0% found this document useful (0 votes)
3 views9 pages

Topic6 Computer Security Teaching Notes

This document provides an introductory overview of computer security, covering its definition, the CIA triad, types of security, common threats, and protective measures. It emphasizes the importance of safeguarding information and outlines practical steps for individuals and organizations to enhance their security practices. Additionally, it highlights the legal and ethical dimensions of computer security in Uganda.

Uploaded by

tinaamarion
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views9 pages

Topic6 Computer Security Teaching Notes

This document provides an introductory overview of computer security, covering its definition, the CIA triad, types of security, common threats, and protective measures. It emphasizes the importance of safeguarding information and outlines practical steps for individuals and organizations to enhance their security practices. Additionally, it highlights the legal and ethical dimensions of computer security in Uganda.

Uploaded by

tinaamarion
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

BILLBRAIN INSTITUTE OF TECHNOLOGY

Fundamentals of IT & Computer Systems

Topic 6: Computer Security


Teaching Notes — Introductory Level

Session Overview
This session covers the definition of computer security, the CIA triad, why security matters, the five types of
computer security, common threats, protective measures, strong passwords, and the benefits of good security
practice. No prior security background assumed.

1. Definition of Computer Security


Computer security is the protection of computer systems, hardware, software, networks, and data from
unauthorized access, misuse, theft, damage, or cyberattacks. It involves policies, technologies, and practices
that keep information safe and accessible only to authorized users.
The main objective of computer security is to protect the Confidentiality, Integrity, and Availability (CIA) of
information.
Ask the class: “Have you ever lost data, had a phone hacked, or received a suspicious message asking for
money or passwords?” Use responses to connect the topic to everyday life — mobile money fraud, WhatsApp
scams, and social media account takeovers are common local examples.

2. The CIA Triad


The CIA Triad is the foundational model for thinking about security goals. Every security measure discussed
in this topic exists to protect one or more of these three properties.

Principle Meaning & Examples Importance

Confidentiality Ensures information is only Prevents unauthorized people from


accessible to authorized individuals. viewing private information; protects
E.g. using passwords to protect personal and business secrets.
accounts, encrypting sensitive files,
restricting access to confidential
documents.

Integrity Ensures data remains accurate, Ensures information can be trusted;


complete, and unaltered except by prevents fraud and errors.
authorized users. E.g. preventing
unauthorized changes to student
results, protecting financial records,
using checksums and digital
signatures.

Availability Ensures systems and information are Minimizes downtime; ensures


accessible whenever authorized users continuous business operations.
need them. E.g. regular maintenance,
data backups, UPS, disaster recovery
plans.
Teaching Tip
Draw a triangle on the board with C, I, A at each corner. For every threat discussed later, ask students which
corner(s) of the triangle it attacks.
3. Importance of Computer Security
Computer security matters to both individuals and organizations, for reasons including:
1. Protects personal information — names, addresses, passwords, bank details, and medical records.
Example: a bank protects customers' account details from hackers.
2. Prevents financial loss — cybercriminals steal money through online fraud, identity theft, or
ransomware. Example: a company infected by ransomware may lose millions of shillings before
recovering its data.
3. Protects business information — customer records, employee information, and financial data. Example:
an online shop protects customer payment information.
4. Ensures privacy — prevents unauthorized individuals from accessing confidential information.
5. Prevents data loss — data can be lost through viruses, hardware failure, accidental deletion, or natural
disasters; regular backups help recover it.
6. Maintains business continuity — enables organizations to keep operating during cyberattacks or system
failures.
7. Protects intellectual property — software, research, inventions, and confidential documents.
8. Builds customer trust — customers prefer businesses that protect their information.

4. Types of Computer Security

4.1 Physical Security


Protects computer equipment from theft, damage, or unauthorized physical access.
• Security guards
• CCTV cameras
• Biometric systems
• Locked computer laboratories
• Access control cards
• Fire extinguishers and smoke detectors
• UPS and air conditioning
Example: A school computer laboratory remains locked after lessons.

4.2 Network Security


Protects computer networks from unauthorized access and attacks.
• Firewalls
• VPN (Virtual Private Network)
• Intrusion Detection Systems (IDS)
• Intrusion Prevention Systems (IPS)
• Secure Wi-Fi passwords
Example: A university uses a firewall to block malicious traffic.

4.3 Application Security


Protects software from vulnerabilities and cyberattacks.
• Secure programming
• User authentication
• Software updates
• Regular security testing
Example: A banking application requires login credentials and two-factor authentication.

4.4 Data Security


Protects stored and transmitted information.
• Encryption
• Password protection
• File permissions
• Regular backups
Example: A hospital encrypts patient records.

4.5 Internet Security


Protects users while browsing online.
• HTTPS websites (look for the padlock icon before entering sensitive information)
• Antivirus software
• Safe browsing habits — hover over links before clicking, avoid downloads from untrusted sources
• Spam filters
Example: Avoid entering passwords on unsecured (non-HTTPS) websites.
5. Common Computer Security Threats
Threats fall broadly into malicious software (malware), attacks on credentials, and social engineering
(manipulating people rather than technology).

5.1 Malware
Virus
A malicious program that attaches itself to files and spreads when infected files are opened.
• Effects: corrupts files, slows computers, deletes information.
• Prevention: install antivirus software, scan USB drives, avoid unknown downloads.

Worm
Spreads automatically through networks without user action.
• Effects: consumes bandwidth, slows network performance.
• Prevention: keep software updated, use firewalls.

Trojan Horse
Appears to be legitimate software but performs harmful actions after installation.
• Example: a fake game secretly steals passwords.

Ransomware
Encrypts a victim's files and demands payment to restore access.
• Example: a school cannot access student records until a ransom is paid.

Spyware
Secretly collects user information.
• Examples: password theft, monitoring browsing habits.

Adware
Floods the user with unwanted advertisements, often bundled with free downloads.

5.2 Credential & System Attacks


Hacking
Gaining unauthorized access to computer systems.
Password Attacks
Attackers try to guess or steal passwords.
• Brute-force attack — systematically trying every possible combination.
• Dictionary attack — trying common words and known passwords.

Man-in-the-Middle (MITM)
An attacker secretly intercepts communication between two parties, often over unsecured public Wi-Fi.
Denial-of-Service (DoS)
Overwhelming a system with traffic so legitimate users cannot access it.

5.3 Social Engineering


Social engineering attacks manipulate people rather than technology, and are the most common way real-
world accounts get compromised.
Phishing
Tricks users into revealing sensitive information via fraudulent emails or messages.
• Example: a fake bank email asks users to enter their passwords.
Smishing
Phishing carried out via SMS.
• Example: “You have won 2,000,000 UGX, send your mobile money PIN to claim.”

Vishing
Phishing carried out via phone calls, often impersonating a bank or mobile money agent.
Pretexting
The attacker invents a false scenario to extract information.
• Example: someone pretends to be an IT technician to obtain passwords.

Baiting
Luring a victim with something enticing, such as a USB drive labelled “Salary List” left in an office.

Local Example to Discuss


Mobile money fraud in Uganda often combines vishing and pretexting: a caller pretends to be a mobile money
agent and asks the victim to “confirm” a PIN or complete a fake reversal transaction. Ask students to identify
which technique(s) this uses.
6. Computer Security Measures
• Install antivirus software.
• Update operating systems regularly.
• Use strong passwords.
• Enable two-factor authentication (2FA).
• Install firewalls.
• Encrypt sensitive files.
• Back up important data regularly.
• Avoid suspicious emails and links.
• Download software only from trusted websites.
• Lock computers when unattended.
• Educate users about cyber threats.

Why 2FA Matters


Two-factor authentication combines something you know (a password) with something you have (a
phone/authenticator code) or something you are (a fingerprint). Even if a password is stolen, 2FA can stop an
attacker from accessing the account. Encourage students to enable it on email, banking, and social media
accounts.

7. Characteristics of a Strong Password


A strong password should:
• Be at least 12 characters long.
• Contain uppercase and lowercase letters.
• Include numbers and special symbols.
• Avoid personal information (names, birthdays, phone numbers).
• Be unique for each account.
Example: B!T2026@Secure

8. Benefits of Computer Security


• Protects confidential information.
• Prevents cyberattacks.
• Reduces financial losses.
• Improves productivity.
• Protects organizational reputation.
• Ensures business continuity.
• Increases customer confidence.
• Complies with legal and regulatory requirements.
9. Legal and Ethical Context (Uganda)
Security is not only technical — it has legal dimensions. Students should understand that unauthorized access,
data theft, and online fraud are criminal offences.
• The Computer Misuse Act, 2011 (Uganda) criminalizes unauthorized access to computer systems,
electronic fraud, and cyberstalking/cyberharassment.
• The Data Protection and Privacy Act, 2019 (Uganda) governs how organizations must collect, store, and
process personal data.
• Ethical computing means using technical skills responsibly — e.g. never accessing systems or accounts
without permission, even “just to test.”

10. Key Takeaways


9. Computer security protects the confidentiality, integrity, and availability of information (CIA triad).
10. There are five main types of computer security: physical, network, application, data, and internet
security.
11. Most real-world attacks exploit human behaviour (social engineering) as much as technical flaws.
12. Strong, unique passwords plus two-factor authentication are the single most effective personal
protections.
13. Regular backups protect against data loss and ransomware.
14. Security is also a legal and ethical responsibility, not just a technical one.

11. Discussion Questions & Class Activity


Discussion Questions
15. Describe a suspicious message you or someone you know has received. What made it suspicious?
16. Which part of the CIA triad does a ransomware attack primarily violate? Explain your reasoning.
17. Give one example each of physical, network, and data security measures used at Billbrain or in your
own life.
18. Why is two-factor authentication more effective than a password alone?

Class Activity: “Spot the Phish”


Show students 3–4 example messages (a mix of genuine and fake mobile money / email notifications). In
small groups, have them identify red flags (sender address, urgency, spelling errors, suspicious links) and
decide which are phishing attempts. Discuss as a class.

Facilitator Note
Keep examples realistic and locally relevant (mobile money, WhatsApp, campus email) so students
immediately connect the concepts to their own digital lives. Where possible, demonstrate a real (safe)
example, such as checking a URL or enabling 2FA on a test account.

You might also like