Unit 8: Information Security and Cyber Law
Complete Class 11 Computer Science Unit 8 notes covering digital society, computer ethics, information security, cybercrime, malware, IPR, digital signatures, cyber law and ICT policy in Nepal.
Welcome to Nepal eNotes. Unit 8 focuses on safe, responsible and legal use of computers, networks and digital technology.
You will learn about computer ethics, the CIA Triad, cybercrime, malicious software, cybercrime prevention, intellectual property rights, digital signatures, cyber law and ICT policy in Nepal.
Information Security = Protect digital information
Cyber Law = Legal rules governing digital activities
- 8.1 Digital Society and Computer Ethics
- 8.2 Concept of Information Security
- 8.3 Concept of Cybercrime
- 8.4 Malicious Software and Spam
- 8.5 Protection from Cybercrime
- 8.6 Intellectual Property Rights
- 8.7 Digital Signature
- 8.8 Cyber Law in Nepal
- 8.9 ICT Policy in Nepal
- Quick Revision
- Sample Board Exam Questions
- Important Questions
Digital Society
A digital society is a society in which computers, the internet and digital devices play a major role in everyday communication, education, business, work and public services.
Examples of activities that increasingly use digital technology include:
- Online banking
- Digital education
- Online shopping
- Government services
- Communication and social networking
Computer Ethics
Computer ethics guides people to use computers and digital technology responsibly by following moral, ethical and legal principles.
Ethical Practices
- Respect other people’s privacy.
- Do not access another person’s account or data without permission.
- Do not use technology to harm or harass others.
- Do not spread false or harmful information.
- Give proper credit for another person’s work.
- Do not use pirated software.
- Use shared computer and network resources responsibly.
Computer ethics refers to moral principles that guide the responsible use of computers and digital technologies.
Information security is the practice of protecting digital data and computer systems from unauthorized access, use, disclosure, modification, disruption or destruction.
CIA Triad
The three major goals of information security are known as the CIA Triad.
🔒 Confidentiality
Only authorized people should be allowed to access or view information.
✅ Integrity
Information should remain accurate and should not be changed by unauthorized people.
⚡ Availability
Authorized users should be able to access information and systems whenever they are needed.
| Principle | Meaning |
|---|---|
| Confidentiality | Prevent unauthorized access to information. |
| Integrity | Keep information accurate and unchanged. |
| Availability | Keep systems and information accessible when needed. |
C = Confidentiality
I = Integrity
A = Availability
Cybercrime refers to criminal activities carried out using computers, networks or the internet, either as the target of the crime or as the tool used to commit it.
| Cybercrime | Meaning |
|---|---|
| Hacking | Unauthorized access to a computer system or network. |
| Phishing | Tricking people into revealing passwords, banking details or other sensitive information using fake messages or websites. |
| Identity Theft | Stealing personal information and using it to impersonate another person. |
| Cyberbullying | Using online platforms to threaten, harass or humiliate another person. |
| Software Piracy | Illegal copying, distribution or use of licensed software. |
| Financial Fraud | Unauthorized use of banking, card or digital-wallet information for theft. |
Malicious software or malware refers to software designed to damage, disrupt or gain unauthorized access to a computer system.
| Type | How It Works |
|---|---|
| Virus | Attaches itself to another file or program and spreads when that file is executed or shared. |
| Worm | Can spread automatically across networks without attaching itself to another file. |
| Trojan Horse | Appears to be legitimate software but performs harmful actions in the background. |
| Spyware | Secretly monitors user activity and collects information. |
| Ransomware | Locks or encrypts files and demands payment for restoring access. |
| Adware | Automatically displays unwanted advertisements. |
Spam
Spam refers to unwanted, irrelevant or repetitive messages usually sent in bulk through email or messaging platforms.
Some spam messages may also contain malware or phishing links.
Virus = Needs a host file
Worm = Spreads by itself
Trojan = Pretends to be legitimate software
Users can reduce the risk of cybercrime by following safe digital practices.
Strong Passwords
Use strong and unique passwords for different accounts.
Two-Factor Authentication
Enable 2FA to add another verification step.
Software Updates
Keep operating systems and applications updated.
Antivirus
Install and regularly update antivirus software.
Avoid Suspicious Links
Do not open unknown links or attachments.
Firewall
Use a firewall to control network traffic.
Regular Backup
Keep backup copies of important files.
Protect Personal Information
Avoid unnecessarily sharing sensitive information online.
Intellectual Property Rights (IPR) are legal rights that give creators control over the use of their original creations, such as software, books, music, inventions, designs or brand identities.
| Type of IPR | What It Protects |
|---|---|
| Copyright | Original creative works such as software, books, films and music. |
| Patent | New inventions or technical processes. |
| Trademark | Brand names, logos and symbols that identify a business or product. |
| Trade Secret | Confidential business information such as a secret formula or process. |
Book / Software → Copyright
New Invention → Patent
Brand Logo → Trademark
A digital signature uses an electronic cryptographic method to verify the authenticity and integrity of a digital document or message.
According to the supplied notes, a digital signature should not be confused with a scanned image of a handwritten signature.
Main Purposes
Authentication
Confirms the identity of the sender or signer.
Integrity
Confirms that the signed document has not been changed.
Non-Repudiation
Helps prevent the signer from later denying that the document was signed.
Digital Signature = Authentication + Integrity + Non-Repudiation
Cyber law refers to legal rules governing activities carried out through computers, networks and the internet.
According to your supplied notes, Nepal’s foundational cyber legislation is the Electronic Transaction Act, 2063 (2006).
Main Provisions Mentioned in the Notes
- Legal recognition of electronic records.
- Legal recognition of digital signatures.
- A system for licensing and regulating certifying authorities.
- Provisions relating to unauthorized access and other computer-related offences.
- Provisions relating to computer-related fraud.
- Rules concerning illegal electronic material.
- An Information Technology Tribunal for related disputes.
Electronic Transaction Act 2063 is the main cyber-law framework identified in the supplied Unit 8 notes.
An ICT Policy is a government framework that defines the goals, vision and strategies for the development and use of information and communication technology.
The supplied notes identify the ICT Policy, 2072 (2015) as Nepal’s ICT policy framework covered in this unit.
Main Objectives Mentioned in the Notes
- Expand access to reliable and affordable internet and ICT infrastructure.
- Improve access to technology in rural areas.
- Promote e-governance.
- Encourage growth of the IT industry.
- Improve digital literacy.
- Promote ICT use in education, healthcare and other public sectors.
ETA vs ICT Policy
| Electronic Transaction Act | ICT Policy |
|---|---|
| Focuses mainly on legal rules. | Focuses on national ICT goals and development. |
| Covers electronic activities and cyber offences. | Promotes ICT infrastructure and digital development. |
| Legal framework. | Policy and strategic framework. |
⚡ Quick Revision – Unit 8
- Digital society uses digital technology in everyday life.
- Computer ethics guides responsible use of technology.
- Information security protects data and systems.
- CIA Triad: Confidentiality, Integrity and Availability.
- Cybercrime includes hacking, phishing, identity theft, cyberbullying, piracy and financial fraud.
- Virus attaches to another file.
- Worm spreads automatically across networks.
- Trojan disguises itself as legitimate software.
- Spyware secretly collects user information.
- Ransomware locks or encrypts files.
- Spam means unsolicited bulk messages.
- Use strong passwords and 2FA.
- Keep software and antivirus updated.
- Use firewall and regular backups.
- IPR protects creators and original works.
- Main IPR types: Copyright, Patent, Trademark and Trade Secret.
- Digital signature provides authentication, integrity and non-repudiation.
- The supplied notes identify Electronic Transaction Act 2063 as Nepal’s foundational cyber law.
- The supplied notes identify ICT Policy 2072 as the ICT policy framework covered by this unit.
📝 Sample Board Exam Questions
Multiple Choice Questions
- It needs a host file to spread.
- It spreads on its own across a network.
- It disguises itself as legitimate software.
- It only affects mobile devices.
- Copyright
- Patent
- Trademark
- Trade Secret
- ICT Policy 2072
- Electronic Transaction Act 2063
- Right to Information Act
- Telecommunications Act
Short Answer Question
⭐ Important Questions
- What is a digital society? How has it changed people’s daily life?
- What is computer ethics? Mention any four ethical practices.
- What is information security? Explain the CIA Triad.
- Define cybercrime. Explain any four types of cybercrime.
- What is malware?
- Differentiate between virus, worm and Trojan horse.
- What is spam? Why can it become a security risk?
- List any five methods of protection from cybercrime.
- What is Intellectual Property Rights?
- Explain copyright, patent and trademark with examples.
- What is a digital signature?
- Explain authentication, integrity and non-repudiation.
- What is cyber law?
- Explain the main provisions of the Electronic Transaction Act 2063 as covered in this unit.
- What is ICT Policy?
- Mention four objectives of ICT Policy in Nepal as stated in the notes.
- Differentiate between the Electronic Transaction Act and ICT Policy.
Frequently Asked Questions
Information security is the practice of protecting digital data and computer systems against unauthorized access, modification, disclosure, disruption or destruction.
The CIA Triad consists of Confidentiality, Integrity and Availability, which are the three major goals of information security.
A virus normally attaches itself to another file or program, while a worm can spread automatically through networks without attaching itself to a host file.
Information security focuses on protecting systems and information through practices such as passwords, antivirus, firewalls and backups. Cyber law refers to the legal rules that govern digital activities and cyber offences.
A digital signature is a cryptographic method used to verify the identity of a sender or signer and help ensure that a digital document has not been altered.
The supplied notes describe three main benefits: authentication, integrity and non-repudiation.
Intellectual Property Rights are legal rights that protect the creators of original works, inventions, designs, software and brand identities.
Conclusion
Unit 8 introduces the security, ethical and legal responsibilities that come with using digital technologies.
For NEB examination preparation, focus especially on computer ethics, CIA Triad, types of cybercrime, virus vs worm vs Trojan, cybercrime protection, IPR, digital signatures, Electronic Transaction Act 2063 and ICT Policy 2072.
Continue learning with Nepal eNotes for more NEB Class 11 Computer Science notes and exam preparation materials.
Discussion
Share a helpful question, idea, or explanation with other students.