FM-AA-CIA-15 Rev.
0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
STUDY GUIDE FOR MODULE NO. ___
1
INTRODUCTION TO
INFORMATION SECURITY
MODULE OVERVIEW
This chapter introduces information security. It focuses on generic computer and Internet security
concepts and describes how to develop an organization's comprehensive security plan. The chapter explains
the nuances of general network security and Internet security. It explores why it is necessary and how a
comprehensive security policy can be created to protect networks from unauthorized access.
MODULE LEARNING OBJECTIVES
At the end of this learning activity, you should be able to:
1. Understand the definition of information security.
2. Comprehend the history of computer security and how it evolved into information security.
3. Understand the key terms and critical concepts of information security.
4. Outline the phases of the security systems development life cycle.
5. Understand the roles of professionals involved in information security within an organization.
LEARNING CONTENTS | INFORMATION SECURITY
▪ "Information security is a confident awareness that the risks to information and the measures in place
to control them are in equilibrium." —Jim Anderson, Inovant (2002)
▪ Information security encompasses the procedures and approaches created and applied to safeguard
confidential, private, and sensitive information or data, whether in print, electronic, or other forms, from
unauthorized access, usage, misuse, disclosure, destruction, alteration, or disruption.
▪ It is essential to examine the roots of this field and how they have shaped our current understanding of
information security.
PANGASINAN STATE UNIVERSITY 1
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
LEARNING CONTENTS | History of Information Security
▪ The history of information security has its roots in computer security. The demand for computer
security—securing and protecting physical locations, hardware, and software from threats emerged
during World War II, as the first mainframes were created to assist with computations for communication
code breaking (see Figure 1-1), were used. The origins of information security can be linked to the early
development of computer security. The necessity to protect physical locations, hardware, and software
from threats emerged during World War II, when the first mainframes were created to assist with
communication code-breaking efforts (see Figure 1-1).
▪ It began immediately after the first mainframes were developed.
▪ They were created to aid code-breaking computations during World War II.
▪ Physical controls limit authorized personnel's access to sensitive military locations, such as badges,
keys, and facial recognition, which are basic methods used to guard against physical theft, espionage,
and sabotage.
▪ One of the 1st documented problems.
▪ The early 1960s
▪ Not physical
▪ Accidental file switch
▪ Entire password file
▪ printed on every output file.
PANGASINAN STATE UNIVERSITY 2
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
▪ In the 1960s, additional mainframes were brought online, and the Advanced Research Projects Agency
(ARPA) began exploring the feasibility of redundant networked communications.
▪ Larry Roberts played a crucial role in the development of ARPANET from its early stages.
▪ ARPANET is the first Internet
▪ ARPANET's popularity increased in the 1970s and 80s, raising concerns about its potential for
misuse.
▪ Critical security issues with ARPANET were recognized, including the lack of safety procedures
for dial-up connections and the absence of user identification and authorization mechanisms.
▪ Information security began with Rand Report R-609 (the paper that started the study of
computer security)
▪ The scope of computer security expanded beyond physical protection to encompass:
▪ Data safety
▪ Restricting unauthorized access to data
▪ Engaging personnel from various organizational levels
▪ The initial recognition of management and policy roles
▪ Multiplexed Information and Computing Service (Multics)
▪ Operating System; Security is the primary goal
▪ Need to go farther
▪ Several developers created Unix.
PANGASINAN STATE UNIVERSITY 3
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
▪ In the late 1970s, microprocessors expanded computing capabilities and security threats.
▪ From mainframe to PC
▪ Decentralized computing
▪ The need for sharing resources increased.
▪ Major changed computing
▪ The 1990s
▪ As networks of computers became more widespread, the need to connect these networks also
grew.
▪ The Internet emerged as the first example of a global network of interconnected networks.
▪ In the early days of the Internet, Security was often considered a low priority.
▪ This initial neglect has led to many of the problems that continue to affect e-mail and other
online services today.
▪ The Present
▪ The Internet connects millions of computer networks, many needing to be secured.
▪ The Security of a computer's data is impacted by the Security of every computer it is connected
to.
LEARNING CONTENTS | Security
What is Security?
▪ "Security refers to the quality or state of being free from danger.”
▪ A successful organization should implement multiple layers of Security to ensure comprehensive
protection:
▪ Physical Security
▪ Personal Security
▪ Operations security
▪ Communications security
▪ Network security
▪ Information security
PANGASINAN STATE UNIVERSITY 4
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
What is Information Security?
▪ It protects information and its critical elements, including systems and hardware, that store and transmit
it.
▪ Necessary tools: policy, awareness, training, education, technology
▪ CIA triangle was standard based on confidentiality, integrity, and availability.
▪ CIA triangle has now expanded into a list of critical characteristics of information.
LEARNING CONTENTS | Critical Characteristics of Information
▪ The worth of information is derived from its inherent attributes:
▪ Timeliness
▪ There is only value if there is time.
▪ Availability
▪ No interference or obstruction
▪ Required format.
▪ Accuracy
▪ Free from mistakes
▪ Authenticity
▪ Quality or state of being genuine, i.e., sender of an e-mail.
PANGASINAN STATE UNIVERSITY 5
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
▪ Confidentiality
▪ Disclosure or exposure to unauthorized individuals or the system is prevented.
▪ Integrity
▪ Complete, intact, and unaltered.
▪ Cornerstone
▪ File size, hash values, error-correcting codes, and retransmission
▪ Utility
▪ Being beneficial for a specific purpose
▪ Possession
▪ Ownership
▪ A breach of confidentiality leads to a violation of ownership, not vice versa.
LEARNING CONTENTS | Components of an Information System
An Information System (IS) encompasses the complete array of software, hardware, data, personnel,
procedures, and networks required to leverage information as a resource within an organization.
▪ Software
▪ Perhaps the most difficult to secure.
▪ Easy target
▪ Exploitation is a substantial portion of attacks on information.
PANGASINAN STATE UNIVERSITY 6
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
▪ Hardware
▪ Physical security policies
▪ Securing physical location is important
▪ Laptops
▪ Flash memory
▪ Data
▪ Often most asset
▪ The main target of intentional attacks
▪ People
▪ Weakest link
▪ Social engineering
▪ Must be well-trained and informed.
▪ Procedures
▪ Threat to integrity of data
▪ Networks
▪ Locks and keys won’t work.
LEARNING CONTENTS | Securing Components
▪ Computers can be the subject of an attack or the object of an attack.
▪ When the subject of an attack is the computer, it is used as an active tool to conduct an attack.
▪ When the object of an attack, the computer is the entity being attacked.
▪ Two types of attack
▪ Direct: Hackers use their computers to break into a system.
▪ Indirect: The system is compromised and used to attack other systems.
PANGASINAN STATE UNIVERSITY 7
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
LEARNING CONTENTS | Balancing Information Security and Access
▪ It is impossible to obtain perfect Security—it is a process, not an absolute one.
▪ Security should be viewed as a balance between protection and accessibility.
▪ Achieving this balance requires setting a security level that ensures adequate protection against threats
while allowing reasonable access.
▪ Even with the best planning and implementation, it is impossible to obtain perfect Security; that is, it is
a process, not an absolute. Security should be taken as a balance between protection and availability.
To achieve balance, the level of Security should allow reasonable access while protecting against
threats. The figure below illustrates the basic idea of balancing security and information system access.
PANGASINAN STATE UNIVERSITY 8
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
LEARNING CONTENTS | Approaches to Information Security Implementation: Bottom-Up
Approach
▪ Grassroots effort: systems administrators attempt to improve the Security of their systems.
▪ Key advantage: technical expertise of individual administrators.
▪ It seldom works, as it lacks several critical features:
▪ Participant support
▪ Organizational staying power
LEARNING CONTENTS | Approaches to Information Security Implementation: Top-Down
▪ Initiated by upper management
▪ Issue policy, procedures, and processes
▪ Dictate goals and expected outcomes of the project.
▪ Determine accountability for each required action.
▪ The most successful also involve formal development strategies called systems development
life cycle.
PANGASINAN STATE UNIVERSITY 9
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
LEARNING CONTENTS | Systems Development Life Cycle
▪ The systems development life cycle (SDLC) is the methodology and design for implementing
information security within an organization.
▪ Methodology is a formal approach to problem-solving based on a structured sequence of procedures.
▪ Using a methodology ensures a rigorous process.
▪ Avoids missing steps.
▪ The objective is to develop a thorough and all-encompassing security framework.
▪ Traditional SDLC consists of six general phases.
▪ The phases of the traditional SDLC can be modified to accommodate the unique requirements of an
IS project.
▪ It involves identifying specific threats and developing controls to address them.
▪ Security SDLC is a structured program rather than a collection of disjointed, unrelated activities.
▪ Investigation
▪ It outlines the project's process, outcomes, goals, and constraints, starting with the enterprise
information security policy.
▪ Analysis
▪ Existing security policies, legal issues,
▪ Perform risk analysis.
PANGASINAN STATE UNIVERSITY 10
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
▪ Logical Design
▪ It develops and outlines plans for information security.
▪ Incident response actions: Continuity planning, Incident response, Disaster recovery
▪ Conducts a feasibility analysis to decide whether the project should proceed internally or be
outsourced.
▪ Physical Design
▪ The needed security technology is evaluated, alternatives are generated, and the final design
is selected.
▪ Implementation
▪ Security solutions are procured, tested, implemented, and tested once more.
▪ Personnel issues were evaluated, and specific training and education programs were
conducted.
▪ The entire tested package is presented to management for final approval.
▪ Maintenance and Change
▪ Most important
▪ Constant changing threats
▪ Constant monitoring, testing, updating, and implementing change.
LEARNING CONTENTS | Security Professionals and the Organization
▪ Security is crucial to a company's success, as it safeguards sensitive digital information and protects
technical systems from viruses and hackers. Given its critical role, Security remains a priority for
companies, with ongoing investments even during economic downturns.
▪ A wide range of professionals is required to support a diverse information security program.
▪ Senior management is a crucial component; additional administrative support and technical expertise
are required to implement the details of the IS program.
Senior Management
▪ Chief Information Officer (CIO)
▪ Senior technology officer
▪ Mainly accountable for advising senior executives on strategic planning matters.
PANGASINAN STATE UNIVERSITY 11
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
▪ Chief Information Security Officer (CISO)
▪ Primarily responsible for the organization's assessment, management, and implementation of
IS.
▪ Usually reports directly to the CIO.
Information Security Project Team
▪ Several individuals who are experienced in one or more facets of technical and non-technical areas:
▪ Champion: Senior executive who promotes the project
▪ Team leader: project manager, departmental level manager
▪ Security policy developers
▪ Risk assessment specialists
▪ Security professionals
▪ Systems administrators
▪ End users
Data Ownership
▪ Data Owner: accountable for the Security and management of a specific information set.
▪ Data Custodian: in charge of storing, maintaining, and protecting information.
▪ Data Users: individuals who use information to complete daily tasks and contribute to the
organization's mission.
Communities of Interest
▪ Group of individuals united by similar interests/values in an organization.
▪ Information Security Management and Professionals
▪ Information Technology Management and Professionals
▪ Organizational Management and Professionals
PANGASINAN STATE UNIVERSITY 12
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
LEARNING CONTENTS | Key Terms, Summary
Key Terms
▪ Access ▪ Risk
▪ Asset ▪ Security Blueprint
▪ Attack ▪ Security Model
▪ Control, Safeguard or Countermeasure ▪ Security Posture or Security Profile
▪ Exploit ▪ Subject
▪ Exposure ▪ Threats
▪ Hacking ▪ Threat Agent
▪ Object ▪ Vulnerability
Summary:
▪ Information security is defined as a "well-informed assurance that the balance between information
risks and controls is maintained."
▪ Computer security emerged following the development of the first mainframes.
▪ Successful organizations incorporate several layers of Security:
▪ Physical, personal, operations, communications, network, and information.
▪ Security should be viewed as a balance between protection and accessibility.
▪ Information security should be managed similarly to any central system within an organization,
utilizing a methodology such as Security SDLC.
▪ Implementing information security is often described as a fusion of art and science.
PANGASINAN STATE UNIVERSITY 13
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
LEARNING ACTIVITY
Analysis of RA 10175
Instructions:
Read the Law: Access and read the full text of the Philippine law RA 10175, also known as the
Cybercrime Prevention Act of 2012, at [Link].
Respond to the Questions:
a. Definition of Information Security: Does RA 10175 define "information security"? Provide details from the text
if available.
b. Importance of Definition: Discuss why the law does or does not need to define "information security." Consider
the implications of including or excluding this definition in the context of legal clarity and enforcement.
c. Need for Revision: Evaluate whether RA 10175 requires revision to keep up with the rapidly changing
technology landscape. Justify your position with examples or arguments about current technological
advancements and their impact on cybersecurity laws.
Submission: Provide your answers in a well-organized report or essay format. Use relevant citations from the
law as needed.
Rubrics:
Criteria Excellent (4) Good (3) Fair (2) Poor (1)
Definition of Provides a precise, Provides a clear answer Provides a vague or Fails to address the
Information Security detailed analysis of but with minimal details incomplete answer with question or needs to
whether RA 10175 or needs complete few details or citations. provide correct
defines information citations. information.
security, with accurate
citations.
Importance of Thoroughly discusses Discusses the Provides a fundamental Minimal discussion with
Definition why the law does or importance with good discussion with limited weak arguments or
does not need to define arguments but needs arguments or examples. missing rationale.
information security, more depth or detail.
with solid arguments
and examples.
Need for Revision Provides a Evaluates the need for Provides an essential Fails to provide a
comprehensive revision with good evaluation with limited precise evaluation or
evaluation of whether arguments but lacks arguments or examples. justification for the need
the law needs revision, some detail or for revision.
with well-supported examples.
arguments and
examples of current
technology trends.
Clarity and Answers are well- Answers are primarily Answers could be more Answers could be better
Organization organized, clearly clear and organized with organized and clear, and organized, more
written, and free of minor errors. there are several errors. precise, or contain
errors. numerous errors.
Use of Citations Effectively uses citations It uses some citations Minimal use of citations No use of citations or
from the law to support but only sometimes or citations needs to be citations is incorrect.
answers. effectively. better integrated.
Total Score: ____ /20
PANGASINAN STATE UNIVERSITY 14
FM-AA-CIA-15 Rev. 0 10-July-2020
Study Guide in Information Assurance and Security Module No. 1
REFERENCES
Books and Journal Articles
Aryanti, U., Anwar, M. T., & Rahmawati, T. (2023). Information security risk management using OCTAVE
Allegro method at university. International Journal of Engineering Education and Research, 3(4).
[Link]
Whitman, M. E., & Mattord, H. J. (2021). Principles of Information Security (6th ed.). Cengage Learning.
Yankson, B., Delgado, E., Al-Jabri, A., Gitin, N., & Davidson, S. (2022). Social media privacy using the EDEE
security model. Proceedings of the International Conference on Cyber Warfare and Security, 366-374.
Online Resources
Barakat, S. (2020). Analyzing computer security. Retrieved from
[Link]
Innovative Architects. (n.d.). System development life cycle. Retrieved from
[Link]
LawPhil. (2012). Republic Act No. 10175. Retrieved from
[Link]
Miller, A. (2012). Information security and privacy. In Handbook of Information Security, Threats,
Vulnerabilities, Prevention, Detection and Management (pp. 553-564). Wiley.
[Link]
Smith, L. (2019, March 13). Consider these information security organizations. LiveAbout.
[Link]
Smith, L. (2019, March 13). Leading information security organizations. The Balance Careers. Retrieved from
[Link]
SANS Institute. (n.d.). Information security. Retrieved from [Link]
Tayyab, A. (2017). Ch01 Introduction
to information security [PowerPoint slides]. SlideShare.
[Link]
World Colleges Information. (n.d.). Information security. Retrieved from
[Link]
PANGASINAN STATE UNIVERSITY 15