0% found this document useful (0 votes)
2 views104 pages

Sci 407 Issca Module Notes

The document outlines the course SCI 407 Information Systems Security and Audit at South Eastern Kenya University, detailing its purpose, expected learning outcomes, and content related to information security management and auditing. It emphasizes the importance of understanding information systems, their components, and the classification of systems, while also addressing the risks and controls associated with information security. Assessment methods for the course include assignments, projects, continuous assessments, and an end-of-semester examination.

Uploaded by

nyangau seth
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views104 pages

Sci 407 Issca Module Notes

The document outlines the course SCI 407 Information Systems Security and Audit at South Eastern Kenya University, detailing its purpose, expected learning outcomes, and content related to information security management and auditing. It emphasizes the importance of understanding information systems, their components, and the classification of systems, while also addressing the risks and controls associated with information security. Assessment methods for the course include assignments, projects, continuous assessments, and an end-of-semester examination.

Uploaded by

nyangau seth
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

SCI 407 Information Systems Security and Audit

SOUTH EASTERN KENYA UNIVERSITY

SCHOOL OF INFORMATION AND COMMUNICATION TECHNOLOGY

SCI 407 Information Systems Security and Audit

August 2020

1|Page
SCI 407 Information Systems Security and Audit

Course Purpose
The objectives of this course is to offer the students a holistic overview of Information Security issues
pertinent in an enterprise as well as the necessary Information Security Management systems,
aspects regarding IS Security Policy, Controls and Auditing of information security systems and
network infrastructure security.

Expected Learning Outcomes:


At the end of the unit, the learner should be able to:
• Explain in detail fundamentals issues involved in and the potential pitfalls of development,
installations, operations and maintenance of information systems.
• Explain in depth the relevant issues of IS audit and its significance in different systems.
• Describe and explain IS audit training, working, accreditation, and IS audit professionals
bodies
• Demonstrate a detailed understanding of the fundamental issues of information systems
security and assurance
• Develop an appreciation of computer internal and external threats to information systems
and appropriate countermeasures
• Demonstrate a detailed understanding of the current audit frameworks and standards
• Apply the acquired knowledge to secure and protect the information assets of an
organization

Course Content

Information Audit Planning Processes; Effective information system audit; Production of audit
Programmes; Role of audit in systems development; Audit automation and system testing; Data
forensics; Evidence security and preservation; Information security in computer and
communication systems; Security risks and hazards; Security control levels; Identification,
Authentication and authorization; Computer cryptosystems; Message Digest; Applications to
information schemes and digital signatures; Key distribution; Key agreement; Authentication;
Secret sharing; Security policies; Risk management.

Course assessment:
Assignments 5%
Project 10%
Continuous Assessment Tests 15%
Total Continuous Assessment 30%
End of Semester Examination 70%
Total 100%

2|Page
SCI 407 Information Systems Security and Audit

TOPIC ONE: INTRODUCTION TO SYSTEMS

The information and communication technologies (ICTs) advances made available enormous and
vast amounts of information. This availability generates also significant risks to computer
systems, information and to the critical operations and infrastructures they support. In spite
of significant advances in the information security area, many information systems are still
vulnerable to inside or outside attacks. The existence of an internal audit for information system
security increases the probability of adopting adequate security measures and preventing
these attacks or lowering the negative consequences.

NATURE OF SYSTEMS.
A System. Defn:
1. Is an assemblage of procedures, processes, methods, routines or techniques or components
united by some form of regulated interaction to form an organized whole.
2. Is a set of items, equipment, processes and/or people working jointly with an aim of achieving
a common goal(s).
3. Is a purposeful collection of interrelated components that work together to achieve some
objective.
- A system is established to achieve some specific objective(s) i.e. the system does some useful
job/task and should be active and efficient in its operations e.g. banking system
- The system has been identified by a person as being of special interest.
- The system breakdown whenever any of its components malfunctions or is removed.
- All systems have a boundary within which they operate. Outside this boundary is the
environment, from which (raw materials) inputs are communicated from and to which results
or outputs (end/finished products) are communicated to.
- Systems are made up of sub systems. The subsystems continually interact with each other.

Examples of systems
- Education system, Economic system, Political system, Transport system, Business system,
Heating system, Security system, Lighting system, Water system, Waste system, Drainage
system, Accounting system, Information system, all programs are systems, Library info
system, even human beings are systems.

3|Page
SCI 407 Information Systems Security and Audit

SYSTEM FUNCTIONS/COMPONENTS OF AN OPEN SYSTEM.

INPUT STORAGE
PROCESS OUTPUT

+ve or –ve
Feedback

CONTROL

1. Input

- The component that receives the raw materials from the environment and introduce them into
the system ready to be processed.
- The raw materials e.g. data to be processed into information must first be collected and
communicated from the external environment into the system (EDP) by the input function.
- In an Electronic Data Processing system data is collected and communicated from the external
environment and introduced into the system for processing into information. The input function
in an EDP system involves data collection, data capture and data entry.
- The nature of input is influenced by the nature of the system.

2. Process.
- The component of an open system which manipulates and transforms the raw materials (inputs)
into finished/end products or end results/outputs.
- In an EDP system input raw data is manipulated into information using the stored set of
instructions. The process may be manual, mechanical or electrical (automatic) to derive
information/end products.

3. Output
- Involves communication of the end products or outputs/results to the external environment to
the recipient/end users for consumption or to another data processing (information) system.
- In an EDP system information is produced in form of business report documents e.g.
statements, invoices, result slips, transcripts, bills (water, electricity) e.t.c.

4. Storage
- The component which stores inputs awaiting processing, intermediate results (semi processed
input) and finished products awaiting delivery to the consumers in the environment. In an EDP
system the storage media would be like tapes, compact disks, flash disks, cassette tapes etc
which are used to store master files, transaction files, sort files etc.

4|Page
SCI 407 Information Systems Security and Audit

- The nature of storage is determined by the nature of the system and the nature of what is to be
stored.

5. Control
- This component includes the feedback concept that furnishes descriptive information on the
input, storage and output functions or components of the system.
- Negative feedback, is when non standard or sub standard output is achieved, is meant to
regulate the system. Positive feedback encourages further output the way they are.
- The control system is usually stored within the system as programs, to relate and tie together
all the system components, if the system is computer based.

Importance of systems study


1. It provides a theoretical framework which allows performance of a system to be monitored.
2. It stresses that all sub systems must work in harmony in order to achieve the overall goals of a
system.
3. It recognizes the fact that conflicts can arise in any system leading to sub-optimization thus
making the system not to achieve its goals.
4. It allows an individual to recognize that he is a sub system within a big system.
5. The design of sub system must support the goals of the entire/total system.

Classification of systems.
Systems can be classified according to their openness or closeness.

Open system
- Is a system which communicates (interacts) with its environment. E.g. Business System,
Economic System, Information System, Transport System, Social systems etc. Open systems
can get disorganized i.e. when the system can not reorganize itself according to its internal
subsystem forces, the system therefore should be regulated. The process whereby the system
is regulated is known as negative feedback.
- Organisations as open systems attempt to monitor and anticipate environmental disturbances.
Some disturbances are so great or unexpected that they threaten the existence of the
organisation. All business organizations are open systems, for them to exist they must have the
capability to adapt in the face of changing markets conditions; globalization, liberalisation,
competition, technology, the law, conflict, etc.

Characteristics of an open system


1. It must be designed to achieve a predetermined objective.
2. A system contains a set of interacting elements or components.
3. The properties and the behaviour of the system components are inextricably intermingled.
4. An open system comprises of input, output, storage and processing as major elements.
5. A system operates within specified boundaries and interacts with other systems.
6. A system has some controls and these controls help it not to operate beyond its boundaries.
7. A system must give priority to the objectives of the whole system as compared to the objectives
of a subsystem.

5|Page
SCI 407 Information Systems Security and Audit

8. Successful functioning of each system component depends on the functioning of some other
components.
9. Systems are hierarchical in that, they include other systems i.e. subsystems. Note: Sub-systems
can operate as independent systems in their own right.

Closed system
- This is a system that doesn’t interact with the environment at all, which means the system
doesn’t communicate from (no inputs) or to (no outputs) its environment. Whatever happens
in the system doesn’t affect the environment and vice versa. It corrects and controls itself. Is
isolated from its environment. Are self-contained, environmental factors does not influence
their behaviour.
- They are more relevant to scientific, mechanical and physical systems else all social and
economic systems have some interaction with their environment.

OPEN SYSTEM CLOSED SYSTEM


1. Interacts with environment constantly 1. Doesn’t interact or react with the
environment at all.
2. Has an infinite scope 2. Has limited scope
3. Relevant variable keep on interacting 3. The variables are self contained
4. Generally flexible and abstract. 4. Rigid and mathematical

Open-Loop System
Is a system which does not act in controlled manner, i.e. there is no feedback loop and so no
measure of performance against standards. Control is external to the system, is not automatic and
can be made without monitoring the output of the system. It relies on externally imposed control.
E.g. A department without a budget system will have to be controlled from outside the department
– perhaps by cash limit, an immersion heater without an automatic thermostat. Control is therefore
not an integral part of the system and the heater must be externally controlled by switching it on
and off at appropriate times.

Closed-Loop System
Is a system that functions in a controlled manner, such a system accepts inputs, works upon them
according to some pre-defined processing rules, and produces outputs, so that a system can
function in a controlled manner, their must be feedback. A system which have control as integral
or part of the system & feedback based on output measurement so that necessary corrections are
made to the input. E.g. Mechanical systems like speed governors on engines, thermostats in heating
systems are totally closed loop systems, stock control system etc.

System can also be classified as


a) Deterministic (Mechanistic) System
b) Probabilistic System
c) Cybernetics/stochastic System

6|Page
SCI 407 Information Systems Security and Audit

1. Deterministic (Mechanistic) systems


- Is a system that functions according to some predefined/predetermined procedures and hence
their future behaviour can be predicted accurately or with 100% certainty depending on the
situation events. Is a system where you can foretell their output by their input.
- For their future to be predicted accurately, the current state of affairs and their operational
behaviour or properties are precisely known e.g. behaviour of a planet in its orbit, the solar
system, a computer program, a machine producing a component etc.

2. Probabilistic or stochastic systems


- System which depend on probability. You can’t foretell their future behaviour with 100%
accuracy/certainty.
- Expected output from its input can’t be predicted definitely because they have a variety of
uncertainties, therefore a lot of control effort need to be directed to these systems. E.g. Business
systems, Economic systems, Political systems, Industrial systems etc.

3. Cybernetic systems
- Also described as adaptive, self-regulating or self-organizing systems.
- Are systems that have to adapt to the environment for their survival. They adapt and react to
inputs or stimuli. The method of adaptation is uncertain and the same inputs do not always
produce the same responses. E.g. Social groups like human beings, plants and organisations
which have to react to their environment.

System classification depend on whether man-made or God made/creation


1. Natural system
These are systems which are God made or natural e.g. solar system, eco-systems, human being
and their sub-systems.

2. Artificial/Physical/Concrete systems
- Those created by human being. They are made/created by man rather than occur by nature.
- Physical systems consists of elements which are co-ordinated and operate as a whole entity to
achieve a certain objective(s) e.g. Transport system which consists of persons, vehicles, and
the organisation that transport goods and/or passengers, Computer system, Banking system,
cooling system, drainage system, heating, pumping system etc.

3. Abstract systems.
- An abstract system is an orderly arrangement of conceptual items or components.
- They can further be classified as
a) Procedural system – Refers to an orderly arrangement of procedures e.g. laws enforced.
b) Conceptual system – Refers to a symbolic system e.g. Einstein’s theory of the universe.
It is based on the principles that measures of motion, space and time are relative.

4. Human-machine systems
These are systems that are designed to help in accomplishing certain set goals e.g. help in decision
making. The machine elements e.g. hardware and software are relatively closed and deterministic
whereas the human elements of the system are open and probabilistic. These then implies that
these systems can be controlled e.g. the computer can be emphasised and the human person only

7|Page
SCI 407 Information Systems Security and Audit

monitors the machine operation. A good example is where the machine is used for regular
“programmed” decisions and it alerts the person to exceptions for processing as “unprogrammed
decisions”.

Discrete and continuous systems

Systems thinking/Systems approach


Definition: Is the application of formal systems theory and concepts to systems problem solving.
System theory and concepts help us understand the way systems are organized, and how they work.
Techniques teach us how to apply the theory and concepts to build useful real-world systems.

Note: A system can be described as being either soft or hard.

1. Soft systems
Human activity systems are said to be soft systems. They are described as soft because of three
main reasons:
(a) Their boundaries may be fluid or keep on changing.
(b) Their goals and objectives usually conflict and may not be captured clearly at any one time
because they are based on human factors like attitudes and preferences.
(c) It is difficult to precisely define exact measures of performance for them.
Example 1. A Political system. It is very difficult to model a system that will predict the political
mood in a country over a period of time.
Example 2. A sales tracking and prediction system in an organization. Sales in an organization
depend on human factors like attitude in the market place.

2. Hard systems
- Are systems whose goals and objectives are clearly defined and the outcomes from the systems
processes are predictable and can be modelled accurately. Such systems are based on proven
scientific laws like mathematical formulas or engineering solutions.
Example. A stock management system in a supermarket. It is possible to know exactly the
stock levels, cost and sale price and to predict accurately the profit if all the stock is sold.

NB: A good system incorporates both hard and soft aspects of a system. For example, a stock
management system should be able to show when the demand for a certain item rises so that a
decision can be made to stock more. New demand is driven by soft aspects in people’s lives like
attitude and seasons.

Hard properties are those that can be defined, measured or assessed in an objective way whereas
Soft properties are more imprecise and are matters of individual values and tastes. E.g. If an
organisation re-locate from Nairobi city centre to Machakos town. This has hard (i.e. measurable)
effects e.g. saving in office rent and also soft effects e.g. impact on morale and family life caused
by the disruption.

8|Page
SCI 407 Information Systems Security and Audit

TOPIC TWO: NATURE OF INFORMATION SYSTEMS.

1. Information System
Defn: Is a set of persons, procedures, technological and other resources that collects, transforms
and disseminates information in an organization. Computer Based Information System/EDP uses
hardware, software & live ware to provide information.

2. Management Information System. (MIS)


Describes a broad class of Information System that is designed to provide information needed for
effective decision making at various levels of management. These levels include:-
a) Basic business operations
b) Tactical decision making
c) Strategic decision making
MIS is a system that aids management in making/carrying out and controlling decisions. [Link]
provides routine summary reports on the firm’s performance. The reports are used to monitor and
control the business and predict future performance.

MIS Definition.
1. Is an assemblage of facilities and personnel for collecting, processing, storing, retrieving and
transmitting information that is required by one or more managers in performance of their
functions.
2. An integrated man-machine(s) system for providing information to support the planning,
controlling, organizing, managing operations and decision-making functions in an
organization.
3. Any telecommunications and/or computer related equipment or interconnected system or sub-
systems of equipment that is used in acquisition, storage, manipulation, management,
movement, control, display, switching, interchange, transmission or reception of voice and/or
data and includes, hardware, software and live ware.
4. It is a system using formalised procedures to provide management at all levels in all functions
with appropriate information, based on data from both internal and external sources, to enable
them to make timely and effective decisions for planning, directing and controlling the
activities for which they are responsible.

Management.
Is a process, in the sense of a sequence of operations or functions necessary to achieve certain end
results. Management is a human and social process, it’s a continuous process to the extent that the
cycle of stages or steps is never ending and it’s repeated over and over again.

Functions of management
1. Planning – management’s responsibility that requires the manager to formulate goals &
objectives & develop short-term and long-term plans to achieve these goals. Planning is
the managerial process of deciding in advance what is to be done, how it is to be done,
when to do it and by who(m) to do it. It is done on both a formal and informal basis and
the planning process uses info from internal and external sources. The process gathers,

9|Page
SCI 407 Information Systems Security and Audit

translates, understands and communicates info that will help to improve the quality of
current decisions which are based on future expectations.
2. Organizing and Coordinating – involves the development of an organizational structure &
a framework of standards, procedures & policies designed to carry out ongoing business
activities to achieve the required objectives.

3. Controlling – refers to managements’ responsibility to monitor and evaluate organisational


performance & the business environment so that steps can be taken to improve performance
& modify, as necessary in response to the marketplace. This includes keeping alert to new
opportunities in the marketplace & recognizing new business opportunities.
4. Staffing – refers to management’s responsibility for identifying the personnel needs of the
organisation & selecting the personnel as well as training staff. Many organizations have
personnel (Human Resource) managers to take charge of these activities.
5. Supervising – refers to management’s responsibility to provide employees with the
supervision, guidance & counselling necessary to keep them motivated & working
productively toward the achievement of the organisation’s objectives. This involves
recognition of good work, e.g. thro’ trips, certificates, bonuses, cash awards or other awards
and suggestions on how to improve performance. Educational seminars. W/shops may also
be held to upgrade employee knowledge of the company or perhaps to help deal with stress
and improve their health.
6. Motivating – Meeting the social & psychological needs of employees in the fulfilment of
organisational goals.
7. Directing

Levels of management
1. Strategic management, e.g. CEO, board of directors, board of trustee, board of governors

Characteristics of useful strategic information


a. Largely external
b. Largely concerned with the future
c. Qualitative and quantitative. Quantitative opinions, judgements, insights and
observations are vital, especially for political and social factors.
d. Largely informal.
e. Boundary free. Info is broad ranging and reflects a holistic view of the organisation.
f. Multi-dimensional. Strategic mgmt must consider all facets of problems at a wide
view.
2. Tactical management , e.g. all types of middle management, departmental managers, like
human resource manager, sales manager, accountant

Types of tactical level MIS


a. Decision support systems
b. Control systems
c. Database systems
d. Enquiry systems

10 | P a g e
SCI 407 Information Systems Security and Audit

3. Operational management, e.g. foremen, supervisor, chief clerk, data entry clerk, data
preparation clerk, computer operator, media librarian,

Note: Some organisation structures are tall and others flat e.g. Ford Company has 13 distinct levels
of management and Toyota has 6 levels.

Data are the facts, events, transactions and figures which have been recorded. Data represent
unstructured facts about events, objects, or people. They are the input raw materials from which
information is produced.

Information
Definition. Data that has been processed into a form that is meaningful to the recipient and is of
real or perceived value in current or prospective decisions. Information refers to data which is
organized and meaningful to the person who receives it. Information comes from selecting data,
summarising it, and presenting it in such a way that it is useful to the recipient.

Characteristics of useful and effective information


1. Accuracy - Information should be accurate as far as possible and if not, then the level of
accuracy should be within limits For information to be of value, it should be accurate and truly
reflect the situation or behaviour of an event as it really is. Otherwise, the user/recipient will
take the incorrect information as correct, may use it for decision making with a disastrous
result.
2. Format - Info is of value if it’s provided to the user in the form it’s useful and best understood
by him. E.g. top management level may require information on key matters in a summarized
form and the operations managers in detailed form.
3. Relevance – It refers to current utility of information in decision making or problem solving.
The information given to each manager should be relevant to his responsibilities and
authorities. The flow of information should be from one level to another in the direction of
where the decision is to be taken.
4. Brevity - Information should not only be clear but also brief. Brevity do not mean, matters be
left out but means maximum info be communicated in minimum words. Graphs, charts, tables,
and figures help in making the information brief i.e. a picture is worth a thousand words.
5. Timelines - Information should be made available to the recipient when it is needed for a
particular purpose and not either before or after the time it’s needed. Delayed information has
far less value.
6. Completeness - Information is considered as complete if it tells the user all what he wishes to
know about a particular situation or problem. The more complete the information is, the higher
its value.
7. Purpose - The basic purpose of information is to inform, evaluate, persuade or organize other
information, create new concepts, identify problems, solve problems, decision making,
planning, initiating, controlling and searching.
8. Reliability - Information should be reliable or dependable.
9. Validity - It measures the closeness of the information for the purpose which it purports to
serve.
Note: To support making of intelligent & knowledgeable decisions, information generated at all
levels of management must be: - Correct (accurate), Complete (include all relevant data), Current

11 | P a g e
SCI 407 Information Systems Security and Audit

(be timely), Concise (include only relevant data), Clear (be understandable), Cost effective (be
efficiently obtained) and Time sensitive (be based on historical, current, and/or future information
and needs as required).Effective information is that from a source the user has confidence,
communicated to the right person, communicated in time for its purpose, that which contains the
right level of detail, communicated by an appropriate channel of communication and that which is
understandable by the user.

Functions performed by information / (Importance/significance) of information


1. It improves the knowledge of management or individuals to be able to make sound decisions.
2. The reduction of uncertainty. Relevant information helps to reduce the uncertainty/unknown
especially in planning and decision making.
3. As an aid to monitoring and control. By providing info about performance and the extent of
deviations from planned levels of performance management are better able to control
operation.
4. As a means of communication. Managers need to know about developments, plans, forecasts,
and impending changes etc.
5. As a memory supplement. By having historical info about performance, transactions, results
of past actions and decisions available for reference, personal memories are supplanted.
6. As an aid to simplification. By reducing uncertainty and enhancing understanding, problems
and situations are simplified and become more manageable.

System
The word system connotes plan, method, order, and arrangement. A system is a regularly
interacting or inter-dependent group of items forming a united whole. A system is thus a set of
interacting elements with each other to achieve a predetermined objective or goal. Each system is
composed of sub-systems. Thus every system is part of a larger system. E.g. an A/c or finance dept
is a subsystem of an organisation. The organisation contains other subsystems like Production,
Marketing, ICT, Research & Development, Public relations etc.

- The information in respect of any system helps the management to make some important
decisions. So the information systems are developed to help the managers in their decision
making process. The decision making process is based on the support of the information system
in the organisations. The managers must be aware of the problem before a decision is made. A
problem exists when real situation is different from the expected one. After the problem has
been identified, the causes of existence of the problem must be identified and then the solution
to the problem has to be found.

Objectives of M.I.S.
1. M.I.S is a systematic procedure to provide relevant information in right time, in right format, to
all levels in the organization, for providing support to the decision making activities in the
organization.

Main objectives of an efficient M.I.S


1. Facilitates the decision making process in an organization by providing all levels of
management with accurate timely information to help the managers in selecting the best cause
of action.

12 | P a g e
SCI 407 Information Systems Security and Audit

2. Provide each manager at each level, the planning and control tools and help in highlighting the
critical factors to be closely monitored for successful operation of the organization.
3. Help the management in getting the required information for controlling the activities of the
organization.
4. Create a process of communication with information wherein information is recorded, stored
and retrieved for decision making, planning, operation and control within an organization.
5. Evaluate an approach to information system design that conceives the business enterprise an
entity composed of interdependent sub-systems, which will permit optimum management
decision making.
6. Provide a system of people, equipment, procedures, documents and communications that
collects, validates, operates on, transforms, stores, retrieves and presents data/information for
use in planning, budgeting, accounting, controlling and other management processes.

Characteristics of an effective/well-designed M.I.S


1. Flexibility - All organizations are dynamic and changes occur because of a wide range of
reasons. A good/effective MIS must be able to adapt to meet these changes.
2. Reliability - is crucial to performance and can be ensured only by thorough checking and
testing.
3. Simplicity - Simplicity in design will find its way thro’ the system. Simple systems will be
easy to operate and control.
4. Economy - The MIS should be cost-effective. Cost should be carefully monitored once the
system has been implemented and compared with the original budget.
5. Helpfulness - The MIS should help in the planning, operation and control of the business.
6. Consistency - The MIS should be consistent.
7. Management-oriented - Development of the information system efforts should start from an
appraisal of system needs and overall business organisation objectives. Such a system isn’t
necessarily for top management only, it may also meet the information requirements of middle
level or operational levels of management as well.
8. Management-directed- Because of management orientation of M.I.S, it is necessary that
management should actively direct the system’s development efforts. For system’s
effectiveness, it is necessary for magmt to devote their sufficient time not only at the stage of
designing the system but also at its review stage as well, to ensure that the implemented system
meets the specifications of the designed system.
9. Integrated - Developed M.I.S should be an integrated one i.e. the functional and operational
information sub-system should be tied together into one entity. An integrated info system has
the capability of generating more meaningful info to management.
10. Subsystem concept - Even though the MIS is viewed as a single entity, it must be broken
down into digestible sub-systems which can be implemented one at a time by developing a
phasing plan. The breakdown of MIS into meaningful sub-systems sets the stage for this
phasing plan.
11. Common database - A database is a motor that holds the functional systems together. It’s
defined as a super file which consolidates and integrates data records formerly stored in many
separate data files.

So Management Information System includes


1. Decision Support System (DSS)

13 | P a g e
SCI 407 Information Systems Security and Audit

2. Executive Support System ( ESS)


3. Management Information Systems (MIS)
4. Expert Systems (ES)
5. Office Automation Systems (OAS)
6. Transaction Processing System (TPS)

1. Decision Support Systems ( DSS)


- Is a type of MIS that is more user friendly It’s a set of programs and hardware that allows
managers to interact with it to help make decisions. Its intended to help high level managers in
their decision making. Its used in planning, modelling, analyzing alternatives and decision
making. It’s designed to improve the analytical capability of the decision maker.
- This system helps to solve semi-structured problems. A semi-structured problem is one in
which only parts of the problem have a clear-cut answer produced by a well accepted
methodology.

Objectives of a D.S.S.
1) Analyze unexpected problems.
2) Interprete information flow and decision making activities.
3) Support all management levels
4) Be easy to use yet powerful and flexible.

Characteristics/Qualities of an effective D.S.S.


1. Its decision focused and provides an access to an array of decision and analytical models.
2. Provides support for unstructured complex decision making problems.
3. Its design is oriented for top management functions where a lot of external information is
also used.
4. Presence of a comprehensive database and a model base, providing flexibility, adaptability
and quick response to the user.
5. Its suitability to the personnel decision making styles of individual decision makers.
6. Its capability to simulate business decisions mathematically and predict the result that will
occur from taking one course of action versus another.
7. It has strong analytical capability.
8. Ability to analyze non-routine problems.
9. In supporting decision making process DSS, neither replaces judgement nor makes a
decision for the users.
10. Ease to use i.e. its user friendly.
11. Supports decision making and problem solving at all levels of an organization.
12. Enhance co-ordination between the decision makers especially when many people have to
co-operate to make decision.
13. Should be process independent and user controlled so that the user can direct the problem
solving or decision making.

M.I.S. D.S.S.
1. Supports decisions by management 1. Provides technical decisions.
2. Assist in making structured decisions for 2. Assist in semi-structured and unstructured
operational & tactical planning control decision usually at top level (strategic level)

14 | P a g e
SCI 407 Information Systems Security and Audit

3. Indirect support design for managers 3. Direct support tailored for decision making
by style
4. Periodic exception and on demand 4. Interactive inquires and responses
structured reports
5. Format is pre-specified i.e. fixed 5. Format is flexible and adaptable
6. Information is produced by mathematical & 6. Information is produced by analytical
statistical analysis of data modelling
7. Uses hardware/software and databases 7. Uses hardware & model bases
8. Controlled by information systems 8. Controlled by end users
specialists

Components/elements of D.S.S
1. Data. The data input is obtained from Transaction Processing System i.e. source documents
2. Model - The system uses models e.g. linear programming to allow evaluation and analysis of
different alternatives under similar constraints.
3. User Interface – The use of G.U.I. (Graphic User Interface) which allows the manager enter
commands and seek answers during interrogations.
4. Decision Maker - The system requires a manager with vast training, experience and
management acumen.
5. Hardware
6. Software. Types of software necessary.
a) DBMS for managing a large database is needed.
b) Simulation and application languages to be used in model building.
c) A DSS query language as communication link.
d) DSS executive software for handling the operational duties of DSS.

Types of D.S.S.
1. Ad hoc. Are general DSS designed to handle a wide variety of management decision problems
and are especially suited to unexpected, non-recurring management problems.
2. Institutional. Are special and use terminology and analysis procedures established within
certain areas like medicine, engineering etc.

D.S.S applications i.e. where to apply DSS


1. Where there is enormous computation
2. Where there is large data manipulation.
3. Where there is a large database
4. Where judgement is required in a complex situation to determine the problem and solution.
5. Where there are complex inter-relationships.
6. Where several people are involved in problem-solving and decision making process, each
contributing some special expertise, then the coordinating power of the computer is needed.
7. Where there is analysis by stages.
8. Where human judgement is required.
9. Marketing
10. Accounting
11. Sensitivity risk analysis

15 | P a g e
SCI 407 Information Systems Security and Audit

Tools/packages that can be used in D.S.S include:-


1. Linear programming
2. Regression modelling
3. Sensitivity & risk analysis using spreadsheets.

Main areas of interest


1. Where the problem is too complex to be solved manually
2. Where there is a need to conduct sensitive analysis involving computations
3. Where several people are involved in problem solving activities.
4. Where personal judgment is required without much need of automated program.

Executive Support Systems (E.S.S)/Executive Information Systems (E.I.S.)

Is a special easy-to-use MIS designed for top magmt people who are not familiar with computer
systems. They use graphics and touch screens to aid senior executives in collecting & obtaining
the info they want. Is a software application that seeks to capture expertise in limited domains of
knowledge and experience and apply this expertise in order to solve some problems. ESS provides
managers with a flexible means of accessing information of tactical and strategic levels. ESS helps
the managers to drill into the data, present the information in appropriate formats and find the
information they need whenever they need it.

Characteristics of ESS
1. Convenience - The system must be easy to use, convenient and fast enough to reduce time
wastage. The use of touch screens, icons, mouse, menus i.e. WIMP-Windows, Icons, Menus,
and Pull-down menus is therefore important.
2. Easy access to data - There should be rapid access to data which permits both vertical and
horizontal drilling, evaluation and explorations.
3. Data analysis - ESS should provide facilities for projections and analysis. Thus ratio and
trends, calculations, business forecasts e.t.c are common. Provide tools for analysis and also
provides presentation aids.
4. Quality of presentation - ESS provide efficient and understandable formats using colours,
graphs, diagrams & tables.
5. Are ease to use.

Advantages/benefits of an ESS
1. It can be able to account how it has arrived at a given decision.
2. Can solve problems in a given domain well or better than human decision makers.
3. They are not emotional in their decision making. A human begin may at times be controlled
by emotions
4. Can apply human knowledge to a well understood problem.
5. One doesn’t need to be an expert because a clerk can be as good as a consultant if he is
supported by an ESS.
6. Avails information on demand.
7. Uses graphics which are easy to understand.
8. Provides opportunity to identify information useful to a system.

16 | P a g e
SCI 407 Information Systems Security and Audit

Management Information Systems (MIS)/Information Reporting System (IRS)


Provides middle management with reports that summarize & categorise info derived from all the
organizations’ databases. The purpose of the report is to allow magmt to spot trends & to get an
overview of current activities, as well as to monitor & control operational-level activities.
Note: Although the term MIS is used to refer specifically any type of info system for managers, it
is also used to refer specifically to middle management information systems. The scope of the
reports & the features of their info vary according to the purpose. There is less need at the middle-
management level for instant info than at the operational level. Reports can be periodic e.g. income
statements, balance sheets, on demand or event initiated.
Examples of reports generated by an MIS:-
 Sales region analysis
 Annual budget analysis
 Capital investment analysis
 Production schedules

Transaction Processing System (TPS)/Operations Information System (OIS)


Data or information processing systems perform the essential role of collecting and processing the
daily transactions of the organisation, hence the alternative term, transaction processing system.
Can be centralized or distributed data processing system. These includes all forms of ledger
keeping, accounts receivable and payable, invoicing, credit control, rate demands and stock
movements. TPS represents the lowest level in an organisation’s use of information systems. They
provide management with basic raw materials used for DSS to produce management reports such
as sales analysis figures etc. They mainly keep track of elementary and routine activities and
transactions of the organisation, such as sales receipts, cash deposit, payroll, credit decisions.
Support of day-to-day business operating activities or transactions is the first and most important
objective of an information system. A computer-based TPS/Operations Information System or
EDP system is focused at the operational level of the business.
The management info produced by TPS consists of detailed reports of daily transactions (e.g. list
of items sold or all the accounting transactions that have been recorded in various ledgers and
registers or future transactions e.g. list of items that need to be ordered.
TPS operate in only within one functional area of business e.g. Marketing, R&D, Accounting &
Finance; Production has its own TPS.

Characteristics of Transaction Processing Systems (TPS)


They:-
1. Are pre-specified (i.e. their functions, decisions, rules and output formats cannot usually be
changed by the end-user)
2. Are the source of data for other information systems e.g. DSS
3. Interact with the business environment
4. Are oriented towards the operational level of management.

Artificial Intelligence (AI)


- Is a new field/branch of computer science which researches and seeks, to produce systems that
are intelligent i.e. systems that are capable of simulating or mimicking human intelligence. AI
involves the ability of the computer to perform human thinking and reasoning.

17 | P a g e
SCI 407 Information Systems Security and Audit

- Areas were AI is applied are; Machine learning (to create machines or computer systems that
are able to learn new concepts all by themselves); intelligent computer-aided learning systems;
intelligent robots; language understanding and communication; machine vision systems; and
expert systems (machines that mimic human expertise so that they can be used for day-to-day
problem-solving and decision-making in domains of expertise just like human experts, by the
experts themselves, or by those less-qualified).

Expert Systems (ESs)/Knowledge-Based Systems(KBSs)


- Are currently the most commercially successful products of AI research. Have emerged from
the field of AI, which is the branch of computer science that is attempting to create computer
systems that simulate human reasoning and sensation. Are computer programs that copy the
knowledge of human expertise in a particular field. Acts as a consultant or expert to the user.
- An ESs is a knowledge intensive program that solves a problem involving human expertise. It
can assist in decision making activities by asking relevant questions and explaining the reasons
for adopting certain actions. Such program are important in that:-
(a) They preserve knowledge of experts that can be lost thro’ death or retirement.
(b) Put info in active form to be summarised immediately.
(c) Assist juniors to think like professionals
(d) Save time associated with training or employment of experts
- Are used in different sectors of society to enhance the decision-making and problem-solving
of experts in various domains.
- ESs are forms of computer systems with an increasing range of applications within the different
domains of expert decision-making and problem-solving in all sectors of society.
Examples: Medical and Legal expert systems.

Characteristics/features of an Expert system


(a) Solves problems just like human experts or even better than them
(b) Uses artificial intelligence in form of rules

Applications of ESs
- ES technology is in use in an ever widening number of commercial applications such as
education/training, engineering and manufacturing, computing, banking and finance, law,
marketing and advertising, insurance, medicine, agriculture, geology and chemistry/chemicals.
- Used in surgery, security and helps users in making investment decision.
- Are also used in medical research, diagnosis, geological prospecting, predicting crop disease,
mass-spectrogram interpretation, accounting, personnel and management.
- Investment decisions e.g. mergers, acquisitions, raising capital etc
- Marketing policy, Taxation policy
- Most ESs can enhance the productivity and performance of inexperienced users but not
improve their knowledge ESs or Knowledge-Based Systems (KBSs) are computer programs
which mimic the performance of a human expert in limited areas of expertise.
- Are developed to assist human experts or to be used by the less experienced (or novices) in
areas (or domains) of knowledge.
- ESs makes use of a stored representation of the knowledge and experience of experts working
in well-defined areas of knowledge. They usually represent this knowledge in the form of rules
& sometimes as some sort of description of important characteristics relevant to the problem.

18 | P a g e
SCI 407 Information Systems Security and Audit

They can generate explanations for their ‘reasoning’, answer why and how they reached their
decision & in general present their information in a way that is easily understood.
- They capture not only factual but also judgmental knowledge. They are capable of qualitative
reasoning in fuzzy areas of problem-solving and decision-making, such as when the
information is incomplete or uncertain. ESs are mainly used to solve problems that are not
solvable with conventional algorithmic and diagnosis.
- Are designed with the help of human experts who solve a range of problems and describe their
thought processes as they proceed. The programmer (in this case a knowledge engineer)
attempts to transfer the knowledge & methods of reasoning of the expert into a computer
program that captures it. It is impossible to complete the building of an ES in a single devpt
phase to incorporate all the expertise it requires.
- It is normal to progress through a series of prototypes, each one becoming more comprehensive
and sophisticated.
- The initial & in many cases most time-consuming task is concerned with the structuring of the
knowledge and rules that cover routine basic activities often considered as trivial by the human
expert. Thereafter, the system is made to incorporate the more expert tasks by being continually
updated to reflect new knowledge and information. The knowledge is codified in high level
computer languages such as LISP, FRANZ LISP & PROLOG.
- Knowledge is also codified in existing expert systems shells such as Emycin, Expert, AL/X,
Loops, Nexpert objects, Flex e.t.c.
- The systems contain an inference engine without a domain knowledge base – to be included
later.

Additional applications of Expert Systems


Medical diagnosing (e.g. MYCIN), Personal tax planning, Product pricing, Selection of selling
methods, Statutory sick pay entitlement and claims, Credit approval in banking, Air crew
scheduling, Geological exploration (e.g. PROSPECTOR), Financial planning, Software
application assistance (e.g. on line help systems or ‘help wizards’)

Generalized architecture of an Expert System.


Facts Base
- Made up of the immutable facts of the domain, together with the facts involving the particular
problem to be solved.
- Facts base is also known as the working memory of the system.

19 | P a g e
SCI 407 Information Systems Security and Audit

Knowledge Base/Database
- Contains data conditions etc about the problem under interrogation. It stores knowledge of
human expert in the form of rules.
- Is where all the knowledge of the field is stored. It consists of rules (or other knowledge
representation formalisms - objects, frames or sematic networks). Rules permit deductions to
be made from the given facts, so as to add new facts to the knowledge base.

Inference
Engine

User Facts Knowledge


USER Interface Base Base

Inference Engine
- A computer program which formulates questions and draw conclusions. It acts a rule
interpreter.
- Is a general purpose problem-solving module of the ES that acts as the control scheme which
directs the firing of rules of the Es.
- It uses the knowledge base to reason about the problem, given the contents of the facts base. It
is made up of a patterned matching algorithm or fitter that examines the conditions of a rule to
find whether or not it holds, according to the contents of the facts base.

Explanation software
- It interprets and analyses the results from inference engine.

User Interface
- Enables the user to interact with the Expert system.
- Due to the ability of ESs to tackle problems within areas that require knowledge and experience
(abilities which conventional computer programs do not have), they can assist many categories
of workers in different areas of work.
- ESs can be used to do the following types of problem-solving: Interpretation, planning,
monitoring, diagnosis, assistance in design/development, control/optimization,
education/training and design evaluation.

Benefits of an Expert System are;


1. Consistency, portability, permanence, flexibility, effectiveness and efficiency.
2. ESs can also be designed to help organizations develop a ‘knowledge bank’ (a store) of the
composite knowledge of their members.

20 | P a g e
SCI 407 Information Systems Security and Audit

3. The components of the knowledge bank could be in the form of strategic planning/decision-
making knowledge, rare skills/expertise archiving, knowledge gained from in-house experts or
knowledge gained from exit interviews of experts who were leaving the organization.
4. ESs can be used to handle, interpret and analyze large amounts of data for national planning.
ESs can be used in rural areas where highly experienced managers, doctors, accountants or
lawyers might not want to work. They can be used by less experienced people to reach the
same level of decision-making in the domain as the experts.

Office Automation Systems (OAS)


This describes the phenomenon of merging computing and telecommunication technologies to
produce the electronic office, alias/a.k.a. ideal/paperless/automated/modern office. OAS involves
intensive and extensive application (use) of ICT in modern offices. ICT/OAS is the acquisition,
processing, storage, and dissemination of vocal, pictorial, textual and numeric information by a
micro-electronic based combination of computing and telecommunication systems.

Objective of office automation system (OAS)


1. Facilitates faster and more accurate data processing operations.
2. Access more extensive data over a short period.
3. Lowers operating costs by reducing labour and clerical expenses
4. Removes/reduce stationery and related resources from offices thus reducing operating costs.
5. Encourages telecommunication integration which altogether reduces production and
distribution costs.

Spectrum/range/variety of Office Automation Systems (OAS)

1. Electronic Publishing Systems – Manipulate word, numbers and images to meaningful


documents like newsletters, books, letters, project proposals, reports etc. This includes:-
a. Word processing systems
b. Desktop publishing (D.T.P.) systems
2. Electronic Communication Systems
a. Electronic mail
b. Voice mail (Voice store and forward) – Involves use of digitized voice messages
rather than electronic text. You first dial the number of voice mail service. In some
secure systems, you may be asked to enter an identification code. Once you are
accepted, you dial the voice mail number of the person you wish to contact and
speak your message.
c. Facsimile (Fax) allow organisations send messages in text, video, voice form and
transmit copies of document within seconds reducing flow of paper messages.
d. Cell phones
3. Electronic Meeting Systems (EMS) or Video conferencing – Involve use of video and audio
communications to allow conferences & meetings to be held by participants who are scattered
across the room, a building, a country or the globe. Reducing need to travel to & from meeting,
saving employee time, increase productivity and reduce travel expenses and energy used.
4. Teleconferencing – Is a form of EMS. Sessions are held in real time, with major participants
being televised while participants at remote site usually take part with voice input of questions
& responses. Several communication carriers & hotel chains now offer teleconferencing

21 | P a g e
SCI 407 Information Systems Security and Audit

services for such events like sales meetings, new product announcements & employee
education & training.
5. Office Management Systems (OMS) – Is an office automation category that integrates
electronic calendars, tickler files, electronic mail directories, schedulers and task management
systems. Provides computer-based support services to managers & other office professional to
help them organise their work activities. Office management s/ware computerizes manual
methods of planning e.g. paper calendars, appointment books, directories, file folders, memos
and notes. OMS can help end users & work groups organize routine office tasks e.g. you could
enter the date & time of a meeting into an electronic calendar. Tickler file will automatically
remind you of important events. Electronic scheduler use the electronic calendar of several
people to help you schedule meetings & other activities.
6. Telecommuting (Teleworking) – Is the use of telecommunication links by workers to replace
commuting to work from their homes or to carry out work activities from temporary locations
other than offices & homes. Telecommuter can access their organisation’s’ network and
databases. Telecommuting workers & their colleagues also use e-mail or voice mail to
communicate with each other about job assignments. Telecommuting is being tried by major
corporations and independent professionals. It’s most popular with people whose jobs involve
a lot of individual work e.g. programmers. It is especially useful for the handicapped persons
and working parents of young children.
7. [Document] Image processing – It allows users to electronically capture, store, process &
retrieve images of documents that may include numeric data text, h/writing, graphics &
photographs. Electronic Document Management (EDM) is based on image processing
technology. EDM may interface with other systems e.g. w/processing, DTP, e-mail and voice
mail. Image processing has improved productivity and has resulted to significant cost savings.
8. Videotext – Refers to sending & receiving information & displaying it on screen using either
broadcasting (Teletex) or telephone lines (view data)
9. Computer output on microfilm (COM)
10. Graphic user interface (GUI)

11. E-business and E-commerce.


a. Teleshopping – Stock enquiry & ordering, mail order, purchase of goods &
services, airline, theatre reservation.
b. Telebanking - Electronic Funds Transfer (EFT), the switching of monies to &
from bank accounts using telecommunication facilities.
c. Global Positioning System (GPS) that uses satellites to track a user’s position,
velocity and time in their location. M-commerce with the use of GPS will enable
users and merchants to disseminate receive and access info and services specific to
their location (e.g. find hotels, bank cash point locations, shopping centres etc.
12. Telesoftware – Downloading of computer s/ware
13. Telepublishing – Encompasses electronically published books, educational materials,
newspapers etc.
14. Electronic Data Interchange (EDI) – Direct computer to computer exchange of standard
business documents e.g. invoices, bills of lading and purchase orders, between two separate
organizations. EDI transmits an actual transaction as opposed to text message as in e-mail.
15. Teletext – Is a non-interactive (i.e. one way) form of videotext transmitted as part of a TV
broadcast. The number of frames sent are restricted to keep down the waiting time. It’s used

22 | P a g e
SCI 407 Information Systems Security and Audit

by BBC and ITV for newsflashes, and subtitles etc. To receive these info customers can rent
or buy special Teletext receivers or adapters for existing 625-line television sets.
16. Multi-media conferencing,
17. Use of cell phones to conduct office operations/activities.
18. Use of electronic spreadsheets, Databases, Graphics application packages in modern offices.
19. E-marketing; B2C, B2B, C2B i.e. Business to Customer, Business to Business, Customer to
Business etc

23 | P a g e
SCI 407 Information Systems Security and Audit

TOPIC THREE: INFORMATION SYSTEMS SECURITY

Definition: Information systems security is the policies, procedures and technical measures used
to prevent unauthorised access, alteration, theft or physical damage to information systems. It
involves the safeguards required to protect info systems against threats/hazards which might cause
unauthorized modification, disclosure, destruction of data/information or software. Security
controls should be put in place to protect computer based-information systems (hardware,
software, live ware and database) against the hazards to which computerized information systems
are exposed. Security controls help assure high systems standards and performance by protecting
the system against hardware, software, and live ware failure.

Protection should cover the following areas:-


1. Data and information from hazards and abuse.
2. Unauthorized use of the computer and allied resources.
3. Accidental alteration of data, programs, and information.
4. Privacy of data, information and programs.
5. To ensure both hardware and software have longer life span.

Environmental threats/hazards to information systems resources.


1. Fire – Is the most serious and costly hazard as it utterly destroys everything i.e. data,
information, software, hardware, live ware, ancillary equipment and the premises. To
fight/avoid fire:-
a. Use halon gas fire extinguishers, as carbon dioxide extinguishers will endanger any
trapped personnel and the water extinguishers will damage the hardware and storage
media.
b. Store storage media in fire proof cabinets and lockable metal boxes.
c. Install smoke detectors.
d. Training staff on fire fighting skills.
e. Strict observation of safety procedures e.g. avoiding smoking in computer installations
premises.
f. Place exit signs in conspicuous positions.
2. Water/Flood and moisture. Causes the metallic components to rust. Floods cause serious
damage to hardware, network cables and wiring. Security measures against this hazards
includes:-
a. Setting up computer rooms on higher grounds to avoid floods. Avoid installation of the
information system in the basement especially in flood prone areas.
b. Adequate drainage system.
c. Use of water proof ceilings and floors.
3. Other natural disasters. Includes cyclones, hurricanes, lightening and earthquakes. Protection
against natural disasters should be considered when choosing the location of the computer
information system.
a. Avoid areas prone to floods, lightening and tremors.
b. Erect lightening arrestors.

24 | P a g e
SCI 407 Information Systems Security and Audit

4. Excessive heat or temperature. Excessive heat or temperature form the computer itself or
outside the environment can destroy computer storage media or devices. Security measures:-
a. Efficient ventilation system.
b. Installing cooling systems in the computer rooms e.g. use of fans and air conditioners.
5. Civil strife and Terrorism. Terrorist attack includes activities like political terrorists e.g.
bombs, criminal types of activities, hooliganism, individuals with grudges and people
intending to cause general disruption. Security measure includes:-
a. Control physical access to the premises housing the info system i.e. comp labs, comp
rooms, computer resource centre, IT centre, the name various from one organisation to
another.
b. Avoided terrorism and hooliganism triggering activities e.g. exploitation of workers.
c. Consult with police and fire authorities/brigade about potential risks and co-operate
with them conscientiously.
6. Sabotage. It is one of the greatest physical risks to computer installations. Saboteurs can do
enormous damage to computerized info systems with little risk of apprehension e.g. bomb can
be planted, a communication line can be cut or disconnected, deadly computer virus can be
deliberately introduced etc. Providing adequate security against such acts of sabotage is
extremely difficult and expensive.
7. People threats. These include carelessness, clumsiness and accidental destruction/erasure of
data, info or programs as well as theft and piracy of data & software. Security measures:-

a. Have a good office layout e.g. such that the supervisor can see what the people under
him are doing.
b. Limit access to sensitive organisation information.
c. Have lockable and disk locks.
d. Terminate/dismiss employee with a penchant of misusing the computer resources or
re-locate them to another department.
e. Careful recruitment of staff.

8. Environmental problems/conditions. More often that not computers are housed in premises
that were not originally meant to contain them. This can bring about environmental problems
e.g. water and steam pipes may run near or thro’ a computer lab, where bursting pipes could
cause extensive/considerable damage to the info system. Database on storage media can be
destroyed by magnetic fields emanating from electric motors in the vicinity. External radiation,
smoke and dust from the surroundings are also hazardous to comp info systems especially
storage media. Environmental problems include brownouts (temporary power surges (drops)),
power spikes, power failures, Measures to counteract these:-

a. Locate IT centre away from this threats.


b. Thorough and regular cleaning of the computer labs.
c. Covering the computer and allied resources with water proof plastic dust covers when
they are not in use.
d. Have dust mats, double door and monitoring devices to prevent entry of dust,
e. General building safeguards, use slab for the walls, water proof ceiling and roofs and
easy to clean floor.

25 | P a g e
SCI 407 Information Systems Security and Audit

f. Use UPS, power stabilizers, surge protectors, voltage regulators etc to protect the
h/ware from power fluctuations.

9. Computer virus. This is a computer program developed by malicious computer programmers


for destructive or disruptive purposes. They are hidden instructions that become attached to
other programs or files and cause them to malfunction. It’s a rogue program that spreads
rampantly through computer systems, destroying data or causing the system to become
congested and malfunction. Examples of computer viruses; Melissa, Nimba, Code Red,
Sircam, Love Bug, Egerton Lab, Amoeba, Friday the 13th, etc. They can be passed from one
computer to another (spread) thro’ secondary storage media, thro’ data transmission in
computer networks, downloading affected files from the internet, and thro’ e-mails or
malicious employees can knowingly or unknowingly introduce virus in an organizations
information system. Other sources of virus spread include; pirated software, games programs,
freeware & shareware. Security measures to curb virus threat:-

a. Install anti-virus software in the info system and scan storage media regularly.
Examples of anti-virus MacAfee, Kaspersky, Dr Solomon’s anti-virus toolkit, Norton
anti-virus,
b. Avoid freeware and shareware which have been prime entry point for viruses.
c. Storage media for the organisation should not be used elsewhere and private media
should not be used in the organisations computer systems, unless under special
circumstances and express authority is granted by the ICT depart top management.
d. Make backup copies as soon as you open new software package and store the copies
off-site.
e. Quarantine each new piece of software on an isolated computer and review it carefully
before installing it on a network.
f. Restrict access to info system resources to only the authorised personnel.
g. Check all programs regularly for change of size, which could be a sign of tampering or
virus infiltration.
h. Institute a plan for immediate removal of all copies of suspicious programs and back
up of related data.
i. Make sure all purchased software is in its original wrapping or sealed-disk container.
j. Install firewall. Firewall is a device that stands in btw the organisations network and
the internet checking any type of incoming and outgoing traffic that could potentially
damage the network & the organisation’s information system. It stops the viruses in the
internet finding way into the organisation’s computer information system.

10. Cyber crime. Computer criminality is another threat to computer info system security
especially software. Computer crime takes different forms. This includes outright theft of
cables, h/ware, storage media etc., software piracy, theft of computer time, financial fraud,
funds embezzlement, unauthorized alteration of programs and data, theft of computer time,
data/info theft (commercial espionage), and malicious destruction of database/hardware or
software, unauthorised access (hacking and cracking).

26 | P a g e
SCI 407 Information Systems Security and Audit

Note: Hackers gain unauthorised access to computer systems mainly for the fun and thrill of it
whist Crackers gain unauthorised access to computer systems in order to perpetrate theft for
profit, for criminal mischief or for destruction.

Physical security:

This includes:-

1. Hiring of security guards to control access to the building housing the info system.
2. Using keyboard locks on terminals used by authorised users.
3. Use of disk locks and disk banks.
4. Strengthening computer labs by putting strong window grills and metallic doors.
5. Installation of electronic surveillance system. This is used by the supervisors of the computer
and other electronic equipment to monitor worker’s performance often without their
knowledge.
6. Data encryption. Data is often sent in coded or encrypted, form over communications lines to
keep it secure from unauthorised eyes. Encryption is the encoding of data by converting the
standard computer code into a secret code for transmission. After delivery to the destination
the data is converted back (decrypted) into standard computer code.
7. Use of passwords – a password is a secret code (word, numbers, symbols or a combination)
that must be typed in to gain access to a computer system, a program or a database/file. An
effective well-designed password is that which can not easily be guessed by hackers or crackers
trying to break into a computerized information system.
8. Biometrics – Is the use of individual body characteristics instead of passwords to gain entry
into the computer system e.g. finger print, kiss on screen, lip prints signature, photograph etc.
9. Set up a clear and firm management system security policy on crimes and frauds.
10. Monitor and investigate error logs and reports on regular basis.
11. Carry out risk analysis to examine the organisation’s exposure to possible fraud.
12. If possible let there be only one entrance and one exit for ICT centre with trained security
guard(s) stationed there.
13. Establish effective security procedures e.g. for regular back up software and database.
14. Paper shredders. Sensitive reports should never be disposed off by simply being thrown in
waste containers.
15. Obfuscation – means to isolate by confusing, bewildering, obscuring or hiding something from
a potential penetrate.

27 | P a g e
SCI 407 Information Systems Security and Audit

TOPIC FOUR : COMPUTER SYSTEM CONTROLS

Any information system or data processing system, whether computerized or not, must incorporate
controls to ensure that it works efficiently, i.e. it must:

a) Process all the required data accurately.


b) Provide for continuity and change.
c) Contain sufficient controls to satisfy the auditors.
d) Provide the required amount of data security.

In a computer environment four elements must be controlled i.e. Source document, Input,
Processing and Output.

Computer system controls can be divided into 3 main areas:

1. Administrative controls.
2. System development controls.
3. Procedural and processing controls.

1. Administrative Controls.
Administrative controls are the responsibility of the management whereas procedural controls are
the concern of the system analyst, and system development controls should be decided jointly btw
system analyst and the management.

These controls ensure that proper procedures are followed to maintain discipline and efficiency
over the day-to-day running of the computer department.

An efficient administrative control system will involve the following aspects:

(i) Separation of duties.


(ii) Control over personnel running the computer department.
(iii) File control.
(iv) Security against fire hazards.
(v) Stand-by arrangements and insurance.

Administrative controls can be divided into 2:

(a) Organizational Controls


These are necessary because a new function may be introduced into the structure of the
organization, which concentrates data processing in one area, whereas previously many user
departments could have been involved.

To minimize this problem, a Distributed Data Processing system is used, whereby


minicomputers or microcomputers carrying out routine data processing are set up at remote
locations, but linked to a central computer.

28 | P a g e
SCI 407 Information Systems Security and Audit

(b) Operations Controls


These are methods and procedures established to:

(i) Ensure that operations staff follow the correct procedures.


(ii) Provide adequate arrangements for the physical security of records and files.

The most important points of the Operations control are that:

1) Access to source documents should be restricted to data preparation and control staff.
2) Access to the computer should be restricted to operation staff.
3) Computer operators and programmers must not originate live entries.
4) Control staff should not have other EDP duties.

In order to make the controls more effective, the functions of data processing staff, operators,
control clerks and librarians must be properly specified and documented.

The proper development and maintenance of operations control will help to: -

(i) Prevent or detect accidental errors which may occur during processing.
(ii) Prevent or detect fraudulent manipulation of data during processing.
(iii) Prevent access to and misuse of personal or otherwise classified information.
(iv) Prevent the destruction of records.
A computer control department/section must be established. This department must be
independent of other operating functions. The main function of this department is to ensure
that data is processed accurately and completely.

2. System Development Controls


Systems development controls should be decided jointly between the System analyst and the
management.

It is important to lay down high standards of control. This is because of the time spent on systems
development, the cost involved, and the probable complexity and volume of detail involved.

The main objectives of systems development control are:

(i) To ensure that an application is computerized only if it is beneficial to do so.


(ii) To establish a basis for management review and understanding of the system.
(iii) To ensure the development of effective systems and programs, and reduce wasted
programming effort.
(iv) To ensure that systems and programs are effectively maintained.
(v) To ensure that proper and complete documentation of the system is created and maintained.

These controls cover such areas as the development, implementation and maintenance of all
System and Application software.

29 | P a g e
SCI 407 Information Systems Security and Audit

The main requirements and techniques of systems development control are:

(1) Standard procedures and documentation.


(2) File conversion.
(3) Review procedures.
(4) System and program amendments.

3. Procedural and Processing Controls


Procedural controls are normally the concern of the System analyst.

Procedural controls are all those controls exercised over a particular application:

(a) Input controls.


(b) Processing and File controls.
(c) Hardware controls.
(d) Software (program) controls.
(e) Output controls.

Sometimes, the term “Processing controls” is used to describe all the controls applied in the Data
processing cycle.
Note that, some controls will be performed clerically, while others are performed by the computer
itself, and are known as Program or Software controls.

The aim of procedural control is to:

(i) Ensure that the data processing is complete, e.g. by the setting up of batch controls and
subsequent reconciliations by the computer and manually.
(ii) Ensure the accuracy of data processing, e.g., by proper setting up of well-designed source
documents, verification, program validation, etc.
(iii) Ensure that only authorized data is processed, e.g., by manually authorizing input, restricted
access to computer files.
(iv) Ensure that proper management and audit trails are laid down.

The system should have maximum safeguards against error and fraud in order to prevent:

(1) Incorrect recording of data at the point of document creation.


(2) Loss of data in handling.
(3) Introduction of unauthorized data.
(4) Incorrect conversion into machine-sensible form.
(5) Incorrect processing.
(6) Incorrect utilization of computer Input.

(a) Input Controls


Input controls should be established efficiently.

30 | P a g e
SCI 407 Information Systems Security and Audit

The main objectives of Input controls are to ensure that:

(i) All source documents are correctly completed and are transmitted to the computer
department.
(ii) All source documents are received by the computer department and are correctly converted
into the computer input media (e.g. Magnetic tape, floppy disc, etc).
(iii) All the data on the input medium is transmitted accurately to the computer centre and
accepted by the computer.

(b) Processing and File Controls


Controls must be applied to ensure the accuracy of processing the data. These will include:
(i) Hardware controls.
(ii) File controls.
(iii) Software controls.

(c) Hardware Controls


All equipment must be properly maintained and kept in the recommended environment.

Magnetic tape and disc systems require fairly rigid temperature, humidity and power
specifications, and therefore control devices should be used to detect variations from the norm.

The equipment itself should have proper hardware controls, which may include:

(i) Parity checks.


(ii) Overflow checks.
(iii) Validity checks.
(iv) Printer timing checks.
(v) Terminal readiness checks.
(vi) Data transmission checks.
(vii) Keeping of daily computer logs.

4. File Controls
To ensure that only the right files are used in processing,

(i) Proper file conversion controls must be exercised during Systems implementation.
(ii) All staff should be properly trained and provided with operation manuals.
(iii) Computer files should be controlled by a Librarian.
(iv) Computer files should have external file labels.
(v) Computer files should have internal file labels.

Note. The Input file labels can be checked by the computer operating systems. They comprise of:
(1). Header records, which contain;

(i) Label identifiers.


(ii) File identifier.
(iii) Generation/run number of creation.

31 | P a g e
SCI 407 Information Systems Security and Audit

(iv) Date of creation.


(v) Retention period.

(2). Trailer records, which contain;


(i) End-of-file marker.
(ii) Control totals.

(d) Software (Program) Controls


To ensure that only valid data is processed, all input should undergo validation tests.

The Data vet program may be applied to batches of data or to individual transactions (in an Online
or Real-time system), and any erroneous records rejected and reported (on a VDU in online input).

Software control procedures should detect some errors immediately after they occur.

The following is a brief classification of the most commonly used checks;

(i) Automatic file label checking.


(ii) Read-after-write check to compare data written in an output record with that retained in the
Main memory.
(iii) Address comparison check to compare address location where data is held to that specified
by the program instruction.
(iv) Arithmetic checks on the accuracy of a calculation.
(v) Overflow checks to ensure that, if the result of a calculation cannot be fitted in the address
allocated, the overflow part will not be lost.
(vi) Input/Output Control (IOCS) check. IOCS is a software package supplied by the
manufacturers. They can also be developed by individual users. This checks the accuracy
of input and output.

(e) Output Controls


The computer should be programmed to write Page numbers, descriptive headings, and processing
dates on all point outs.

Output controls are designed to ensure that:

(i) All output is received from the computer.


(ii) Where possible, the Output is reconciled with input. Control totals can be manually
reconciled by the control/user departments or by the computer.
(iii) All output and the rejection and exception reports are acted on.
Proper procedures should exist for error correction and re-input, e.g. every error should be
logged, and cleared on re-input.
(iv) Output is correctly distributed and its distribution logged.

Master File Controls


There are 3 important aspects in Master file control;

32 | P a g e
SCI 407 Information Systems Security and Audit

(1). Amendment to standing data.


(2). Maintenance of standing data.
(3). Maintenance of transaction data.

The degree of control required for standing data is more than that for transaction data.

Once standing data is entered into master files, it is important that there are adequate controls to
ensure that the data remain unaltered until an authorized change is made. This can be achieved
by;

 Periodically printing out of standing data so as to check with clerically held information.
 Establishing independent control totals for periodic verification with equivalent totals
accumulated in the files.
 Using the computer programs to establish and verify the control totals.

The degree of control required to maintain transaction data on master files varies according to the
contents of the file.

5. Library Controls
In order to adequately operate a tape library, procedures and controls must be established and
maintained if maximum and efficient usage is to be realized from Magnetic tapes.

For efficient tape library controls, the following should be provided:

 A quick means for physically locating any reel of tape in the library.

 Since the tape file may have more than one reel, each reel should be identified with the file
number and reel number.
 If a file or reel is missing from the library, the name of the person to whom it was issued should
be recorded.
 Identify the expiry of the scratch date so that tape reels may be released for reuse. A Scratch
date is the date that the data recorded on a particular tape is no longer required.
 Maintenance of records should be written in short, easily understood terms, and requires a
minimum number of entries.

Note: Library controls for Magnetic tapes may be setup in various ways as long as they provide
the proper control of all tape reels in the computer center. However, each time the tape status
changes, all records belonging to that tape must be changed accordingly.

Other types of controls


1. Organisational controls
2. Documentation controls
3. Management controls

33 | P a g e
SCI 407 Information Systems Security and Audit

4. Sociological controls
5. Technological controls
6. Environmental controls

34 | P a g e
SCI 407 Information Systems Security and Audit

TOPIC FIVE: AUDITING COMPUTERIZED INFORMATION SYSTEMS

Auditing: Defn: - Involves having an expert who is not involved in setting up or using a system,
examine information in order to ascertain its reliability. Auditing is also a security measure.

Objectives/Aims of auditing a computer-based information system


1. To ensure the quality of the information contained in/produced by the system i.e. the aim is
quality assurance of information.
2. To ensure that the system is working properly and that the (financial) information can be relied
upon.
3. To review and evaluate whether proper and adequate data processing controls, administrative
controls and procedural controls have been developed and implemented.
4. To determine whether resources are being used in a cost/effective manner.
5. To check that assets are properly safeguarded and not used improperly.
6. To review integrity, reliability and efficiency of the information system and the financial
reports it produces.
7. To establish the image of the computer as a corporate aid for use by any department that needs
it.
8. To maintain proper managerial controls of computer resources and EDP activities.
9. To include a test of accuracy and integrity of the data processing of several important computer
applications.
10. To ensure that the reporting structure of the ICT department is proper.
11. To reduce or eliminate the possibility of fraud or errors in the information system.

2 types of Audit/Auditors
1. Internal Audits
Aim to prevent fraud by evaluating internal (financial) control systems, and are a useful resource
to help in the development of control procedures for information systems.

- Done by internal Auditors, who are employees of the organization that owns the I.S.
- Internal auditors study the controls used in the information system to make sure that they are
adequate & that they are doing what they are purported to be doing/supposed to do.
- Internal auditors also test the adequacy of security controls.
- Though they work for the same organization, internal auditors do not report to the people
responsible for the system they are auditing.
- Their work is often more in-depth than that of external auditors.

2. External Audit
- Gives an independent, reliable and expert opinion about financial statements: Do the financial
statements, give a true and fair view/reflection of the state of the business/organization?
- Done by external auditors, who audit the system to ensure the fairness of the financial
statements being produces.
- They may also be brought in if there is something out of the ordinary accruing that involves
organization employees, e.g. suspected computer fraud or funds embezzlement.

35 | P a g e
SCI 407 Information Systems Security and Audit

- Auditors may require that certain self-checking mechanisms and authorization procedures be
incorporated in organization/systems, especially those supporting pension funds, or financial
institutions e.g. banks are obvious examples.

NB: It is very much better & easier, if these audit requirements can be taken into account at the
specification & design stage, rather than after the system is complete, so the analyst must talk to
all the relevant authorities & find out their requirements alongside those of the more obvious users
of the system.

3 methods/ways of auditing Computer-Based Information Systems (CB-MIS)

Three common methods of auditing in a computer.


1. Auditing around the computer.
2. Auditing through the computer
3. Auditing with the computer

1. Auditing around the computer


- No attempt is made to check the internal processes of the system. The auditor concentrates on
the inputs & outputs and checks that the outputs derived from the inputs are correct according
to the procedures carried out. This technique/method/way/type of audit regards the computer
processing as taking place in a ‘black box’.
- Suitable for relatively simple systems. The computer is treated as a ‘black box’. Auditor looks
at input & output but ignores what goes on in between.

- Began in early days when the auditor was unfamiliar with the comp terminologies,
programming & the controls used in a computer system. In this method the comp is viewed as
a ‘black’ box & the auditor do not review/examine the comp system & programs but
review/examine the input and output documents only.
- The controls & procedures are considered unimportant as long as the output generated could
be traced back to the input and the input was deemed valid.
- The auditors select input & test them against the appropriate output and vice versa. If they
match and proved to be accurate it is assumed that the system of controls is operational and
that it is working properly.

Advantages of auditing around the computer.


1. There is little risk in tampering with live data.
2. Little technical training of the auditor is required. The auditor need not be computer skilled.
3. It is simple, straight forward & easily understood.
4. The costs of audit resources are generally low.

Disadvantages
1. Many computerised systems are voluminous for proper manual testing.
2. No means are provided by which the auditors get involved and gain firm understanding of the
computer system.

36 | P a g e
SCI 407 Information Systems Security and Audit

3. It ignores the system of controls & thereby fails to recognize potential errors or weaknesses
within the system.
4. It represents after the fact rather than preventive auditing.
5. It makes no use of the most powerful and valuable audit tool, the computer.
6. To all intents and purposes it does not achieve the auditor’s goals [adequately].

2. Auditing through the computer.


- Checks the external inputs & outputs & the internal processes. Computer audit s/ware packages
are usually used to do this.
- With increasing complexity of Info Systems & the greater extent to which they are used in
business organizations this technique/method/way/type of audit is now common place.

This technique places a greater emphasis on testing the comp system that produces the output
rather than testing the output itself.

The auditor tests & verifies:-


a) The effectiveness of control procedures over comp operations & computer programs.
b) The correctness of internal processing.
This audit technique requires that two basics are accomplished. They are:-
a) The review of and verification of source transactions.
b) The actual testing of computer programs, logic and programmed controls.
This technique should be thought of as a testing of the program’s logic rather than a test of the
computer’s accuracy.
One of the key tools in applying this technique is the preparation by the auditor of a series of test
transactions normally referred to as TESTDECK; this test deck should include both valid and
invalid transactions.
- The test deck is run on the computer using the same programs that were used to operate a
particular application that is being tested.

Advantages of auditing through the computer


1. It helps the auditor become more involved in the system, thereby increasing his knowledge &
ability to perform more complex audits in the future.
2. It works as an aid in making compliance tests and an aid in the evaluation of programmed
controls.
3. It increases the service to clients – because controls and operations are checked or at least
observed/examined by the auditor.
4. The test results are readily identifiable and can be used as a measure of internal processing
reliability.
5. It utilizes the computer as a tool for performing audit functions.

Disadvantages of auditing through the computer.


1. It requires computer time.
2. It requires more technical knowledge and therefore more skilled personnel.
3. It represents after the fact testing rather than preventive testing.
4. It represents only a limited test of the system test deck.

37 | P a g e
SCI 407 Information Systems Security and Audit

3. Auditing with the computer


- All audits including computerized accounting records should be executed in accordance with
the Auditing Standards & with the guidance of the auditing guidelines.
- Computer Assisted Audit Techniques (CAAT) have been developed to overcome the problems
of auditing computerized systems.

Auditors can use the computer to assist them in various auditing tasks. Where an accounting
information system has been computerized, infact, auditing with the computer is virtually
mandatory because the accounting data are stored on the computer storage media and manual
access is impossible.
There are audit packages which are used to do this type of auditing or an in-house program can be
developed for the purpose.

Advantages of auditing with the computer.


1. It uses computer as an auditing tool.
2. It is very fast
3. It keeps the auditors abreast with the computer technology.
4. It is a more thorough auditing system
5. It represents preventive testing.

Disadvantages
1. Demands technical knowledge of computers
2. Requires computer time.

2 Main/Principal CAATs
1. Use of ‘test data’ to test the operation of the client’s programs.
2. Use of audit s/ware - comp programs developed for audit purposes to examine the contents &
do work on the contents of the client’s computer files.

Problems/challenges of auditing computerised systems.


1. Are complex & difficult to understand, partly because of the specialist vocabulary used. Larger
audit firms have set up specialist sections of computer auditors. The relationship between
general audit staff & computer audit staff has to be defined.
2. EDP/Computerized systems are much more complex
3. Technical language is used
4. Many controls are program controls
5. Frequent changes are made to information systems and programs.
6. Too much documentation is available.
7. Lack of visible evidence. Data is stored on magnetic and optical media. The information
contained in the records is not easily examined. This is an obvious problem for the auditor.
8. Many computerized systems produce acres of point-outs & the auditor may well be faced with
a surfeit of record rather than a shortage.

38 | P a g e
SCI 407 Information Systems Security and Audit

9. An Auditor can fully understand a manual system in a matter of hours at most. A computerized
system cannot usually be fully comprehended without expert knowledge & a great deal of time.
(Lack of computer literacy on part of Auditors).
10. If storage of comp. files holding customer’s statements of accounts is not maintained properly,
it may be difficult & time consuming for the Auditor to access them.
11. Lack of knowledge of computer terms and concepts.
12. I.T. personnel responsible for developing the info systems may have little or no knowledge
about accountancy, auditing or the legal framework within which their systems are to operate;
this may lead to problems.
13. It is difficult to follow an audit trail in computerized info systems becoz the data within a
computer system is ‘invisible’ to the human being as it is kept in machine-sensible form.

Solutions/remedies to these problems


1. The auditor should acquire working knowledge of computerized info systems & its
ramifications. At least one member of the audit team should have extensive first-hand
experience of computing.
2. A sound working relationship btw the I.T. staff and the auditors of computerized systems.
3. Auditors should be actively involved in system devept and system modifications especially in
the following stages
a. Project feasibility study
b. Systems design
c. Program testing and system testing
d. Implementation of the system
4. Auditors should insist on a strict segregation of duties, as in I.T. organizational chart to prevent
collusion.
5. Employ ‘auditing round the computer’ approach. Thus treating the computer as a ‘black box’.
The auditor is not concerned with what happens inside the computer. This approach requires
less computer knowledge on the part of the auditor and may be effective for simple systems.
6. An audit trail may be created where one does not exist. Print outs can be requested on a regular
or an ad-hoc basis, either of exceptional items or at random. This will allow the auditors to
check that transactions are correctly acted on.

7. Standard audit packages are available which:-


a. allow random sampling of contents of a file, perhaps printing every nth record.
b. cause exceptional items to be printed.
c. give control totals of certain important fields. When such packages are not
available, they can be developed internally/in-house.
8. Spot checks on the computer installation, and on certain systems which run on the computer,
should be made. These will allow the auditors to ensure that standards are being adhered to in
all areas – analysis, programming, operations, the library, data preparation & data control –
and that, in particular, documentation standards are being enforced.
9. Questionnaires and checklists can be used by the auditors to ensure that all aspects of control
are covered.
10. Throughout their work, the auditors must ask questions. Experience will often allow them to
sense whether or not something is wrong with a system.

39 | P a g e
SCI 407 Information Systems Security and Audit

Audit trail. Definition


1. It is the path which a transaction traces through a data processing system from source
documents to summary reports. It refers to the facilities or procedures which allow a
transaction to be traced through all stages of data processing beginning with its transformation
into info on a final output document.
2. Involves tracing/trailing/following the outputs from the inputs especially in an accounting
information system to ascertain proper recording, posting and accepted accounting procedures
were followed in production of final management accounts.
3. An Audit trail can also refer to a careful study of an information system by experts (auditors,
analyst/project managers/system designers/developers) in order to establish or find out all the
weaknesses in the system that could lead to security threats and weak access points for cyber
criminals. An audit of the information system may seek to answer the following questions.

a) Is the information system meeting all its original intended design objectives?
b) Have all the security measures been put in place to reduce the risk of computer crimes?
c) Are the computers secured in physically restricted areas?
d) Is there backup for data and information of the system that can ensure continuity of services
even when something serious happens to the current system?
e) What real risks face the system at present or in future?

Audit trail consist of such things as reference numbers, dates and names which are recorded in
files, ledgers and journals to facilitate the tracking of these records to source documents or to
record in other files.

Audit trails are tools designed to help the management in four ways

1. To provide access to info in order to answer inquiries of customers and others.


2. To provide a means to trace and verify transaction detail involving asset control such as
disbursements.
3. To provide a means to analyse and compare summarised operating results compiled within the
structure of the system.
4. To provide proof of the facts required to establish validity of accounting transactions to meet
tax and other legal requirement through trails to communication media and other records or
studies.
The auditor uses audit trails which the management has found necessary for internal purposes.

There is lack of audit trial when:-


a) The comp generates totals, analysis and balances without printing out details.
b) Exception reports are produced e.g. on overdue accounts without any assurance, apart from
a knowledge of the correctness of the program, that the list is complete.
Techniques used to overcome loss of audit trail
a) Special print outs for auditors. The auditor may request the management to print out the
statements required to reconstruct the audit trail with the help of the computer.
b) Maintenance of file on ‘grandfather, father, and son principle’ can help to show the auditor
the building up of the computer produced balances.
c) Programmed interrogation facilities

40 | P a g e
SCI 407 Information Systems Security and Audit

d) Clerical re-creation
e) Total testing & comparison with other data, budgets, previous periods.
f) Alternative tests e.g. physical stock counts.
g) The use of test packs to verify program performance.

Planning the audit in a computer environment.


All audits must be planned.
1. Auditors need to be involved in computerised systems at the planning, development &
implementation stages. Knowledge of the system gained at these stages will enable the auditor
to plan his audit with an understanding of the system.
2. Timing is more important in computerised systems than in manual ones. The auditor need to
be present when data & files are available. More frequent visits to the client are usually
required.
3. Recording methods involves use of secondary storage media.
4. The allocation of suitably qualified staff to audit.
5. The extent to which CAATS can be used also require planning in advance.
Some Audit firms have setup special comp audit departments to audit computerised systems.

Duties of computer audit staff.


1. To develop a working relationship with the client who is installing an EDP/computerized info
system.
2. To undertake the system evaluation & write the audit program.
3. To device & carryout the special auditing techniques.
4. To supervise the general audit staff in areas where the special expertise of the comp audit
development is needed.

Computer audit programs


- Consists of computer programs used by an Auditor to:-
1. Read disks & tape files & extract specified information from the files.
2. Carry out audit work on the contents of the file.

- These programs are sometimes known as enquiry or interrogation programs. Are usually coded
in HLLs e.g. COBOL, PASCAL. Are coded by or for an audit firm but client’s own
interrogation programs can be used; such programs are available from s/ware houses.
- Staff unskilled in programming can be easily taught to put their search or operating
requirements into a simple form which the comp audit program can interpret & apply to the
files selected.

Uses of computer audit programs


1. Selection of representative or randomly choosen transactions or items for audit tests, e.g. Item
number 36 and every 14th item thereafter.
2. Scrutiny of files & selection of exceptional items for examination e.g. all wages payments over
£120, or all stock lines worth more than £1,000 in total.
3. Comparison of two files and printing out differences e.g. payrolls at two selected dates.
4. Preparation of exception reports e.g. overdue debts.

41 | P a g e
SCI 407 Information Systems Security and Audit

5. Stratification of data e.g. stock lines or debtors, with a view to examination only to material
items.
6. Carrying out detail tests and calculations
7. Verifying data such as stock or fixed assets at the interim stage & then comparing the examined
file with the year end file so that only changed items need be examined at the final audit.
8. Comparison of files at succeeding year ends e.g. to identify changes in the composition of
stock.

Advantages of computer audit programs


1. Examination of data is more rapid.
2. Examination of data is more accurate
3. The only practical method of examining large amounts of data
4. Gives the auditor practical acquaintance with live files
5. Provides new opportunities to the auditor.
6. Less time consuming
7. Less paper work
8. Less disruptive to business operations
9. Overcomes in some cases a loss of audit trail
10. Relatively cheap to use once set up costs have been incurred.

Disadvantages
1. Can be expensive to setup or acquire
2. Some technical knowledge is required
3. Standard comp audit programs may be compatible with the variety of programming languages
used in business information systems.
4. Detailed knowledge of system & programs is required. Some auditors would dispute the need
for this detailed knowledge to be gained.
5. Difficult in obtaining computer time especially for testing.

- Use of audit s/ware raises the visibility of the auditor in the eyes of the company/organization.
It makes the audit more credible.

42 | P a g e
SCI 407 Information Systems Security and Audit

TOPIC Six: Information Security Cyber Law


Cyberspace

Cyberspace can be defined as an intricate environment that involves interactions between people,
software, and services. It is maintained by the worldwide distribution of information and
communication technology devices and networks.

With the benefits carried by the technological advancements, the cyberspace today has become a
common pool used by citizens, businesses, critical information infrastructure, military and
governments in a fashion that makes it hard to induce clear boundaries among these different
groups. The cyberspace is anticipated to become even more complex in the upcoming years, with
the increase in networks and devices connected to it.

Cyber security

Cybersecurity denotes the technologies and procedures intended to safeguard computers,


networks, and data from unlawful admittance, weaknesses, and attacks transported through the
Internet by cyber delinquents.

ISO 27001 (ISO27001) is the international Cybersecurity Standard that delivers a model for
creating, applying, functioning, monitoring, reviewing, preserving, and improving an Information
Security Management System.

The Ministry of Communication and Information Technology under the government of India
provides a strategy outline called the National Cybersecurity Policy. The purpose of this
government body is to protect the public and private infrastructure from cyber-attacks.

Cybersecurity Policy

The cybersecurity policy is a developing mission that caters to the entire field of Information and
Communication Technology (ICT) users and providers. It includes −

 Home users
 Small, medium, and large Enterprises
 Government and non-government entities

It serves as an authority framework that defines and guides the activities associated with the
security of cyberspace. It allows all sectors and organizations in designing suitable cybersecurity
policies to meet their requirements. The policy provides an outline to effectively protect
information, information systems and networks.

It gives an understanding into the Government’s approach and strategy for security of cyber space
in the country. It also sketches some pointers to allow collaborative working across the public and
private sectors to safeguard information and information systems. Therefore, the aim of this policy

43 | P a g e
SCI 407 Information Systems Security and Audit

is to create a cybersecurity framework, which leads to detailed actions and programs to increase
the security carriage of cyberspace.

Cyber Crime

The Information Technology Act 2000 or any legislation in the Country does not describe or
mention the term Cyber Crime. It can be globally considered as the gloomier face of technology.
The only difference between a traditional crime and a cyber-crime is that the cyber-crime involves
in a crime related to computers. Let us see the following example to understand it better −

Traditional Theft − A thief breaks into Ram’s house and steals an object kept in the house.

Hacking − A Cyber Criminal/Hacker sitting in his own house, through his computer, hacks the
computer of Ram and steals the data saved in Ram’s computer without physically touching the
computer or entering in Ram’s house.

The I.T. Act, 2000 defines the terms −

 access in computer network in section 2(a)


 computer in section 2(i)
 computer network in section (2j)
 data in section 2(0)
 information in section 2(v).

To understand the concept of Cyber Crime, you should know these laws. The object of offence or
target in a cyber-crime are either the computer or the data stored in the computer.

Nature of Threat

Among the most serious challenges of the 21st century are the prevailing and possible threats in
the sphere of cybersecurity. Threats originate from all kinds of sources, and mark themselves in
disruptive activities that target individuals, businesses, national infrastructures, and governments
alike. The effects of these threats transmit significant risk for the following −

 public safety
 security of nations
 stability of the globally linked international community

Malicious use of information technology can easily be concealed. It is difficult to determine the
origin or the identity of the criminal. Even the motivation for the disruption is not an easy task to
find out. Criminals of these activities can only be worked out from the target, the effect, or other
circumstantial evidence. Threat actors can operate with considerable freedom from virtually
anywhere. The motives for disruption can be anything such as −

 simply demonstrating technical prowess


 theft of money or information

44 | P a g e
SCI 407 Information Systems Security and Audit

 extension of state conflict, etc.

Criminals, terrorists, and sometimes the State themselves act as the source of these threats.
Criminals and hackers use different kinds of malicious tools and approaches. With the criminal
activities taking new shapes every day, the possibility for harmful actions propagates.

Enabling People

The lack of information security awareness among users, who could be a simple school going
kid, a system administrator, a developer, or even a CEO of a company, leads to a variety of cyber
vulnerabilities. The awareness policy classifies the following actions and initiatives for the
purpose of user awareness, education, and training −

 A complete awareness program to be promoted on a national level.


 A comprehensive training program that can cater to the needs of the national information
security (Programs on IT security in schools, colleges, and universities).
 Enhance the effectiveness of the prevailing information security training programs. Plan
domain-specific training programs (e.g., Law Enforcement, Judiciary, E-Governance,
etc.)
 Endorse private-sector support for professional information security certifications.

Information Technology Act

The Government of India enacted The Information Technology Act with some major objectives
which are as follows −

 To deliver lawful recognition for transactions through electronic data interchange (EDI)
and other means of electronic communication, commonly referred to as electronic
commerce or E-Commerce. The aim was to use replacements of paper-based methods of
communication and storage of information.

45 | P a g e
SCI 407 Information Systems Security and Audit

 To facilitate electronic filing of documents with the Government agencies and further to
amend the Indian Penal Code, the Indian Evidence Act, 1872, the Bankers' Books
Evidence Act, 1891 and the Reserve Bank of India Act, 1934 and for matters connected
therewith or incidental thereto.

The Information Technology Act, 2000, was thus passed as the Act No.21 of 2000. The I. T. Act
got the President’s assent on June 9, 2000 and it was made effective from October 17, 2000. By
adopting this Cyber Legislation, India became the 12th nation in the world to adopt a Cyber Law
regime.

Mission and Vision Cybersecurity Program


Mission

The following mission caters to cybersecurity −

 To safeguard information and information infrastructure in cyberspace.


 To build capabilities to prevent and respond to cyber threats.
 To reduce vulnerabilities and minimize damage from cyber incidents through a
combination of institutional structures, people, processes, technology, and cooperation.

Vision

To build a secure and resilient cyberspace for citizens, businesses, and Government

46 | P a g e
SCI 407 Information Systems Security and Audit

TOPIC Seven: Cyber Law Objectives


The recent Edward Snowden revelations on the US surveillance program PRISM have
demonstrated how a legal entity network and computer system outside a particular jurisdiction is
subject to surveillance without the knowledge of such legal entities. Cyber cases related to
interception and snooping are increasing at an alarming rate. To curb such crimes, cyber laws are
being amended quite regularly.

Emerging Trends of Cyber Law

Reports reveal that upcoming years will experience more cyber-attacks. So organizations are
advised to strengthen their data supply chains with better inspection methods.

Some of the emerging trends of cyber law are listed below −

 Stringent regulatory rules are put in place by many countries to prevent unauthorized
access to networks. Such acts are declared as penal offences.
 Stakeholders of the mobile companies will call upon the governments of the world to
reinforce cyber-legal systems and administrations to regulate the emerging mobile threats
and crimes.
 The growing awareness on privacy is another upcoming trend. Google’s chief internet
expert Vint Cerf has stated that privacy may actually be an anomaly.
 Cloud computing is another major growing trend. With more advancements in the
technology, huge volumes of data will flow into the cloud which is not completely
immune to cyber-crimes.
 The growth of Bitcoins and other virtual currency is yet another trend to watch out for.
Bitcoin crimes are likely to multiply in the near future.
 The arrival and acceptance of data analytics, which is another major trend to be followed,
requires that appropriate attention is given to issues concerning Big Data.

Create Awareness

While the U.S. government has declared October as the National Cybersecurity Awareness
month, India is following the trend to implement some stringent awareness scheme for the
general public.

The general public is partially aware of the crimes related to virus transfer. However, they are
unaware of the bigger picture of the threats that could affect their cyber-lives. There is a huge
lack of knowledge on e-commerce and online banking cyber-crimes among most of the internet
users.

Be vigilant and follow the tips given below while you participate in online activities −

 Filter the visibility of personal information in social sites.


 Do not keep the "remember password" button active for any email address and passwords

47 | P a g e
SCI 407 Information Systems Security and Audit

 Make sure your online banking platform is secure.


 Keep a watchful eye while shopping online.
 Do not save passwords on mobile devices.
 Secure the login details for mobile devices and computers, etc.

Areas of Development

The "Cyberlaw Trends in India 2013" and "Cyber law Developments in India in 2014" are two
prominent and trustworthy cyber-law related research works provided by Perry4Law
Organization (P4LO) for the years 2013 and 2014.

There are some grave cyber law related issues that deserve immediate consideration by the
government of India. The issues were put forward by the Indian cyber law roundup of 2014
provided by P4LO and Cyber Crimes Investigation Centre of India (CCICI). Following are some
major issues −

 A better cyber law and effective cyber-crimes prevention strategy


 Cyber-crimes investigation training requirements
 Formulation of dedicated encryption laws
 Legal adoption of cloud computing
 Formulation and implementation of e-mail policy
 Legal issues of online payments
 Legality of online gambling and online pharmacies
 Legality of Bitcoins
 Framework for blocking websites
 Regulation of mobile applications

With the formation of cyber-law compulsions, the obligation of banks for cyber-thefts and cyber-
crimes would considerably increase in the near future. Indian banks would require to keep a
dedicated team of cyber law experts or seek help of external experts in this regard.

The transactions of cyber-insurance should be increased by the Indian insurance sector as a


consequence of the increasing cyber-attacks and cyber-crimes.

International Network on Cybersecurity

To create an international network on cybersecurity, a conference was held in March 2014 in


New Delhi, India.

The objectives set in the International Conference on Cyberlaw & Cybercrime are as follows −

 To recognize the developing trends in Cyberlaw and the legislation impacting cyberspace
in the current situation.
 To generate better awareness to battle the latest kinds of cybercrimes impacting all
investors in the digital and mobile network.

48 | P a g e
SCI 407 Information Systems Security and Audit

 To recognize the areas for stakeholders of digital and mobile network where Cyberlaw
needs to be further evolved.
 To work in the direction of creating an international network of cybercrimes. Legal
authorities could then be a significant voice in the further expansion of cyber-crimes and
cyber law legislations throughout the globe.

Intellectual Property Right


Intellectual property rights are the legal rights that cover the privileges given to individuals who
are the owners and inventors of a work, and have created something with their intellectual
creativity. Individuals related to areas such as literature, music, invention, etc., can be granted
such rights, which can then be used in the business practices by them.

The creator/inventor gets exclusive rights against any misuse or use of work without his/her prior
information. However, the rights are granted for a limited period of time to maintain equilibrium.

The following list of activities which are covered by the intellectual property rights are laid down
by the World Intellectual Property Organization (WIPO) −

 Industrial designs
 Scientific discoveries
 Protection against unfair competition
 Literary, artistic, and scientific works
 Inventions in all fields of human endeavor
 Performances of performing artists, phonograms, and broadcasts
 Trademarks, service marks, commercial names, and designations
 All other rights resulting from intellectual activity in the industrial, scientific, literary, or
artistic fields

Types of Intellectual Property Rights

Intellectual Property Rights can be further classified into the following categories −

 Copyright
 Patent
 Patent
 Trade Secrets, etc.

49 | P a g e
SCI 407 Information Systems Security and Audit

Advantages of Intellectual Property Rights

Intellectual property rights are advantageous in the following ways −

 Provides exclusive rights to the creators or inventors.


 Encourages individuals to distribute and share information and data instead of keeping it
confidential.
 Provides legal defense and offers the creators the incentive of their work.
 Helps in social and financial development.

Intellectual Property Rights in India

To protect the intellectual property rights in the Indian territory, India has defined the formation
of constitutional, administrative and jurisdictive outline whether they imply the copyright, patent,
trademark, industrial designs, or any other parts of the intellectual property rights.

Back in the year 1999, the government passed an important legislation based on international
practices to safeguard the intellectual property rights. Let us have a glimpse of the same −

 The Patents (Amendment) Act, 1999, facilitates the establishment of the mail box system
for filing patents. It offers exclusive marketing rights for a time period of five years.
 The Trade Marks Bill, 1999, replaced the Trade and Merchandise Marks Act, 1958
 The Copyright (Amendment) Act, 1999, was signed by the President of India.
 The sui generis legislation was approved and named as the Geographical Indications of
Goods (Registration and Protection) Bill, 1999.
 The Industrial Designs Bill, 1999, replaced the Designs Act, 1911.
 The Patents (Second Amendment) Bill, 1999, for further amending the Patents Act of
1970 in compliance with the TRIPS.

50 | P a g e
SCI 407 Information Systems Security and Audit

Intellectual Property in Cyber Space

Every new invention in the field of technology experiences a variety of threats. Internet is one
such threat, which has captured the physical marketplace and have converted it into a virtual
marketplace.

To safeguard the business interest, it is vital to create an effective property management and
protection mechanism keeping in mind the considerable amount of business and commerce
taking place in the Cyber Space.

Today it is critical for every business to develop an effective and collaborative IP management
mechanism and protection strategy. The ever-looming threats in the cybernetic world can thus be
monitored and confined.

Various approaches and legislations have been designed by the law-makers to up the ante in
delivering a secure configuration against such cyber-threats. However it is the duty of the
intellectual property right (IPR) owner to invalidate and reduce such mala fide acts of criminals
by taking proactive measures.

Cyber Security Strategies


To design and implement a secure cyberspace, some stringent strategies have been put in place.
This chapter explains the major strategies employed to ensure cybersecurity, which include the
following −

 Creating a Secure Cyber Ecosystem


 Creating an Assurance Framework
 Encouraging Open Standards
 Strengthening the Regulatory Framework
 Creating Mechanisms for IT Security
 Securing E-governance Services
 Protecting Critical Information Infrastructure

Strategy 1 − Creating a Secure Cyber Ecosystem

The cyber ecosystem involves a wide range of varied entities like devices (communication
technologies and computers), individuals, governments, private organizations, etc., which
interact with each other for numerous reasons.

This strategy explores the idea of having a strong and robust cyber-ecosystem where the cyber-
devices can work with each other in the future to prevent cyber-attacks, reduce their
effectiveness, or find solutions to recover from a cyber-attack.

Such a cyber-ecosystem would have the ability built into its cyber devices to permit secured
ways of action to be organized within and among groups of devices. This cyber-ecosystem can

51 | P a g e
SCI 407 Information Systems Security and Audit

be supervised by present monitoring techniques where software products are used to detect and
report security weaknesses.

A strong cyber-ecosystem has three symbiotic structures − Automation, Interoperability, and


Authentication.

 Automation − It eases the implementation of advanced security measures, enhances the


swiftness, and optimizes the decision-making processes.
 Interoperability − It toughens the collaborative actions, improves awareness, and
accelerates the learning procedure. There are three types of interoperability −
o Semantic (i.e., shared lexicon based on common understanding)
o Technical
o Policy − Important in assimilating different contributors into an inclusive cyber-
defense structure.
 Authentication − It improves the identification and verification technologies that work
in order to provide −
o Security
o Affordability
o Ease of use and administration
o Scalability
o Interoperability

Comparison of Attacks

The following table shows the Comparison of Attack Categories against Desired Cyber
Ecosystem Capabilities −

52 | P a g e
SCI 407 Information Systems Security and Audit

Case Study

The following diagram was prepared by Guilbert Gates for The New York Times, which shows
how an Iranian plant was hacked through the internet.

53 | P a g e
SCI 407 Information Systems Security and Audit

Explanation − A program was designed to automatically run the Iranian nuclear plant.
Unfortunately, a worker who was unaware of the threats introduced the program into the
controller. The program collected all the data related to the plant and sent the information to the
intelligence agencies who then developed and inserted a worm into the plant. Using the worm,
the plant was controlled by miscreants which led to the generation of more worms and as a
result, the plant failed completely.

Types of Attacks

The following table describes the attack categories −

54 | P a g e
SCI 407 Information Systems Security and Audit

Attack Category Description of Attack


Methods used to damage networks and systems. It includes the
following −

Attrition  distributed denial of service attacks


 impair or deny access to a service or application
 resource depletion attacks

Any malicious software used to interrupt normal computer


operation and harm information assets without the owner’s
Malware
consent. Any execution from a removable device can enhance the
threat of a malware.
An attempt to intentionally exploit weaknesses to get unethical
access, usually conducted remotely. It may include −

 data-leakage attacks
 injection attacks and abuse of functionality
 spoofing
 time-state attacks
Hacking
 buffer and data structure attacks
 resource manipulation
 stolen credentials usage
 backdoors
 dictionary attacks on passwords
 exploitation of authentication

Using social tactics such as deception and manipulation to acquire


access to data, systems or controls. It includes −

Social Tactics  pre-texting (forged surveys)


 inciting phishing
 retrieving of information through conversation

Misuse of rights to data and controls by an individual in an


organization that would violate the organization’s policies. It
includes −
Improper Usage (Insider
Threat)
 installation of unauthorized software
 removal of sensitive data

Human-Driven attacks such as −


Physical Action/Loss or
 stolen identity tokens and credit cards
Theft of Equipment
 fiddling with or replacing card readers and point of sale
terminals

55 | P a g e
SCI 407 Information Systems Security and Audit

 interfering with sensors


 theft of a computing device used by the organization, such
as a laptop

Single attach techniques which contains several advanced attack


Multiple Component
techniques and components.
Attacks such as −

Other  supply chain attacks


 network investigation

Strategy 2 − Creating an Assurance Framework

The objective of this strategy is to design an outline in compliance with the global security
standards through traditional products, processes, people, and technology.

To cater to the national security requirements, a national framework known as the


Cybersecurity Assurance Framework was developed. It accommodates critical infrastructure
organizations and the governments through "Enabling and Endorsing" actions.

Enabling actions are performed by government entities that are autonomous bodies free from
commercial interests. The publication of "National Security Policy Compliance Requirements"
and IT security guidelines and documents to enable IT security implementation and compliance
are done by these authorities.

Endorsing actions are involved in profitable services after meeting the obligatory qualification
standards and they include the following −

 ISO 27001/BS 7799 ISMS certification, IS system audits etc., which are essentially the
compliance certifications.
 'Common Criteria' standard ISO 15408 and Crypto module verification standards, which
are the IT Security product evaluation and certification.
 Services to assist consumers in implementation of IT security such as IT security
manpower training.

Trusted Company Certification

Indian IT/ITES/BPOs need to comply with the international standards and best practices on
security and privacy with the development of the outsourcing market. ISO 9000, CMM, Six
Sigma, Total Quality Management, ISO 27001 etc., are some of the certifications.

Existing models such as SEI CMM levels are exclusively meant for software development
processes and do not address security issues. Therefore, several efforts are made to create a
model based on self-certification concept and on the lines of Software Capability Maturity
Model (SW-CMM) of CMU, USA.

56 | P a g e
SCI 407 Information Systems Security and Audit

The structure that has been produced through such association between industry and government,
comprises of the following −

 standards
 guidelines
 practices

These parameters help the owners and operators of critical infrastructure to manage
cybersecurity-related risks.

Strategy 3 − Encouraging Open Standards

Standards play a significant role in defining how we approach information security related issues
across geographical regions and societies. Open standards are encouraged to −

 Enhance the efficiency of key processes,


 Enable systems incorporations,
 Provide a medium for users to measure new products or services,
 Organize the approach to arrange new technologies or business models,
 Interpret complex environments, and
 Endorse economic growth.

Standards such as ISO 27001[3] encourage the implementation of a standard organization


structure, where customers can understand processes, and reduce the costs of auditing.

Strategy 4 − Strengthening the Regulatory Framework

The objective of this strategy is to create a secure cyberspace ecosystem and strengthen the
regulatory framework. A 24X7 mechanism has been envisioned to deal with cyber threats
through National Critical Information Infrastructure Protection Centre (NCIIPC). The Computer
Emergency Response Team (CERT-In) has been designated to act as a nodal agency for crisis
management.

Some highlights of this strategy are as follows −

 Promotion of research and development in cybersecurity.


 Developing human resource through education and training programs.
 Encouraging all organizations, whether public or private, to designate a person to serve as
Chief Information Security Officer (CISO) who will be responsible for cybersecurity
initiatives.
 Indian Armed Forces are in the process of establishing a cyber-command as a part of
strengthening the cybersecurity of defense network and installations.
 Effective implementation of public-private partnership is in pipeline that will go a long
way in creating solutions to the ever-changing threat landscape.

57 | P a g e
SCI 407 Information Systems Security and Audit

Strategy 5 − Creating Mechanisms for IT Security

Some basic mechanisms that are in place for ensuring IT security are − link-oriented security
measures, end-to-end security measures, association-oriented measures, and data encryption.
These methods differ in their internal application features and also in the attributes of the
security they provide. Let us discuss them in brief.

Link-Oriented Measures

It delivers security while transferring data between two nodes, irrespective of the eventual source
and destination of the data.

End-to-End Measures

It is a medium for transporting Protocol Data Units (PDUs) in a protected manner from source to
destination in such a way that disruption of any of their communication links does not violate
security.

Association-Oriented Measures

Association-oriented measures are a modified set of end-to-end measures that protect every
association individually.

Data Encryption

It defines some general features of conventional ciphers and the recently developed class of
public-key ciphers. It encodes information in a way that only the authorized personnel can
decrypt them.

Strategy 6 − Securing E-Governance Services

Electronic governance (e-governance) is the most treasured instrument with the government to
provide public services in an accountable manner. Unfortunately, in the current scenario, there is
no devoted legal structure for e-governance in India.

Similarly, there is no law for obligatory e-delivery of public services in India. And nothing is
more hazardous and troublesome than executing e-governance projects without sufficient
cybersecurity. Hence, securing the e-governance services has become a crucial task, especially
when the nation is making daily transactions through cards.

Fortunately, the Reserve Bank of India has implemented security and risk mitigation measures
for card transactions in India enforceable from 1st October, 2013. It has put the responsibility of
ensuring secured card transactions upon banks rather than on customers.

58 | P a g e
SCI 407 Information Systems Security and Audit

"E-government" or electronic government refers to the use of Information and Communication


Technologies (ICTs) by government bodies for the following −

 Efficient delivery of public services


 Refining internal efficiency
 Easy information exchange among citizens, organizations, and government bodies
 Re-structuring of administrative processes.

Strategy 7 − Protecting Critical Information Infrastructure

Critical information infrastructure is the backbone of a country’s national and economic security.
It includes power plants, highways, bridges, chemical plants, networks, as well as the buildings
where millions of people work every day. These can be secured with stringent collaboration
plans and disciplined implementations.

Safeguarding critical infrastructure against developing cyber-threats needs a structured approach.


It is required that the government aggressively collaborates with public and private sectors on a
regular basis to prevent, respond to, and coordinate mitigation efforts against attempted
disruptions and adverse impacts to the nation’s critical infrastructure.

It is in demand that the government works with business owners and operators to reinforce their
services and groups by sharing cyber and other threat information.

A common platform should be shared with the users to submit comments and ideas, which can
be worked together to build a tougher foundation for securing and protecting critical
infrastructures.

The government of USA has passed an executive order "Improving Critical Infrastructure
Cybersecurity" in 2013 that prioritizes the management of cybersecurity risk involved in the
delivery of critical infrastructure services. This Framework provides a common classification and
mechanism for organizations to −

 Define their existing cybersecurity bearing,


 Define their objectives for cybersecurity,
 Categorize and prioritize chances for development within the framework of a constant
process, and
 Communicate with all the investors about cybersecurity.

Policies To Mitigate Cyber Risk


This chapter takes you through the various policies laid to minimize cyber risk. It is only with
well-defined policies that the threats generated in the cyberspace can be reduced.

59 | P a g e
SCI 407 Information Systems Security and Audit

Promotion of R&D in Cybersecurity

Due to the ever-increasing dependence on the Internet, the biggest challenge we face today is the
security of information from miscreants. Therefore, it is essential to promote research and
development in cybersecurity so that we can come up with robust solutions to mitigate cyber
risks.

Cybersecurity Research

Cybersecurity Research is the area that is concerned with preparing solutions to deal with cyber
criminals. With increasing amount of internet attacks, advanced persistent threats and phishing,
lots of research and technological developments are required in the future.

Cybersecurity Research-Indian Perspective

In the recent years, India has witnessed an enormous growth in cyber technologies. Hence it calls
for an investment in the research and development activities of cybersecurity. India has also seen
many successful research outcomes that were translated into businesses, through the advent of
local cybersecurity companies.

Threat Intelligence

Research work to mitigate cyber-threats is already being commenced in India. There is a


proactive response mechanism in place to deal with cyber threats. Research and Development
activities are already underway at various research organizations in India to fight threats in
cyberspace.

Next Generation Firewall

Multi-identity based expertise such as Next Generation Firewall that offers security intelligence
to enterprises and enable them to apply best suited security controls at the network perimeter are
also being worked on.

Secured Protocol and Algorithms

Research in protocols and algorithms is a significant phase for the consolidation of cybersecurity
at a technical level. It defines the rules for information sharing and processing over cyberspace.
In India, protocol and algorithm level research includes −

 Secure Routing Protocols


 Efficient Authentication Protocols
 Enhanced Routing Protocol for Wireless Networks
 Secure Transmission Control Protocol
 Attack Simulation Algorithm, etc.

60 | P a g e
SCI 407 Information Systems Security and Audit

Authentication Techniques

Authentication techniques such as Key Management, Two Factor Authentication, and Automated
key Management provide the ability to encrypt and decrypt without a centralized key
management system and file protection. There is continuous research happening to strengthen
these authentication techniques.

BYOD, Cloud and Mobile Security

With the adoption of varied types of mobile devices, the research on the security and privacy
related tasks on mobile devices has increased. Mobile security testing, Cloud Security, and
BYOD (Bring Your Own Device) risk mitigation are some of the areas where a lot of research is
being done.

Cyber Forensics

Cyber Forensics is the application of analysis techniques to collect and recover data from a
system or a digital storage media. Some of the specific areas where research is being done in
India are −

 Disk Forensics
 Network Forensics
 Mobile Device Forensics
 Memory Forensics
 Multimedia Forensics
 Internet Forensics

Reducing Supply Chain Risks

Formally, supply chain risk can be defined as −

Any risk that an opponent may damage, write some malicious function to it, deconstruct the
design, installation, procedure, or maintenance of a supply item or a system so that the entire
function can be degraded.

Supply Chain Issues

Supply chain is a global issue and there is a requirement to find out the interdependencies among
the customers and suppliers. In today’s scenario it is important to know − What are the SCRM
problems? and How to address the problems?

An effective SCRM (Supply Chain Risk Management) approach requires a strong public-private
partnership. Government should have strong authorities to handle supply chain issues. Even
private sectors can play a key role in a number of areas.

61 | P a g e
SCI 407 Information Systems Security and Audit

We cannot provide a one-size-fits-all resolution for managing supply chain risks. Depending on
the product and the sector, the costs for reducing risks will weigh differently. Public Private
Partnerships should be encouraged to resolve risks associated with supply chain management.

Mitigate Risks through Human Resource Development

Cybersecurity policies of an organization can be effective, provided all its employees understand
their value and exhibit a strong commitment towards implementing them. Human resource
directors can play a key role in keeping organizations safe in cyberspace by applying the
following few points.

Taking Ownership of the Security Risk Posed by Employees

As most of the employees do not take the risk factor seriously, hackers find it easy to target
organizations. In this regard, HR plays a key role in educating employees about the impact their
attitudes and behavior have on the organization’s security.

Ensuring that Security Measures are Practical and Ethical

Policies of a company must be in sync with the way employees think and behave. For example,
saving passwords on systems is a threat, however continuous monitoring can prevent it. The HR
team is best placed to advise whether policies are likely to work and whether they are
appropriate.

Identifying Employees who may Present a Particular Risk

It also happens that cyber-criminals take the help of insiders in a company to hack their network.
Therefore it is essential to identify employees who may present a particular risk and have
stringent HR policies for them.

Creating Cybersecurity Awareness

Cybersecurity in India is still in its evolution stage. This is the best time to create awareness on
issues related to cyber security. It would be easy to create awareness from the grass-root level
like schools where users can be made aware how Internet works and what are its potential
threats.

Every cyber café, home/personal computers, and office computers should be protected through
firewalls. Users should be instructed through their service providers or gateways not to breach
unauthorized networks. The threats should be described in bold and the impacts should be
highlighted.

Subjects on cybersecurity awareness should be introduced in schools and colleges to make it an


ongoing process.

62 | P a g e
SCI 407 Information Systems Security and Audit

The government must formulate strong laws to enforce cybersecurity and create sufficient
awareness by broadcasting the same through television/radio/internet advertisements.

Information Sharing

United States proposed a law called Cybersecurity Information Sharing Act of 2014 (CISA)
to improve cybersecurity in the country through enhanced sharing of information about
cybersecurity threats. Such laws are required in every country to share threat information among
citizens.

Cybersecurity Breaches Need a Mandatory Reporting Mechanism

The recent malware named Uroburos/Snake is an example of growing cyber-espionage and


cyber-warfare. Stealing of sensitive information is the new trend. However, it is unfortunate that
the telecom companies/internet service providers (ISPs) are not sharing information pertaining to
cyber-attacks against their networks. As a result, a robust cybersecurity strategy to counter
cyber-attacks cannot be formulated.

This problem can be addressed by formulating a good cybersecurity law that can establish a
regulatory regime for obligatory cybersecurity breach notifications on the part of telecom
companies/ISPs.

Infrastructures such as automated power grids, thermal plants, satellites, etc., are vulnerable to
diverse forms of cyber-attacks and hence a breach notification program would alert the agencies
to work on them.

Implementing a Cybersecurity Framework

Despite the fact that companies are spending on cybersecurity initiatives, data breaches continue
to occur. According to The Wall Street Journal, "Global cybersecurity spending by critical
infrastructure industries was expected to hit $46 billion in 2013, up 10% from a year earlier
according to Allied Business Intelligence Inc." This calls for the effective implementation of the
cybersecurity framework.

Components of Cybersecurity Framework

The Framework comprises of three main components −

 The Core,
 Implementation Tiers, and
 Framework Profiles.

63 | P a g e
SCI 407 Information Systems Security and Audit

The Framework Core

The Framework Core is a set of cybersecurity activities and applicable references that having
five simultaneous and constant functions − Identify, Protect, Detect, Respond, and Recover. The
framework core has methods to ensure the following −

 Develop and implement procedures to protect the most critical intellectual property and
assets.
 Have resources in place to identify any cybersecurity breach.
 Recover from a breach, if and when one occurs.

The Implementation Tiers

The Framework Implementation Tiers define the level of sophistication and consistency an
organization employs in applying its cybersecurity practices. It has the following four levels.

Tier 1 (Partial) − In this level, the organization’s cyber-risk management profiles are not
defined. There is a partial consciousness of the organization’s cybersecurity risk at the
organization level. Organization-wide methodology to managing cybersecurity risk has not been
recognized.

64 | P a g e
SCI 407 Information Systems Security and Audit

Tier 2 (Risk Informed) − In this level, organizations establish a cyber-risk management policy
that is directly approved by the senior management. The senior management makes efforts to
establish risk management objectives related to cybersecurity and implements them.

Tier 3 (Repeatable) − In this level, the organization runs with formal cybersecurity measures,
which are regularly updated based on requirement. The organization recognizes its dependencies
and partners. It also receives information from them, which helps in taking risk-based
management decisions.

Tier 4 (Adaptive) − In this level, the organization adapts its cybersecurity practices "in real-
time" derived from previous and current cybersecurity activities. Through a process of incessant
development in combining advanced cybersecurity technologies, real-time collaboration with
partners, and continuous monitoring of activities on their systems, the organization’s
cybersecurity practices can quickly respond to sophisticated threats.

The Framework Profile

The Framework Profile is a tool that provides organizations a platform for storing information
concerning their cybersecurity program. A profile allows organizations to clearly express the
goals of their cybersecurity program.

Where do You Start with Implementing the Framework?

The senior management including the directors should first get acquainted with the Framework.
After which, the directors should have a detailed discussion with the management about the
organization’s Implementation Tiers.

Educating the managers and staff on the Framework will ensure that everyone understands its
importance. This is an important step towards the successful implementation of a vigorous
cybersecurity program. The information about existing Framework Implementations may help
organizations with their own approaches.

Network Security
Network security is the security provided to a network from unauthorized access and risks. It is
the duty of network administrators to adopt preventive measures to protect their networks from
potential security threats.

Computer networks that are involved in regular transactions and communication within the
government, individuals, or business require security. The most common and simple way of
protecting a network resource is by assigning it a unique name and a corresponding password.

65 | P a g e
SCI 407 Information Systems Security and Audit

Types of Network Security Devices


Active Devices

These security devices block the surplus traffic. Firewalls, antivirus scanning devices, and
content filtering devices are the examples of such devices.

Passive Devices

These devices identify and report on unwanted traffic, for example, intrusion detection
appliances.

Preventative Devices

These devices scan the networks and identify potential security problems. For example,
penetration testing devices and vulnerability assessment appliances.

Unified Threat Management (UTM)

These devices serve as all-in-one security devices. Examples include firewalls, content filtering,
web caching, etc.

Firewalls

A firewall is a network security system that manages and regulates the network traffic based on
some protocols. A firewall establishes a barrier between a trusted internal network and the
internet.

Firewalls exist both as software that run on a hardware and as hardware appliances. Firewalls
that are hardware-based also provide other functions like acting as a DHCP server for that
network.

Most personal computers use software-based firewalls to secure data from threats from the
internet. Many routers that pass data between networks contain firewall components and
conversely, many firewalls can perform basic routing functions.

Firewalls are commonly used in private networks or intranets to prevent unauthorized access
from the internet. Every message entering or leaving the intranet goes through the firewall to be
examined for security measures.

An ideal firewall configuration consists of both hardware and software based devices. A firewall
also helps in providing remote access to a private network through secure authentication
certificates and logins.

66 | P a g e
SCI 407 Information Systems Security and Audit

Hardware and Software Firewalls

Hardware firewalls are standalone products. These are also found in broadband routers. Most
hardware firewalls provide a minimum of four network ports to connect other computers. For
larger networks − e.g., for business purpose − business networking firewall solutions are
available.

Software firewalls are installed on your computers. A software firewall protects your computer
from internet threats.

Antivirus

An antivirus is a tool that is used to detect and remove malicious software. It was originally
designed to detect and remove viruses from computers.

Modern antivirus software provide protection not only from virus, but also from worms, Trojan-
horses, adwares, spywares, keyloggers, etc. Some products also provide protection from
malicious URLs, spam, phishing attacks, botnets, DDoS attacks, etc.

Content Filtering

Content filtering devices screen unpleasant and offensive emails or webpages. These are used as
a part of firewalls in corporations as well as in personal computers. These devices generate the
message "Access Denied" when someone tries to access any unauthorized web page or email.

Content is usually screened for pornographic content and also for violence- or hate-oriented
content. Organizations also exclude shopping and job related contents.

Content filtering can be divided into the following categories −

 Web filtering
 Screening of Web sites or pages
 E-mail filtering
 Screening of e-mail for spam
 Other objectionable content

Intrusion Detection Systems

Intrusion Detection Systems, also known as Intrusion Detection and Prevention Systems, are the
appliances that monitor malicious activities in a network, log information about such activities,
take steps to stop them, and finally report them.

Intrusion detection systems help in sending an alarm against any malicious activity in the
network, drop the packets, and reset the connection to save the IP address from any blockage.
Intrusion detection systems can also perform the following actions −

67 | P a g e
SCI 407 Information Systems Security and Audit

 Correct Cyclic Redundancy Check (CRC) errors


 Prevent TCP sequencing issues
 Clean up unwanted transport and network layer options

Information Technology Act, 2000


As discussed in the first chapter, the Government of India enacted the Information Technology
(I.T.) Act with some major objectives to deliver and facilitate lawful electronic, digital, and
online transactions, and mitigate cyber-crimes.

Salient Features of I.T Act

The salient features of the I.T Act are as follows −

 Digital signature has been replaced with electronic signature to make it a more
technology neutral act.
 It elaborates on offenses, penalties, and breaches.
 It outlines the Justice Dispensation Systems for cyber-crimes.
 It defines in a new section that cyber café is any facility from where the access to the
internet is offered by any person in the ordinary course of business to the members of the
public.
 It provides for the constitution of the Cyber Regulations Advisory Committee.
 It is based on The Indian Penal Code, 1860, The Indian Evidence Act, 1872, The
Bankers' Books Evidence Act, 1891, The Reserve Bank of India Act, 1934, etc.
 It adds a provision to Section 81, which states that the provisions of the Act shall have
overriding effect. The provision states that nothing contained in the Act shall restrict any
person from exercising any right conferred under the Copyright Act, 1957.

Scheme of I.T Act

The following points define the scheme of the I.T. Act −

 The I.T. Act contains 13 chapters and 90 sections.


 The last four sections namely sections 91 to 94 in the I.T. Act 2000 deals with the
amendments to the Indian Penal Code 1860, The Indian Evidence Act 1872, The
Bankers’ Books Evidence Act 1891 and the Reserve Bank of India Act 1934 were
deleted.
 It commences with Preliminary aspect in Chapter 1, which deals with the short, title,
extent, commencement and application of the Act in Section 1. Section 2 provides
Definition.
 Chapter 2 deals with the authentication of electronic records, digital signatures, electronic
signatures, etc.
 Chapter 11 deals with offences and penalties. A series of offences have been provided
along with punishment in this part of The Act.

68 | P a g e
SCI 407 Information Systems Security and Audit

 Thereafter the provisions about due diligence, role of intermediaries and some
miscellaneous provisions are been stated.
 The Act is embedded with two schedules. The First Schedule deals with Documents or
Transactions to which the Act shall not apply. The Second Schedule deals with electronic
signature or electronic authentication technique and procedure. The Third and Fourth
Schedule are omitted.

Application of the I.T Act

As per the sub clause (4) of Section 1, nothing in this Act shall apply to documents or
transactions specified in First Schedule. Following are the documents or transactions to which
the Act shall not apply −

 Negotiable Instrument (Other than a cheque) as defined in section 13 of the Negotiable


Instruments Act, 1881;
 A power-of-attorney as defined in section 1A of the Powers-of-Attorney Act, 1882;
 A trust as defined in section 3 of the Indian Trusts Act, 1882;
 A will as defined in clause (h) of section 2 of the Indian Succession Act, 1925 including
any other testamentary disposition;
 Any contract for the sale or conveyance of immovable property or any interest in such
property;
 Any such class of documents or transactions as may be notified by the Central
Government.

Amendments Brought in the I.T Act

The I.T. Act has brought amendment in four statutes vide section 91-94. These changes have
been provided in schedule 1-4.

 The first schedule contains the amendments in the Penal Code. It has widened the scope
of the term "document" to bring within its ambit electronic documents.
 The second schedule deals with amendments to the India Evidence Act. It pertains to the
inclusion of electronic document in the definition of evidence.
 The third schedule amends the Banker's Books Evidence Act. This amendment brings
about change in the definition of "Banker's-book". It includes printouts of data stored in
a floppy, disc, tape or any other form of electromagnetic data storage device. Similar
change has been brought about in the expression "Certified-copy" to include such
printouts within its purview.
 The fourth schedule amends the Reserve Bank of India Act. It pertains to the regulation
of fund transfer through electronic means between the banks or between the banks and
other financial institution.

69 | P a g e
SCI 407 Information Systems Security and Audit

Intermediary Liability

Intermediary, dealing with any specific electronic records, is a person who on behalf of another
person accepts, stores or transmits that record or provides any service with respect to that
record.

According to the above mentioned definition, it includes the following −

 Telecom service providers


 Network service providers
 Internet service providers
 Web-hosting service providers
 Search engines
 Online payment sites
 Online auction sites
 Online market places and cyber cafes

Highlights of the Amended Act

The newly amended act came with following highlights −

 It stresses on privacy issues and highlights information security.


 It elaborates Digital Signature.
 It clarifies rational security practices for corporate.
 It focuses on the role of Intermediaries.
 New faces of Cyber Crime were added.

Digital & Electronic Signatures


Digital Signature

A digital signature is a technique to validate the legitimacy of a digital message or a document. A


valid digital signature provides the surety to the recipient that the message was generated by a
known sender, such that the sender cannot deny having sent the message. Digital signatures are
mostly used for software distribution, financial transactions, and in other cases where there is a
risk of forgery.

Electronic Signature

An electronic signature or e-signature, indicates either that a person who demands to have
created a message is the one who created it.

A signature can be defined as a schematic script related with a person. A signature on a


document is a sign that the person accepts the purposes recorded in the document. In many

70 | P a g e
SCI 407 Information Systems Security and Audit

engineering companies digital seals are also required for another layer of authentication and
security. Digital seals and signatures are same as handwritten signatures and stamped seals.

Digital Signature to Electronic Signature

Digital Signature was the term defined in the old I.T. Act, 2000. Electronic Signature is the
term defined by the amended act (I.T. Act, 2008). The concept of Electronic Signature is broader
than Digital Signature. Section 3 of the Act delivers for the verification of Electronic Records by
affixing Digital Signature.

As per the amendment, verification of electronic record by electronic signature or electronic


authentication technique shall be considered reliable.

According to the United Nations Commission on International Trade Law (UNCITRAL),


electronic authentication and signature methods may be classified into the following categories −

 Those based on the knowledge of the user or the recipient, i.e., passwords, personal
identification numbers (PINs), etc.
 Those bases on the physical features of the user, i.e., biometrics.
 Those based on the possession of an object by the user, i.e., codes or other information
stored on a magnetic card.
 Types of authentication and signature methods that, without falling under any of the
above categories might also be used to indicate the originator of an electronic
communication (Such as a facsimile of a handwritten signature, or a name typed at the
bottom of an electronic message).

According to the UNCITRAL MODEL LAW on Electronic Signatures, the following


technologies are presently in use −

 Digital Signature within a public key infrastructure (PKI)


 Biometric Device
 PINs
 Passwords
 Scanned handwritten signature
 Signature by Digital Pen
 Clickable “OK” or “I Accept” or “I Agree” click boxes

Offences & Penalties


The faster world-wide connectivity has developed numerous online crimes and these increased
offences led to the need of laws for protection. In order to keep in stride with the changing
generation, the Indian Parliament passed the Information Technology Act 2000 that has been
conceptualized on the United Nations Commissions on International Trade Law (UNCITRAL)
Model Law.

71 | P a g e
SCI 407 Information Systems Security and Audit

The law defines the offenses in a detailed manner along with the penalties for each category of
offence.

Offences

Cyber offences are the illegitimate actions, which are carried out in a classy manner where either
the computer is the tool or target or both.

Cyber-crime usually includes the following −

 Unauthorized access of the computers


 Data diddling
 Virus/worms attack
 Theft of computer system
 Hacking
 Denial of attacks
 Logic bombs
 Trojan attacks
 Internet time theft
 Web jacking
 Email bombing
 Salami attacks
 Physically damaging computer system.

The offences included in the I.T. Act 2000 are as follows −

 Tampering with the computer source documents.


 Hacking with computer system.
 Publishing of information which is obscene in electronic form.
 Power of Controller to give directions.
 Directions of Controller to a subscriber to extend facilities to decrypt information.
 Protected system.
 Penalty for misrepresentation.
 Penalty for breach of confidentiality and privacy.
 Penalty for publishing Digital Signature Certificate false in certain particulars.
 Publication for fraudulent purpose.
 Act to apply for offence or contravention committed outside India Confiscation.
 Penalties or confiscation not to interfere with other punishments.
 Power to investigate offences.

Example

Offences Under The It Act 2000

Section 65. Tampering with computer source documents

72 | P a g e
SCI 407 Information Systems Security and Audit

Whoever knowingly or intentionally conceals, destroys or alters or intentionally or knowingly


causes another to conceal, destroy or alter any computer source code used for a computer,
computer program, computer system or computer network, when the computer source code is
required to be kept or maintained by law for the being time in force, shall be punishable with
imprisonment up to three year, or with fine which may extend up to two lakh rupees, or with
both.

Explanation − For the purpose of this section “computer source code” means the listing of
programs, computer commands, design and layout and program analysis of computer resource in
any form.

Object − The object of the section is to protect the “intellectual property” invested in the
computer. It is an attempt to protect the computer source documents (codes) beyond what is
available under the Copyright Law

Essential ingredients of the section

knowingly or intentionally concealing

knowingly or intentionally destroying

knowingly or intentionally altering

knowingly or intentionally causing others to conceal

knowingly or intentionally causing another to destroy

knowingly or intentionally causing another to alter.

This section extends towards the Copyright Act and helps the companies to protect their source
code of their programs.

Penalties − Section 65 is tried by any magistrate.

This is cognizable and non-bailable offence.

Penalties − Imprisonment up to 3 years and / or

Fine − Two lakh rupees.

73 | P a g e
SCI 407 Information Systems Security and Audit

The following table shows the offence and penalties against all the mentioned sections of the I.T.
Act −

Bailability and
Section Offence Punishment
Congizability
Offence is Bailable,
Tampering with Computer Imprisonment up to 3 years
65 Cognizable and triable by
Source Code or fine up to Rs 2 lakhs
Court of JMFC.
Imprisonment up to 3 years Offence is Bailable,
66 Computer Related Offences
or fine up to Rs 5 lakhs Cognizable and
Sending offensive messages Offence is Bailable,
Imprisonment up to 3 years
66-A through Communication Cognizable and triable by
and fine
service, etc... Court of JMFC
Dishonestly receiving stolen Offence is Bailable,
Imprisonment up to 3 years
66-B computer resource or Cognizable and triable by
and/or fine up to Rs. 1 lakh
communication device Court of JMFC
Imprisonment of either Offence is Bailable,
66-C Identity Theft description up to 3 years Cognizable and triable by
and/or fine up to Rs. 1 lakh Court of JMFC
Imprisonment of either Offence is Bailable,
Cheating by Personation by
66-D description up to 3 years Cognizable and triable by
using computer resource
and /or fine up to Rs. 1 lakh Court of JMFC
Offence is Bailable,
Imprisonment up to 3 years
66-E Violation of Privacy Cognizable and triable by
and /or fine up to Rs. 2 lakh
Court of JMFC
Offence is Non-Bailable,
Imprisonment extend to
66-F Cyber Terrorism Cognizable and triable by
imprisonment for Life
Court of Sessions
On first Conviction,
imprisonment up to 3 years
Publishing or transmitting and/or fine up to Rs. 5 lakh Offence is Bailable,
67 obscene material in On Subsequent Conviction Cognizable and triable by
electronic form imprisonment up to 5 years Court of JMFC
and/or fine up to Rs. 10
lakh
On first Conviction
imprisonment up to 5 years
Publishing or transmitting
and/or fine up to Rs. 10 Offence is Non-Bailable,
of material containing
67-A lakh On Subsequent Cognizable and triable by
sexually explicit act, etc...
Conviction imprisonment Court of JMFC
in electronic form
up to 7 years and/or fine up
to Rs. 10 lakh

74 | P a g e
SCI 407 Information Systems Security and Audit

On first Conviction
imprisonment of either
description up to 5 years
Publishing or transmitting
and/or fine up to Rs. 10 Offence is Non Bailable,
of material depicting
67-B lakh On Subsequent Cognizable and triable by
children in sexually explicit
Conviction imprisonment of Court of JMFC
act etc., in electronic form
either description up to 7
years and/or fine up to Rs.
10 lakh
Intermediary intentionally
or knowingly contravening
Imprisonment up to 3 years Offence is Bailable,
67-C the directions about
and fine Cognizable.
Preservation and retention
of information
Failure to comply with the
Imprisonment up to 2 years Offence is Bailable, Non-
68 directions given by
and/or fine up to Rs. 1 lakh Cognizable.
Controller
Failure to assist the agency
referred to in sub section (3)
in regard interception or Imprisonment up to 7 years Offence is Non-Bailable,
69
monitoring or decryption of and fine Cognizable.
any information through
any computer resource
Failure of the intermediary
to comply with the direction
issued for blocking for Imprisonment up to 7 years Offence is Non-Bailable,
69-A
public access of any and fine Cognizable.
information through any
computer resource
Intermediary who
intentionally or knowingly
contravenes the provisions
of sub-section (2) in regard Imprisonment up to 3 years Offence is Bailable,
69-B
monitor and collect traffic and fine Cognizable.
data or information through
any computer resource for
cybersecurity
Any person who secures
access or attempts to secure Imprisonment of either
Offence is Non-Bailable,
70 access to the protected description up to 10 years
Cognizable.
system in contravention of and fine
provision of Sec. 70
Indian Computer
Imprisonment up to 1 year Offence is Bailable, Non-
70-B Emergency Response Team
and/or fine up to Rs. 1 lakh Cognizable
to serve as national agency

75 | P a g e
SCI 407 Information Systems Security and Audit

for incident response. Any


service provider,
intermediaries, data centres,
etc., who fails to prove the
information called for or
comply with the direction
issued by the ICERT.
Misrepresentation to the Imprisonment up to 2 years
Offence is Bailable, Non-
71 Controller to the Certifying and/ or fine up to Rs. 1
Cognizable.
Authority lakh.
Breach of Confidentiality Imprisonment up to 2 years Offence is Bailable, Non-
72
and privacy and/or fine up to Rs. 1 lakh. Cognizable.
Disclosure of information in Imprisonment up to 3 years Offence is Cognizable,
72-A
breach of lawful contract and/or fine up to Rs. 5 lakh. Bailable
Publishing electronic
Imprisonment up to 2 years Offence is Bailable, Non-
73 Signature Certificate false
and/or fine up to Rs. 1 lakh Cognizable.
in certain particulars
Publication for fraudulent Imprisonment up to 2 years Offence is Bailable, Non-
74
purpose and/or fine up to Rs. 1 lakh Cognizable.
Compounding of Offences

As per Section 77-A of the I. T. Act, any Court of competent jurisdiction may compound offences,
other than offences for which the punishment for life or imprisonment for a term exceeding three
years has been provided under the Act.

No offence shall be compounded if −

 The accused is, by reason of his previous conviction, is liable to either enhanced
punishment or to the punishment of different kind; OR
 Offence affects the socio economic conditions of the country; OR
 Offence has been committed against a child below the age of 18 years; OR
 Offence has been committed against a woman.

The person alleged of an offence under this Act may file an application for compounding in the
Court. The offence will then be pending for trial and the provisions of Sections 265-B and 265-C
of Cr. P.C. shall apply.

IT Security & Cyber Law Summary


Cyber Laws are the sole savior to combat cyber-crime. It is only through stringent laws that
unbreakable security could be provided to the nation’s information. The I.T. Act of India came
up as a special act to tackle the problem of Cyber Crime. The Act was sharpened by the
Amendment Act of 2008.

76 | P a g e
SCI 407 Information Systems Security and Audit

Cyber Crime is committed every now and then, but is still hardly reported. The cases of cyber-
crime that reaches to the Court of Law are therefore very few. There are practical difficulties in
collecting, storing and appreciating Digital Evidence. Thus the Act has miles to go before it can
be truly effective.

In this tutorial, we have tried to cover all the current and major topics related to Cyber Laws and
IT Security. We would like to quote the words of a noted cyber law expert and Supreme Court
advocate Mr Pavan Duggal to conclude this tutorial.

While the lawmakers have to be complemented for their admirable work removing various
deficiencies in the Indian Cyberlaw and making it technologically neutral, yet it appears that there
has been a major mismatch between the expectation of the nation and the resultant effect of the
amended legislation. The most bizarre and startling aspect of the new amendments is that these
amendments seek to make the Indian cyberlaw a cyber-crime friendly legislation; − a legislation
that goes extremely soft on cyber criminals, with a soft heart; a legislation that chooses to
encourage cyber criminals by lessening the quantum of punishment accorded to them under the
existing law; .... a legislation which makes a majority of cybercrimes stipulated under the IT Act
as bailable offences; a legislation that is likely to pave way for India to become the potential cyber-
crime capital of the world.

Cyber Crimes FAQs


1. What is Cybercrime?

A. Cybercrime refers to all the activities done with criminal intent in cyberspace. Because of the
anonymous nature of the internet, miscreants engage in a variety of criminal activities. The field
of cybercrime is just emerging and new forms of criminal activities in cyberspace are coming to
the forefront with each passing day.

2. Do we have an exhaustive definition of Cybercrime?

A. No, unfortunately we don’t have an exhaustive definition of cybercrime. However, any online
activity which basically offends human sensibilities can be regarded as a cybercrime.

3. What are the various categories of Cybercrimes?

A. Cybercrimes can be basically divided into three major categories −

 Cybercrimes against persons,


 Cybercrimes against property, and
 Cybercrimes against Government.

4. Tell us more about Cybercrimes against persons.

77 | P a g e
SCI 407 Information Systems Security and Audit

A. Cybercrimes committed against persons include various crimes like transmission of child
pornography, harassment using e-mails and cyber-stalking. Posting and distributing obscene
material is one of the most important Cybercrimes known today.

5. Is Cyber harassment also a Cybercrime?

A. Cyber harassment is a distinct cybercrime. Various kinds of harassment does occur in


cyberspace. Harassment can be sexual, racial, religious, or other. Cyber harassment as a crime
also brings us to another related area of violation of privacy of netizens. Violation of privacy of
online citizens is a Cybercrime of a grave nature.

6. What are Cybercrimes against property?

A. Cybercrimes against all forms of property include unauthorized computer trespassing through
cyberspace, computer vandalism, transmission of harmful programs, and unauthorized
possession of computerized information.

7. Is hacking a Cybercrime?

A. Hacking is amongst the gravest Cybercrimes known till date. It is a dreadful feeling to know
that a stranger has broken into your computer system without your knowledge and has tampered
with precious confidential data.

The bitter truth is that no computer system in the world is hacking proof. It is unanimously
agreed that any system, however secure it might look, can be hacked. The recent denial of
service attacks seen over the popular commercial sites like E-bay, Yahoo, and Amazon are a new
category of Cybercrimes which are slowly emerging as being extremely dangerous.

Using one's own programming abilities to gain unauthorized access to a computer or network is a
very serious crime. Similarly, the creation and dissemination of harmful computer programs
which do irreparable damage to computer systems is another kind of Cybercrime.

8. What is Cybercrime against Government?

A. Cyber Terrorism is one distinct example of cybercrime against government. The growth of
Internet has shown that the medium of cyberspace is being used by individuals and groups to
threaten the governments as also to terrorize the citizens of a country. This crime manifests itself
into terrorism when an individual hacks into a government or military maintained website.

9. Is there any comprehensive law on Cybercrime today?

A. As of now, we don’t have any comprehensive laws on cybercrime anywhere in the world.
This is the reason that the investigating agencies like FBI are finding the Cyberspace to be an
extremely difficult terrain. Cybercrimes fall into that grey area of Internet law which is neither
fully nor partially covered by the existing laws. However, countries are taking crucial measures
to establish stringent laws on cybercrime.

78 | P a g e
SCI 407 Information Systems Security and Audit

10. Is there any recent case which demonstrates the importance of having a cyber law on
cybercrime within the national jurisdictions of countries?

A. The most recent case of the virus "I love you" demonstrates the need for having cyber laws
concerning cybercrimes in different national jurisdictions. At the time of the web publication of
this feature, Reuters has reported that "The Philippines has yet to arrest the suspected creator of
the 'Love Bug' computer virus because it lacks laws that deal with computer crime, a senior
police officer said". The fact of the matter is that there are no laws relating to cybercrime in the
Philippines.

11. What is Vishing?

A. Vishing is the criminal practice of using social influence over the telephone system, most
often using features facilitated by Voice over IP (VoIP), to gain access to sensitive information
such as credit card details from the public. The term is a combination of "Voice" and phishing.

12. What is Mail Fraud?

A. Mail fraud is an offense under United States federal law, which includes any scheme that
attempts to unlawfully obtain money or valuables in which the postal system is used at any point
in the commission of a criminal offense.

13. What is ID Spoofing?

A. It is the practice of using the telephone network to display a number on the recipient's Caller
ID display which is not that of the actual originating station.

14. What is Cyber espionage?

A. It is the act or practice of obtaining secrets from individuals, competitors, rivals, groups,
governments, and enemies for military, political, or economic advantage using illegal
exploitation methods on the internet.

15. What is the meaning of Sabotage?

A. Sabotage literally means willful damage to any machinery or materials or disruption of work.
In the context of cyberspace, it is a threat to the existence of computers and satellites used by
military activities

16. Name the democratic country in which The Cyber Defamation law was first introduced.

A. South Korea is the first democratic country in which this law was introduced first.

17. What are Bots?

79 | P a g e
SCI 407 Information Systems Security and Audit

A. Bots are one of the most sophisticated types of crime-ware facing the internet today. Bots earn
their unique name by performing a wide variety of automated tasks on behalf of the cyber
criminals. They play a part in "denial of service" attack in internet.

18. What are Trojans and Spyware?

A. Trojans and spyware are the tools a cyber-criminal might use to obtain unauthorized access
and steal information from a victim as part of an attack.

19. What are Phishing and Pharming?

A. Phishing and Pharming are the most common ways to perform identity theft which is a form
of cyber-crime in which criminals use the internet to steal personal information from others.

20. Mention some tips to prevent cyber-crimes.

 Read the latest ways hackers create phishing scams to gain access to your personal
information.
 Install a firewall on your computer to keep unwanted threats and attacks to a minimum.
 Use caution while opening emails and clicking links. You should read carefully while
downloading content from unverified sources.
 Create strong passwords for any websites where personal information is stored.

Managing IS and the Law

Confidentiality and Privacy

There is an ongoing conflict between privacy and accessibility. While society feels there should
be universal accessibility of information, there is also the feeling that individual information or
information owned by an individual or organization should be protected such that only what he
owner wants seen can be accessed.

Privacy: This is the individual’s right to determine for themselves what about them is
communicated to others [i.e. at the personal level]
Confidentiality: An organization’s right to determine what will be communicated about
commercially held information that is not about people i.e. sales data, R&D findings, profitability
records, etc. [i.e. at the commercial level]

Privacy and confidentiality is important. However, there should be free interaction through the
disclosure of information. The are no explicit legal precepts about privacy and confidentiality.
However, other laws provide limited indirect cover e.g. laws on contract, defamation, trespass,
copyright, etc.
Personal data protection must be a balance between the individual and society and the legal
framework is the correct way that authority regulates that balance.

80 | P a g e
SCI 407 Information Systems Security and Audit

The notion of privacy goes beyond the content of a data to the use the data will be made of. This
varies between societies, countries and individuals.)

Privacy Issues
1) Fair use: Data should be used to in support of the organization’s specific business mission.
This requires the organization to seek an individual’s permission before passing data to others
(informed consent). It is increasingly being felt that personal data should not be used for
marketing purposes for instance direct advertising. There is also the fear that the collected,
reformatted information about individuals may fall into the wrong hands and is used for
political harassment or to allow criminals to identify soft targets (lucrative individuals)
2) Gate Keeping: The restricted access to services, privileges, benefits or opportunities on the
basis of certain data values. Some gate keeping seems inevitable and acceptable e.g. entry to a
university based on certain points e.g. grading or scoring system for credit provision. However,
the same principle can be used to keep “trouble makers” out. The only problem is, “who
decides who is a trouble maker?’’

Data Protection Act 1984 (UK)

 The act gives individuals rights about what may be stored and processed about them on
computer or other automatic data processing medium.
 It also gives the right to examine the information, challenge it, if appropriate have it amended
or deleted where necessary and, in some cases claim compensation for damages.
 The act also places certain obligations on the data user in that they must register their data use
with the data protection register, and implement good practice regarding the usage and
disclosure of information held.

Responsibility Rights of the Data


of the Data User Subject
Adhere to the eight data protection  Establish what personal data is stored by
principles sending a subject access request
Register data use to validate  Ensure data stored is accurate and
adherence to the data protection correctly collected, stored or used
principles
 Can complain to data protection
registrar
 Can claim compensation through court
actions.

81 | P a g e
SCI 407 Information Systems Security and Audit

Principles upon Which Data Protection Act is Founded

I. The information to be contained in personal data shall be obtained, and personal data shall
be processed fairly and lawfully.
II. Personal data shall be held only for one or more specified and lawful purpose(s)
III. Personal data held for any purpose or purposes shall not be used or disclosed in any manner
incompatible with that purpose or those purposes
IV. Personal data held for any purpose or purposes shall be adequate, relevant and not
excessive in relation to that purpose or those purposes.
V. Personal data shall be accurate and, where necessary kept up to date.
VI. Personal data held for any purpose or purposes shall not be kept for longer than is necessary
for that purpose or those purposes.
VII. An individual shall be entitled at reasonable intervals and without undue delay or expense:
to be informed by any data user whether he holds personal data of which that individual is
target, to access any such data held by a data user, and where appropriate to have such data
corrected or erased.
VIII. Appropriate security measures shall be undertaken against unauthorized access to, or
alteration, disclosure or destruction of, personal data and against accidental loss or
destruction of personal data.

Example Data Users that hold data and use it for certain purposes:
Banks, insurance companies, credit rating bureaus, hospitals, doctors, police, government
agencies, post office, education and school records, driver and vehicle license center, customs and
excise, revenue authority, employers, etc.

Subject Access Exemptions


Judicial appointment
Legal professional privilege
Statistical or research data
Back up data
Credit reference data
Data incriminating the data user

Total Exemptions
Information required by law to be public e.g. share registers
National Security data
Employee data for calculation of wages, pensions, keeping accounts, or keeping records of
purchases or sales for accounting purposes
Data used only for preparing text documents, house hold affairs or for recreational use
[Everyone else must apply for registration]

Copyright and Software Protection

82 | P a g e
SCI 407 Information Systems Security and Audit

“Intellectual Property Protection”. [Patents, Copyright, trademarks, Design]

Hardware developments are covered for protecting ownership by the law on patents. There is need
for software to be protected because of the high amounts of investments towards developments
(failure will mean. Failure to have software protection will mean that ‘small fish’ and new comers
may not go far. There is however need to guard against being too draconian (suppose Newton
had patented all acknowledgement of the laws of gravity?)
UK patents act 1977 protects monopoly right to inventions. This specifically excludes programs
(software) as inventions. This means that only organizations developing new hardware
components or physical devices can use this form of protection. IS management is not covered by
trademarks act 1938, which protects areas of organizations.
Confidence

Ways of working, plans, interactions are all trade secrets and protection for them is achieved
through the law of confidentiality. This has to be built in by direct contractual obligation e.g.
members of the IS function are duty bound contractually as per their employment not to disclose
plans to develop an innovative use of IS. To ensure consultants and contractors keep confidence,
there is need to build this in when coming up with contractual documents.

Copyright
Copyright, designs and patents acts 1988 confirms that software is a literally work for the purpose
of copyright. Copyright means that there are a number of actions that only the copyright owner
may do. These are:
 To copy the work
 To issue copies of the work to public (including rental copies)
 To perform, show or play the work in public
 To broadcast the work or include it in a cable programme service
 To make an adaptation of the work or do any of the above with an adaptation.

The copyright (computer programs) regulations 1992 make permissible some further specific to
computer programs such as taking back up copy. Chips are covered by their own special form of
copyright, Designs and patents act, 1988.

Issues of legality
Reverse engineering as copyright primarily protects the source code and documentation. In the
US, there has been many “look and feel” copyright case in the judicial system.

Other ways of protecting software


 Randomizing blocks in the source code to ‘hide’ its logic even when the object code is dis-
assembled.
 Making lower prices to make illegal copies less attractive.
 Need for hardware devices to be present for the software to work on (very inconvenience for
users).

83 | P a g e
SCI 407 Information Systems Security and Audit

Software Piracy

This is the breach of copyright of a mass-market product, or a breach of a bespoke development.


Software piracy is the clearly detectable copying of commercially available software e.g. popular
PC software, which is readily copyable and readily seleable as many have the skills and equipment
and interest to illegal copies. The critical issue is the detection of pirated software, which is the
difficult part. Software houses are anxious to protect their development after investing large
amounts of resources. Software Piracy is very widespread.

Ordinary users unaware of the law - 59%


Budget-conscious MIS managers - 21%
Unscrupulous resellers - 7%
Students - 1%

1100 software piracy investigations 1992 – offender analysis [courtesy of Wendy Robson]

Need for Software Management charter


 Ensure staff understand the law and its penalties
 Appoint a software auditor
 Conduct audits and regular unannounced software inspections
 Maintain a register of all software bought and its location
 Ensure secure storage of original media
 Budget enough and plan ahead to meet further needs
 Initiate internal disciplining procedures for illegal copies.

Contracts

Areas of Contracts

Functionality
Reliability
Performance
Portability
Maintainability
Availability
Economy

84 | P a g e
SCI 407 Information Systems Security and Audit

Areas to be addressed

Specify what deliverables will constitute acceptable completion of the assignment


Define a time schedule for completing each deliverable
Obtain estimated cost of each deliverable
Specify certain daily sums to be deducted from the amount owed if the consultant fails to meet
certain time performance limitations.
Specify the right to terminate at will without prior written notice
Require written status reports or meetings on a regular and specified basis.
Clearly identify the responsibilities of both client and the consultant.

Health and safety

Need to address the effects of the computer on the working place and the nature of work and the
body, eyes, back, etc

Information systems and Crime

Input fraud – entry of unauthorized instructions.


Data fraud – alteration of input data
Output fraud – suppression of data
Program fraud – creating or altering a program to perform a fraudulent act.

Computer – Assisted Crime

Hacking
Viruses
Computer Chip theft

Many “computer crimes” are traditional crimes simply using a computer as a tool e.g. on-line
banking theft of fraud.

Sample Information Security Policy

I. POLICY

A. It is the policy of ORGANIZATION XYZ that information, as defined hereinafter,


in all its forms--written, spoken, recorded electronically or printed--will be
protected from accidental or intentional unauthorized modification, destruction or
disclosure throughout its life cycle. This protection includes an appropriate level

85 | P a g e
SCI 407 Information Systems Security and Audit

of security over the equipment and software used to process, store, and transmit
that information.
B. All policies and procedures must be documented and made available to
individuals responsible for their implementation and compliance. All activities
identified by the policies and procedures must also be documented. All the
documentation, which may be in electronic form, must be retained for at least 6
(six) years after initial creation, or, pertaining to policies and procedures, after
changes are made. All documentation must be periodically reviewed for
appropriateness and currency, a period of time to be determined by each entity
within ORGANIZATION XYZ.

C. At each entity and/or department level, additional policies, standards and


procedures will be developed detailing the implementation of this policy and set
of standards, and addressing any additional information systems functionality in
such entity and/or department. All departmental policies must be consistent with
this policy. All systems implemented after the effective date of these policies are
expected to comply with the provisions of this policy where possible. Existing
systems are expected to be brought into compliance where possible and as soon
as practical.
II. SCOPE

A. The scope of information security includes the protection of the confidentiality,


integrity and availability of information.
B. The framework for managing information security in this policy applies to all
ORGANIZATION XYZ entities and workers, and other Involved Persons and all
Involved Systems throughout ORGANIZATION XYZ as defined below in
INFORMATION SECURITY DEFINITIONS.
C. This policy and all standards apply to all protected health information and other
classes of protected information in any form as defined below in INFORMATION
CLASSIFICATION.

III. RISK MANAGEMENT

A. A thorough analysis of all ORGANIZATION XYZ information networks and


systems will be conducted on a periodic basis to document the threats and
vulnerabilities to stored and transmitted information. The analysis will examine
the types of threats – internal or external, natural or manmade, electronic and non-
electronic-- that affect the ability to manage the information resource. The
analysis will also document the existing vulnerabilities within each entity which
potentially expose the information resource to the threats. Finally, the analysis
will also include an evaluation of the information assets and the technology
associated with its collection, storage, dissemination and protection.
From the combination of threats, vulnerabilities, and asset values, an estimate of
the risks to the confidentiality, integrity and availability of the information will be

86 | P a g e
SCI 407 Information Systems Security and Audit

determined. The frequency of the risk analysis will be determined at the entity
level.
B. Based on the periodic assessment, measures will be implemented that reduce the
impact of the threats by reducing the amount and scope of the vulnerabilities.

IV. INFORMATION SECURITY DEFINITIONS

Affiliated Covered Entities: Legally separate, but affiliated, covered entities which
choose to designate themselves as a single covered entity for purposes of HIPAA.

Availability: Data or information is accessible and usable upon demand by an


authorized person.
Confidentiality: Data or information is not made available or disclosed to unauthorized
persons or processes.
HIPAA: The Health Insurance Portability and Accountability Act, a federal law passed in
1996 that affects the healthcare and insurance industries. A key goal of the HIPAA
regulations is to protect the privacy and confidentiality of protected health information by
setting and enforcing standards.
Integrity: Data or information has not been altered or destroyed in an unauthorized
manner.
Involved Persons: Every worker at ORGANIZATION XYZ -- no matter what their status.
This includes physicians, residents, students, employees, contractors, consultants,
temporaries, volunteers, interns, etc.
Involved Systems: All computer equipment and network systems that are operated
within the ORGANIZATION XYZ environment. This includes all platforms (operating
systems), all computer sizes (personal digital assistants, desktops, mainframes, etc.),
and all applications and data (whether developed in-house or licensed from third parties)
contained on those systems.
Protected Health Information (PHI): PHI is health information, including demographic
information, created or received by the ORGANIZATION XYZ entities which relates to
the past, present, or future physical or mental health or condition of an individual; the
provision of health care to an individual; or the past, present, or future payment for the
provision of health care to an individual and that identifies or can be used to identify the
individual.
Risk: The probability of a loss of confidentiality, integrity, or availability of information
resources.

V. INFORMATION SECURITY RESPONSIBILITIES

A. Information Security Officer: The Information Security Officer (ISO) for each
entity is responsible for working with user management, owners, custodians, and
users to develop and implement prudent security policies, procedures, and
controls, subject to the approval of ORGANIZATION XYZ. Specific
responsibilities include:

87 | P a g e
SCI 407 Information Systems Security and Audit

1. Ensuring security policies, procedures, and standards are in place and


adhered to by entity.
2. Providing basic security support for all systems and users.
3. Advising owners in the identification and classification of computer
resources. See Section VI Information Classification.
4. Advising systems development and application owners in the
implementation of security controls for information on systems, from the
point of system design, through testing and production implementation.
5. Educating custodian and user management with comprehensive
information about security controls affecting system users and application
systems.
6. Providing on-going employee security education.
7. Performing security audits.
8. Reporting regularly to the ORGANIZATION XYZ Oversight Committee on
entity’s status with regard to information security.
B. Information Owner: The owner of a collection of information is usually the
manager responsible for the creation of that information or the primary user of
that information. This role often corresponds with the management of an
organizational unit. In this context, ownership does not signify proprietary
interest, and ownership may be shared. The owner may delegate ownership
responsibilities to another individual by completing the ORGANIZATION XYZ
Information Owner Delegation Form. The owner of information has the
responsibility for:
1. Knowing the information for which she/he is responsible.
2. Determining a data retention period for the information, relying on advice
from the Legal Department.
3. Ensuring appropriate procedures are in effect to protect the integrity,
confidentiality, and availability of the information used or created within
the unit.
4. Authorizing access and assigning custodianship.
5. Specifying controls and communicating the control requirements to the
custodian and users of the information.
6. Reporting promptly to the ISO the loss or misuse of ORGANIZATION
XYZ information.
7. Initiating corrective actions when problems are identified.
8. Promoting employee education and awareness by utilizing programs
approved by the ISO, where appropriate.
9. Following existing approval processes within the respective organizational
unit for the selection, budgeting, purchase, and implementation of any
computer system/software to manage information.
C. Custodian: The custodian of information is generally responsible for the
processing and storage of the information. The custodian is responsible for the

88 | P a g e
SCI 407 Information Systems Security and Audit

administration of controls as specified by the owner. Responsibilities may


include:
1. Providing and/or recommending physical safeguards.
2. Providing and/or recommending procedural safeguards.
3. Administering access to information.
4. Releasing information as authorized by the Information Owner and/or the
Information Privacy/ Security Officer for use and disclosure using
procedures that protect the privacy of the information.
5. Evaluating the cost effectiveness of controls.
6. Maintaining information security policies, procedures and standards as
appropriate and in consultation with the ISO.
7. Promoting employee education and awareness by utilizing programs
approved by the ISO, where appropriate.
8. Reporting promptly to the ISO the loss or misuse of ORGANIZATION
XYZ information.
9. Identifying and responding to security incidents and initiating appropriate
actions when problems are identified.
D. User Management: ORGANIZATION XYZ management who supervise users as
defined below. User management is responsible for overseeing their employees'
use of information, including:
1. Reviewing and approving all requests for their employees access
authorizations.
2. Initiating security change requests to keep employees' security record
current with their positions and job functions.
3. Promptly informing appropriate parties of employee terminations and
transfers, in accordance with local entity termination procedures.
4. Revoking physical access to terminated employees, i.e., confiscating
keys, changing combination locks, etc.
5. Providing employees with the opportunity for training needed to properly
use the computer systems.
6. Reporting promptly to the ISO the loss or misuse of ORGANIZATION
XYZ information.
7. Initiating corrective actions when problems are identified.
8. Following existing approval processes within their respective organization
for the selection, budgeting, purchase, and implementation of any
computer system/software to manage information.
E. User: The user is any person who has been authorized to read, enter, or update
information. A user of information is expected to:
1. Access information only in support of their authorized job responsibilities.
2. Comply with Information Security Policies and Standards and with all
controls established by the owner and custodian.

89 | P a g e
SCI 407 Information Systems Security and Audit

3. Refer all disclosures of PHI (1) outside of ORGANIZATION XYZ and (2)
within ORGANIZATION XYZ, other than for treatment, payment, or health
care operations, to the applicable entity’s Medical/Health Information
Management Department. In certain circumstances, the Medical/Health
Information Management Department policies may specifically delegate
the disclosure process to other departments. (For additional information,
see ORGANIZATION XYZ Privacy/Confidentiality of Protected Health
Information (PHI) Policy.)
4. Keep personal authentication devices (e.g. passwords, SecureCards,
PINs, etc.) confidential.
5. Report promptly to the ISO the loss or misuse of ORGANIZATION XYZ
information.
6. Initiate corrective actions when problems are identified.

VI. INFORMATION CLASSIFICATION


Classification is used to promote proper controls for safeguarding the confidentiality of
information. Regardless of classification the integrity and accuracy of all classifications of
information must be protected. The classification assigned and the related controls
applied are dependent on the sensitivity of the information. Information must be
classified according to the most sensitive detail it includes. Information recorded in
several formats (e.g., source document, electronic record, report) must have the same
classification regardless of format. The following levels are to be used when classifying
information:
A. Protected Health Information (PHI)
1. PHI is information, whether oral or recorded in any form or medium, that:
a. is created or received by a healthcare provider, health plan, public
health authority, employer, life insurer, school or university or
health clearinghouse; and
b. relates to past, present or future physical or mental health or
condition of an individual, the provision of health care to an
individual, or the past present or future payment for the provision
of health care to an individual; and
c. includes demographic data, that permits identification of the
individual or could reasonably be used to identify the individual.
2. Unauthorized or improper disclosure, modification, or destruction of this
information could violate state and federal laws, result in civil and criminal
penalties, and cause serious damage to ORGANIZATION XYZ and its
patients or research interests.
B. Confidential Information
1. Confidential Information is very important and highly sensitive material
that is not classified as PHI. This information is private or otherwise
sensitive in nature and must be restricted to those with a legitimate
business need for access.

90 | P a g e
SCI 407 Information Systems Security and Audit

Examples of Confidential Information may include: personnel information,


key financial information, proprietary information of commercial research
sponsors, system access passwords and information file encryption keys.
2. Unauthorized disclosure of this information to people without a business
need for access may violate laws and regulations, or may cause
significant problems for ORGANIZATION XYZ, its customers, or its
business partners. Decisions about the provision of access to this
information must always be cleared through the information owner.
C. Internal Information
1. Internal Information is intended for unrestricted use within
ORGANIZATION XYZ, and in some cases within affiliated organizations
such as ORGANIZATION XYZ business partners. This type of information
is already widely-distributed within ORGANIZATION XYZ, or it could be
so distributed within the organization without advance permission from
the information owner.
Examples of Internal Information may include: personnel directories,
internal policies and procedures, most internal electronic mail messages.
2. Any information not explicitly classified as PHI, Confidential or Public will,
by default, be classified as Internal Information.
3. Unauthorized disclosure of this information to outsiders may not be
appropriate due to legal or contractual provisions.
D. Public Information
1. Public Information has been specifically approved for public release by a
designated authority within each entity of ORGANIZATION XYZ.
Examples of Public Information may include marketing brochures and
material posted to ORGANIZATION XYZ entity internet web pages.
2. This information may be disclosed outside of ORGANIZATION XYZ.

VII. COMPUTER AND INFORMATION CONTROL


All involved systems and information are assets of ORGANIZATION XYZ and are expected to
be protected from misuse, unauthorized manipulation, and destruction. These protection
measures may be physical and/or software based.
A. Ownership of Software: All computer software developed by ORGANIZATION
XYZ employees or contract personnel on behalf of ORGANIZATION XYZ or
licensed for ORGANIZATION XYZ use is the property of ORGANIZATION XYZ
and must not be copied for use at home or any other location, unless otherwise
specified by the license agreement.
B. Installed Software: All software packages that reside on computers and
networks within ORGANIZATION XYZ must comply with applicable licensing
agreements and restrictions and must comply with ORGANIZATION XYZ
acquisition of software policies.
C. Virus Protection: Virus checking systems approved by the Information Security
Officer and Information Services must be deployed using a multi-layered
approach (desktops, servers, gateways, etc.) that ensures all electronic files are

91 | P a g e
SCI 407 Information Systems Security and Audit

appropriately scanned for viruses. Users are not authorized to turn off or disable
virus checking systems.
D. Access Controls: Physical and electronic access to PHI, Confidential and
Internal information and computing resources is controlled. To ensure
appropriate levels of access by internal workers, a variety of security measures
will be instituted as recommended by the Information Security Officer and
approved by ORGANIZATION XYZ. Mechanisms to control access to PHI,
Confidential and Internal information include (but are not limited to) the following
methods:
1. Authorization: Access will be granted on a “need to know” basis and
must be authorized by the immediate supervisor and application owner
with the assistance of the ISO. Any of the following methods are
acceptable for providing access under this policy:
a. Context-based access: Access control based on the context of a
transaction (as opposed to being based on attributes of the
initiator or target). The “external” factors might include time of day,
location of the user, strength of user authentication, etc.
b. Role-based access: An alternative to traditional access control
models (e.g., discretionary or non-discretionary access control
policies) that permits the specification and enforcement of
enterprise-specific security policies in a way that maps more
naturally to an organization’s structure and business activities.
Each user is assigned to one or more predefined roles, each of
which has been assigned the various privileges needed to perform
that role.
c. User-based access: A security mechanism used to grant users of
a system access based upon the identity of the user.
2. Identification/Authentication: Unique user identification (user id) and
authentication is required for all systems that maintain or access PHI,
Confidential and/or Internal Information. Users will be held accountable
for all actions performed on the system with their user id.
a. At least one of the following authentication methods must be
implemented:
1. strictly controlled passwords (Attachment 1 – Password
Control Standards),
2. biometric identification, and/or
3. tokens in conjunction with a PIN.
b. The user must secure his/her authentication control (e.g.
password, token) such that it is known only to that user and
possibly a designated security manager.
c. An automatic timeout re-authentication must be required after a
certain period of no activity (maximum 15 minutes).
d. The user must log off or secure the system when leaving it.

92 | P a g e
SCI 407 Information Systems Security and Audit

3. Data Integrity: ORGANIZATION XYZ must be able to provide


corroboration that PHI, Confidential, and Internal Information has not
been altered or destroyed in an unauthorized manner. Listed below are
some methods that support data integrity:
a. transaction audit
b. disk redundancy (RAID)
c. ECC (Error Correcting Memory)
d. checksums (file integrity)
e. encryption of data in storage
f. digital signatures
4. Transmission Security: Technical security mechanisms must be put in
place to guard against unauthorized access to data that is transmitted
over a communications network, including wireless networks. The
following features must be implemented:
a. integrity controls and
b. encryption, where deemed appropriate
5. Remote Access: Access into ORGANIZATION XYZ network from
outside will be granted using ORGANIZATION XYZ approved devices
and pathways on an individual user and application basis. All other
network access options are strictly prohibited. Further, PHI, Confidential
and/or Internal Information that is stored or accessed remotely must
maintain the same level of protections as information stored and
accessed within the ORGANIZATION XYZ network.
6. Physical Access: Access to areas in which information processing is
carried out must be restricted to only appropriately authorized individuals.
The following physical controls must be in place:
a. Mainframe computer systems must be installed in an access-
controlled area. The area in and around the computer facility must
afford protection against fire, water damage, and other
environmental hazards such as power outages and extreme
temperature situations.
b. File servers containing PHI, Confidential and/or Internal
Information must be installed in a secure area to prevent theft,
destruction, or access by unauthorized individuals.
c. Workstations or personal computers (PC) must be secured
against use by unauthorized individuals. Local procedures and
standards must be developed on secure and appropriate
workstation use and physical safeguards which must include
procedures that will:
1. Position workstations to minimize unauthorized viewing of
protected health information.
2. Grant workstation access only to those who need it in order to
perform their job function.

93 | P a g e
SCI 407 Information Systems Security and Audit

3. Establish workstation location criteria to eliminate or


minimize the possibility of unauthorized access to
protected health information.
4. Employ physical safeguards as determined by risk
analysis, such as locating workstations in controlled
access areas or installing covers or enclosures to preclude
passerby access to PHI.
5. Use automatic screen savers with passwords to protect
unattended machines.
d. Facility access controls must be implemented to limit physical
access to electronic information systems and the facilities in which
they are housed, while ensuring that properly authorized access is
allowed. Local policies and procedures must be developed to
address the following facility access control requirements:
1. Contingency Operations – Documented procedures that allow
facility access in support of restoration of lost data under the
disaster recovery plan and emergency mode operations plan
in the event of an emergency.
2. Facility Security Plan – Documented policies and
procedures to safeguard the facility and the equipment
therein from unauthorized physical access, tampering, and
theft.
3. Access Control and Validation – Documented procedures
to control and validate a person’s access to facilities based
on their role or function, including visitor control, and
control of access to software programs for testing and
revision.
4. Maintenance records – Documented policies and
procedures to document repairs and modifications to the
physical components of the facility which are related to
security (for example, hardware, walls, doors, and locks).
7. Emergency Access:
a. Each entity is required to establish a mechanism to provide
emergency access to systems and applications in the event that
the assigned custodian or owner is unavailable during an
emergency.
b. Procedures must be documented to address:
1. Authorization,
2. Implementation, and
3. Revocation
E. Equipment and Media Controls: The disposal of information must ensure the
continued protection of PHI, Confidential and Internal Information. Each entity
must develop and implement policies and procedures that govern the receipt and
removal of hardware and electronic media that contain PHI into and out of a

94 | P a g e
SCI 407 Information Systems Security and Audit

facility, and the movement of these items within the facility. The following
specification must be addressed:
1. Information Disposal / Media Re-Use of:
a. Hard copy (paper and microfilm/fiche)
b. Magnetic media (floppy disks, hard drives, zip disks, etc.) and
c. CD ROM Disks
2. Accountability: Each entity must maintain a record of the movements of
hardware and electronic media and any person responsible therefore.
3. Data backup and Storage: When needed, create a retrievable, exact
copy of electronic PHI before movement of equipment.
F. Other Media Controls:
1. PHI and Confidential Information stored on external media (diskettes, cd-
roms, portable storage, memory sticks, etc.) must be protected from theft
and unauthorized access. Such media must be appropriately labeled so
as to identify it as PHI or Confidential Information. Further, external media
containing PHI and Confidential Information must never be left
unattended in unsecured areas.
2. PHI and Confidential Information must never be stored on mobile
computing devices (laptops, personal digital assistants (PDA), smart
phones, tablet PC’s, etc.) unless the devices have the following minimum
security requirements implemented:
a. Power-on passwords
b. Auto logoff or screen saver with password
c. Encryption of stored data or other acceptable safeguards
approved by Information Security Officer
Further, mobile computing devices must never be left unattended in
unsecured areas.
3. If PHI or Confidential Information is stored on external medium or mobile
computing devices and there is a breach of confidentiality as a result,
then the owner of the medium/device will be held personally accountable
and is subject to the terms and conditions of ORGANIZATION XYZ
Information Security Policies and Confidentiality Statement signed as a
condition of employment or affiliation with ORGANIZATION XYZ.
H. Data Transfer/Printing:
1. Electronic Mass Data Transfers: Downloading and uploading PHI,
Confidential, and Internal Information between systems must be strictly
controlled. Requests for mass downloads of, or individual requests for,
information for research purposes that include PHI must be approved
through the Internal Review Board (IRB). All other mass downloads of
information must be approved by the Application Owner and include only
the minimum amount of information necessary to fulfill the request.
Applicable Business Associate Agreements must be in place when

95 | P a g e
SCI 407 Information Systems Security and Audit

transferring PHI to external entities (see ORGANIZATION XYZ policy B-2


entitled “Business Associates”).
2. Other Electronic Data Transfers and Printing: PHI, Confidential and
Internal Information must be stored in a manner inaccessible to
unauthorized individuals. PHI and Confidential information must not be
downloaded, copied or printed indiscriminately or left unattended and
open to compromise. PHI that is downloaded for educational purposes
where possible should be de-identified before use.
I. Oral Communications: ORGANIZATION XYZ staff should be aware of their
surroundings when discussing PHI and Confidential Information. This includes
the use of cellular telephones in public areas. ORGANIZATION XYZ staff should
not discuss PHI or Confidential Information in public areas if the information can
be overheard. Caution should be used when conducting conversations in: semi-
private rooms, waiting rooms, corridors, elevators, stairwells, cafeterias,
restaurants, or on public transportation.
J. Audit Controls: Hardware, software, and/or procedural mechanisms that record
and examine activity in information systems that contain or use PHI must be
implemented. Further, procedures must be implemented to regularly review
records of information system activity, such as audit logs, access reports, and
security incident tracking reports. These reviews must be documented and
maintained for six (6) years.
K. Evaluation: ORGANIZATION XYZ requires that periodic technical and non-
technical evaluations be performed in response to environmental or operational
changes affecting the security of electronic PHI to ensure its continued
protection.
L. Contingency Plan: Controls must ensure that ORGANIZATION XYZ can recover from any
damage to computer equipment or files within a reasonable period of time. Each entity is
required to develop and maintain a plan for responding to a system emergency or other
occurrence (for example, fire, vandalism, system failure and natural disaster) that damages
systems that contain PHI, Confidential, or Internal Information. This will include developing
policies and procedures to address the following:
1. Data Backup Plan:
a. A data backup plan must be documented and routinely updated to create and
maintain, for a specific period of time, retrievable exact copies of
information.
b. Backup data must be stored in an off-site location and protected from
physical damage.
c. Backup data must be afforded the same level of protection as the original
data.
2. Disaster Recovery Plan: A disaster recovery plan must be developed and
documented which contains a process enabling the entity to restore any loss of data in
the event of fire, vandalism, natural disaster, or system failure.
3. Emergency Mode Operation Plan: A plan must be developed and documented
which contains a process enabling the entity to continue to operate in the event of
fire, vandalism, natural disaster, or system failure.

96 | P a g e
SCI 407 Information Systems Security and Audit

4. Testing and Revision Procedures: Procedures should be developed and


documented requiring periodic testing of written contingency plans to discover
weaknesses and the subsequent process of revising the documentation, if necessary.
5. Applications and Data Criticality Analysis: The criticality of specific applications
and data in support of other contingency plan components must be assessed and
documented.

97 | P a g e
SCI 407 Information Systems Security and Audit

Compliance [§ 164.308(a)(1)(ii)(C)]
A. The Information Security Policy applies to all users of ORGANIZATION XYZ
information including: employees, medical staff, students, volunteers, and outside
affiliates. Failure to comply with Information Security Policies and Standards by
employees, medical staff, volunteers, and outside affiliates may result in disciplinary
action up to and including dismissal in accordance with applicable ORGANIZATION XYZ
procedures, or, in the case of outside affiliates, termination of the affiliation. Failure to
comply with Information Security Policies and Standards by students may constitute
grounds for corrective action in accordance with ORGANIZATION XYZ procedures.
Further, penalties associated with state and federal laws may apply.
B. Possible disciplinary/corrective action may be instituted for, but is not limited to, the
following:
1. Unauthorized disclosure of PHI or Confidential Information as specified in
Confidentiality Statement.
2. Unauthorized disclosure of a sign-on code (user id) or password.
3. Attempting to obtain a sign-on code or password that belongs to another
person.
4. Using or attempting to use another person's sign-on code or password.
5. Unauthorized use of an authorized password to invade patient privacy by
examining records or information for which there has been no request for
review.
6. Installing or using unlicensed software on ORGANIZATION XYZ computers.
7. The intentional unauthorized destruction of ORGANIZATION XYZ
information.
8. Attempting to get access to sign-on codes for purposes other than official
business, including completing fraudulent documentation to gain access.

98 | P a g e
SCI 407 Information Systems Security and Audit

--- ATTACHMENT 1 ---

Password Control Standards

The ORGANIZATION XYZ Information Security Policy requires the use of strictly
controlled passwords for accessing Protected Health Information (PHI), Confidential
Information (CI) and Internal Information (II). (See ORGANIZATION XYZ Information
Security Policy for definition of these protected classes of information.)
Listed below are the minimum standards that must be implemented in order to ensure
the effectiveness of password controls.

Standards for accessing PHI, CI, II:


Users are responsible for complying with the following password standards:
1. Passwords must never be shared with another person, unless the person is a
designated security manager.
2. Every password must, where possible, be changed regularly – (between 45
and 90 days depending on the sensitivity of the information being accessed)
3. Passwords must, where possible, have a minimum length of six characters.
4. Passwords must never be saved when prompted by any application with the
exception of central single sign-on (SSO) systems as approved by the ISO.
This feature should be disabled in all applicable systems.
5. Passwords must not be programmed into a PC or recorded anywhere that
someone may find and use them.
6. When creating a password, it is important not to use words that can be found
in dictionaries or words that are easily guessed due to their association with
the user (i.e. children’s names, pets’ names, birthdays, etc…). A combination
of alpha and numeric characters are more difficult to guess.
Where possible, system software must enforce the following password standards:
1. Passwords routed over a network must be encrypted.

2. Passwords must be entered in a non-display field.


3. System software must enforce the changing of passwords and the minimum
length.
4. System software must disable the user identification code when more than
three consecutive invalid passwords are given within a 15 minute timeframe.
Lockout time must be set at a minimum of 30 minutes.
5. System software must maintain a history of previous passwords and prevent
their reuse.

99 | P a g e
SCI 407 Information Systems Security and Audit

References
 Information Security Principles and Practices, Mark Merkow and Jim Breithaupt, Prentice Hall
 Computer Security Fundamentals, Chuck Easttom, Prentice Hall
 Computer Security: Art and Science, Matt Bishop, Addison- Wesley

100 | P a g e
SCI 407 Information Systems Security and Audit

SOUTH EASTERN KENYA UNIVERSITY

UNIVERSITY EXAMINATIONS 2015/2016


EXAMINATION FOR THE DEGREE OF BACHELOR OF
INFORMATION TECHNOLOGY/ BACHELOR OF COMPUTER
SCIENCE

SCI 407 Information Systems Security, Control and Audit

DATE: /DECEMBER 2015 TIME: 2 HOURS

INSTRUCTIONS TO CANDIDATES
a) Answer ALL questions from section A(Compulsory)

b) Answer ANY TWO questions from section B

101 | P a g e
SCI 407 Information Systems Security and Audit

SECTION A: ANSWER ALL QUESTIONS {30 MARKS}.

QUESTION ONE

a) The key concept of ISMS is for an organization to design, implement and maintain a
coherent suite of processes and systems for effectively managing information
accessibility, thus ensuring the Confidentiality, Integrity and Availability of information
assets and minimizing information security risks. In the context of this define the
following terms.

i. Information systems Security ;


ii. Security risks. (4 Marks)

b) Describe four risk control strategies (4 marks)


c) Explain components of Information Security. (6 Marks)
d) Identify four containment strategies for incident Response (4 Marks)
e) Categorize the classes of attacks within information security context (4 Marks)
f) Define the term audit trail. (2 Marks)
g) Differentiate between control and audit. (4 Marks)
h) State the purpose of security measures in an information system. (2 Marks)

SECTION B: ANSWER ANY TWO QUESTIONS {20 MARK EACH}.

QUESTION TWO

a) Passwords are the most common form of authentication security. Explain three qualities of a
good password. (3 Marks)

b) A quality information security program begins and ends with policy. Using Bulls’ Eye Model,
justify this statement. (4 Marks)

c) You work for a large organization that has developed a large scale ICT infrastructure which is
primarily used for its newly launched e-business applications. The organization has realized they

102 | P a g e
SCI 407 Information Systems Security and Audit

did not pay adequate attention to the security of its information resources. Management would
like to get a solution.

i. Identify ten major network threats to the information resources in your organization.
Explain how they will affect your company. (5 Marks)

ii. With aid of a diagram design suitable a security system for your company, clearly
identifying the major security components of your design. (8 Marks)

QUESTION THREE

a) Contingency planning and Business continuity planning is crucial in the event of disaster of great
Magnitude threatening the entire business operation.

(i) Explain the terms Contingency planning and Business continuity planning. (4
Marks)
(ii) Outline the options available in Business continuity Strategies. (6
Marks)

b) Explain the following terms as used in disaster recovery and business continuity strategies.

i. Cold sites
ii. Warm sites
iii. Hot sites (6 Marks)

c) Discuss the role of ethics In information security management (4 Marks)

QUESTION FOUR

a) Explain the following terms as used in ISSCA.


i. Copyrights
ii. Trade Secret

103 | P a g e
SCI 407 Information Systems Security and Audit

iii. Patents
iv. Trademark (4 Marks)

b) An insurance company zigma has in the recent past experienced tremendous growth and
consequently grown and expanded in branch network. In one of the local branches, its performance has
been out of line with the rest of the branches. The management has decided to send auditors to unearth
the reasons for its dismal performance. In their course of duty they discover serious security breaches
with how data computer is kept and backed up. Additionally there is indiscriminate use of computer
resources including internet access by all and sundry. As an Information security Expert;

(i) Explain the term computer controls. (2 Marks)


(ii) Explain unethical behaviors in the company. (4 Marks)
(iii) Briefly explain the salient features of administrative controls. (3 Marks)
(iv) Explain the difference between internal and external audit. (3 Marks)
(v) Discus four reasons why carry out IT/IS audit. (4 Marks)

104 | P a g e

You might also like