0% found this document useful (0 votes)
7 views18 pages

mcs215 Cheatcode

Uploaded by

Sakshi Ujjlayan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views18 pages

mcs215 Cheatcode

Uploaded by

Sakshi Ujjlayan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

1.

Explain the following in brief :

• (a) Explain any five security issues in cyberspace.

• (b) What are the three governing principles of data security ? Explain how these three
principles can be implemented.

• (c) Explain any two strategies of regulating the Internet.

• (d) What is the meaning of Intellectual Property ? Explain the following forms of
intellectual property : (i) Copyright and related rights (ii) Patents

1. (a) Five Security Issues in Cyberspace

1. Phishing Attacks
Fake emails or websites trick users into revealing sensitive information like passwords or
bank details. These look legitimate but are designed to steal data.

2. Malware (Malicious Software)


Malware includes viruses, worms, Trojans, and ransomware. It damages, steals, or locks data
and spreads across systems or networks without permission.

3. Hacking and Unauthorized Access


Hackers break into systems to steal, modify, or destroy data. This violates data privacy and
can cause serious harm to individuals and organizations.

4. Identity Theft
Criminals steal someone's personal information (like Aadhaar number, PAN card, etc.) and
impersonate them for fraudulent activities such as taking loans or making online purchases.

5. Denial of Service (DoS) Attacks


Attackers overload a website or server with traffic to crash it, making it unavailable to
legitimate users. This affects business operations and damages reputation.

1. (b) Three Governing Principles of Data Security and Their Implementation

The three main principles are known as the CIA Triad:

1. Confidentiality

o Meaning: Only authorized users should access sensitive data.

o Implementation: Use strong passwords, encryption, access controls, and multi-factor


authentication.

2. Integrity

o Meaning: Data should remain accurate, consistent, and unaltered unless done by
authorized people.

o Implementation: Use checksums, hashing algorithms, and audit trails to detect


tampering or corruption.

3. Availability
o Meaning: Data should be accessible to authorized users when needed.

o Implementation: Use backup systems, uptime monitoring, firewalls, and disaster


recovery plans to avoid downtime.

1. (c) Two Strategies of Regulating the Internet

1. Government Regulations and Laws


Governments can introduce cyber laws (like India’s IT Act 2000) to protect users from online
fraud, cyberbullying, data theft, and more. These laws create legal consequences for misuse
of the Internet.

2. Self-regulation by Platforms
Many tech companies and social media platforms use internal policies and content
moderation tools to block harmful content, fake news, and abuse. They also enforce
community standards and user guidelines.

1. (d) Intellectual Property and Its Forms

Intellectual Property (IP) refers to creations of the mind like inventions, literary works, symbols,
names, and designs. It gives legal rights to the creators for their original work.

(i) Copyright and Related Rights

• Copyright gives protection to authors and creators of original works such as books, music,
movies, software, etc.

• It ensures that only the creator can reproduce, distribute, or modify their work.

• Related rights apply to performers, producers, and broadcasters who are involved in the
distribution or public presentation of copyrighted works.

(ii) Patents

• A patent is a legal right granted to inventors for new inventions that are useful, novel, and
non-obvious.

• It gives the inventor exclusive rights to manufacture, use, or sell the invention for a specific
period (usually 20 years).

• Patents are commonly granted for new machines, technical processes, or scientific
innovations.

2. (a) How can technology be used to answer the following security issues?

(i) Unauthorized Access

• Solution:

o Use authentication mechanisms like strong passwords, biometric scans (fingerprint,


face ID), and multi-factor authentication (MFA).
o Access control systems like role-based access ensure only specific users can access
certain data.

(ii) Malwares

• Solution:

o Install antivirus and anti-malware software that scans and removes threats.

o Use firewalls to monitor and block suspicious network traffic.

o Keep systems updated with the latest security patches.

(iii) Phishing

• Solution:

o Use email filters and anti-phishing tools to block malicious emails.

o Browser security warnings can alert users about fake websites.

o Educate users with cybersecurity awareness training to recognize phishing attempts.

2. (b) What is the use of cryptography? Explain substitution cipher with an example.

Use of Cryptography:

• Cryptography is the science of securing information by converting it into a form that is


unreadable to unauthorized users.

• It ensures confidentiality, integrity, authentication, and non-repudiation in communication.

Substitution Cipher (with Example):

• A substitution cipher replaces each letter of the plaintext with another letter using a fixed
rule.

• Example – Caesar Cipher:

o Shift each letter by 3 positions to the right.

o Plaintext: HELLO
Shifted: H → K, E → H, L → O, L → O, O → R

o Ciphertext: KHOOR

3. (a) Explain the concept and uses of digital signature and digital certificates.

Digital Signature:

• A digital signature is a mathematical technique used to validate the authenticity and


integrity of a message or document.

• It proves that the message was created by the real sender and was not altered during
transmission.
• It uses public key cryptography and provides non-repudiation.

Uses:

• In e-commerce, online banking, software distribution, legal documents, etc., to ensure trust
and authenticity.

Digital Certificate:

• A digital certificate is an electronic document issued by a Certificate Authority (CA) that


proves the ownership of a public key.

• It contains the public key, owner's identity, and CA's digital signature.

• It ensures that the user or website is genuine and trustworthy.

3. (b) Explain the following terms:

(i) Security Audit

• A security audit is a process to evaluate the security of a system or network by checking


policies, controls, and configurations.

• It helps find vulnerabilities, ensures compliance with regulations, and improves overall
security posture.

(ii) Security Policy

• A security policy is a formal document that defines how an organization manages, protects,
and distributes sensitive information.

• It outlines rules, procedures, and responsibilities for users to ensure data security and
minimize risk.

4. (a) Purpose of Filtering Devices and Rating Systems on the Internet + Offences in Indian Cyber
Law

Purpose:

1. Filtering Devices:

o These tools block or restrict access to inappropriate or harmful websites (like adult
content, hate speech, violence).

o Used by parents, schools, workplaces to protect users from harmful or illegal


content.

2. Rating Systems:

o Websites and software can be rated based on content (e.g., age-appropriate levels:
13+, 18+).

o Helps users make informed decisions and ensures safe browsing, especially for
children.

Offences Under Indian Cyber Law (IT Act 2000):


Some offences related to online content include:

• Publishing or transmitting obscene material in electronic form (Section 67).

• Child pornography (Section 67B).

• Defamation and cyberstalking through social media.

• Hate speech or content promoting enmity.

• Spreading fake news or misleading information.

These offences are punishable with fines, imprisonment, or both depending on the severity.

4. (b) Four Categories of Cyber Crimes and Examples

1. Cyber Crimes Against Individuals

• Cyberstalking

• Identity theft

• Online harassment

• Phishing and email spoofing

2. Cyber Crimes Against Property

• Hacking

• Credit card fraud

• Intellectual property theft

• Spreading malware or ransomware

3. Cyber Crimes Against Government

• Cyber terrorism

• Attacks on government websites

• Spying or leaking sensitive data

• Disrupting public utilities through hacking

4. Cyber Crimes Against Society

• Distribution of child pornography

• Online gambling

• Cyber trafficking

• Spreading communal hate or rumors

Difference Between Cyber Crime and Traditional Crime:


Aspect Cyber Crime Traditional Crime

Medium Done via computers & internet Done physically

Speed Happens in real-time (fast) Usually slower

Reach Global (no physical boundaries) Limited to a specific location

Detection Harder to trace and prove Easier with witnesses or evidence

5. (a) What is Cyber Forensics? Explain with Example

Cyber Forensics:

• Also called Digital Forensics, it is the process of collecting, analyzing, and preserving
electronic evidence from digital devices.

• Used in solving cyber crimes by finding who did it, when, how, and what data was affected.

Example:

If someone hacks a bank server and steals data:

• Cyber forensic experts will analyze logs, devices, IP addresses, and files to track the hacker
and gather evidence that can be presented in court.

5. (b) What is a Trademark? Types of Remedies for Trademark Infringement

Trademark:

• A trademark is a recognizable symbol, logo, word, or design that represents a company or


product and sets it apart from others.

• Examples: Nike’s tick mark (✔), Apple logo, Coca-Cola’s brand name.

Remedies Against Infringement:

1. Civil Remedies:

o Injunction: Court order to stop the infringer from using the trademark.

o Damages: Compensation for loss caused by the infringement.

o Account of profits: Infringer pays the profit earned by using the trademark.

2. Criminal Remedies:

o Imprisonment and/or fine for intentional use of fake trademarks.

3. Administrative Remedies:

o Trademark registration authorities can cancel or oppose wrongful registrations or


duplications.
6. (a) Digital Signature

A digital signature is like an electronic fingerprint used to verify the authenticity and integrity of
digital messages or documents.

Key Features:

• It proves that the document was sent by the real sender (authenticity).

• It ensures the content has not been changed (integrity).

• It uses public key cryptography, where a private key signs the data and a public key verifies
it.

Example:

In e-filing of income tax or digital contracts, digital signatures are used to legally verify the
documents.

6. (b) Pros and Cons of Digital Security

Pros:

1. Data Protection: Secures sensitive data from hackers and unauthorized access.

2. Privacy Assurance: Helps individuals and businesses maintain privacy.

3. Prevents Cyber Crimes: Reduces risks of malware, phishing, and fraud.

4. Boosts Trust: Builds user confidence in online services.

Cons:

1. High Costs: Setting up firewalls, encryption, and security software can be expensive.

2. Complexity: Managing security protocols requires technical knowledge.

3. False Sense of Safety: Users may become careless, thinking software will handle everything.

4. Privacy Concerns: Overuse of monitoring tools may invade personal privacy.

6. (c) Cyber Security Threats

These are dangers that can damage or steal data, disrupt digital operations, or harm systems.

Common Cyber Threats:

1. Malware: Viruses, worms, Trojans, and ransomware that damage or steal data.

2. Phishing Attacks: Fake emails or websites that trick users into revealing personal info.

3. Denial of Service (DoS): Overloading servers to make websites unavailable.

4. Hacking: Unauthorized access to systems or networks.

5. Zero-Day Exploits: Attacks using unknown software vulnerabilities.


6. (d) UNCITRAL Model Law

Meaning:

UNCITRAL stands for United Nations Commission on International Trade Law.


The Model Law on Electronic Commerce (1996) was created to help countries frame laws for
electronic transactions and e-commerce.

Purpose:

• To promote uniformity in international e-commerce laws.

• To give legal recognition to electronic records, contracts, and digital signatures.

Example:

India’s Information Technology Act, 2000 is largely based on the UNCITRAL Model Law.

7. Issues Arising Due to Linking, Inlining, and Framing

1. Linking:

• It means adding a hyperlink that takes the user to another website.

• Issue:
The linked site may not want traffic redirected to them without permission.
It can also imply endorsement or partnership that doesn’t exist.

2. Inlining (Inline Linking):

• It displays content (like images or videos) from another website on your own site without
hosting it.

• Issue:

o It uses the original site’s bandwidth without consent.

o May violate copyright laws since content is shown without hosting or licensing it.

3. Framing:

• It displays another website’s content within a frame on your own site, making it look like
part of your site.

• Issue:

o Can mislead users about who owns the content.

o May violate copyright or trademark rights.

o Affects the reputation or branding of the original content owner.


8. Conditions Under Which a Person is Liable to Pay Damages Under the IT Act, 2000

Under Section 43 and 66 of the Information Technology Act, 2000, a person is liable to pay
compensation/damages or face penalty if they access or damage a computer system or data
without permission.

Key Conditions:

1. Unauthorized Access
Accessing a computer, system, or network without the owner's consent.

2. Data Theft or Downloading Without Permission


Copying or downloading files, data, or information from someone else’s computer system.

3. Spreading Viruses or Malware


Introducing malicious programs like viruses, Trojans, or worms that damage data or systems.

4. Disruption of Services
Disrupting or causing denial of access to any computer or network.

5. Manipulating or Deleting Data


Damaging, deleting, altering, or disrupting any data or programs.

6. Stealing Digital Devices or Credentials


Hacking passwords, stealing devices, or tampering with biometric devices.

Penalty:

• Compensation up to ₹1 crore (as per Section 43).

• If done dishonestly or fraudulently → Criminal offense under Section 66, punishable with
imprisonment up to 3 years and/or fine up to ₹5 lakh.

9. “Authentication is One of the Most Important Information Security Objectives” – Critical


Examination

Why Authentication is Important:

1. Access Control:
Ensures that only authorized users can access systems or data.

2. Data Privacy:
Protects sensitive information like banking details, emails, or company secrets.

3. User Accountability:
Identifies the user responsible for actions, which is crucial for tracking misuse.

4. Prevents Unauthorized Use:


Stops hackers, identity thieves, and intruders from exploiting the system.

However, Challenges Include:

1. Weak Passwords:
If users choose simple passwords, authentication becomes ineffective.
2. Stolen Credentials:
Passwords or biometric data can be hacked or misused.

3. Cost and Complexity:


Implementing strong multi-factor authentication (MFA) requires resources and user training.

Conclusion:

Authentication is essential for security but must be supported with encryption, firewalls, and user
education to be fully effective.

10. Data Security Measures (Brief Explanation)

Data security means protecting digital data from unauthorized access, corruption, or loss. Below
are key measures:

1. Encryption:

• Converts readable data into unreadable format.

• Only authorized users with a decryption key can access the original data.

2. Access Control:

• Grants system access only to authorized individuals.

• Uses passwords, biometrics, role-based permissions.

3. Firewalls:

• Hardware or software that monitors and blocks unauthorized network traffic.

• Protects systems from external threats.

4. Antivirus and Anti-malware:

• Detects and removes malicious software.

• Protects data from corruption or theft.

5. Regular Backups:

• Copies of important data are stored separately.

• Ensures data recovery in case of loss or attack.

6. Multi-Factor Authentication (MFA):

• Combines multiple layers like password + OTP or fingerprint.

• Increases protection from unauthorized access.

7. Physical Security:

• Restricts access to servers or devices (e.g., security locks, surveillance).

8. Security Policies and Training:

• Educates employees about phishing, safe internet use, and company protocol
11. (a) The Concept and Need for Cyber Security

Concept:

Cyber security is the practice of protecting computers, servers, networks, and data from
unauthorized access, attacks, or damage.

Need for Cyber Security:

1. Protects Sensitive Data – Prevents theft of financial, personal, and business data.

2. Ensures Business Continuity – Avoids service disruptions caused by cyberattacks.

3. Prevents Financial Loss – Cyberattacks can cause huge losses for companies and individuals.

4. Builds Trust – A secure system earns user confidence.

5. Supports Legal Compliance – Helps meet data protection regulations like GDPR or IT Act,
2000.

11. (b) Types of Conventional Ciphers

Conventional ciphers are basic encryption techniques used before modern encryption methods. Two
major types:

1. Substitution Cipher:

o Each letter in the plaintext is replaced with another letter or symbol.

o Example: Caesar Cipher – shifts letters by a fixed number of positions (e.g., A → D).

2. Transposition Cipher:

o The position of letters is changed according to a rule, without altering the actual
letters.

o Example: Plaintext "HELLO" can become "LLEHO" using a certain key.

11. (c) Filtering Devices and Rating Systems

Filtering Devices:

• Tools that block or restrict access to specific websites or content.

• Used by parents, schools, and organizations to protect users from harmful or illegal material
(e.g., pornographic, violent, or phishing websites).

Rating Systems:

• Label content based on suitability for different age groups.

• Example: PEGI (for games), TV ratings, or internet content labels like 13+, 18+.

• Helps in safe browsing and making informed choices.


11. (d) Difference Between Cyber Crimes and Traditional Crimes

Aspect Cyber Crimes Traditional Crimes

Medium Computer and internet Physical tools or human action

Reach Global – can affect anyone anywhere Usually local or within a boundary

Speed of Execution Instant or real-time Takes time and physical effort

Evidence Digital logs, IP addresses, etc. Physical evidence (fingerprints, CCTV)

Example Hacking, phishing, identity theft Theft, murder, robbery

12. Core Elements of Data Security

The three core elements of data security are:

1. Confidentiality

• Ensures that only authorized users can access sensitive data.

• Techniques: Encryption, passwords, access control.

2. Integrity

• Ensures that data is not altered or tampered with during storage or transmission.

• Techniques: Hashing, checksums, version control.

3. Availability

• Ensures that data is available when needed by authorized users.

• Techniques: Backups, redundancy, disaster recovery systems.

These three are together known as the CIA Triad – the foundation of information security.

13. Copyright Issues in the Digital Medium – Critical Examination

What is Copyright?

Copyright gives creators legal rights over their original works like music, books, videos, software, etc.

Issues in the Digital Medium:

1. Easy Copying and Distribution

o Digital content (e.g., songs, books, software) can be copied and shared instantly
without the owner’s permission.

2. Piracy and Illegal Downloads

o Widespread downloading and streaming of copyrighted content without paying or


crediting the owner.
3. Lack of Awareness

o Many users don't know that downloading or sharing copyrighted material is illegal.

4. Jurisdictional Problems

o Digital content spreads globally, but copyright laws differ from country to country.
This makes enforcement difficult.

5. Fair Use vs. Infringement

o It’s hard to define the boundary between "fair use" (like educational or review
purposes) and illegal use.

6. User-Generated Content

o Platforms like YouTube, Instagram, etc., allow users to upload content. But often,
they unknowingly use copyrighted material (music, clips, etc.).

Conclusion:

While copyright is meant to protect creators, the digital world makes enforcement challenging.
Governments and platforms must work together to improve laws, raise awareness, and implement
better monitoring tools.

14. Law in the United States for Regulation of Cyberspace

The United States follows a sector-based and decentralized approach to cyberspace regulation.
Instead of one single law, it has multiple laws targeting different areas of cyber activity.

Key Cyber Laws in the U.S.:

1. Computer Fraud and Abuse Act (CFAA), 1986

o Makes unauthorized access to computers, data theft, and hacking illegal.

o Used widely to prosecute cybercriminals.

2. Electronic Communications Privacy Act (ECPA), 1986

o Protects the privacy of emails, phone calls, and other digital communications.

o Restricts unauthorized surveillance or wiretapping.

3. Children’s Online Privacy Protection Act (COPPA), 1998

o Regulates the collection of personal data from children under 13.

o Requires parental consent before collecting children's data.

4. Digital Millennium Copyright Act (DMCA), 1998

o Protects copyright in the digital world.

o Punishes online piracy and sets rules for copyright infringement on digital platforms.

5. USA PATRIOT Act (2001)


o Allows surveillance of digital communication for national security and anti-terrorism
efforts.

Features of U.S. Cyber Law Approach:

• Strong focus on privacy, freedom of expression, and security.

• Heavy involvement of private companies in enforcement (e.g., Google, Facebook).

• Laws constantly updated to address new digital threats.

15. What is Cryptography? Discuss RSA Algorithm

Cryptography:

Cryptography is the science of securing information by converting it into unreadable format


(ciphertext) using mathematical algorithms. Only authorized users can decrypt it to access the
original message (plaintext).

It ensures:

• Confidentiality – Keeps information secret.

• Integrity – Prevents tampering.

• Authentication – Verifies user identity.

• Non-repudiation – Prevents denial of actions.

RSA Algorithm (Rivest–Shamir–Adleman)

RSA is a public-key cryptography algorithm used for encryption and digital signatures.

Steps:

1. Key Generation:

o Choose two large prime numbers: p and q

o Compute: n = p × q

o Calculate: φ(n) = (p - 1)(q - 1)

o Choose e (encryption key), such that 1 < e < φ(n) and e is co-prime to φ(n)

o Compute d (decryption key) such that (d × e) mod φ(n) = 1

2. Public Key = (e, n)


Private Key = (d, n)

3. Encryption:

o Ciphertext C = (M^e) mod n

4. Decryption:
o Original Message M = (C^d) mod n

Example:

• If M = 7, e = 5, n = 33, then:
C = (7^5) mod 33 = 16807 mod 33 = 31

• Decryption with d = 29:


M = (31^29) mod 33 = 7 → original message recovered.

16. (a) Data Management

Data management involves collecting, storing, organizing, and protecting data so that it can be
accessed and used efficiently and securely.

Key Activities:

• Data entry and storage

• Data backup and recovery

• Data security and privacy

• Database management systems (DBMS)

Example: A hospital managing patient records using a secure database.

16. (b) Copyright and Related Rights

Copyright:

• Legal right given to creators of original works (books, music, films, software, etc.)

• Gives exclusive rights to reproduce, distribute, perform, or display the work.

Related Rights:

• Protect rights of performers (singers, actors), producers of sound recordings, and


broadcasting organizations.

• These rights ensure that others cannot commercially exploit their performance or production
without permission.

16. (c) Advantages of Public Key Cryptography

1. Secure Key Distribution:

o No need to share private keys, reducing the risk of interception.

2. Confidentiality and Authentication:

o Ensures both data privacy and identity verification.

3. Digital Signatures:
o Verifies the integrity and source of digital data.

4. Scalability:

o Works well for large networks (like the Internet) where many users communicate
securely.

16. (d) Need for Regulation of Cyberspace

1. To Prevent Cybercrimes:

o Laws are needed to stop hacking, identity theft, cyberstalking, and online fraud.

2. To Protect Privacy:

o Regulation ensures user data is not misused or leaked.

3. To Handle Cross-Border Issues:

o Cyberspace is global, so laws help coordinate action between countries.

4. To Maintain National Security:

o Prevents misuse of the internet by terrorists or criminals.

5. To Encourage E-commerce and Innovation:

o Legal frameworks boost trust in online transactions and digital startups.

17. Security Issues in Cyberspace

Cyberspace, which includes all computer networks and the internet, faces several serious security
issues due to increasing dependence on digital platforms.

Major Cybersecurity Issues:

1. Hacking and Unauthorized Access

o Hackers gain illegal access to systems to steal, alter, or delete information.

2. Phishing and Identity Theft

o Fake websites or emails trick users into giving personal information like bank
credentials, leading to financial frauds.

3. Malware Attacks

o Malicious software like viruses, worms, ransomware can damage files, steal data, or
demand ransom for unlocking systems.

4. Denial of Service (DoS) Attacks

o Overloads a system or website with traffic, making it unavailable to users.

5. Cyberstalking and Online Harassment

o Using online platforms to stalk, threaten, or bully individuals.


6. Data Breaches

o Large-scale leakage of personal or financial information due to weak security or


insider threats.

Why It Matters:

• Affects personal privacy, financial stability, business operations, and even national security.

18. Note on Cyber Forensics

Cyber Forensics (Digital Forensics):

It is the scientific process of identifying, collecting, preserving, analyzing, and presenting digital
evidence from computers, networks, and other electronic devices.

Purpose:

To investigate cybercrimes like hacking, fraud, cyberstalking, identity theft, or data breaches.

Key Steps:

1. Identification: Finding digital devices and sources of evidence.

2. Preservation: Ensuring no tampering happens during evidence collection.

3. Analysis: Examining files, logs, emails, IP addresses, etc.

4. Presentation: Preparing reports and presenting digital evidence in court.

Example:

If a company is hacked, cyber forensic experts can trace the attack origin by analyzing system logs
and network activity to identify the hacker and gather court-admissible evidence.

19. Overview of Cyberspace Regulation in India

India regulates cyberspace through various laws, policies, and enforcement agencies, mainly
governed by the Information Technology (IT) Act, 2000.

Key Points:

1. IT Act, 2000:

o India’s primary law to regulate electronic transactions and cybercrimes.

o Covers hacking, identity theft, cyberstalking, data protection, and digital signatures.

2. Amendments:

o In 2008, major changes were made to address cyber terrorism, data privacy, and
online obscenity.

3. Regulatory Bodies:

o CERT-In (Computer Emergency Response Team – India) handles cyber incidents.


o Ministry of Electronics and IT (MeitY) handles digital governance.

4. Cybercrime Cells:

o Law enforcement units across states deal with online crimes and complaints.

5. Personal Data Protection Bill (Pending):

o Aims to enhance privacy rights and regulate how companies collect and store user
data.

6. Social Media & Content Regulation:

o Guidelines issued in 2021 make platforms responsible for monitoring harmful or


illegal content.

20. Six Principles of Security Management

Security management ensures that an organization's digital assets are protected using structured
policies and practices.

1. Confidentiality

• Ensures that information is accessible only to authorized users.

• Tools: Encryption, access controls.

2. Integrity

• Protects data from being changed or tampered with.

• Tools: Hashing, audit logs.

3. Availability

• Ensures data and systems are accessible when needed.

• Tools: Backups, failover systems, cloud storage.

4. Accountability

• Tracks user activity to identify who did what and when.

• Tools: Audit trails, user logs.

5. Non-Repudiation

• Prevents a user from denying their actions.

• Tools: Digital signatures, receipts, secure logging.

6. Authentication

• Verifies the identity of users and systems before allowing access.

• Tools: Passwords, biometrics, OTPs, certificates.

You might also like