SLU-IFT132: Introduction to Information Systems
Week 7 Lecture Note: IT Security
7.0 Introduction to IT Security
IT Security is the practice of protecting computer systems, networks, and data from
unauthorized access, damage, or disruption. It ensures that information systems operate
safely and reliably in both personal and organizational environments. With increasing
dependence on digital systems, security has become a fundamental requirement in
modern information systems.
1. IT security protects digital systems from unauthorized access and misuse.
2. It combines technology, policies, and human behavior.
3. It is essential due to rising cyber threats and digital dependency.
7.1 Principles of Information Security (CIA Triad)
The CIA triad is the foundation of information security. It defines the three main goals
that every secure system must achieve to protect information assets effectively.
1. Confidentiality ensures that only authorized users can access information.
2. Integrity ensures that data remains accurate and unchanged unless authorized.
3. Availability ensures that systems and data are accessible when needed.
4. These principles collectively maintain trust and reliability in information
systems.
7.2 Types of Security Threats
Security threats are actions or events that compromise system safety or data integrity.
These threats may come from software, attackers, or user negligence.
1. Malware is malicious software designed to damage systems or steal data.
2. Viruses, worms, and ransomware spread and disrupt normal system
operations.
3. Phishing attacks deceive users into revealing sensitive information.
4. Hacking involves unauthorized access to computer systems.
5. Social engineering manipulates human behavior to gain confidential data.
7.3 Security Measures and Protection Techniques
Security measures are methods used to defend systems against attacks and unauthorized
access. They form the technical defense layer of IT security.
1. Encryption converts data into unreadable form to protect confidentiality.
2. Firewalls filter network traffic based on security rules.
3. Antivirus software detects and removes malicious programs.
4. Intrusion Detection Systems (IDS) monitor systems for suspicious activity.
5. These tools work together to create layered security protection.
7.4 Safe Internet Practices (Cyber Hygiene)
Cyber hygiene refers to safe habits users follow to protect themselves online. It helps
reduce the risk of cyberattacks caused by human error.
1. Users should use strong, unique passwords for different accounts.
2. Regular software updates help fix security vulnerabilities.
3. Avoid clicking on unknown links or downloading suspicious files.
4. Always log out of systems after use, especially on shared devices.
5. Good cyber hygiene improves overall system security.
7.5 Authentication and Access Control
Authentication and access control ensure that only authorized individuals can access
system resources. They are essential for protecting sensitive data.
1. Authentication verifies the identity of users before system access.
2. Methods include passwords, biometrics, PINs, and security tokens.
3. Access control determines user permissions within a system.
4. Role-Based Access Control (RBAC) assigns access based on job roles.
5. These systems prevent unauthorized system usage.
7.6 Network Security
Network security focuses on protecting data during transmission across computer
networks. It ensures secure communication between systems.
1. VPNs create encrypted connections over public networks.
2. Intrusion Detection Systems monitor network activities for threats.
3. Firewalls protect network boundaries from unauthorized access.
4. Secure protocols ensure safe data transmission.
5. Network security prevents interception and data theft.
7.7 Cybercrime and Legal Frameworks
Cybercrime involves illegal activities carried out using digital systems. It affects
individuals, organizations, and governments globally.
1. Cybercrime includes hacking, identity theft, and online fraud.
2. Phishing and scams are common forms of cybercrime.
3. Cyber laws regulate and punish illegal digital activities.
4. Nigeria has legal frameworks for cybercrime prevention.
5. Compliance ensures responsible use of technology.
7.8 Security Awareness and User Responsibility
Security awareness focuses on educating users about cyber risks and safe behavior.
Users play a major role in maintaining system security.
1. Users must understand common cyber threats and risks.
2. Organizations provide training to improve awareness.
3. Users must protect passwords and sensitive information.
4. Suspicious activities should be reported immediately.
5. Human behavior is critical in preventing security breaches.
7.9 Types of Firewalls and Their Functions
Firewalls are security systems that control network traffic. Different types provide
different levels of protection depending on system needs.
1. Packet-filtering firewalls inspect data packets based on rules.
2. Stateful firewalls analyze connection states for better filtering decisions.
3. Proxy firewalls act as intermediaries between users and networks.
4. Next-generation firewalls combine multiple advanced security features.
5. Firewalls form the first line of network defense.
7.10 Types of Malware and Their Characteristics
Malware includes different types of harmful software designed to disrupt systems or
steal information.
1. Viruses attach to files and spread when executed.
2. Worms replicate across networks without user action.
3. Trojans disguise themselves as legitimate programs.
4. Ransomware encrypts data and demands payment.
5. Spyware secretly collects user information.
7.11 Digital Forensics and Investigation
Digital forensics is the process of investigating cyber incidents using digital evidence.
It is used to track attackers and understand security breaches.
1. It involves collecting evidence from digital devices.
2. Forensic tools analyze system activities and data traces.
3. Evidence must be preserved in a legally acceptable manner.
4. It helps identify how and when attacks occurred.
5. It supports legal prosecution of cybercriminals.
7.12 Backup and Disaster Recovery Systems
Backup and disaster recovery ensure system continuity after failures or attacks. They
protect organizations from data loss.
1. Data backup involves creating copies of important information.
2. Backup types include full, incremental, and differential backups.
3. Disaster recovery plans define system restoration procedures.
4. Cloud storage is commonly used for secure backups.
5. These systems minimize downtime and data loss.
7.13 Cybersecurity Policies in Organizations
Cybersecurity policies define rules for protecting organizational systems and data.
They ensure consistent security practices.
1. Policies define acceptable system and internet usage.
2. They regulate password and data handling practices.
3. Employees must comply with organizational security rules.
4. Policies reduce human-related security risks.
5. They ensure standardized protection across organizations.
7.14 Ethical Hacking and Penetration Testing
Ethical hacking involves legally testing systems for vulnerabilities. It helps
organizations strengthen their security.
1. Ethical hackers simulate real cyberattacks.
2. Penetration testing identifies system weaknesses.
3. Vulnerabilities are reported for correction.
4. It improves system defense before real attacks occur.
5. It is a proactive security strategy.