CRISC - Certified in Risk and Information Systems Control term definition - Part 40

0.0(0)
Studied by 2 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

Last updated 1:42 AM on 11/13/22
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards
Passive assault
Intruders attempt to learn some characteristic of the data being transmitted.
2
New cards
Passive response
A response option in intrusion detection in which the system simply reports and records the problem detected, relying on the user to take subsequent action.
3
New cards
Password
A protected, generally computer-encrypted string of characters that authenticate a computer user to the computer system.
4
New cards
Password cracker
A tool that tests the strength of user passwords by searching for passwords that are easy to guess. It repeatedly tries words from specially crafted dictionaries and often also generates thousands (and in some cases, even millions) of permutations of characters, numbers and symbols.
5
New cards
Patch management
An area of systems management that involves acquiring, testing and installing multiple patches (code changes) to an administered computer system in order to maintain up-to-date software and often to address security risk.
6
New cards
Payback period
The length of time needed to recoup the cost of capital investment. Financial amounts in the payback formula are not discounted. Note that the payback period does not take into account cash flows after the payback period and therefore is not a measure of the profitability of an investment project. The scope of the internal rate of return (IRR), net present value (NPV) and payback period is the useful economic life of the project up to a maximum of five years.
7
New cards
Payment system
A financial system that establishes the means for transferring money between suppliers and users of funds, ordinarily by exchanging debits or credits between banks or financial institutions.
8
New cards
Payroll system
An electronic system for processing payroll information and the related electronic (e.g., electronic timekeeping and/or human resources [HR] system), human (e.g., payroll clerk), and external party (e.g., bank) interfaces. In a more limited sense, it is the electronic system that performs the processing for generating payroll checks and/or bank direct deposits to employees.
9
New cards
Penetration testing
A live test of the effectiveness of security defenses through mimicking the actions of real-life attackers
10
New cards
Performance
In IT, the actual implementation or achievement of a process.
11
New cards
Performance driver
A measure that is considered the "driver" of a lag indicator. It can be measured before the outcome is clear and, therefore, is called a "lead indicator.
12
New cards
Performance indicators
A set of metrics designed to measure the extent to which performance objectives are being achieved on an on-going basis.
13
New cards
Performance management
In IT, the ability to manage any type of measurement, including employee, team, process, operational or financial measurements. The term connotes closed-loop control and regular monitoring of the measurement.
14
New cards
Performance testing
Comparing the system’s performance to other equivalent systems, using well-defined benchmarks.
15
New cards
Peripherals
Auxiliary computer hardware equipment used for input, output and data storage.
16
New cards
Personal digital assistant (PDA)
Also called palmtop and pocket computer, PDA is a handheld device that provide computing, Internet, networking and telephone characteristics.
17
New cards
Personal identification number (PIN)
A type of password (i.e., a secret number assigned to an individual) that, in conjunction with some means of identifying the individual, serves to verify the authenticity of the individual.
18
New cards
Pervasive IS control
General control designed to manage and monitor the IS environment and which, therefore, affects all IS-related activities.
19
New cards
Phase of BCP
A step-by-step approach consisting of various phases
20
New cards
Phishing
This is a type of electronic mail (e-mail) attack that attempts to convince a user that the originator is genuine, but with the intention of obtaining information for use in social engineering.