Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Softwares and Software Security: CS Professional Study Guide

Softwares and Software Security covers what software is, how it is built (SDLC), how it is licensed and protected, what threats and vulnerabilities attack it, which controls reduce risk, and which standards and laws apply. In the exam, you identify the issue in a case, state the rule or control, apply it to the facts and conclude.

What this chapter covers

This chapter is about software as a business asset and as a risk. You start with the types of software: system software such as operating systems and utilities, and application software used for specific tasks. You then follow software through its Software Development Life Cycle (SDLC), from planning to maintenance, and see where security should be built in.

Next, the chapter deals with who owns and may use software. This is software licensing and intellectual property: copyright, licence terms, proprietary and open-source models. After that it turns to what can go wrong: vulnerabilities and threats, then the controls and best practices that reduce them, and finally the standards and legal framework that make security a compliance duty.

This chapter is the base for the rest of Elective 4.4. The AI, data analytics and cyber security parts of the paper all run on software. A company secretary advises on policy, contracts, compliance and board-level risk. So you must be able to link a technical weakness to a legal consequence, such as a data breach, a licence violation or a failed audit.

Paper 4.4 is a written, case-based paper, and this chapter gives you the vocabulary and the logic for many answers in the rest of the paper. Questions here often describe a company situation, such as a breach, an unlicensed copy or a poorly controlled development project, and ask what went wrong and what the company should do. If you know the terms, the controls and the legal hooks, you can write structured answers that earn marks across several chapters, not just this one.

Softwares and Software Security: topics in the order to study them

  1. 1Types of Software: System and Application SoftwareStart here because every later topic uses these terms, and you need to know what is being developed, licensed and attacked.
  2. 2Software Development Life Cycle (SDLC)It shows how software is made, so you can see at which stage a flaw enters and where a control belongs.
  3. 3Software Licensing and Intellectual PropertyOnce you know how software is built, you can study who owns it and on what terms others may use it.
  4. 4Software Vulnerabilities and ThreatsYou need to know what can go wrong before you can understand why controls exist.
  5. 5Software Security Controls and Best PracticesControls answer the threats you have just studied, so they are easiest to learn straight after them.
  6. 6Software Security Standards and Legal FrameworkStudy this last, because standards and laws make sense once you know the risks and the controls they aim to govern.

How to prepare Softwares and Software Security

Treat this chapter as a chain: software, its creation, its ownership, its risks, its controls and its regulation. Prepare each link so you can connect it to the next in a written answer.

  1. Read the topics in the study order above and make a one-page map showing how each topic leads to the next.
  2. For each topic, write short definitions in your own words, then add one Indian company example, such as a bank, a startup or a listed company.
  3. Draw the SDLC stages and note one security activity for each stage. Practise redrawing it from memory.
  4. Make a two-column table for threats and matching controls, so you can pair a problem with its fix quickly.
  5. Read the standards and legal provisions from the study material carefully. Note exact names and what each one requires. Do not rely on memory for section numbers.
  6. Practise two or three case-style answers using this format: issue, rule or control, application to the facts, conclusion.
  7. Revise the quick points below a day before the exam, then re-attempt one case answer under timed conditions.

Common mistakes in Softwares and Software Security

  • Treating the chapter as pure technology and writing generic IT answers.

    Fix: Tie every technical point to a compliance, contractual or governance consequence and a recommended action.

  • Mixing up vulnerability, threat and risk.

    Fix: Define each in one line: vulnerability is the weakness, threat is the possible exploiter, risk is the likely harm. Use them consistently.

  • Ignoring security in the SDLC and describing only the development stages.

    Fix: For every stage, add one security activity, such as requirement review, secure design, code review, testing or patching.

  • Confusing ownership of software with the right to use it.

    Fix: Remember that a licence normally grants only limited rights. Read the facts for the licence scope before concluding.

  • Quoting section numbers or standard details from memory and getting them wrong.

    Fix: Use only references you have verified in the study material. If unsure, state the rule in plain words.

  • Writing long theory without a conclusion in case questions.

    Fix: Use issue, rule, application, conclusion every time, and keep the conclusion to one or two clear lines.

Last-day revision: Softwares and Software Security

  • System software runs and manages the hardware; application software performs user tasks.
  • SDLC is a structured sequence of stages from planning to maintenance; security should be built into every stage.
  • Fixing a flaw late in the life cycle is usually costlier than fixing it early.
  • Software is generally protected as intellectual property, and a licence sets the terms of use.
  • Using software beyond the licence terms can create legal liability for the company.
  • A vulnerability is a weakness; a threat is something that can exploit it.
  • Threats include malware, phishing, injection attacks and insider misuse.
  • Controls can be preventive, detective or corrective; learn one example of each.
  • Good practices include patching, access control, testing, secure coding and regular audits.
  • Standards give a benchmark for security management; laws make certain duties mandatory.
  • In a case answer, always link the facts to a specific control or legal duty.
  • Always end with a clear conclusion and a practical recommendation.

Softwares and Software Security practice questions

Softwares and Software Security: frequently asked questions

Is Softwares and Software Security part of the compulsory papers?

No. It belongs to Elective 4.4, Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice, which is one of the options in Elective 1 (Paper 4). You study it only if you choose that elective.

How should I study the technical terms if I have no IT background?

Start with simple definitions and one real-life example for each term. Focus on what the term means for a company and what action or control follows. You do not need to code to answer well.

Do I need to memorise section numbers for this chapter?

Learn the key provisions and what they require, but quote a section number only when you are sure of it. A correct rule stated in plain words earns more than a wrong number.

What kind of questions come from this chapter?

Expect written, case-based questions. You may be asked to explain a concept, identify a security or licensing issue in a scenario, and advise on controls or compliance. Elective papers are open book, but you still need to know where to find and how to apply the material quickly.