Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Softwares and Software Security: formula sheet

Full chapter guide

Key formulas

Basic classification by purpose
Software = System software + Application software
Utilities, drivers, firmware and translators sit under system software. Programming tools are usually treated as system software.
Classification by licence
Open source (source code open) vs Proprietary (source code closed)
Open source is not the same as free of cost. The licence terms still bind you.
System vs application test
Manages the machine = system software; serves a user task = application software
Use this one-line test for any example in a question.
Application software by build
Packaged (ready-made) vs Customised or bespoke (built for one client)
A useful extra point in a differentiate answer.
Phases of SDLC (in order)
Planning → Requirements → Design → Development → Testing → Deployment → Maintenance
Some books merge or rename phases. Keep the order and say which version you follow.
Waterfall model
Linear: finish one phase, then start the next
Best for stable requirements. Weak when change is likely.
Agile model
Short iterations (sprints) + frequent feedback = working software in small increments
Best for changing requirements and close customer involvement.
Spiral model
Each loop = plan + risk analysis + build + evaluate
Risk analysis in every loop is the key feature.
DevOps
Development + Operations + automation (CI/CD)
Aims at fast, frequent and reliable releases.
Secure SDLC
Security activity in every phase, not only at testing
Shift security left: address it early in the cycle.
Licence versus ownership
Licence = right to use on terms; copyright stays with the owner
Buying a licence does not transfer ownership of the software or its code.
Copyright in software
Computer programme = literary work; protection arises automatically on creation
Registration is not a condition of protection. It is useful as evidence.
Patent position in India
Computer programme per se: not patentable; technical effect or contribution: may qualify
Do not say software is never patentable.
Freeware vs shareware
Freeware = free, no payment due; Shareware = free trial, payment to continue or unlock
Neither gives source code or modification rights by default.
Open source vs freeware
Open source = source code available plus rights to modify and share; Freeware = no price only
Free of cost does not mean open source.
Risk relationship
Risk = Threat × Vulnerability × Impact
A conceptual relationship, not a numeric calculation. If any one is absent, risk is low.
Vulnerability vs threat vs exploit
Vulnerability = weakness; Threat = possible danger; Exploit = method that uses the weakness
Define all three separately. Examiners often test the difference.
Malware spread rule
Virus needs a host and user action; Worm self-spreads; Trojan disguises and does not self-replicate
Use this one-line contrast in any 'differentiate' question.
SQL injection defence
Parameterised query + input validation + least privilege
Parameterised queries are the primary defence; the others support it.
Zero-day
Unknown to vendor + no patch + exploited = zero-day attack
Once the vendor issues a patch, it is no longer a zero-day, though unpatched systems stay exposed.
Control types
Preventive + Detective + Corrective
Classify every control you name into one of these three groups. It shows structure in your answer.
Least privilege
User access = only what the job needs, nothing more
Reduces damage from errors, insider misuse and stolen credentials.
Confidentiality, Integrity, Availability
CIA triad = Confidentiality + Integrity + Availability
Link each control to the goal it protects. Encryption mainly protects confidentiality; backups protect availability.
Vulnerability assessment vs penetration test
VA = find and list weaknesses; PT = exploit them to prove impact
VA is broad and usually automated. PT is deeper, targeted, manual and needs written authorisation.
Patch cycle
Identify → Assess risk → Test → Deploy → Verify → Record
Use this order when asked how to run patch management.
ISO/IEC 27001 core idea
ISMS = scope + risk assessment + risk treatment + controls + monitoring + continual improvement
A management system standard. Certification is voluntary and given by an independent certification body.
Three security goals (CIA)
Confidentiality + Integrity + Availability
Every control and every breach in a case can be mapped to one or more of these.
Section 43A test
Body corporate + sensitive personal data + negligence in reasonable security practices + wrongful loss or gain = compensation
All elements must be present. Compensation is claimed through the adjudication process under the Act.
Section 43 (civil liability)
Act without permission of owner (access, virus, damage, disruption) = compensation
Civil remedy. If done dishonestly or fraudulently, Section 66 applies as an offence.
Section 72A
Service provider or any person + lawful contract + disclosure of personal information + intent to cause or knowing likelihood of wrongful loss or gain = punishment
Applies to disclosure in breach of a lawful contract, which is different from negligence under Section 43A.
OWASP Top 10 status
OWASP Top 10 = awareness list, voluntary, revised periodically
Not a statute. Do not say it is mandatory.

Quick revision

  • System software runs and manages the hardware; application software performs user tasks.
  • SDLC is a structured sequence of stages from planning to maintenance; security should be built into every stage.
  • Fixing a flaw late in the life cycle is usually costlier than fixing it early.
  • Software is generally protected as intellectual property, and a licence sets the terms of use.
  • Using software beyond the licence terms can create legal liability for the company.
  • A vulnerability is a weakness; a threat is something that can exploit it.
  • Threats include malware, phishing, injection attacks and insider misuse.
  • Controls can be preventive, detective or corrective; learn one example of each.
  • Good practices include patching, access control, testing, secure coding and regular audits.
  • Standards give a benchmark for security management; laws make certain duties mandatory.
  • In a case answer, always link the facts to a specific control or legal duty.
  • Always end with a clear conclusion and a practical recommendation.

Common mistakes

  • Treating utility software as application software. Fix: Ask whether it maintains or protects the system. If yes, it is utility software under system software.
  • Saying open source always means free of cost. Fix: Say that source code is available and use is governed by a licence. Some open source products are sold with support.
  • Listing the SDLC phases in the wrong order, such as testing before development. Fix: Remember the story: plan, find needs, design, build, test, release, maintain.
  • Saying agile has no planning or documentation. Fix: Say agile plans in short cycles and values working software and feedback. It is disciplined, not unplanned.
  • Treating freeware and open source as the same thing Fix: Say freeware means no price only, while open source means source code access plus rights to modify and share under stated conditions.
  • Saying shareware is free software Fix: Write that shareware is a trial. Payment is needed to continue after the period or to unlock full features.
  • Using virus, worm and trojan as if they mean the same thing. Fix: Anchor on spread: virus needs a host file, worm spreads alone, trojan disguises itself and does not self-replicate.
  • Saying a zero-day is a brand-new virus. Fix: A zero-day is a flaw unknown to the vendor with no patch available. It is about the vulnerability, not the type of malware.
  • Treating vulnerability assessment and penetration testing as the same thing. Fix: State that assessment finds and lists weaknesses, while penetration testing exploits them with authorisation to show real impact.
  • Saying patching is optional or only needed after an attack. Fix: Explain that patches close known flaws and delay lets attackers use them. Describe a regular, risk-ranked cycle.

Exam tips

  • Always give named examples. A bare definition rarely earns full marks in a descriptive answer.
  • For differentiate questions, write in point-wise pairs and cover at least four distinct points.
  • Name the basis of classification before listing types. It shows structure.
  • In case-based questions, classify the software first, then state the legal or security consequence.
  • Spend your last line on a practical control: patching, licence audit, vetting of open source.
  • Learn the seven phases in order and write one purpose line for each.
  • For comparison questions, give at least five points in a clear list and end with suitability.
  • In case questions, quote the facts that decide the model before naming it.