CRISC - Certified in Risk and Information Systems Control term definition - Part 44

0.0(0)
studied byStudied by 3 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/19

flashcard set

Earn XP

Description and Tags

IT Governance Basic

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

20 Terms

1
New cards
Professional judgement
The application of relevant knowledge and experience in making informed decisions about the courses of action that are appropriate in the circumstances of the IS audit and assurance engagement
2
New cards
Professional skepticism
An attitude that includes a questioning mind and a critical assessment of audit evidence. American Institute of Certified Public Accountants (AICPA) AU 230.07
3
New cards
Public switched telephone network (PSTN)
A communications system that sets up a dedicated channel (or circuit) between two points for the duration of the transmission.
4
New cards
primitive
A primitive is a fundamental interface, block of code or basic functionality that can be deployed and reused within broader systems or interfaces. Primitives can be combined in various ways to accomplish particular tasks. In cryptosystems, primitives form the building blocks of cryptographic algorithms.
5
New cards
private key cryptosystems
Private key cryptosystems involve secret, private keys. The keys are also known as symmetric ciphers because the same key both encrypts message plaintext from the sender and decrypts resulting ciphertext for a recipient. See symmetric cipher.
6
New cards
Public key cryptosystem
Public key cryptosystems combine a widely distributed public key and a closely held, protected private key. A message that is encrypted by the public key can only be decrypted by the mathematically related, counterpart private key. Conversely, only the public key can decrypt data that was encrypted by its corresponding private key. See asymmetric cipher.
7
New cards
Quality Assurance (QA)
A planned and systematic patter of all actions necessary to provide adequate confidence that an item or product conforms to established technical requirements. (ISO/IEC 24765)
8
New cards
Quality management system (QMS)
A system that outlines the policies and procedures necessary to improve and control the various processes that will ultimately lead to improved enterprise performance.
9
New cards
Queue
A group of items that is waiting to be serviced or processed.
10
New cards
Quick ship
A recovery solution provided by recovery and/or hardware vendors and includes a pre-established contract to deliver hardware resources within a specified number amount of hours after a disaster occurs.
11
New cards
Quality
Being fit for purpose (achieving intended value)
12
New cards
RACI chart
Illustrates who is Responsible, Accountable, Consulted and Informed within an organizational framework.
13
New cards
Radio wave interference
The superposition of two or more radio waves resulting in a different radio wave pattern that is more difficult to intercept and decode properly.
14
New cards
Random access memory (RAM)
The computer’s primary working memory.
15
New cards
Range check
Range checks ensure that data fall within a predetermined range.
16
New cards
Rapid application development
A methodology that enables enterprises to develop strategically important systems faster, while reducing development costs and maintaining quality by using a series of proven application development techniques, within a well-defined methodology.
17
New cards
Real-time analysis
Analysis that is performed on a continuous basis, with results gained in time to alter the run-time system.
18
New cards
Real-time processing
An interactive online system capability that immediately updates computer files when transactions are initiated through a terminal.
19
New cards
Reasonable assurance
A level of comfort short of a guarantee, but considered adequate given the costs of the control and the likely benefits achieved.
20
New cards
Reasonableness check
Compares data to predefined reasonability limits or occurrence rates established for the data.