unethical.
As technology advances, computers continue to have a greater impact on society. Therefore,
computer ethics promotes the discussion of how much influence computers should have in areas
such as artificial intelligence and human communication. As the world of computers evolves,
computer ethics continues to create ethical standards that address new issues raised by new
technologies.
The Ten standard commandments for Computer Ethics are:
1. We should not use a computer to harm other people.
2. We should not interfere with other people's computer work.
3. We should not access toother files.
4. We should not use a computer to steal.
5. We should not use a computer to bear false witness.
6. We should not use or copy software for which you have not paid.
7. We should not use other people's computer resources without authorization.
8. We should maintain the understanding of Intellectual Propriety Rights.
9. We think about the social consequences of the program we develop.
10. We should use a computer in ways that show consideration and respect to all.
Concept of Information security
Information security, sometimes abbreviated to Info
Sec, is a set of practices intended to keep data secure
from unauthorized access or alterations, both when it's
being stored and when it's being transmitted from one
machine or physical location to another. You might
sometimes see it referred to as data security.
Information security refers to the processes and
methodologies, which are designed and implemented to
protect print, electronic, or any other form of
confidential, private and sensitive information or data
from unauthorized access, use, misuse, disclosure,
destruction, modification, or disruption.
Information security is a set of practices designed to
keep personal data secure from unauthorized access and alteration during storing or transmitting
from one place to another. Information security is designed and implemented to protect the print,
electronic and other private, sensitive and personal data from unauthorized persons. It is used to
protect data from being misused, disclosure, destruction, modification, and disruption
Information Security Principles
The basic components of information security are confidentiality, integrity and availability.
Confidentiality: Confidentiality is the mechanism to give authorized to access to the data. We should
be able to identify the authorized users and block the attempts to access from unauthorized users.
Passwords, encryption, authentication, and defense against penetration attacks are all techniques
Approved by CDC, Nepal Information Security and Cyber Law 463
applied to maintain confidentiality.
Integrity means maintaining data in its correct form and preventing it from being improperly
modified. Many of the techniques that ensure confidentiality will also protect data integrity. Integrity
discuss the completeness of data. We have to be assured that there is no loss of any part of information.
Availability is the mirror image of confidentiality: while you need to make sure that unauthorized
users cannot access your data, you also need to ensure that those who have the proper permissions
can access it. Ensuring data availability means matching network and computing resources to the
volume of data access you expect and implementing a good backup policy for disaster recovery purposes.
Information security policy
Information security policy is a document that an enterprise draws up, based on its specific needs. It
helps to establish what data to protect and in what ways. These policies guide an organization during
the decision-making about obtaining cyber security tools. It also mandates employee behavior and
responsibilities.
An organization information security policy should include
▪ It should describe the purpose of the Info Sec program and objectives
▪ It must define the key terms used in the document to ensure shared understanding
▪ It must contain password policy
▪ It should determine who has access to what data
▪ It must include the employee’s roles and responsibilities to safeguard data
Information security vs. cyber security
Information security and cyber security may be used substitutable but they are two different things.
Cyber security is a practice used to provide security from online attacks, while information security
is a specific discipline that falls under cyber security. Information security is designed and
implemented to protect the print, electronic and other private, sensitive and personal data from
unauthorized persons.
Concept of Cybercrime
Cyber crime is defined as a crime where a
computer is the object of the crime or is used as a
tool to commit a crime. A cybercriminal may use a
device to access a user’s personal information,
confidential business information, government
information, or disable a device. It is also a Cyber
crime to sell and reproduce the above information
online.
Cyber crime is criminal activity done using
computers and the Internet. This includes anything
from downloading illegal music files to stealing millions of Rupees from online bank accounts.
Cyber crime also includes non-monetary offenses, such as creating and distributing viruses on other
computers or posting confidential business information on the Internet. Cybercriminals or hackers
who want to make money commit Cyber crime. Some cybercriminals are organized, use advanced
techniques and are technically skilled. Rarely, Cyber crime aims to damage computers for reasons
other than profit. These could be political or personal.
464 Computer Science - XI Approved by CDC, Nepal
Types of Cyber Crime
Most Cyber crime falls under two main categories:
▪ Criminal activity that targets
▪ Criminal activity that uses computers to commit other crimes.
Cyber crime that targets computers often involves viruses and other types of malware.
Cybercriminals may infect computers with viruses and malware to damage devices or stop them
working. They may also use malware to delete or steal data.
Here are some specific examples of the different types of Cyber crime:
▪ Email and internet fraud.
▪ Identity fraud (where personal information is stolen and used).
▪ Theft of financial or card payment data.
▪ Theft and sale of corporate data.
▪ Cyber extortion (demanding money to prevent a threatened attack).
Malicious software and Spam
Malware is related to the malicious software. It is a software
developed by cyber attackers with the intention of gaining access
or causing damage to a computer or network. Malicious
software or malware is any kind of program that designed to
harm your devices in any way. Computer virus is a type of
malware. Other types of malware include spyware, rootkits, and
worms. Once your device is infected with malware, it will disrupt
your computer in various ways depending on its type. Some
malwares are:
▪ Virus: Virus is a software that modifies your computer programs to potentially damage
your files and even corrupt your hard drives. Other types of viruses can also block your
internet access and slow down your computer.
▪ Spyware: Spyware is a program that hackers use to spy or track your activity on your
device. It can gather confidential information, such as passwords and bank account
information, and sent it to another entity without your consent.
▪ Rootkits: Rootkit is a collection of computer programs that may unauthorized control
your device from the root or admin level, hence the term rootkit. Once it gains
administrator access, it can maintain its privilege by disrupting the program that might
otherwise detect it, such as an antivirus program.
▪ Worm: Worm is similar to a virus. The only difference is worm is a standalone software
that does not need a host. Just like a virus, it can replicate and spread to other devices over
the network.
Phishing
Phishing attacks are intended to take a person’s login and password so that the digital criminal can
take over the control of the victim’s social network, email and online banking details. Seventy
percent of the web users pick a similar password for relatively every web service they utilize. This is
the reason phishing is so compelling, as the criminal, by utilizing the same login subtle elements, he
can get into different private accounts and control them for their own benefit.
Approved by CDC, Nepal Information Security and Cyber Law 465
Spamming
Spam is defined as unwanted and unsolicited messages sent to an enormous list of recipients. Spam
may or may not be malware. Typically, spam is sent in an email form for a commercial purpose.
Spam can turn into malware when it contains a malicious program that accesses your device when
you open the email attachments or links.
Protection from Cyber Crime
Now we have to discuss about the best ways to protect
our computer and personal data from the hackers and
intruders. Here are some safety measurement.
▪ Keep software and operating system updated
Keeping your software and operating system up to
date ensures that you benefit from the latest security
patches to protect your computer.
▪ Use anti-virus software and keep it updated
Anti-virus software allows you to scan, detect and
remove threats before they become a problem.
Having this protection in place helps to protect your
computer and your data from Cyber crime, giving
you piece of mind.
▪ Use strong passwords
Be sure to use strong passwords that people will not guess and do not record them anywhere.
On the other hand, use a trustworthy password manager to generate strong passwords randomly
to make this easier.
▪ Never open attachments in spam emails
A classic way that computers are infected by malware attacks and other forms of Cyber crime is
via email attachments in spam emails. Never open an attachment from a sender you do not
know.
▪ Do not click on links in spam emails or untrusted websites
Another way people become victims of Cyber crime is by clicking on links in spam emails or
other messages, or unfamiliar websites. Avoid doing this to stay safe online.
▪ Do not give out personal information unless secure
Never give out personal data over the phone or via email unless you are completely sure the
line or email is secure.
▪ Contact companies directly about suspicious requests
If you get asked for data from a company who has called you, hang up. Call them back using
the number on their official website to ensure you are speaking to them and not a
cybercriminal.
466 Computer Science - XI Approved by CDC, Nepal
▪ Be mindful of which website URLs you visit
Keep an eye on the URLs you are clicking on. Do they look legitimate? Avoid clicking on links
with unfamiliar or spam my looking URLs.
▪ Keep an eye on your bank statements
Keep an eye on your bank statements and query any unfamiliar transactions with the bank. The
bank can investigate whether they are fraudulent.
Cyber Law in Nepal
Nepal is a developing county. Like other
sector Information and communication
Technology (ICT) sector is also on developing
stage. So the business sector, government
sector and public sector are using IT as a
major tool to support all types of business
process. So it was very essentials to legalize
the digital activities like online work to make
it useful and standard.
So Nepal has formulated some cyber law to
support and legalize the online trading
activities, government activities, tax payment and electronic payment using some electronic card. It
has a strong provision of punishment against the illegal work on such activities. According to the
levels of cyber crime, criminals will be punished. It prevents from the hacking, faking digital
signature, privacy issues, damage of program source code etc. The cyber law is popular as an
electronic transaction act 2061 BS (2004). It addresses the following aspects to control the cyber
crime and other indiscipline on cyber field in Nepal. These are listed as below:
▪ It explains the provisions to punish to hackers who download, copy and manipulate data
without getting permission of the owner and who introduce virus in to the system and disrupts a
computer or networked environment.
▪ It provides a detailed provision for controlling and verifying the authorities to use digital data.
▪ It provides legal provision to give online banking, electronic fund transfer (EFT) etc.
▪ It gives legal provision to use the digital signature which is very essentials to identify and verify
the documents.
▪ It provides provision of the appeal judicial body to listen the cyber related issues.
▪ It helps for electronic data transaction, electronic filing of documents, use of public and private
key for security management etc.
Intellectual Property Rights (IPR)
Nepal finalized a new Intellectual Property Rights (IPR) Policy in March 2017. This policy has been
used as the foundation to prepare a draft Law on IPR, which is undergoing review. There is reason to
expect that the new legislation will represent a substantial improvement over existing laws and
regulations. Under the existing IPR regime, the Ministry of Culture, Tourism, and Civil Aviation
oversees copyright issues while the Ministry of Industry looks after patent and trademark issues.
However, the new policy calls for a single government entity to enforce the range of IPR issues.
Approved by CDC, Nepal Information Security and Cyber Law 467
Registration of a patent under the Patent, Design, and Trademark Act does not provide automatic
protection to foreign trademarks and designs. Similarly, Nepal does not automatically recognize
patents awarded by other nations. There is recognition that this is a shortcoming in Nepal’s IPR
regime, and it is likely that it will be reformed along with the new IPR Law. The Copyright Act of
2002 covers most modern forms of authorship and provides adequate periods of protection. Most of
these policies are expected to be updated in accordance with new IPR Policy. Nepal faces serious
challenges in preventing the sale of counterfeit goods. Enforcement of IPR violations is sporadic at
best. Law enforcement officials do not receive adequate training on IPR issues and offenders can
often pay a small bribe to avoid prosecution.
Digital Signature
It is similar to our general signature which is used to check the authenticity of the document and
process. It is also used for same purpose but processed on
electronic forms. So it is called "digital signature". It
includes marking as digital images of paper based
signature. So the sender and receiver can verify it to
authenticate the message or information used on electronic
transaction. Digital signature serves the following general
purposes.
▪ Evidence
▪ Senders’ authenticity
▪ Approval of documents etc.
Information Technology Policy
Objectives
The information technology policy shall be developed to attain the following objectives.
1. To make information technology accessible to the public and increase employment through this
means.
2. To build a knowledge-based society.
3. To establish knowledge-based industries.
Strategies
The information technology strategies adopted to accomplish the above-mentioned objectives of
rapid development and expansion of information technology in a fair and competitive environment
shall be the following:
1. The government will act as a promoter, facilitator, and regulator.
2. Carry on research, develop and expand information technology with a high priority to
participation of the private sector.
3. Prepare capable manpower with the involvement of both public and private sectors for
sustainable development and expansion of information technology.
4. Encourage native and foreign investment for the development of information technology and
infrastructure pertaining to information technology.
5. Place Nepal on the global map through information technology.
6. Legalize and promote e-commerce.
7. Assist in e-governance by using information technology.
468 Computer Science - XI Approved by CDC, Nepal
8. Utilize information technology in the development of rural areas.
9. Promote information technology industries.
10. Create a healthy, competitive environment for information technology service providers and
provide them speedy and qualitative service at a reasonable cost.
11. Include computer education in curriculum from the school level.
12. Enhance professional efficiency through the use of information technology.
13. Expand the information technology network to the rural areas.
14. Establish Nepal in the international market in information technology.
15. Increase export of services related to information technology (software and hardware) to 10
billion rupees within the next five years.
Information Technology Policy
The policies to be pursued for the implementation of the above-mentioned strategies shall be as
follows:
1. To declare information technology sectors a prioritized sector.
2. To follow a single-door system for the development of information technology.
3. To prioritize research and development of information technology.
4. To create a conducive environment that will attract investment in the private sector, keeping in
view the private sector's role in the development of information technology.
5. To provide internet facilities to all Village Development committees of the country in phases.
6. To render assistance to educational institutions and encourage native and foreign training as a
necessity of fulfilling the requirement of qualified manpower in various fields pertaining to
information technology.
7. To computerize the records of each governmental office and build websites for them for the
flow of information.
8. To increase the use of computers in the private sector.
9. To develop physical and virtual information technology park in various places with the private
sector's participation for the development of information technology.
10. To use information technology to promote e-commerce, e-education, e-health, among others,
and to transfer technology in rural areas.
11. To establish National Information Technology Centre.
12. To establish a national level fund by mobilizing the resources obtained from His Majesty's
Government, donor agencies, and private sectors so as to contribute to research and
development of information technology and other activities pertaining to it.
13. To establish venture capital funds with the joint participation of public and private sectors.
14. To include computer education in the curriculum from the school level and broaden its scope.
15. To establish Nepal in the global market through the use of information technology.
16. To draft necessary laws that provides legal sanctions to the use of information technology.
17. To gradually use information technology in all types of governmental activities and provide
legal sanctions to its uses in such activities.
Approved by CDC, Nepal Information Security and Cyber Law 469
Workshop
Long Answer Questions
1. Discuss the concept of Cyber-crime? Why it occurs? Explain
2. What is IT policy? Discuss the strategies and objective of IT policy.
3. What are malicious software? Discuss some examples of malicious software.
4. What is digital society? Explain its impact on our society with example
5. How can you protect your system from Cyber-crime? Explain some popular safety
measurements to protect the system from Cyber-crimes.
Short Answer Question
1. Discuss the process to protect from cyber-crime.
2. What is computer ethics? Explain with some examples.
3. Discuss the concept of Information Security. Discuss the principles of information security.
4. What is Spamming? Explain
5. Discuss the term IPR with reference to Nepal.
6. Discuss the cyber law in Nepal.
7. Define the term digital signature with its uses.
8. What is phishing? Explain
470 Computer Science - XI Approved by CDC, Nepal
Bibliography
▪ Adhikary, Shankar Nath: Fundamentals of Computer, Budhha Publication, Kathmandu
Nepal
▪ Adhikary, Shankar Nath: Introduction to Computer Application, Pioneer Publication,
Kathmandu Nepal
▪ Adhikary, Shankar Nath: Introduction to Management Information System, Budhha
Publication, Kathmandu Nepal
▪ Aspray, William, ed. Computing Before Computers. Ames, IA: Iowa State University Press,
1990.
▪ B.S. Gottfried, Schaum’s Outline Series for Programming with C, Second Edition, Tata McGraw
Hill Publishing Company, 2001..
▪ Basandra, S. K. (2008), Computers Today Updated Edition, Galgotia Publication.
▪ Busby, Michael and Russel A. Stultz: Microsoft Office 2003, BPB Publication
▪ Daniels, Jerry D. Digital Design from Zero to One. New York, NY: John Wiley & Sons,
1996.
▪ Deitel, Harvey M. An Introduction to Operating Systems, 2nd edition. Reading, MA:
Addison-Wesley, 1990.
▪ Deitel, Harvey M. An Introduction to Operating Systems, revised 1st edition. Reading, MA:
Addison-Wesley, 1984.
▪ Digital Research, CP/M Operating System Manual. Pacific Grove, CA: Digital Research,
1982.
▪ Dilson, Jesse. The Abacus: A Pocket Computer. New York, NY: St. Martin's Press, 1994.
Originally published in 1968.
▪ Floyd, Thomas L. Digital Fundamentals, 6th edition. Englewood Cliffs, NJ: Prentice Hall,
1997.
▪ Gajski, Daniel D. Principles of Digital Design. Upper Saddle River, NJ: Prentice Hall, 1997.
▪ Gardner, Martin. Knotted Doughnuts and Other Mathematical Entertainments. New York:
W. H. Freeman and Company, 1986.
▪ Gibson, Victor E. Microprocessors: Fundamental Concepts and Applications. Albany, NY:
Delmar Publisher, Inc., 1994.
▪ Gillie, Angelo C. Binary Arithmetic and Boolean Algebra. New York, NY: McGraw-Hill
Book Company, 1965.
▪ Knuth, Donald E. Selected Papers on Computer Languages. Center for the Study of
Language and Information, 2002.
▪ Kojima, Takashi. The Japanese Abacus: Its Use and Theory. Rutland, VT: Charles E. Tuttle
Company, 1954.
Approved by CDC, Nepal Information Security and Cyber Law 471
▪ Leon, Alexis and Leon, Mathews, Fundamental of Information Technology, New Delhi:
Vikash Publishing Houses.
▪ Malvino, Albert Paul and Jerald A. Brown. Digital Computer Fundamentals, 3rd edition.
New York, NY: Glencoe (Macmillan/McGraw-Hill), 1993.
▪ Mano, M. Morris and Charles R. Kime. Logic and Computer Design Fundamentals. Upper
Saddle River, NJ: Prentice Hall, 1997.
▪ Napier, John. The Construction of the Wonderful Canon of Logarithms. New York, NY:
The Classics of Science Library, 1997. A republication of a translation by William Rae
MacDonald published by William Blackwood and Sons in 1889.
▪ Oberman, R.M.M. Digital Circuits for Binary Arithmetic. London, England: The Macmillan
Press Ltd., 1979.
▪ Rajaraman, V. (2007), Fundamental of Computer, Prentics Hall, Fourth Edition.
▪ Ram B: Computer Fundamental, Willey Eastern Publication
▪ Sammet, Jean B. Programming Languages: History and Fundamentals. Englewood Cliffs,
NJ: Prentice-Hall, Inc., 1969.
▪ Saxena S: A First Course in Computers, Vikas Publication
▪ Sinha, P. K. (2003), Computer Fundamentals (Cd) 4th Edition, BPP Publication.
▪ URL: [Link]
▪ URL: [Link]
▪ von Neumann, John. The Computer and the Brain. New Haven, CT: Yale University Press,
1958.
▪ Wexelblat, Richard L. History of Programming Languages. New York, NY: Academic
Press, 1981.
▪ Yashavant P. Kanetkar, Let Us C E/D, BPB Publications, 2008
472 Computer Science - XI Approved by CDC, Nepal