Sci 407 Issca Module Notes
Sci 407 Issca Module Notes
August 2020
1|Page
SCI 407 Information Systems Security and Audit
Course Purpose
The objectives of this course is to offer the students a holistic overview of Information Security issues
pertinent in an enterprise as well as the necessary Information Security Management systems,
aspects regarding IS Security Policy, Controls and Auditing of information security systems and
network infrastructure security.
Course Content
Information Audit Planning Processes; Effective information system audit; Production of audit
Programmes; Role of audit in systems development; Audit automation and system testing; Data
forensics; Evidence security and preservation; Information security in computer and
communication systems; Security risks and hazards; Security control levels; Identification,
Authentication and authorization; Computer cryptosystems; Message Digest; Applications to
information schemes and digital signatures; Key distribution; Key agreement; Authentication;
Secret sharing; Security policies; Risk management.
Course assessment:
Assignments 5%
Project 10%
Continuous Assessment Tests 15%
Total Continuous Assessment 30%
End of Semester Examination 70%
Total 100%
2|Page
SCI 407 Information Systems Security and Audit
The information and communication technologies (ICTs) advances made available enormous and
vast amounts of information. This availability generates also significant risks to computer
systems, information and to the critical operations and infrastructures they support. In spite
of significant advances in the information security area, many information systems are still
vulnerable to inside or outside attacks. The existence of an internal audit for information system
security increases the probability of adopting adequate security measures and preventing
these attacks or lowering the negative consequences.
NATURE OF SYSTEMS.
A System. Defn:
1. Is an assemblage of procedures, processes, methods, routines or techniques or components
united by some form of regulated interaction to form an organized whole.
2. Is a set of items, equipment, processes and/or people working jointly with an aim of achieving
a common goal(s).
3. Is a purposeful collection of interrelated components that work together to achieve some
objective.
- A system is established to achieve some specific objective(s) i.e. the system does some useful
job/task and should be active and efficient in its operations e.g. banking system
- The system has been identified by a person as being of special interest.
- The system breakdown whenever any of its components malfunctions or is removed.
- All systems have a boundary within which they operate. Outside this boundary is the
environment, from which (raw materials) inputs are communicated from and to which results
or outputs (end/finished products) are communicated to.
- Systems are made up of sub systems. The subsystems continually interact with each other.
Examples of systems
- Education system, Economic system, Political system, Transport system, Business system,
Heating system, Security system, Lighting system, Water system, Waste system, Drainage
system, Accounting system, Information system, all programs are systems, Library info
system, even human beings are systems.
3|Page
SCI 407 Information Systems Security and Audit
INPUT STORAGE
PROCESS OUTPUT
+ve or –ve
Feedback
CONTROL
1. Input
- The component that receives the raw materials from the environment and introduce them into
the system ready to be processed.
- The raw materials e.g. data to be processed into information must first be collected and
communicated from the external environment into the system (EDP) by the input function.
- In an Electronic Data Processing system data is collected and communicated from the external
environment and introduced into the system for processing into information. The input function
in an EDP system involves data collection, data capture and data entry.
- The nature of input is influenced by the nature of the system.
2. Process.
- The component of an open system which manipulates and transforms the raw materials (inputs)
into finished/end products or end results/outputs.
- In an EDP system input raw data is manipulated into information using the stored set of
instructions. The process may be manual, mechanical or electrical (automatic) to derive
information/end products.
3. Output
- Involves communication of the end products or outputs/results to the external environment to
the recipient/end users for consumption or to another data processing (information) system.
- In an EDP system information is produced in form of business report documents e.g.
statements, invoices, result slips, transcripts, bills (water, electricity) e.t.c.
4. Storage
- The component which stores inputs awaiting processing, intermediate results (semi processed
input) and finished products awaiting delivery to the consumers in the environment. In an EDP
system the storage media would be like tapes, compact disks, flash disks, cassette tapes etc
which are used to store master files, transaction files, sort files etc.
4|Page
SCI 407 Information Systems Security and Audit
- The nature of storage is determined by the nature of the system and the nature of what is to be
stored.
5. Control
- This component includes the feedback concept that furnishes descriptive information on the
input, storage and output functions or components of the system.
- Negative feedback, is when non standard or sub standard output is achieved, is meant to
regulate the system. Positive feedback encourages further output the way they are.
- The control system is usually stored within the system as programs, to relate and tie together
all the system components, if the system is computer based.
Classification of systems.
Systems can be classified according to their openness or closeness.
Open system
- Is a system which communicates (interacts) with its environment. E.g. Business System,
Economic System, Information System, Transport System, Social systems etc. Open systems
can get disorganized i.e. when the system can not reorganize itself according to its internal
subsystem forces, the system therefore should be regulated. The process whereby the system
is regulated is known as negative feedback.
- Organisations as open systems attempt to monitor and anticipate environmental disturbances.
Some disturbances are so great or unexpected that they threaten the existence of the
organisation. All business organizations are open systems, for them to exist they must have the
capability to adapt in the face of changing markets conditions; globalization, liberalisation,
competition, technology, the law, conflict, etc.
5|Page
SCI 407 Information Systems Security and Audit
8. Successful functioning of each system component depends on the functioning of some other
components.
9. Systems are hierarchical in that, they include other systems i.e. subsystems. Note: Sub-systems
can operate as independent systems in their own right.
Closed system
- This is a system that doesn’t interact with the environment at all, which means the system
doesn’t communicate from (no inputs) or to (no outputs) its environment. Whatever happens
in the system doesn’t affect the environment and vice versa. It corrects and controls itself. Is
isolated from its environment. Are self-contained, environmental factors does not influence
their behaviour.
- They are more relevant to scientific, mechanical and physical systems else all social and
economic systems have some interaction with their environment.
Open-Loop System
Is a system which does not act in controlled manner, i.e. there is no feedback loop and so no
measure of performance against standards. Control is external to the system, is not automatic and
can be made without monitoring the output of the system. It relies on externally imposed control.
E.g. A department without a budget system will have to be controlled from outside the department
– perhaps by cash limit, an immersion heater without an automatic thermostat. Control is therefore
not an integral part of the system and the heater must be externally controlled by switching it on
and off at appropriate times.
Closed-Loop System
Is a system that functions in a controlled manner, such a system accepts inputs, works upon them
according to some pre-defined processing rules, and produces outputs, so that a system can
function in a controlled manner, their must be feedback. A system which have control as integral
or part of the system & feedback based on output measurement so that necessary corrections are
made to the input. E.g. Mechanical systems like speed governors on engines, thermostats in heating
systems are totally closed loop systems, stock control system etc.
6|Page
SCI 407 Information Systems Security and Audit
3. Cybernetic systems
- Also described as adaptive, self-regulating or self-organizing systems.
- Are systems that have to adapt to the environment for their survival. They adapt and react to
inputs or stimuli. The method of adaptation is uncertain and the same inputs do not always
produce the same responses. E.g. Social groups like human beings, plants and organisations
which have to react to their environment.
2. Artificial/Physical/Concrete systems
- Those created by human being. They are made/created by man rather than occur by nature.
- Physical systems consists of elements which are co-ordinated and operate as a whole entity to
achieve a certain objective(s) e.g. Transport system which consists of persons, vehicles, and
the organisation that transport goods and/or passengers, Computer system, Banking system,
cooling system, drainage system, heating, pumping system etc.
3. Abstract systems.
- An abstract system is an orderly arrangement of conceptual items or components.
- They can further be classified as
a) Procedural system – Refers to an orderly arrangement of procedures e.g. laws enforced.
b) Conceptual system – Refers to a symbolic system e.g. Einstein’s theory of the universe.
It is based on the principles that measures of motion, space and time are relative.
4. Human-machine systems
These are systems that are designed to help in accomplishing certain set goals e.g. help in decision
making. The machine elements e.g. hardware and software are relatively closed and deterministic
whereas the human elements of the system are open and probabilistic. These then implies that
these systems can be controlled e.g. the computer can be emphasised and the human person only
7|Page
SCI 407 Information Systems Security and Audit
monitors the machine operation. A good example is where the machine is used for regular
“programmed” decisions and it alerts the person to exceptions for processing as “unprogrammed
decisions”.
1. Soft systems
Human activity systems are said to be soft systems. They are described as soft because of three
main reasons:
(a) Their boundaries may be fluid or keep on changing.
(b) Their goals and objectives usually conflict and may not be captured clearly at any one time
because they are based on human factors like attitudes and preferences.
(c) It is difficult to precisely define exact measures of performance for them.
Example 1. A Political system. It is very difficult to model a system that will predict the political
mood in a country over a period of time.
Example 2. A sales tracking and prediction system in an organization. Sales in an organization
depend on human factors like attitude in the market place.
2. Hard systems
- Are systems whose goals and objectives are clearly defined and the outcomes from the systems
processes are predictable and can be modelled accurately. Such systems are based on proven
scientific laws like mathematical formulas or engineering solutions.
Example. A stock management system in a supermarket. It is possible to know exactly the
stock levels, cost and sale price and to predict accurately the profit if all the stock is sold.
NB: A good system incorporates both hard and soft aspects of a system. For example, a stock
management system should be able to show when the demand for a certain item rises so that a
decision can be made to stock more. New demand is driven by soft aspects in people’s lives like
attitude and seasons.
Hard properties are those that can be defined, measured or assessed in an objective way whereas
Soft properties are more imprecise and are matters of individual values and tastes. E.g. If an
organisation re-locate from Nairobi city centre to Machakos town. This has hard (i.e. measurable)
effects e.g. saving in office rent and also soft effects e.g. impact on morale and family life caused
by the disruption.
8|Page
SCI 407 Information Systems Security and Audit
1. Information System
Defn: Is a set of persons, procedures, technological and other resources that collects, transforms
and disseminates information in an organization. Computer Based Information System/EDP uses
hardware, software & live ware to provide information.
MIS Definition.
1. Is an assemblage of facilities and personnel for collecting, processing, storing, retrieving and
transmitting information that is required by one or more managers in performance of their
functions.
2. An integrated man-machine(s) system for providing information to support the planning,
controlling, organizing, managing operations and decision-making functions in an
organization.
3. Any telecommunications and/or computer related equipment or interconnected system or sub-
systems of equipment that is used in acquisition, storage, manipulation, management,
movement, control, display, switching, interchange, transmission or reception of voice and/or
data and includes, hardware, software and live ware.
4. It is a system using formalised procedures to provide management at all levels in all functions
with appropriate information, based on data from both internal and external sources, to enable
them to make timely and effective decisions for planning, directing and controlling the
activities for which they are responsible.
Management.
Is a process, in the sense of a sequence of operations or functions necessary to achieve certain end
results. Management is a human and social process, it’s a continuous process to the extent that the
cycle of stages or steps is never ending and it’s repeated over and over again.
Functions of management
1. Planning – management’s responsibility that requires the manager to formulate goals &
objectives & develop short-term and long-term plans to achieve these goals. Planning is
the managerial process of deciding in advance what is to be done, how it is to be done,
when to do it and by who(m) to do it. It is done on both a formal and informal basis and
the planning process uses info from internal and external sources. The process gathers,
9|Page
SCI 407 Information Systems Security and Audit
translates, understands and communicates info that will help to improve the quality of
current decisions which are based on future expectations.
2. Organizing and Coordinating – involves the development of an organizational structure &
a framework of standards, procedures & policies designed to carry out ongoing business
activities to achieve the required objectives.
Levels of management
1. Strategic management, e.g. CEO, board of directors, board of trustee, board of governors
10 | P a g e
SCI 407 Information Systems Security and Audit
3. Operational management, e.g. foremen, supervisor, chief clerk, data entry clerk, data
preparation clerk, computer operator, media librarian,
Note: Some organisation structures are tall and others flat e.g. Ford Company has 13 distinct levels
of management and Toyota has 6 levels.
Data are the facts, events, transactions and figures which have been recorded. Data represent
unstructured facts about events, objects, or people. They are the input raw materials from which
information is produced.
Information
Definition. Data that has been processed into a form that is meaningful to the recipient and is of
real or perceived value in current or prospective decisions. Information refers to data which is
organized and meaningful to the person who receives it. Information comes from selecting data,
summarising it, and presenting it in such a way that it is useful to the recipient.
11 | P a g e
SCI 407 Information Systems Security and Audit
(be timely), Concise (include only relevant data), Clear (be understandable), Cost effective (be
efficiently obtained) and Time sensitive (be based on historical, current, and/or future information
and needs as required).Effective information is that from a source the user has confidence,
communicated to the right person, communicated in time for its purpose, that which contains the
right level of detail, communicated by an appropriate channel of communication and that which is
understandable by the user.
System
The word system connotes plan, method, order, and arrangement. A system is a regularly
interacting or inter-dependent group of items forming a united whole. A system is thus a set of
interacting elements with each other to achieve a predetermined objective or goal. Each system is
composed of sub-systems. Thus every system is part of a larger system. E.g. an A/c or finance dept
is a subsystem of an organisation. The organisation contains other subsystems like Production,
Marketing, ICT, Research & Development, Public relations etc.
- The information in respect of any system helps the management to make some important
decisions. So the information systems are developed to help the managers in their decision
making process. The decision making process is based on the support of the information system
in the organisations. The managers must be aware of the problem before a decision is made. A
problem exists when real situation is different from the expected one. After the problem has
been identified, the causes of existence of the problem must be identified and then the solution
to the problem has to be found.
Objectives of M.I.S.
1. M.I.S is a systematic procedure to provide relevant information in right time, in right format, to
all levels in the organization, for providing support to the decision making activities in the
organization.
12 | P a g e
SCI 407 Information Systems Security and Audit
2. Provide each manager at each level, the planning and control tools and help in highlighting the
critical factors to be closely monitored for successful operation of the organization.
3. Help the management in getting the required information for controlling the activities of the
organization.
4. Create a process of communication with information wherein information is recorded, stored
and retrieved for decision making, planning, operation and control within an organization.
5. Evaluate an approach to information system design that conceives the business enterprise an
entity composed of interdependent sub-systems, which will permit optimum management
decision making.
6. Provide a system of people, equipment, procedures, documents and communications that
collects, validates, operates on, transforms, stores, retrieves and presents data/information for
use in planning, budgeting, accounting, controlling and other management processes.
13 | P a g e
SCI 407 Information Systems Security and Audit
Objectives of a D.S.S.
1) Analyze unexpected problems.
2) Interprete information flow and decision making activities.
3) Support all management levels
4) Be easy to use yet powerful and flexible.
M.I.S. D.S.S.
1. Supports decisions by management 1. Provides technical decisions.
2. Assist in making structured decisions for 2. Assist in semi-structured and unstructured
operational & tactical planning control decision usually at top level (strategic level)
14 | P a g e
SCI 407 Information Systems Security and Audit
3. Indirect support design for managers 3. Direct support tailored for decision making
by style
4. Periodic exception and on demand 4. Interactive inquires and responses
structured reports
5. Format is pre-specified i.e. fixed 5. Format is flexible and adaptable
6. Information is produced by mathematical & 6. Information is produced by analytical
statistical analysis of data modelling
7. Uses hardware/software and databases 7. Uses hardware & model bases
8. Controlled by information systems 8. Controlled by end users
specialists
Components/elements of D.S.S
1. Data. The data input is obtained from Transaction Processing System i.e. source documents
2. Model - The system uses models e.g. linear programming to allow evaluation and analysis of
different alternatives under similar constraints.
3. User Interface – The use of G.U.I. (Graphic User Interface) which allows the manager enter
commands and seek answers during interrogations.
4. Decision Maker - The system requires a manager with vast training, experience and
management acumen.
5. Hardware
6. Software. Types of software necessary.
a) DBMS for managing a large database is needed.
b) Simulation and application languages to be used in model building.
c) A DSS query language as communication link.
d) DSS executive software for handling the operational duties of DSS.
Types of D.S.S.
1. Ad hoc. Are general DSS designed to handle a wide variety of management decision problems
and are especially suited to unexpected, non-recurring management problems.
2. Institutional. Are special and use terminology and analysis procedures established within
certain areas like medicine, engineering etc.
15 | P a g e
SCI 407 Information Systems Security and Audit
Is a special easy-to-use MIS designed for top magmt people who are not familiar with computer
systems. They use graphics and touch screens to aid senior executives in collecting & obtaining
the info they want. Is a software application that seeks to capture expertise in limited domains of
knowledge and experience and apply this expertise in order to solve some problems. ESS provides
managers with a flexible means of accessing information of tactical and strategic levels. ESS helps
the managers to drill into the data, present the information in appropriate formats and find the
information they need whenever they need it.
Characteristics of ESS
1. Convenience - The system must be easy to use, convenient and fast enough to reduce time
wastage. The use of touch screens, icons, mouse, menus i.e. WIMP-Windows, Icons, Menus,
and Pull-down menus is therefore important.
2. Easy access to data - There should be rapid access to data which permits both vertical and
horizontal drilling, evaluation and explorations.
3. Data analysis - ESS should provide facilities for projections and analysis. Thus ratio and
trends, calculations, business forecasts e.t.c are common. Provide tools for analysis and also
provides presentation aids.
4. Quality of presentation - ESS provide efficient and understandable formats using colours,
graphs, diagrams & tables.
5. Are ease to use.
Advantages/benefits of an ESS
1. It can be able to account how it has arrived at a given decision.
2. Can solve problems in a given domain well or better than human decision makers.
3. They are not emotional in their decision making. A human begin may at times be controlled
by emotions
4. Can apply human knowledge to a well understood problem.
5. One doesn’t need to be an expert because a clerk can be as good as a consultant if he is
supported by an ESS.
6. Avails information on demand.
7. Uses graphics which are easy to understand.
8. Provides opportunity to identify information useful to a system.
16 | P a g e
SCI 407 Information Systems Security and Audit
17 | P a g e
SCI 407 Information Systems Security and Audit
- Areas were AI is applied are; Machine learning (to create machines or computer systems that
are able to learn new concepts all by themselves); intelligent computer-aided learning systems;
intelligent robots; language understanding and communication; machine vision systems; and
expert systems (machines that mimic human expertise so that they can be used for day-to-day
problem-solving and decision-making in domains of expertise just like human experts, by the
experts themselves, or by those less-qualified).
Applications of ESs
- ES technology is in use in an ever widening number of commercial applications such as
education/training, engineering and manufacturing, computing, banking and finance, law,
marketing and advertising, insurance, medicine, agriculture, geology and chemistry/chemicals.
- Used in surgery, security and helps users in making investment decision.
- Are also used in medical research, diagnosis, geological prospecting, predicting crop disease,
mass-spectrogram interpretation, accounting, personnel and management.
- Investment decisions e.g. mergers, acquisitions, raising capital etc
- Marketing policy, Taxation policy
- Most ESs can enhance the productivity and performance of inexperienced users but not
improve their knowledge ESs or Knowledge-Based Systems (KBSs) are computer programs
which mimic the performance of a human expert in limited areas of expertise.
- Are developed to assist human experts or to be used by the less experienced (or novices) in
areas (or domains) of knowledge.
- ESs makes use of a stored representation of the knowledge and experience of experts working
in well-defined areas of knowledge. They usually represent this knowledge in the form of rules
& sometimes as some sort of description of important characteristics relevant to the problem.
18 | P a g e
SCI 407 Information Systems Security and Audit
They can generate explanations for their ‘reasoning’, answer why and how they reached their
decision & in general present their information in a way that is easily understood.
- They capture not only factual but also judgmental knowledge. They are capable of qualitative
reasoning in fuzzy areas of problem-solving and decision-making, such as when the
information is incomplete or uncertain. ESs are mainly used to solve problems that are not
solvable with conventional algorithmic and diagnosis.
- Are designed with the help of human experts who solve a range of problems and describe their
thought processes as they proceed. The programmer (in this case a knowledge engineer)
attempts to transfer the knowledge & methods of reasoning of the expert into a computer
program that captures it. It is impossible to complete the building of an ES in a single devpt
phase to incorporate all the expertise it requires.
- It is normal to progress through a series of prototypes, each one becoming more comprehensive
and sophisticated.
- The initial & in many cases most time-consuming task is concerned with the structuring of the
knowledge and rules that cover routine basic activities often considered as trivial by the human
expert. Thereafter, the system is made to incorporate the more expert tasks by being continually
updated to reflect new knowledge and information. The knowledge is codified in high level
computer languages such as LISP, FRANZ LISP & PROLOG.
- Knowledge is also codified in existing expert systems shells such as Emycin, Expert, AL/X,
Loops, Nexpert objects, Flex e.t.c.
- The systems contain an inference engine without a domain knowledge base – to be included
later.
19 | P a g e
SCI 407 Information Systems Security and Audit
Knowledge Base/Database
- Contains data conditions etc about the problem under interrogation. It stores knowledge of
human expert in the form of rules.
- Is where all the knowledge of the field is stored. It consists of rules (or other knowledge
representation formalisms - objects, frames or sematic networks). Rules permit deductions to
be made from the given facts, so as to add new facts to the knowledge base.
Inference
Engine
Inference Engine
- A computer program which formulates questions and draw conclusions. It acts a rule
interpreter.
- Is a general purpose problem-solving module of the ES that acts as the control scheme which
directs the firing of rules of the Es.
- It uses the knowledge base to reason about the problem, given the contents of the facts base. It
is made up of a patterned matching algorithm or fitter that examines the conditions of a rule to
find whether or not it holds, according to the contents of the facts base.
Explanation software
- It interprets and analyses the results from inference engine.
User Interface
- Enables the user to interact with the Expert system.
- Due to the ability of ESs to tackle problems within areas that require knowledge and experience
(abilities which conventional computer programs do not have), they can assist many categories
of workers in different areas of work.
- ESs can be used to do the following types of problem-solving: Interpretation, planning,
monitoring, diagnosis, assistance in design/development, control/optimization,
education/training and design evaluation.
20 | P a g e
SCI 407 Information Systems Security and Audit
3. The components of the knowledge bank could be in the form of strategic planning/decision-
making knowledge, rare skills/expertise archiving, knowledge gained from in-house experts or
knowledge gained from exit interviews of experts who were leaving the organization.
4. ESs can be used to handle, interpret and analyze large amounts of data for national planning.
ESs can be used in rural areas where highly experienced managers, doctors, accountants or
lawyers might not want to work. They can be used by less experienced people to reach the
same level of decision-making in the domain as the experts.
21 | P a g e
SCI 407 Information Systems Security and Audit
services for such events like sales meetings, new product announcements & employee
education & training.
5. Office Management Systems (OMS) – Is an office automation category that integrates
electronic calendars, tickler files, electronic mail directories, schedulers and task management
systems. Provides computer-based support services to managers & other office professional to
help them organise their work activities. Office management s/ware computerizes manual
methods of planning e.g. paper calendars, appointment books, directories, file folders, memos
and notes. OMS can help end users & work groups organize routine office tasks e.g. you could
enter the date & time of a meeting into an electronic calendar. Tickler file will automatically
remind you of important events. Electronic scheduler use the electronic calendar of several
people to help you schedule meetings & other activities.
6. Telecommuting (Teleworking) – Is the use of telecommunication links by workers to replace
commuting to work from their homes or to carry out work activities from temporary locations
other than offices & homes. Telecommuter can access their organisation’s’ network and
databases. Telecommuting workers & their colleagues also use e-mail or voice mail to
communicate with each other about job assignments. Telecommuting is being tried by major
corporations and independent professionals. It’s most popular with people whose jobs involve
a lot of individual work e.g. programmers. It is especially useful for the handicapped persons
and working parents of young children.
7. [Document] Image processing – It allows users to electronically capture, store, process &
retrieve images of documents that may include numeric data text, h/writing, graphics &
photographs. Electronic Document Management (EDM) is based on image processing
technology. EDM may interface with other systems e.g. w/processing, DTP, e-mail and voice
mail. Image processing has improved productivity and has resulted to significant cost savings.
8. Videotext – Refers to sending & receiving information & displaying it on screen using either
broadcasting (Teletex) or telephone lines (view data)
9. Computer output on microfilm (COM)
10. Graphic user interface (GUI)
22 | P a g e
SCI 407 Information Systems Security and Audit
by BBC and ITV for newsflashes, and subtitles etc. To receive these info customers can rent
or buy special Teletext receivers or adapters for existing 625-line television sets.
16. Multi-media conferencing,
17. Use of cell phones to conduct office operations/activities.
18. Use of electronic spreadsheets, Databases, Graphics application packages in modern offices.
19. E-marketing; B2C, B2B, C2B i.e. Business to Customer, Business to Business, Customer to
Business etc
23 | P a g e
SCI 407 Information Systems Security and Audit
Definition: Information systems security is the policies, procedures and technical measures used
to prevent unauthorised access, alteration, theft or physical damage to information systems. It
involves the safeguards required to protect info systems against threats/hazards which might cause
unauthorized modification, disclosure, destruction of data/information or software. Security
controls should be put in place to protect computer based-information systems (hardware,
software, live ware and database) against the hazards to which computerized information systems
are exposed. Security controls help assure high systems standards and performance by protecting
the system against hardware, software, and live ware failure.
24 | P a g e
SCI 407 Information Systems Security and Audit
4. Excessive heat or temperature. Excessive heat or temperature form the computer itself or
outside the environment can destroy computer storage media or devices. Security measures:-
a. Efficient ventilation system.
b. Installing cooling systems in the computer rooms e.g. use of fans and air conditioners.
5. Civil strife and Terrorism. Terrorist attack includes activities like political terrorists e.g.
bombs, criminal types of activities, hooliganism, individuals with grudges and people
intending to cause general disruption. Security measure includes:-
a. Control physical access to the premises housing the info system i.e. comp labs, comp
rooms, computer resource centre, IT centre, the name various from one organisation to
another.
b. Avoided terrorism and hooliganism triggering activities e.g. exploitation of workers.
c. Consult with police and fire authorities/brigade about potential risks and co-operate
with them conscientiously.
6. Sabotage. It is one of the greatest physical risks to computer installations. Saboteurs can do
enormous damage to computerized info systems with little risk of apprehension e.g. bomb can
be planted, a communication line can be cut or disconnected, deadly computer virus can be
deliberately introduced etc. Providing adequate security against such acts of sabotage is
extremely difficult and expensive.
7. People threats. These include carelessness, clumsiness and accidental destruction/erasure of
data, info or programs as well as theft and piracy of data & software. Security measures:-
a. Have a good office layout e.g. such that the supervisor can see what the people under
him are doing.
b. Limit access to sensitive organisation information.
c. Have lockable and disk locks.
d. Terminate/dismiss employee with a penchant of misusing the computer resources or
re-locate them to another department.
e. Careful recruitment of staff.
8. Environmental problems/conditions. More often that not computers are housed in premises
that were not originally meant to contain them. This can bring about environmental problems
e.g. water and steam pipes may run near or thro’ a computer lab, where bursting pipes could
cause extensive/considerable damage to the info system. Database on storage media can be
destroyed by magnetic fields emanating from electric motors in the vicinity. External radiation,
smoke and dust from the surroundings are also hazardous to comp info systems especially
storage media. Environmental problems include brownouts (temporary power surges (drops)),
power spikes, power failures, Measures to counteract these:-
25 | P a g e
SCI 407 Information Systems Security and Audit
f. Use UPS, power stabilizers, surge protectors, voltage regulators etc to protect the
h/ware from power fluctuations.
a. Install anti-virus software in the info system and scan storage media regularly.
Examples of anti-virus MacAfee, Kaspersky, Dr Solomon’s anti-virus toolkit, Norton
anti-virus,
b. Avoid freeware and shareware which have been prime entry point for viruses.
c. Storage media for the organisation should not be used elsewhere and private media
should not be used in the organisations computer systems, unless under special
circumstances and express authority is granted by the ICT depart top management.
d. Make backup copies as soon as you open new software package and store the copies
off-site.
e. Quarantine each new piece of software on an isolated computer and review it carefully
before installing it on a network.
f. Restrict access to info system resources to only the authorised personnel.
g. Check all programs regularly for change of size, which could be a sign of tampering or
virus infiltration.
h. Institute a plan for immediate removal of all copies of suspicious programs and back
up of related data.
i. Make sure all purchased software is in its original wrapping or sealed-disk container.
j. Install firewall. Firewall is a device that stands in btw the organisations network and
the internet checking any type of incoming and outgoing traffic that could potentially
damage the network & the organisation’s information system. It stops the viruses in the
internet finding way into the organisation’s computer information system.
10. Cyber crime. Computer criminality is another threat to computer info system security
especially software. Computer crime takes different forms. This includes outright theft of
cables, h/ware, storage media etc., software piracy, theft of computer time, financial fraud,
funds embezzlement, unauthorized alteration of programs and data, theft of computer time,
data/info theft (commercial espionage), and malicious destruction of database/hardware or
software, unauthorised access (hacking and cracking).
26 | P a g e
SCI 407 Information Systems Security and Audit
Note: Hackers gain unauthorised access to computer systems mainly for the fun and thrill of it
whist Crackers gain unauthorised access to computer systems in order to perpetrate theft for
profit, for criminal mischief or for destruction.
Physical security:
This includes:-
1. Hiring of security guards to control access to the building housing the info system.
2. Using keyboard locks on terminals used by authorised users.
3. Use of disk locks and disk banks.
4. Strengthening computer labs by putting strong window grills and metallic doors.
5. Installation of electronic surveillance system. This is used by the supervisors of the computer
and other electronic equipment to monitor worker’s performance often without their
knowledge.
6. Data encryption. Data is often sent in coded or encrypted, form over communications lines to
keep it secure from unauthorised eyes. Encryption is the encoding of data by converting the
standard computer code into a secret code for transmission. After delivery to the destination
the data is converted back (decrypted) into standard computer code.
7. Use of passwords – a password is a secret code (word, numbers, symbols or a combination)
that must be typed in to gain access to a computer system, a program or a database/file. An
effective well-designed password is that which can not easily be guessed by hackers or crackers
trying to break into a computerized information system.
8. Biometrics – Is the use of individual body characteristics instead of passwords to gain entry
into the computer system e.g. finger print, kiss on screen, lip prints signature, photograph etc.
9. Set up a clear and firm management system security policy on crimes and frauds.
10. Monitor and investigate error logs and reports on regular basis.
11. Carry out risk analysis to examine the organisation’s exposure to possible fraud.
12. If possible let there be only one entrance and one exit for ICT centre with trained security
guard(s) stationed there.
13. Establish effective security procedures e.g. for regular back up software and database.
14. Paper shredders. Sensitive reports should never be disposed off by simply being thrown in
waste containers.
15. Obfuscation – means to isolate by confusing, bewildering, obscuring or hiding something from
a potential penetrate.
27 | P a g e
SCI 407 Information Systems Security and Audit
Any information system or data processing system, whether computerized or not, must incorporate
controls to ensure that it works efficiently, i.e. it must:
In a computer environment four elements must be controlled i.e. Source document, Input,
Processing and Output.
1. Administrative controls.
2. System development controls.
3. Procedural and processing controls.
1. Administrative Controls.
Administrative controls are the responsibility of the management whereas procedural controls are
the concern of the system analyst, and system development controls should be decided jointly btw
system analyst and the management.
These controls ensure that proper procedures are followed to maintain discipline and efficiency
over the day-to-day running of the computer department.
28 | P a g e
SCI 407 Information Systems Security and Audit
1) Access to source documents should be restricted to data preparation and control staff.
2) Access to the computer should be restricted to operation staff.
3) Computer operators and programmers must not originate live entries.
4) Control staff should not have other EDP duties.
In order to make the controls more effective, the functions of data processing staff, operators,
control clerks and librarians must be properly specified and documented.
The proper development and maintenance of operations control will help to: -
(i) Prevent or detect accidental errors which may occur during processing.
(ii) Prevent or detect fraudulent manipulation of data during processing.
(iii) Prevent access to and misuse of personal or otherwise classified information.
(iv) Prevent the destruction of records.
A computer control department/section must be established. This department must be
independent of other operating functions. The main function of this department is to ensure
that data is processed accurately and completely.
It is important to lay down high standards of control. This is because of the time spent on systems
development, the cost involved, and the probable complexity and volume of detail involved.
These controls cover such areas as the development, implementation and maintenance of all
System and Application software.
29 | P a g e
SCI 407 Information Systems Security and Audit
Procedural controls are all those controls exercised over a particular application:
Sometimes, the term “Processing controls” is used to describe all the controls applied in the Data
processing cycle.
Note that, some controls will be performed clerically, while others are performed by the computer
itself, and are known as Program or Software controls.
(i) Ensure that the data processing is complete, e.g. by the setting up of batch controls and
subsequent reconciliations by the computer and manually.
(ii) Ensure the accuracy of data processing, e.g., by proper setting up of well-designed source
documents, verification, program validation, etc.
(iii) Ensure that only authorized data is processed, e.g., by manually authorizing input, restricted
access to computer files.
(iv) Ensure that proper management and audit trails are laid down.
The system should have maximum safeguards against error and fraud in order to prevent:
30 | P a g e
SCI 407 Information Systems Security and Audit
(i) All source documents are correctly completed and are transmitted to the computer
department.
(ii) All source documents are received by the computer department and are correctly converted
into the computer input media (e.g. Magnetic tape, floppy disc, etc).
(iii) All the data on the input medium is transmitted accurately to the computer centre and
accepted by the computer.
Magnetic tape and disc systems require fairly rigid temperature, humidity and power
specifications, and therefore control devices should be used to detect variations from the norm.
The equipment itself should have proper hardware controls, which may include:
4. File Controls
To ensure that only the right files are used in processing,
(i) Proper file conversion controls must be exercised during Systems implementation.
(ii) All staff should be properly trained and provided with operation manuals.
(iii) Computer files should be controlled by a Librarian.
(iv) Computer files should have external file labels.
(v) Computer files should have internal file labels.
Note. The Input file labels can be checked by the computer operating systems. They comprise of:
(1). Header records, which contain;
31 | P a g e
SCI 407 Information Systems Security and Audit
The Data vet program may be applied to batches of data or to individual transactions (in an Online
or Real-time system), and any erroneous records rejected and reported (on a VDU in online input).
Software control procedures should detect some errors immediately after they occur.
32 | P a g e
SCI 407 Information Systems Security and Audit
The degree of control required for standing data is more than that for transaction data.
Once standing data is entered into master files, it is important that there are adequate controls to
ensure that the data remain unaltered until an authorized change is made. This can be achieved
by;
Periodically printing out of standing data so as to check with clerically held information.
Establishing independent control totals for periodic verification with equivalent totals
accumulated in the files.
Using the computer programs to establish and verify the control totals.
The degree of control required to maintain transaction data on master files varies according to the
contents of the file.
5. Library Controls
In order to adequately operate a tape library, procedures and controls must be established and
maintained if maximum and efficient usage is to be realized from Magnetic tapes.
A quick means for physically locating any reel of tape in the library.
Since the tape file may have more than one reel, each reel should be identified with the file
number and reel number.
If a file or reel is missing from the library, the name of the person to whom it was issued should
be recorded.
Identify the expiry of the scratch date so that tape reels may be released for reuse. A Scratch
date is the date that the data recorded on a particular tape is no longer required.
Maintenance of records should be written in short, easily understood terms, and requires a
minimum number of entries.
Note: Library controls for Magnetic tapes may be setup in various ways as long as they provide
the proper control of all tape reels in the computer center. However, each time the tape status
changes, all records belonging to that tape must be changed accordingly.
33 | P a g e
SCI 407 Information Systems Security and Audit
4. Sociological controls
5. Technological controls
6. Environmental controls
34 | P a g e
SCI 407 Information Systems Security and Audit
Auditing: Defn: - Involves having an expert who is not involved in setting up or using a system,
examine information in order to ascertain its reliability. Auditing is also a security measure.
2 types of Audit/Auditors
1. Internal Audits
Aim to prevent fraud by evaluating internal (financial) control systems, and are a useful resource
to help in the development of control procedures for information systems.
- Done by internal Auditors, who are employees of the organization that owns the I.S.
- Internal auditors study the controls used in the information system to make sure that they are
adequate & that they are doing what they are purported to be doing/supposed to do.
- Internal auditors also test the adequacy of security controls.
- Though they work for the same organization, internal auditors do not report to the people
responsible for the system they are auditing.
- Their work is often more in-depth than that of external auditors.
2. External Audit
- Gives an independent, reliable and expert opinion about financial statements: Do the financial
statements, give a true and fair view/reflection of the state of the business/organization?
- Done by external auditors, who audit the system to ensure the fairness of the financial
statements being produces.
- They may also be brought in if there is something out of the ordinary accruing that involves
organization employees, e.g. suspected computer fraud or funds embezzlement.
35 | P a g e
SCI 407 Information Systems Security and Audit
- Auditors may require that certain self-checking mechanisms and authorization procedures be
incorporated in organization/systems, especially those supporting pension funds, or financial
institutions e.g. banks are obvious examples.
NB: It is very much better & easier, if these audit requirements can be taken into account at the
specification & design stage, rather than after the system is complete, so the analyst must talk to
all the relevant authorities & find out their requirements alongside those of the more obvious users
of the system.
- Began in early days when the auditor was unfamiliar with the comp terminologies,
programming & the controls used in a computer system. In this method the comp is viewed as
a ‘black’ box & the auditor do not review/examine the comp system & programs but
review/examine the input and output documents only.
- The controls & procedures are considered unimportant as long as the output generated could
be traced back to the input and the input was deemed valid.
- The auditors select input & test them against the appropriate output and vice versa. If they
match and proved to be accurate it is assumed that the system of controls is operational and
that it is working properly.
Disadvantages
1. Many computerised systems are voluminous for proper manual testing.
2. No means are provided by which the auditors get involved and gain firm understanding of the
computer system.
36 | P a g e
SCI 407 Information Systems Security and Audit
3. It ignores the system of controls & thereby fails to recognize potential errors or weaknesses
within the system.
4. It represents after the fact rather than preventive auditing.
5. It makes no use of the most powerful and valuable audit tool, the computer.
6. To all intents and purposes it does not achieve the auditor’s goals [adequately].
This technique places a greater emphasis on testing the comp system that produces the output
rather than testing the output itself.
37 | P a g e
SCI 407 Information Systems Security and Audit
Auditors can use the computer to assist them in various auditing tasks. Where an accounting
information system has been computerized, infact, auditing with the computer is virtually
mandatory because the accounting data are stored on the computer storage media and manual
access is impossible.
There are audit packages which are used to do this type of auditing or an in-house program can be
developed for the purpose.
Disadvantages
1. Demands technical knowledge of computers
2. Requires computer time.
2 Main/Principal CAATs
1. Use of ‘test data’ to test the operation of the client’s programs.
2. Use of audit s/ware - comp programs developed for audit purposes to examine the contents &
do work on the contents of the client’s computer files.
38 | P a g e
SCI 407 Information Systems Security and Audit
9. An Auditor can fully understand a manual system in a matter of hours at most. A computerized
system cannot usually be fully comprehended without expert knowledge & a great deal of time.
(Lack of computer literacy on part of Auditors).
10. If storage of comp. files holding customer’s statements of accounts is not maintained properly,
it may be difficult & time consuming for the Auditor to access them.
11. Lack of knowledge of computer terms and concepts.
12. I.T. personnel responsible for developing the info systems may have little or no knowledge
about accountancy, auditing or the legal framework within which their systems are to operate;
this may lead to problems.
13. It is difficult to follow an audit trail in computerized info systems becoz the data within a
computer system is ‘invisible’ to the human being as it is kept in machine-sensible form.
39 | P a g e
SCI 407 Information Systems Security and Audit
a) Is the information system meeting all its original intended design objectives?
b) Have all the security measures been put in place to reduce the risk of computer crimes?
c) Are the computers secured in physically restricted areas?
d) Is there backup for data and information of the system that can ensure continuity of services
even when something serious happens to the current system?
e) What real risks face the system at present or in future?
Audit trail consist of such things as reference numbers, dates and names which are recorded in
files, ledgers and journals to facilitate the tracking of these records to source documents or to
record in other files.
Audit trails are tools designed to help the management in four ways
40 | P a g e
SCI 407 Information Systems Security and Audit
d) Clerical re-creation
e) Total testing & comparison with other data, budgets, previous periods.
f) Alternative tests e.g. physical stock counts.
g) The use of test packs to verify program performance.
- These programs are sometimes known as enquiry or interrogation programs. Are usually coded
in HLLs e.g. COBOL, PASCAL. Are coded by or for an audit firm but client’s own
interrogation programs can be used; such programs are available from s/ware houses.
- Staff unskilled in programming can be easily taught to put their search or operating
requirements into a simple form which the comp audit program can interpret & apply to the
files selected.
41 | P a g e
SCI 407 Information Systems Security and Audit
5. Stratification of data e.g. stock lines or debtors, with a view to examination only to material
items.
6. Carrying out detail tests and calculations
7. Verifying data such as stock or fixed assets at the interim stage & then comparing the examined
file with the year end file so that only changed items need be examined at the final audit.
8. Comparison of files at succeeding year ends e.g. to identify changes in the composition of
stock.
Disadvantages
1. Can be expensive to setup or acquire
2. Some technical knowledge is required
3. Standard comp audit programs may be compatible with the variety of programming languages
used in business information systems.
4. Detailed knowledge of system & programs is required. Some auditors would dispute the need
for this detailed knowledge to be gained.
5. Difficult in obtaining computer time especially for testing.
- Use of audit s/ware raises the visibility of the auditor in the eyes of the company/organization.
It makes the audit more credible.
42 | P a g e
SCI 407 Information Systems Security and Audit
Cyberspace can be defined as an intricate environment that involves interactions between people,
software, and services. It is maintained by the worldwide distribution of information and
communication technology devices and networks.
With the benefits carried by the technological advancements, the cyberspace today has become a
common pool used by citizens, businesses, critical information infrastructure, military and
governments in a fashion that makes it hard to induce clear boundaries among these different
groups. The cyberspace is anticipated to become even more complex in the upcoming years, with
the increase in networks and devices connected to it.
Cyber security
ISO 27001 (ISO27001) is the international Cybersecurity Standard that delivers a model for
creating, applying, functioning, monitoring, reviewing, preserving, and improving an Information
Security Management System.
The Ministry of Communication and Information Technology under the government of India
provides a strategy outline called the National Cybersecurity Policy. The purpose of this
government body is to protect the public and private infrastructure from cyber-attacks.
Cybersecurity Policy
The cybersecurity policy is a developing mission that caters to the entire field of Information and
Communication Technology (ICT) users and providers. It includes −
Home users
Small, medium, and large Enterprises
Government and non-government entities
It serves as an authority framework that defines and guides the activities associated with the
security of cyberspace. It allows all sectors and organizations in designing suitable cybersecurity
policies to meet their requirements. The policy provides an outline to effectively protect
information, information systems and networks.
It gives an understanding into the Government’s approach and strategy for security of cyber space
in the country. It also sketches some pointers to allow collaborative working across the public and
private sectors to safeguard information and information systems. Therefore, the aim of this policy
43 | P a g e
SCI 407 Information Systems Security and Audit
is to create a cybersecurity framework, which leads to detailed actions and programs to increase
the security carriage of cyberspace.
Cyber Crime
The Information Technology Act 2000 or any legislation in the Country does not describe or
mention the term Cyber Crime. It can be globally considered as the gloomier face of technology.
The only difference between a traditional crime and a cyber-crime is that the cyber-crime involves
in a crime related to computers. Let us see the following example to understand it better −
Traditional Theft − A thief breaks into Ram’s house and steals an object kept in the house.
Hacking − A Cyber Criminal/Hacker sitting in his own house, through his computer, hacks the
computer of Ram and steals the data saved in Ram’s computer without physically touching the
computer or entering in Ram’s house.
To understand the concept of Cyber Crime, you should know these laws. The object of offence or
target in a cyber-crime are either the computer or the data stored in the computer.
Nature of Threat
Among the most serious challenges of the 21st century are the prevailing and possible threats in
the sphere of cybersecurity. Threats originate from all kinds of sources, and mark themselves in
disruptive activities that target individuals, businesses, national infrastructures, and governments
alike. The effects of these threats transmit significant risk for the following −
public safety
security of nations
stability of the globally linked international community
Malicious use of information technology can easily be concealed. It is difficult to determine the
origin or the identity of the criminal. Even the motivation for the disruption is not an easy task to
find out. Criminals of these activities can only be worked out from the target, the effect, or other
circumstantial evidence. Threat actors can operate with considerable freedom from virtually
anywhere. The motives for disruption can be anything such as −
44 | P a g e
SCI 407 Information Systems Security and Audit
Criminals, terrorists, and sometimes the State themselves act as the source of these threats.
Criminals and hackers use different kinds of malicious tools and approaches. With the criminal
activities taking new shapes every day, the possibility for harmful actions propagates.
Enabling People
The lack of information security awareness among users, who could be a simple school going
kid, a system administrator, a developer, or even a CEO of a company, leads to a variety of cyber
vulnerabilities. The awareness policy classifies the following actions and initiatives for the
purpose of user awareness, education, and training −
The Government of India enacted The Information Technology Act with some major objectives
which are as follows −
To deliver lawful recognition for transactions through electronic data interchange (EDI)
and other means of electronic communication, commonly referred to as electronic
commerce or E-Commerce. The aim was to use replacements of paper-based methods of
communication and storage of information.
45 | P a g e
SCI 407 Information Systems Security and Audit
To facilitate electronic filing of documents with the Government agencies and further to
amend the Indian Penal Code, the Indian Evidence Act, 1872, the Bankers' Books
Evidence Act, 1891 and the Reserve Bank of India Act, 1934 and for matters connected
therewith or incidental thereto.
The Information Technology Act, 2000, was thus passed as the Act No.21 of 2000. The I. T. Act
got the President’s assent on June 9, 2000 and it was made effective from October 17, 2000. By
adopting this Cyber Legislation, India became the 12th nation in the world to adopt a Cyber Law
regime.
Vision
To build a secure and resilient cyberspace for citizens, businesses, and Government
46 | P a g e
SCI 407 Information Systems Security and Audit
Reports reveal that upcoming years will experience more cyber-attacks. So organizations are
advised to strengthen their data supply chains with better inspection methods.
Stringent regulatory rules are put in place by many countries to prevent unauthorized
access to networks. Such acts are declared as penal offences.
Stakeholders of the mobile companies will call upon the governments of the world to
reinforce cyber-legal systems and administrations to regulate the emerging mobile threats
and crimes.
The growing awareness on privacy is another upcoming trend. Google’s chief internet
expert Vint Cerf has stated that privacy may actually be an anomaly.
Cloud computing is another major growing trend. With more advancements in the
technology, huge volumes of data will flow into the cloud which is not completely
immune to cyber-crimes.
The growth of Bitcoins and other virtual currency is yet another trend to watch out for.
Bitcoin crimes are likely to multiply in the near future.
The arrival and acceptance of data analytics, which is another major trend to be followed,
requires that appropriate attention is given to issues concerning Big Data.
Create Awareness
While the U.S. government has declared October as the National Cybersecurity Awareness
month, India is following the trend to implement some stringent awareness scheme for the
general public.
The general public is partially aware of the crimes related to virus transfer. However, they are
unaware of the bigger picture of the threats that could affect their cyber-lives. There is a huge
lack of knowledge on e-commerce and online banking cyber-crimes among most of the internet
users.
Be vigilant and follow the tips given below while you participate in online activities −
47 | P a g e
SCI 407 Information Systems Security and Audit
Areas of Development
The "Cyberlaw Trends in India 2013" and "Cyber law Developments in India in 2014" are two
prominent and trustworthy cyber-law related research works provided by Perry4Law
Organization (P4LO) for the years 2013 and 2014.
There are some grave cyber law related issues that deserve immediate consideration by the
government of India. The issues were put forward by the Indian cyber law roundup of 2014
provided by P4LO and Cyber Crimes Investigation Centre of India (CCICI). Following are some
major issues −
With the formation of cyber-law compulsions, the obligation of banks for cyber-thefts and cyber-
crimes would considerably increase in the near future. Indian banks would require to keep a
dedicated team of cyber law experts or seek help of external experts in this regard.
The objectives set in the International Conference on Cyberlaw & Cybercrime are as follows −
To recognize the developing trends in Cyberlaw and the legislation impacting cyberspace
in the current situation.
To generate better awareness to battle the latest kinds of cybercrimes impacting all
investors in the digital and mobile network.
48 | P a g e
SCI 407 Information Systems Security and Audit
To recognize the areas for stakeholders of digital and mobile network where Cyberlaw
needs to be further evolved.
To work in the direction of creating an international network of cybercrimes. Legal
authorities could then be a significant voice in the further expansion of cyber-crimes and
cyber law legislations throughout the globe.
The creator/inventor gets exclusive rights against any misuse or use of work without his/her prior
information. However, the rights are granted for a limited period of time to maintain equilibrium.
The following list of activities which are covered by the intellectual property rights are laid down
by the World Intellectual Property Organization (WIPO) −
Industrial designs
Scientific discoveries
Protection against unfair competition
Literary, artistic, and scientific works
Inventions in all fields of human endeavor
Performances of performing artists, phonograms, and broadcasts
Trademarks, service marks, commercial names, and designations
All other rights resulting from intellectual activity in the industrial, scientific, literary, or
artistic fields
Intellectual Property Rights can be further classified into the following categories −
Copyright
Patent
Patent
Trade Secrets, etc.
49 | P a g e
SCI 407 Information Systems Security and Audit
To protect the intellectual property rights in the Indian territory, India has defined the formation
of constitutional, administrative and jurisdictive outline whether they imply the copyright, patent,
trademark, industrial designs, or any other parts of the intellectual property rights.
Back in the year 1999, the government passed an important legislation based on international
practices to safeguard the intellectual property rights. Let us have a glimpse of the same −
The Patents (Amendment) Act, 1999, facilitates the establishment of the mail box system
for filing patents. It offers exclusive marketing rights for a time period of five years.
The Trade Marks Bill, 1999, replaced the Trade and Merchandise Marks Act, 1958
The Copyright (Amendment) Act, 1999, was signed by the President of India.
The sui generis legislation was approved and named as the Geographical Indications of
Goods (Registration and Protection) Bill, 1999.
The Industrial Designs Bill, 1999, replaced the Designs Act, 1911.
The Patents (Second Amendment) Bill, 1999, for further amending the Patents Act of
1970 in compliance with the TRIPS.
50 | P a g e
SCI 407 Information Systems Security and Audit
Every new invention in the field of technology experiences a variety of threats. Internet is one
such threat, which has captured the physical marketplace and have converted it into a virtual
marketplace.
To safeguard the business interest, it is vital to create an effective property management and
protection mechanism keeping in mind the considerable amount of business and commerce
taking place in the Cyber Space.
Today it is critical for every business to develop an effective and collaborative IP management
mechanism and protection strategy. The ever-looming threats in the cybernetic world can thus be
monitored and confined.
Various approaches and legislations have been designed by the law-makers to up the ante in
delivering a secure configuration against such cyber-threats. However it is the duty of the
intellectual property right (IPR) owner to invalidate and reduce such mala fide acts of criminals
by taking proactive measures.
The cyber ecosystem involves a wide range of varied entities like devices (communication
technologies and computers), individuals, governments, private organizations, etc., which
interact with each other for numerous reasons.
This strategy explores the idea of having a strong and robust cyber-ecosystem where the cyber-
devices can work with each other in the future to prevent cyber-attacks, reduce their
effectiveness, or find solutions to recover from a cyber-attack.
Such a cyber-ecosystem would have the ability built into its cyber devices to permit secured
ways of action to be organized within and among groups of devices. This cyber-ecosystem can
51 | P a g e
SCI 407 Information Systems Security and Audit
be supervised by present monitoring techniques where software products are used to detect and
report security weaknesses.
Comparison of Attacks
The following table shows the Comparison of Attack Categories against Desired Cyber
Ecosystem Capabilities −
52 | P a g e
SCI 407 Information Systems Security and Audit
Case Study
The following diagram was prepared by Guilbert Gates for The New York Times, which shows
how an Iranian plant was hacked through the internet.
53 | P a g e
SCI 407 Information Systems Security and Audit
Explanation − A program was designed to automatically run the Iranian nuclear plant.
Unfortunately, a worker who was unaware of the threats introduced the program into the
controller. The program collected all the data related to the plant and sent the information to the
intelligence agencies who then developed and inserted a worm into the plant. Using the worm,
the plant was controlled by miscreants which led to the generation of more worms and as a
result, the plant failed completely.
Types of Attacks
54 | P a g e
SCI 407 Information Systems Security and Audit
data-leakage attacks
injection attacks and abuse of functionality
spoofing
time-state attacks
Hacking
buffer and data structure attacks
resource manipulation
stolen credentials usage
backdoors
dictionary attacks on passwords
exploitation of authentication
55 | P a g e
SCI 407 Information Systems Security and Audit
The objective of this strategy is to design an outline in compliance with the global security
standards through traditional products, processes, people, and technology.
Enabling actions are performed by government entities that are autonomous bodies free from
commercial interests. The publication of "National Security Policy Compliance Requirements"
and IT security guidelines and documents to enable IT security implementation and compliance
are done by these authorities.
Endorsing actions are involved in profitable services after meeting the obligatory qualification
standards and they include the following −
ISO 27001/BS 7799 ISMS certification, IS system audits etc., which are essentially the
compliance certifications.
'Common Criteria' standard ISO 15408 and Crypto module verification standards, which
are the IT Security product evaluation and certification.
Services to assist consumers in implementation of IT security such as IT security
manpower training.
Indian IT/ITES/BPOs need to comply with the international standards and best practices on
security and privacy with the development of the outsourcing market. ISO 9000, CMM, Six
Sigma, Total Quality Management, ISO 27001 etc., are some of the certifications.
Existing models such as SEI CMM levels are exclusively meant for software development
processes and do not address security issues. Therefore, several efforts are made to create a
model based on self-certification concept and on the lines of Software Capability Maturity
Model (SW-CMM) of CMU, USA.
56 | P a g e
SCI 407 Information Systems Security and Audit
The structure that has been produced through such association between industry and government,
comprises of the following −
standards
guidelines
practices
These parameters help the owners and operators of critical infrastructure to manage
cybersecurity-related risks.
Standards play a significant role in defining how we approach information security related issues
across geographical regions and societies. Open standards are encouraged to −
The objective of this strategy is to create a secure cyberspace ecosystem and strengthen the
regulatory framework. A 24X7 mechanism has been envisioned to deal with cyber threats
through National Critical Information Infrastructure Protection Centre (NCIIPC). The Computer
Emergency Response Team (CERT-In) has been designated to act as a nodal agency for crisis
management.
57 | P a g e
SCI 407 Information Systems Security and Audit
Some basic mechanisms that are in place for ensuring IT security are − link-oriented security
measures, end-to-end security measures, association-oriented measures, and data encryption.
These methods differ in their internal application features and also in the attributes of the
security they provide. Let us discuss them in brief.
Link-Oriented Measures
It delivers security while transferring data between two nodes, irrespective of the eventual source
and destination of the data.
End-to-End Measures
It is a medium for transporting Protocol Data Units (PDUs) in a protected manner from source to
destination in such a way that disruption of any of their communication links does not violate
security.
Association-Oriented Measures
Association-oriented measures are a modified set of end-to-end measures that protect every
association individually.
Data Encryption
It defines some general features of conventional ciphers and the recently developed class of
public-key ciphers. It encodes information in a way that only the authorized personnel can
decrypt them.
Electronic governance (e-governance) is the most treasured instrument with the government to
provide public services in an accountable manner. Unfortunately, in the current scenario, there is
no devoted legal structure for e-governance in India.
Similarly, there is no law for obligatory e-delivery of public services in India. And nothing is
more hazardous and troublesome than executing e-governance projects without sufficient
cybersecurity. Hence, securing the e-governance services has become a crucial task, especially
when the nation is making daily transactions through cards.
Fortunately, the Reserve Bank of India has implemented security and risk mitigation measures
for card transactions in India enforceable from 1st October, 2013. It has put the responsibility of
ensuring secured card transactions upon banks rather than on customers.
58 | P a g e
SCI 407 Information Systems Security and Audit
Critical information infrastructure is the backbone of a country’s national and economic security.
It includes power plants, highways, bridges, chemical plants, networks, as well as the buildings
where millions of people work every day. These can be secured with stringent collaboration
plans and disciplined implementations.
It is in demand that the government works with business owners and operators to reinforce their
services and groups by sharing cyber and other threat information.
A common platform should be shared with the users to submit comments and ideas, which can
be worked together to build a tougher foundation for securing and protecting critical
infrastructures.
The government of USA has passed an executive order "Improving Critical Infrastructure
Cybersecurity" in 2013 that prioritizes the management of cybersecurity risk involved in the
delivery of critical infrastructure services. This Framework provides a common classification and
mechanism for organizations to −
59 | P a g e
SCI 407 Information Systems Security and Audit
Due to the ever-increasing dependence on the Internet, the biggest challenge we face today is the
security of information from miscreants. Therefore, it is essential to promote research and
development in cybersecurity so that we can come up with robust solutions to mitigate cyber
risks.
Cybersecurity Research
Cybersecurity Research is the area that is concerned with preparing solutions to deal with cyber
criminals. With increasing amount of internet attacks, advanced persistent threats and phishing,
lots of research and technological developments are required in the future.
In the recent years, India has witnessed an enormous growth in cyber technologies. Hence it calls
for an investment in the research and development activities of cybersecurity. India has also seen
many successful research outcomes that were translated into businesses, through the advent of
local cybersecurity companies.
Threat Intelligence
Multi-identity based expertise such as Next Generation Firewall that offers security intelligence
to enterprises and enable them to apply best suited security controls at the network perimeter are
also being worked on.
Research in protocols and algorithms is a significant phase for the consolidation of cybersecurity
at a technical level. It defines the rules for information sharing and processing over cyberspace.
In India, protocol and algorithm level research includes −
60 | P a g e
SCI 407 Information Systems Security and Audit
Authentication Techniques
Authentication techniques such as Key Management, Two Factor Authentication, and Automated
key Management provide the ability to encrypt and decrypt without a centralized key
management system and file protection. There is continuous research happening to strengthen
these authentication techniques.
With the adoption of varied types of mobile devices, the research on the security and privacy
related tasks on mobile devices has increased. Mobile security testing, Cloud Security, and
BYOD (Bring Your Own Device) risk mitigation are some of the areas where a lot of research is
being done.
Cyber Forensics
Cyber Forensics is the application of analysis techniques to collect and recover data from a
system or a digital storage media. Some of the specific areas where research is being done in
India are −
Disk Forensics
Network Forensics
Mobile Device Forensics
Memory Forensics
Multimedia Forensics
Internet Forensics
Any risk that an opponent may damage, write some malicious function to it, deconstruct the
design, installation, procedure, or maintenance of a supply item or a system so that the entire
function can be degraded.
Supply chain is a global issue and there is a requirement to find out the interdependencies among
the customers and suppliers. In today’s scenario it is important to know − What are the SCRM
problems? and How to address the problems?
An effective SCRM (Supply Chain Risk Management) approach requires a strong public-private
partnership. Government should have strong authorities to handle supply chain issues. Even
private sectors can play a key role in a number of areas.
61 | P a g e
SCI 407 Information Systems Security and Audit
We cannot provide a one-size-fits-all resolution for managing supply chain risks. Depending on
the product and the sector, the costs for reducing risks will weigh differently. Public Private
Partnerships should be encouraged to resolve risks associated with supply chain management.
Cybersecurity policies of an organization can be effective, provided all its employees understand
their value and exhibit a strong commitment towards implementing them. Human resource
directors can play a key role in keeping organizations safe in cyberspace by applying the
following few points.
As most of the employees do not take the risk factor seriously, hackers find it easy to target
organizations. In this regard, HR plays a key role in educating employees about the impact their
attitudes and behavior have on the organization’s security.
Policies of a company must be in sync with the way employees think and behave. For example,
saving passwords on systems is a threat, however continuous monitoring can prevent it. The HR
team is best placed to advise whether policies are likely to work and whether they are
appropriate.
It also happens that cyber-criminals take the help of insiders in a company to hack their network.
Therefore it is essential to identify employees who may present a particular risk and have
stringent HR policies for them.
Cybersecurity in India is still in its evolution stage. This is the best time to create awareness on
issues related to cyber security. It would be easy to create awareness from the grass-root level
like schools where users can be made aware how Internet works and what are its potential
threats.
Every cyber café, home/personal computers, and office computers should be protected through
firewalls. Users should be instructed through their service providers or gateways not to breach
unauthorized networks. The threats should be described in bold and the impacts should be
highlighted.
62 | P a g e
SCI 407 Information Systems Security and Audit
The government must formulate strong laws to enforce cybersecurity and create sufficient
awareness by broadcasting the same through television/radio/internet advertisements.
Information Sharing
United States proposed a law called Cybersecurity Information Sharing Act of 2014 (CISA)
to improve cybersecurity in the country through enhanced sharing of information about
cybersecurity threats. Such laws are required in every country to share threat information among
citizens.
This problem can be addressed by formulating a good cybersecurity law that can establish a
regulatory regime for obligatory cybersecurity breach notifications on the part of telecom
companies/ISPs.
Infrastructures such as automated power grids, thermal plants, satellites, etc., are vulnerable to
diverse forms of cyber-attacks and hence a breach notification program would alert the agencies
to work on them.
Despite the fact that companies are spending on cybersecurity initiatives, data breaches continue
to occur. According to The Wall Street Journal, "Global cybersecurity spending by critical
infrastructure industries was expected to hit $46 billion in 2013, up 10% from a year earlier
according to Allied Business Intelligence Inc." This calls for the effective implementation of the
cybersecurity framework.
The Core,
Implementation Tiers, and
Framework Profiles.
63 | P a g e
SCI 407 Information Systems Security and Audit
The Framework Core is a set of cybersecurity activities and applicable references that having
five simultaneous and constant functions − Identify, Protect, Detect, Respond, and Recover. The
framework core has methods to ensure the following −
Develop and implement procedures to protect the most critical intellectual property and
assets.
Have resources in place to identify any cybersecurity breach.
Recover from a breach, if and when one occurs.
The Framework Implementation Tiers define the level of sophistication and consistency an
organization employs in applying its cybersecurity practices. It has the following four levels.
Tier 1 (Partial) − In this level, the organization’s cyber-risk management profiles are not
defined. There is a partial consciousness of the organization’s cybersecurity risk at the
organization level. Organization-wide methodology to managing cybersecurity risk has not been
recognized.
64 | P a g e
SCI 407 Information Systems Security and Audit
Tier 2 (Risk Informed) − In this level, organizations establish a cyber-risk management policy
that is directly approved by the senior management. The senior management makes efforts to
establish risk management objectives related to cybersecurity and implements them.
Tier 3 (Repeatable) − In this level, the organization runs with formal cybersecurity measures,
which are regularly updated based on requirement. The organization recognizes its dependencies
and partners. It also receives information from them, which helps in taking risk-based
management decisions.
Tier 4 (Adaptive) − In this level, the organization adapts its cybersecurity practices "in real-
time" derived from previous and current cybersecurity activities. Through a process of incessant
development in combining advanced cybersecurity technologies, real-time collaboration with
partners, and continuous monitoring of activities on their systems, the organization’s
cybersecurity practices can quickly respond to sophisticated threats.
The Framework Profile is a tool that provides organizations a platform for storing information
concerning their cybersecurity program. A profile allows organizations to clearly express the
goals of their cybersecurity program.
The senior management including the directors should first get acquainted with the Framework.
After which, the directors should have a detailed discussion with the management about the
organization’s Implementation Tiers.
Educating the managers and staff on the Framework will ensure that everyone understands its
importance. This is an important step towards the successful implementation of a vigorous
cybersecurity program. The information about existing Framework Implementations may help
organizations with their own approaches.
Network Security
Network security is the security provided to a network from unauthorized access and risks. It is
the duty of network administrators to adopt preventive measures to protect their networks from
potential security threats.
Computer networks that are involved in regular transactions and communication within the
government, individuals, or business require security. The most common and simple way of
protecting a network resource is by assigning it a unique name and a corresponding password.
65 | P a g e
SCI 407 Information Systems Security and Audit
These security devices block the surplus traffic. Firewalls, antivirus scanning devices, and
content filtering devices are the examples of such devices.
Passive Devices
These devices identify and report on unwanted traffic, for example, intrusion detection
appliances.
Preventative Devices
These devices scan the networks and identify potential security problems. For example,
penetration testing devices and vulnerability assessment appliances.
These devices serve as all-in-one security devices. Examples include firewalls, content filtering,
web caching, etc.
Firewalls
A firewall is a network security system that manages and regulates the network traffic based on
some protocols. A firewall establishes a barrier between a trusted internal network and the
internet.
Firewalls exist both as software that run on a hardware and as hardware appliances. Firewalls
that are hardware-based also provide other functions like acting as a DHCP server for that
network.
Most personal computers use software-based firewalls to secure data from threats from the
internet. Many routers that pass data between networks contain firewall components and
conversely, many firewalls can perform basic routing functions.
Firewalls are commonly used in private networks or intranets to prevent unauthorized access
from the internet. Every message entering or leaving the intranet goes through the firewall to be
examined for security measures.
An ideal firewall configuration consists of both hardware and software based devices. A firewall
also helps in providing remote access to a private network through secure authentication
certificates and logins.
66 | P a g e
SCI 407 Information Systems Security and Audit
Hardware firewalls are standalone products. These are also found in broadband routers. Most
hardware firewalls provide a minimum of four network ports to connect other computers. For
larger networks − e.g., for business purpose − business networking firewall solutions are
available.
Software firewalls are installed on your computers. A software firewall protects your computer
from internet threats.
Antivirus
An antivirus is a tool that is used to detect and remove malicious software. It was originally
designed to detect and remove viruses from computers.
Modern antivirus software provide protection not only from virus, but also from worms, Trojan-
horses, adwares, spywares, keyloggers, etc. Some products also provide protection from
malicious URLs, spam, phishing attacks, botnets, DDoS attacks, etc.
Content Filtering
Content filtering devices screen unpleasant and offensive emails or webpages. These are used as
a part of firewalls in corporations as well as in personal computers. These devices generate the
message "Access Denied" when someone tries to access any unauthorized web page or email.
Content is usually screened for pornographic content and also for violence- or hate-oriented
content. Organizations also exclude shopping and job related contents.
Web filtering
Screening of Web sites or pages
E-mail filtering
Screening of e-mail for spam
Other objectionable content
Intrusion Detection Systems, also known as Intrusion Detection and Prevention Systems, are the
appliances that monitor malicious activities in a network, log information about such activities,
take steps to stop them, and finally report them.
Intrusion detection systems help in sending an alarm against any malicious activity in the
network, drop the packets, and reset the connection to save the IP address from any blockage.
Intrusion detection systems can also perform the following actions −
67 | P a g e
SCI 407 Information Systems Security and Audit
Digital signature has been replaced with electronic signature to make it a more
technology neutral act.
It elaborates on offenses, penalties, and breaches.
It outlines the Justice Dispensation Systems for cyber-crimes.
It defines in a new section that cyber café is any facility from where the access to the
internet is offered by any person in the ordinary course of business to the members of the
public.
It provides for the constitution of the Cyber Regulations Advisory Committee.
It is based on The Indian Penal Code, 1860, The Indian Evidence Act, 1872, The
Bankers' Books Evidence Act, 1891, The Reserve Bank of India Act, 1934, etc.
It adds a provision to Section 81, which states that the provisions of the Act shall have
overriding effect. The provision states that nothing contained in the Act shall restrict any
person from exercising any right conferred under the Copyright Act, 1957.
68 | P a g e
SCI 407 Information Systems Security and Audit
Thereafter the provisions about due diligence, role of intermediaries and some
miscellaneous provisions are been stated.
The Act is embedded with two schedules. The First Schedule deals with Documents or
Transactions to which the Act shall not apply. The Second Schedule deals with electronic
signature or electronic authentication technique and procedure. The Third and Fourth
Schedule are omitted.
As per the sub clause (4) of Section 1, nothing in this Act shall apply to documents or
transactions specified in First Schedule. Following are the documents or transactions to which
the Act shall not apply −
The I.T. Act has brought amendment in four statutes vide section 91-94. These changes have
been provided in schedule 1-4.
The first schedule contains the amendments in the Penal Code. It has widened the scope
of the term "document" to bring within its ambit electronic documents.
The second schedule deals with amendments to the India Evidence Act. It pertains to the
inclusion of electronic document in the definition of evidence.
The third schedule amends the Banker's Books Evidence Act. This amendment brings
about change in the definition of "Banker's-book". It includes printouts of data stored in
a floppy, disc, tape or any other form of electromagnetic data storage device. Similar
change has been brought about in the expression "Certified-copy" to include such
printouts within its purview.
The fourth schedule amends the Reserve Bank of India Act. It pertains to the regulation
of fund transfer through electronic means between the banks or between the banks and
other financial institution.
69 | P a g e
SCI 407 Information Systems Security and Audit
Intermediary Liability
Intermediary, dealing with any specific electronic records, is a person who on behalf of another
person accepts, stores or transmits that record or provides any service with respect to that
record.
Electronic Signature
An electronic signature or e-signature, indicates either that a person who demands to have
created a message is the one who created it.
70 | P a g e
SCI 407 Information Systems Security and Audit
engineering companies digital seals are also required for another layer of authentication and
security. Digital seals and signatures are same as handwritten signatures and stamped seals.
Digital Signature was the term defined in the old I.T. Act, 2000. Electronic Signature is the
term defined by the amended act (I.T. Act, 2008). The concept of Electronic Signature is broader
than Digital Signature. Section 3 of the Act delivers for the verification of Electronic Records by
affixing Digital Signature.
Those based on the knowledge of the user or the recipient, i.e., passwords, personal
identification numbers (PINs), etc.
Those bases on the physical features of the user, i.e., biometrics.
Those based on the possession of an object by the user, i.e., codes or other information
stored on a magnetic card.
Types of authentication and signature methods that, without falling under any of the
above categories might also be used to indicate the originator of an electronic
communication (Such as a facsimile of a handwritten signature, or a name typed at the
bottom of an electronic message).
71 | P a g e
SCI 407 Information Systems Security and Audit
The law defines the offenses in a detailed manner along with the penalties for each category of
offence.
Offences
Cyber offences are the illegitimate actions, which are carried out in a classy manner where either
the computer is the tool or target or both.
Example
72 | P a g e
SCI 407 Information Systems Security and Audit
Explanation − For the purpose of this section “computer source code” means the listing of
programs, computer commands, design and layout and program analysis of computer resource in
any form.
Object − The object of the section is to protect the “intellectual property” invested in the
computer. It is an attempt to protect the computer source documents (codes) beyond what is
available under the Copyright Law
This section extends towards the Copyright Act and helps the companies to protect their source
code of their programs.
73 | P a g e
SCI 407 Information Systems Security and Audit
The following table shows the offence and penalties against all the mentioned sections of the I.T.
Act −
Bailability and
Section Offence Punishment
Congizability
Offence is Bailable,
Tampering with Computer Imprisonment up to 3 years
65 Cognizable and triable by
Source Code or fine up to Rs 2 lakhs
Court of JMFC.
Imprisonment up to 3 years Offence is Bailable,
66 Computer Related Offences
or fine up to Rs 5 lakhs Cognizable and
Sending offensive messages Offence is Bailable,
Imprisonment up to 3 years
66-A through Communication Cognizable and triable by
and fine
service, etc... Court of JMFC
Dishonestly receiving stolen Offence is Bailable,
Imprisonment up to 3 years
66-B computer resource or Cognizable and triable by
and/or fine up to Rs. 1 lakh
communication device Court of JMFC
Imprisonment of either Offence is Bailable,
66-C Identity Theft description up to 3 years Cognizable and triable by
and/or fine up to Rs. 1 lakh Court of JMFC
Imprisonment of either Offence is Bailable,
Cheating by Personation by
66-D description up to 3 years Cognizable and triable by
using computer resource
and /or fine up to Rs. 1 lakh Court of JMFC
Offence is Bailable,
Imprisonment up to 3 years
66-E Violation of Privacy Cognizable and triable by
and /or fine up to Rs. 2 lakh
Court of JMFC
Offence is Non-Bailable,
Imprisonment extend to
66-F Cyber Terrorism Cognizable and triable by
imprisonment for Life
Court of Sessions
On first Conviction,
imprisonment up to 3 years
Publishing or transmitting and/or fine up to Rs. 5 lakh Offence is Bailable,
67 obscene material in On Subsequent Conviction Cognizable and triable by
electronic form imprisonment up to 5 years Court of JMFC
and/or fine up to Rs. 10
lakh
On first Conviction
imprisonment up to 5 years
Publishing or transmitting
and/or fine up to Rs. 10 Offence is Non-Bailable,
of material containing
67-A lakh On Subsequent Cognizable and triable by
sexually explicit act, etc...
Conviction imprisonment Court of JMFC
in electronic form
up to 7 years and/or fine up
to Rs. 10 lakh
74 | P a g e
SCI 407 Information Systems Security and Audit
On first Conviction
imprisonment of either
description up to 5 years
Publishing or transmitting
and/or fine up to Rs. 10 Offence is Non Bailable,
of material depicting
67-B lakh On Subsequent Cognizable and triable by
children in sexually explicit
Conviction imprisonment of Court of JMFC
act etc., in electronic form
either description up to 7
years and/or fine up to Rs.
10 lakh
Intermediary intentionally
or knowingly contravening
Imprisonment up to 3 years Offence is Bailable,
67-C the directions about
and fine Cognizable.
Preservation and retention
of information
Failure to comply with the
Imprisonment up to 2 years Offence is Bailable, Non-
68 directions given by
and/or fine up to Rs. 1 lakh Cognizable.
Controller
Failure to assist the agency
referred to in sub section (3)
in regard interception or Imprisonment up to 7 years Offence is Non-Bailable,
69
monitoring or decryption of and fine Cognizable.
any information through
any computer resource
Failure of the intermediary
to comply with the direction
issued for blocking for Imprisonment up to 7 years Offence is Non-Bailable,
69-A
public access of any and fine Cognizable.
information through any
computer resource
Intermediary who
intentionally or knowingly
contravenes the provisions
of sub-section (2) in regard Imprisonment up to 3 years Offence is Bailable,
69-B
monitor and collect traffic and fine Cognizable.
data or information through
any computer resource for
cybersecurity
Any person who secures
access or attempts to secure Imprisonment of either
Offence is Non-Bailable,
70 access to the protected description up to 10 years
Cognizable.
system in contravention of and fine
provision of Sec. 70
Indian Computer
Imprisonment up to 1 year Offence is Bailable, Non-
70-B Emergency Response Team
and/or fine up to Rs. 1 lakh Cognizable
to serve as national agency
75 | P a g e
SCI 407 Information Systems Security and Audit
As per Section 77-A of the I. T. Act, any Court of competent jurisdiction may compound offences,
other than offences for which the punishment for life or imprisonment for a term exceeding three
years has been provided under the Act.
The accused is, by reason of his previous conviction, is liable to either enhanced
punishment or to the punishment of different kind; OR
Offence affects the socio economic conditions of the country; OR
Offence has been committed against a child below the age of 18 years; OR
Offence has been committed against a woman.
The person alleged of an offence under this Act may file an application for compounding in the
Court. The offence will then be pending for trial and the provisions of Sections 265-B and 265-C
of Cr. P.C. shall apply.
76 | P a g e
SCI 407 Information Systems Security and Audit
Cyber Crime is committed every now and then, but is still hardly reported. The cases of cyber-
crime that reaches to the Court of Law are therefore very few. There are practical difficulties in
collecting, storing and appreciating Digital Evidence. Thus the Act has miles to go before it can
be truly effective.
In this tutorial, we have tried to cover all the current and major topics related to Cyber Laws and
IT Security. We would like to quote the words of a noted cyber law expert and Supreme Court
advocate Mr Pavan Duggal to conclude this tutorial.
While the lawmakers have to be complemented for their admirable work removing various
deficiencies in the Indian Cyberlaw and making it technologically neutral, yet it appears that there
has been a major mismatch between the expectation of the nation and the resultant effect of the
amended legislation. The most bizarre and startling aspect of the new amendments is that these
amendments seek to make the Indian cyberlaw a cyber-crime friendly legislation; − a legislation
that goes extremely soft on cyber criminals, with a soft heart; a legislation that chooses to
encourage cyber criminals by lessening the quantum of punishment accorded to them under the
existing law; .... a legislation which makes a majority of cybercrimes stipulated under the IT Act
as bailable offences; a legislation that is likely to pave way for India to become the potential cyber-
crime capital of the world.
A. Cybercrime refers to all the activities done with criminal intent in cyberspace. Because of the
anonymous nature of the internet, miscreants engage in a variety of criminal activities. The field
of cybercrime is just emerging and new forms of criminal activities in cyberspace are coming to
the forefront with each passing day.
A. No, unfortunately we don’t have an exhaustive definition of cybercrime. However, any online
activity which basically offends human sensibilities can be regarded as a cybercrime.
77 | P a g e
SCI 407 Information Systems Security and Audit
A. Cybercrimes committed against persons include various crimes like transmission of child
pornography, harassment using e-mails and cyber-stalking. Posting and distributing obscene
material is one of the most important Cybercrimes known today.
A. Cybercrimes against all forms of property include unauthorized computer trespassing through
cyberspace, computer vandalism, transmission of harmful programs, and unauthorized
possession of computerized information.
7. Is hacking a Cybercrime?
A. Hacking is amongst the gravest Cybercrimes known till date. It is a dreadful feeling to know
that a stranger has broken into your computer system without your knowledge and has tampered
with precious confidential data.
The bitter truth is that no computer system in the world is hacking proof. It is unanimously
agreed that any system, however secure it might look, can be hacked. The recent denial of
service attacks seen over the popular commercial sites like E-bay, Yahoo, and Amazon are a new
category of Cybercrimes which are slowly emerging as being extremely dangerous.
Using one's own programming abilities to gain unauthorized access to a computer or network is a
very serious crime. Similarly, the creation and dissemination of harmful computer programs
which do irreparable damage to computer systems is another kind of Cybercrime.
A. Cyber Terrorism is one distinct example of cybercrime against government. The growth of
Internet has shown that the medium of cyberspace is being used by individuals and groups to
threaten the governments as also to terrorize the citizens of a country. This crime manifests itself
into terrorism when an individual hacks into a government or military maintained website.
A. As of now, we don’t have any comprehensive laws on cybercrime anywhere in the world.
This is the reason that the investigating agencies like FBI are finding the Cyberspace to be an
extremely difficult terrain. Cybercrimes fall into that grey area of Internet law which is neither
fully nor partially covered by the existing laws. However, countries are taking crucial measures
to establish stringent laws on cybercrime.
78 | P a g e
SCI 407 Information Systems Security and Audit
10. Is there any recent case which demonstrates the importance of having a cyber law on
cybercrime within the national jurisdictions of countries?
A. The most recent case of the virus "I love you" demonstrates the need for having cyber laws
concerning cybercrimes in different national jurisdictions. At the time of the web publication of
this feature, Reuters has reported that "The Philippines has yet to arrest the suspected creator of
the 'Love Bug' computer virus because it lacks laws that deal with computer crime, a senior
police officer said". The fact of the matter is that there are no laws relating to cybercrime in the
Philippines.
A. Vishing is the criminal practice of using social influence over the telephone system, most
often using features facilitated by Voice over IP (VoIP), to gain access to sensitive information
such as credit card details from the public. The term is a combination of "Voice" and phishing.
A. Mail fraud is an offense under United States federal law, which includes any scheme that
attempts to unlawfully obtain money or valuables in which the postal system is used at any point
in the commission of a criminal offense.
A. It is the practice of using the telephone network to display a number on the recipient's Caller
ID display which is not that of the actual originating station.
A. It is the act or practice of obtaining secrets from individuals, competitors, rivals, groups,
governments, and enemies for military, political, or economic advantage using illegal
exploitation methods on the internet.
A. Sabotage literally means willful damage to any machinery or materials or disruption of work.
In the context of cyberspace, it is a threat to the existence of computers and satellites used by
military activities
16. Name the democratic country in which The Cyber Defamation law was first introduced.
A. South Korea is the first democratic country in which this law was introduced first.
79 | P a g e
SCI 407 Information Systems Security and Audit
A. Bots are one of the most sophisticated types of crime-ware facing the internet today. Bots earn
their unique name by performing a wide variety of automated tasks on behalf of the cyber
criminals. They play a part in "denial of service" attack in internet.
A. Trojans and spyware are the tools a cyber-criminal might use to obtain unauthorized access
and steal information from a victim as part of an attack.
A. Phishing and Pharming are the most common ways to perform identity theft which is a form
of cyber-crime in which criminals use the internet to steal personal information from others.
Read the latest ways hackers create phishing scams to gain access to your personal
information.
Install a firewall on your computer to keep unwanted threats and attacks to a minimum.
Use caution while opening emails and clicking links. You should read carefully while
downloading content from unverified sources.
Create strong passwords for any websites where personal information is stored.
There is an ongoing conflict between privacy and accessibility. While society feels there should
be universal accessibility of information, there is also the feeling that individual information or
information owned by an individual or organization should be protected such that only what he
owner wants seen can be accessed.
Privacy: This is the individual’s right to determine for themselves what about them is
communicated to others [i.e. at the personal level]
Confidentiality: An organization’s right to determine what will be communicated about
commercially held information that is not about people i.e. sales data, R&D findings, profitability
records, etc. [i.e. at the commercial level]
Privacy and confidentiality is important. However, there should be free interaction through the
disclosure of information. The are no explicit legal precepts about privacy and confidentiality.
However, other laws provide limited indirect cover e.g. laws on contract, defamation, trespass,
copyright, etc.
Personal data protection must be a balance between the individual and society and the legal
framework is the correct way that authority regulates that balance.
80 | P a g e
SCI 407 Information Systems Security and Audit
The notion of privacy goes beyond the content of a data to the use the data will be made of. This
varies between societies, countries and individuals.)
Privacy Issues
1) Fair use: Data should be used to in support of the organization’s specific business mission.
This requires the organization to seek an individual’s permission before passing data to others
(informed consent). It is increasingly being felt that personal data should not be used for
marketing purposes for instance direct advertising. There is also the fear that the collected,
reformatted information about individuals may fall into the wrong hands and is used for
political harassment or to allow criminals to identify soft targets (lucrative individuals)
2) Gate Keeping: The restricted access to services, privileges, benefits or opportunities on the
basis of certain data values. Some gate keeping seems inevitable and acceptable e.g. entry to a
university based on certain points e.g. grading or scoring system for credit provision. However,
the same principle can be used to keep “trouble makers” out. The only problem is, “who
decides who is a trouble maker?’’
The act gives individuals rights about what may be stored and processed about them on
computer or other automatic data processing medium.
It also gives the right to examine the information, challenge it, if appropriate have it amended
or deleted where necessary and, in some cases claim compensation for damages.
The act also places certain obligations on the data user in that they must register their data use
with the data protection register, and implement good practice regarding the usage and
disclosure of information held.
81 | P a g e
SCI 407 Information Systems Security and Audit
I. The information to be contained in personal data shall be obtained, and personal data shall
be processed fairly and lawfully.
II. Personal data shall be held only for one or more specified and lawful purpose(s)
III. Personal data held for any purpose or purposes shall not be used or disclosed in any manner
incompatible with that purpose or those purposes
IV. Personal data held for any purpose or purposes shall be adequate, relevant and not
excessive in relation to that purpose or those purposes.
V. Personal data shall be accurate and, where necessary kept up to date.
VI. Personal data held for any purpose or purposes shall not be kept for longer than is necessary
for that purpose or those purposes.
VII. An individual shall be entitled at reasonable intervals and without undue delay or expense:
to be informed by any data user whether he holds personal data of which that individual is
target, to access any such data held by a data user, and where appropriate to have such data
corrected or erased.
VIII. Appropriate security measures shall be undertaken against unauthorized access to, or
alteration, disclosure or destruction of, personal data and against accidental loss or
destruction of personal data.
Example Data Users that hold data and use it for certain purposes:
Banks, insurance companies, credit rating bureaus, hospitals, doctors, police, government
agencies, post office, education and school records, driver and vehicle license center, customs and
excise, revenue authority, employers, etc.
Total Exemptions
Information required by law to be public e.g. share registers
National Security data
Employee data for calculation of wages, pensions, keeping accounts, or keeping records of
purchases or sales for accounting purposes
Data used only for preparing text documents, house hold affairs or for recreational use
[Everyone else must apply for registration]
82 | P a g e
SCI 407 Information Systems Security and Audit
Hardware developments are covered for protecting ownership by the law on patents. There is need
for software to be protected because of the high amounts of investments towards developments
(failure will mean. Failure to have software protection will mean that ‘small fish’ and new comers
may not go far. There is however need to guard against being too draconian (suppose Newton
had patented all acknowledgement of the laws of gravity?)
UK patents act 1977 protects monopoly right to inventions. This specifically excludes programs
(software) as inventions. This means that only organizations developing new hardware
components or physical devices can use this form of protection. IS management is not covered by
trademarks act 1938, which protects areas of organizations.
Confidence
Ways of working, plans, interactions are all trade secrets and protection for them is achieved
through the law of confidentiality. This has to be built in by direct contractual obligation e.g.
members of the IS function are duty bound contractually as per their employment not to disclose
plans to develop an innovative use of IS. To ensure consultants and contractors keep confidence,
there is need to build this in when coming up with contractual documents.
Copyright
Copyright, designs and patents acts 1988 confirms that software is a literally work for the purpose
of copyright. Copyright means that there are a number of actions that only the copyright owner
may do. These are:
To copy the work
To issue copies of the work to public (including rental copies)
To perform, show or play the work in public
To broadcast the work or include it in a cable programme service
To make an adaptation of the work or do any of the above with an adaptation.
The copyright (computer programs) regulations 1992 make permissible some further specific to
computer programs such as taking back up copy. Chips are covered by their own special form of
copyright, Designs and patents act, 1988.
Issues of legality
Reverse engineering as copyright primarily protects the source code and documentation. In the
US, there has been many “look and feel” copyright case in the judicial system.
83 | P a g e
SCI 407 Information Systems Security and Audit
Software Piracy
1100 software piracy investigations 1992 – offender analysis [courtesy of Wendy Robson]
Contracts
Areas of Contracts
Functionality
Reliability
Performance
Portability
Maintainability
Availability
Economy
84 | P a g e
SCI 407 Information Systems Security and Audit
Areas to be addressed
Need to address the effects of the computer on the working place and the nature of work and the
body, eyes, back, etc
Hacking
Viruses
Computer Chip theft
Many “computer crimes” are traditional crimes simply using a computer as a tool e.g. on-line
banking theft of fraud.
I. POLICY
85 | P a g e
SCI 407 Information Systems Security and Audit
of security over the equipment and software used to process, store, and transmit
that information.
B. All policies and procedures must be documented and made available to
individuals responsible for their implementation and compliance. All activities
identified by the policies and procedures must also be documented. All the
documentation, which may be in electronic form, must be retained for at least 6
(six) years after initial creation, or, pertaining to policies and procedures, after
changes are made. All documentation must be periodically reviewed for
appropriateness and currency, a period of time to be determined by each entity
within ORGANIZATION XYZ.
86 | P a g e
SCI 407 Information Systems Security and Audit
determined. The frequency of the risk analysis will be determined at the entity
level.
B. Based on the periodic assessment, measures will be implemented that reduce the
impact of the threats by reducing the amount and scope of the vulnerabilities.
Affiliated Covered Entities: Legally separate, but affiliated, covered entities which
choose to designate themselves as a single covered entity for purposes of HIPAA.
A. Information Security Officer: The Information Security Officer (ISO) for each
entity is responsible for working with user management, owners, custodians, and
users to develop and implement prudent security policies, procedures, and
controls, subject to the approval of ORGANIZATION XYZ. Specific
responsibilities include:
87 | P a g e
SCI 407 Information Systems Security and Audit
88 | P a g e
SCI 407 Information Systems Security and Audit
89 | P a g e
SCI 407 Information Systems Security and Audit
3. Refer all disclosures of PHI (1) outside of ORGANIZATION XYZ and (2)
within ORGANIZATION XYZ, other than for treatment, payment, or health
care operations, to the applicable entity’s Medical/Health Information
Management Department. In certain circumstances, the Medical/Health
Information Management Department policies may specifically delegate
the disclosure process to other departments. (For additional information,
see ORGANIZATION XYZ Privacy/Confidentiality of Protected Health
Information (PHI) Policy.)
4. Keep personal authentication devices (e.g. passwords, SecureCards,
PINs, etc.) confidential.
5. Report promptly to the ISO the loss or misuse of ORGANIZATION XYZ
information.
6. Initiate corrective actions when problems are identified.
90 | P a g e
SCI 407 Information Systems Security and Audit
91 | P a g e
SCI 407 Information Systems Security and Audit
appropriately scanned for viruses. Users are not authorized to turn off or disable
virus checking systems.
D. Access Controls: Physical and electronic access to PHI, Confidential and
Internal information and computing resources is controlled. To ensure
appropriate levels of access by internal workers, a variety of security measures
will be instituted as recommended by the Information Security Officer and
approved by ORGANIZATION XYZ. Mechanisms to control access to PHI,
Confidential and Internal information include (but are not limited to) the following
methods:
1. Authorization: Access will be granted on a “need to know” basis and
must be authorized by the immediate supervisor and application owner
with the assistance of the ISO. Any of the following methods are
acceptable for providing access under this policy:
a. Context-based access: Access control based on the context of a
transaction (as opposed to being based on attributes of the
initiator or target). The “external” factors might include time of day,
location of the user, strength of user authentication, etc.
b. Role-based access: An alternative to traditional access control
models (e.g., discretionary or non-discretionary access control
policies) that permits the specification and enforcement of
enterprise-specific security policies in a way that maps more
naturally to an organization’s structure and business activities.
Each user is assigned to one or more predefined roles, each of
which has been assigned the various privileges needed to perform
that role.
c. User-based access: A security mechanism used to grant users of
a system access based upon the identity of the user.
2. Identification/Authentication: Unique user identification (user id) and
authentication is required for all systems that maintain or access PHI,
Confidential and/or Internal Information. Users will be held accountable
for all actions performed on the system with their user id.
a. At least one of the following authentication methods must be
implemented:
1. strictly controlled passwords (Attachment 1 – Password
Control Standards),
2. biometric identification, and/or
3. tokens in conjunction with a PIN.
b. The user must secure his/her authentication control (e.g.
password, token) such that it is known only to that user and
possibly a designated security manager.
c. An automatic timeout re-authentication must be required after a
certain period of no activity (maximum 15 minutes).
d. The user must log off or secure the system when leaving it.
92 | P a g e
SCI 407 Information Systems Security and Audit
93 | P a g e
SCI 407 Information Systems Security and Audit
94 | P a g e
SCI 407 Information Systems Security and Audit
facility, and the movement of these items within the facility. The following
specification must be addressed:
1. Information Disposal / Media Re-Use of:
a. Hard copy (paper and microfilm/fiche)
b. Magnetic media (floppy disks, hard drives, zip disks, etc.) and
c. CD ROM Disks
2. Accountability: Each entity must maintain a record of the movements of
hardware and electronic media and any person responsible therefore.
3. Data backup and Storage: When needed, create a retrievable, exact
copy of electronic PHI before movement of equipment.
F. Other Media Controls:
1. PHI and Confidential Information stored on external media (diskettes, cd-
roms, portable storage, memory sticks, etc.) must be protected from theft
and unauthorized access. Such media must be appropriately labeled so
as to identify it as PHI or Confidential Information. Further, external media
containing PHI and Confidential Information must never be left
unattended in unsecured areas.
2. PHI and Confidential Information must never be stored on mobile
computing devices (laptops, personal digital assistants (PDA), smart
phones, tablet PC’s, etc.) unless the devices have the following minimum
security requirements implemented:
a. Power-on passwords
b. Auto logoff or screen saver with password
c. Encryption of stored data or other acceptable safeguards
approved by Information Security Officer
Further, mobile computing devices must never be left unattended in
unsecured areas.
3. If PHI or Confidential Information is stored on external medium or mobile
computing devices and there is a breach of confidentiality as a result,
then the owner of the medium/device will be held personally accountable
and is subject to the terms and conditions of ORGANIZATION XYZ
Information Security Policies and Confidentiality Statement signed as a
condition of employment or affiliation with ORGANIZATION XYZ.
H. Data Transfer/Printing:
1. Electronic Mass Data Transfers: Downloading and uploading PHI,
Confidential, and Internal Information between systems must be strictly
controlled. Requests for mass downloads of, or individual requests for,
information for research purposes that include PHI must be approved
through the Internal Review Board (IRB). All other mass downloads of
information must be approved by the Application Owner and include only
the minimum amount of information necessary to fulfill the request.
Applicable Business Associate Agreements must be in place when
95 | P a g e
SCI 407 Information Systems Security and Audit
96 | P a g e
SCI 407 Information Systems Security and Audit
97 | P a g e
SCI 407 Information Systems Security and Audit
Compliance [§ 164.308(a)(1)(ii)(C)]
A. The Information Security Policy applies to all users of ORGANIZATION XYZ
information including: employees, medical staff, students, volunteers, and outside
affiliates. Failure to comply with Information Security Policies and Standards by
employees, medical staff, volunteers, and outside affiliates may result in disciplinary
action up to and including dismissal in accordance with applicable ORGANIZATION XYZ
procedures, or, in the case of outside affiliates, termination of the affiliation. Failure to
comply with Information Security Policies and Standards by students may constitute
grounds for corrective action in accordance with ORGANIZATION XYZ procedures.
Further, penalties associated with state and federal laws may apply.
B. Possible disciplinary/corrective action may be instituted for, but is not limited to, the
following:
1. Unauthorized disclosure of PHI or Confidential Information as specified in
Confidentiality Statement.
2. Unauthorized disclosure of a sign-on code (user id) or password.
3. Attempting to obtain a sign-on code or password that belongs to another
person.
4. Using or attempting to use another person's sign-on code or password.
5. Unauthorized use of an authorized password to invade patient privacy by
examining records or information for which there has been no request for
review.
6. Installing or using unlicensed software on ORGANIZATION XYZ computers.
7. The intentional unauthorized destruction of ORGANIZATION XYZ
information.
8. Attempting to get access to sign-on codes for purposes other than official
business, including completing fraudulent documentation to gain access.
98 | P a g e
SCI 407 Information Systems Security and Audit
The ORGANIZATION XYZ Information Security Policy requires the use of strictly
controlled passwords for accessing Protected Health Information (PHI), Confidential
Information (CI) and Internal Information (II). (See ORGANIZATION XYZ Information
Security Policy for definition of these protected classes of information.)
Listed below are the minimum standards that must be implemented in order to ensure
the effectiveness of password controls.
99 | P a g e
SCI 407 Information Systems Security and Audit
References
Information Security Principles and Practices, Mark Merkow and Jim Breithaupt, Prentice Hall
Computer Security Fundamentals, Chuck Easttom, Prentice Hall
Computer Security: Art and Science, Matt Bishop, Addison- Wesley
100 | P a g e
SCI 407 Information Systems Security and Audit
INSTRUCTIONS TO CANDIDATES
a) Answer ALL questions from section A(Compulsory)
101 | P a g e
SCI 407 Information Systems Security and Audit
QUESTION ONE
a) The key concept of ISMS is for an organization to design, implement and maintain a
coherent suite of processes and systems for effectively managing information
accessibility, thus ensuring the Confidentiality, Integrity and Availability of information
assets and minimizing information security risks. In the context of this define the
following terms.
QUESTION TWO
a) Passwords are the most common form of authentication security. Explain three qualities of a
good password. (3 Marks)
b) A quality information security program begins and ends with policy. Using Bulls’ Eye Model,
justify this statement. (4 Marks)
c) You work for a large organization that has developed a large scale ICT infrastructure which is
primarily used for its newly launched e-business applications. The organization has realized they
102 | P a g e
SCI 407 Information Systems Security and Audit
did not pay adequate attention to the security of its information resources. Management would
like to get a solution.
i. Identify ten major network threats to the information resources in your organization.
Explain how they will affect your company. (5 Marks)
ii. With aid of a diagram design suitable a security system for your company, clearly
identifying the major security components of your design. (8 Marks)
QUESTION THREE
a) Contingency planning and Business continuity planning is crucial in the event of disaster of great
Magnitude threatening the entire business operation.
(i) Explain the terms Contingency planning and Business continuity planning. (4
Marks)
(ii) Outline the options available in Business continuity Strategies. (6
Marks)
b) Explain the following terms as used in disaster recovery and business continuity strategies.
i. Cold sites
ii. Warm sites
iii. Hot sites (6 Marks)
QUESTION FOUR
103 | P a g e
SCI 407 Information Systems Security and Audit
iii. Patents
iv. Trademark (4 Marks)
b) An insurance company zigma has in the recent past experienced tremendous growth and
consequently grown and expanded in branch network. In one of the local branches, its performance has
been out of line with the rest of the branches. The management has decided to send auditors to unearth
the reasons for its dismal performance. In their course of duty they discover serious security breaches
with how data computer is kept and backed up. Additionally there is indiscriminate use of computer
resources including internet access by all and sundry. As an Information security Expert;
104 | P a g e