CRISC - Certified in Risk and Information Systems Control term definition - Part 26

0.0(0)
Studied by 2 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

Last updated 11:49 PM on 11/12/22
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards
Hot site
A fully operational offsite data processing facility equipped with both hardware and system software to be used in the event of a disaster.
2
New cards
Hub
A common connection point for devices in a network, hubs are used to connect segments of a local area network (LAN).
3
New cards
Hurdle rate
Also known as required rate of return, above which an investment makes sense and below which it does not. Often based on the cost of capital, plus or minus a risk premium, and often varied based on prevailing economic conditions
4
New cards
Hybrid application controls
Consist of a combination of manual and automated activities, all of which must operate for the control to be effective.
5
New cards
Hyperlink
An electronic pathway that may be displayed in the form of highlighted text, graphics or a button that connects one web page with another web page address.
6
New cards
Hypertext
A language that enables electronic documents that present information to be connected by links instead of being presented sequentially, as is the case with normal text.
7
New cards
Hypertext Markup Language (HTML)
A language designed for the creation of web pages with hypertext and other information to be displayed in a web browser; used to structure information--denoting certain text sure as headings, paragraphs, lists--and can be used to describe, to some degree, the appearance and semantics of a document.
8
New cards
Hypertext Transfer Protocol Secure (HTTPS)
A protocol for accessing a secure web server, whereby all data transferred are encrypted.
9
New cards
Hypertext Transfer Protocol (HTTP)
A communication protocol used to connect to servers on the World Wide Web. Its primary function is to establish a connection with a web server and transmit hypertext markup language (HTML), extensible markup language (XML) or other pages to client browsers.
10
New cards
Hashing
Using a hash function (algorithm) to create hash valued or checksums that validate message integrity
11
New cards
Hijacking
An exploitation of a valid network session for unauthorized purposes
12
New cards
Horizontal defense-in depth
Controls are placed in various places in the path to access an asset (this is functionally equivalent to concentric ring model above).
13
New cards
Human firewall
A person prepared to act as a network layer of defense through education and awareness
14
New cards
hash
A cryptographic hash function takes an input of an arbitrary length and produces an output (also known as a message digest) that is a standard-sized binary string. The output is unique to the input in such a way that even a minor change to the input results in a completely different output. Modern cryptographic hash functions are also resistant to collisions (situations in which different inputs produce identical output); a collision, while possible, is statistically improbable. Cryptographic hash functions are developed so that input cannot be determined readily from the output.
15
New cards
Identity access management (IAM)
Encapsulates people, processes and products to identify and manage the data used in an information system to authenticate users and grant or deny access rights to data and system resources. The goal of IAM is to provide appropriate access to enterprise resources.
16
New cards
Idle standby
A fail-over process in which the primary node owns the resource group and the backup node runs idle, only supervising the primary node.
17
New cards
IEEE (Institute of Electrical and Electronics Engineers)
Pronounced I-triple-E; IEEE is an organization composed of engineers, scientists and students.
18
New cards
Image processing
The process of electronically inputting source documents by taking an image of the document, thereby eliminating the need for key entry.
19
New cards
Impact analysis
A study to prioritize the criticality of information resources for the enterprise based on costs (or consequences) of adverse events. In an impact analysis, threats to assets are identified and potential business losses determined for different time periods. This assessment is used to justify the extent of safeguards that are required and recovery time frames. This analysis is the basis for establishing the recovery strategy.
20
New cards
Impact assessment
A review of the possible consequences of a risk.