☰ Contents · Computing

The concept of information security

Lessons 27 · 1 lessons · N. I. Taylaqov (general editor), A. B. Akhmedov, M. D. Pardayeva, A. A. Abdug‘aniyev, U. M. Mirsanov. Informatics and Information Technologies, Grade 11, 1st edition. “Extremum-press”, Tashkent, 2018
27

The concept of information security and its effectiveness indicators

Textbook: pp. 91–95
GoalTells apart the three properties of information security (confidentiality, integrity, availability), the kinds of threat, and identification, authentication and authorization; calculates password strength and assesses risk.
New words
confidentiality: only permitted people can read the information · maxfiylikintegrity: the information is not changed without permission and stays correct · yaxlitlikavailability: permitted people can use the information when they need it · foydalanuvchanlikauthentication: checking that the user really is who they claim to be · autentifikatsiya
Explanation

Information security is protecting data from loss, theft, forgery and unauthorized use. It has three properties (the CIA triad in international literature): confidentiality (only permitted people read the data), integrity (the data is not changed without permission) and availability (the data can be used when needed). Different data needs different properties most: in a bank payment – integrity (the amount must not change), in a medical record – confidentiality, on a weather site – availability. A threat is of two kinds: disclosing data or changing it; by source it is internal (an employee's mistake or carelessness) or external (an attacker, a virus). In statistics, most breaches involve the human factor: a weak password, falling for a phishing e-mail, not locking a device. Logging in has three steps: identification (introducing yourself – a login), authentication (checking the identity – a password, an SMS code, a fingerprint) and authorization (which rights this user gets). The authentication factors are something you know (a password), something you have (a phone, a card) and something you are (a fingerprint, a face). Combining two factors – two-step verification – makes an account much stronger. Password strength depends on length and variety of characters: a password of length k made from N kinds of characters has N to the power k variants. Risk assessment: risk = probability of an event × damage caused; the cost of protection should not exceed the expected loss. In Uzbekistan the protection of personal data is regulated by law (the Law on Personal Data, 2019), and a separate law on cybersecurity was adopted in 2022. Entering another person's account without permission is unethical and can lead to criminal liability.

Worked examples
A program that scores password strength (Python, tested): def kuch(p): ⏎    ball = 0 ⏎    if len(p) >= 12: ⏎        ball += 1 ⏎    if any(c.islower() for c in p): ⏎        ball += 1 ⏎    if any(c.isupper() for c in p): ⏎        ball += 1 ⏎    if any(c.isdigit() for c in p): ⏎        ball += 1 ⏎    if any(not c.isalnum() for c in p): ⏎        ball += 1 ⏎    return ball ⏎ print(kuch("salom")) ⏎ print(kuch("Bahor-2026-quyosh")) ⏎ print(kuch("Olma7")) The program prints 1, 5 and 3: “salom” has only lowercase letters (1 point), the second password meets all five conditions, “Olma7” is shorter than 12 characters and has no symbol (3 points). This is only a study example; never type your real password into a program or tell it to a friend.
Number of variants: a 4-digit PIN has 10·10·10·10 = 10000 variants; a 6-character password of only lowercase Latin letters has 26⁶ = 308915776; an 8-character one with upper and lower case letters and digits (62 characters) has 62⁸ = 218340105584896. Loss: for an event that happens 4 times a year and costs 3000000 soum each time, the expected yearly loss is 4·3000000 = 12000000 soum.
Class activity

“Protection card”: each student lists their own data (photos, passwords, documents, messages) and for each writes which property (confidentiality, integrity, availability) matters most and how to protect it. Do not write the passwords themselves!

Practice
1
How many variants does a password of 4 lowercase Latin letters have?
2
Write the difference between authentication and authorization in one sentence each.
3
For a bank payment amount, which property is most important: confidentiality, integrity or availability? Explain.
4
Which of password, SMS code and fingerprint is a “something you know”, a “something you have” and a “something you are” factor?