CRISC - Certified in Risk and Information Systems Control term definition - Part 22

0.0(0)
Studied by 2 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

Last updated 11:33 PM on 11/12/22
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards
Event
Something that happens at a specific place and/or time
2
New cards
Event type
For the purpose of IT risk management, one of three possible sorts of events: threat event, loss event and vulnerability event.
3
New cards
Evidence
1 Information that proves or disproves a stated issue. 2 Information that an auditor gathers in the course of performing an IS audit; relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it is used to support.
4
New cards
Exception reports
An exception report is generated by a program that identifies transactions or data that appear to be incorrect.
5
New cards
Exclusive-OR (XOR)
The exclusive-OR operator returns a value of TRUE only if just one of its operands is TRUE. The XOR operation is a Boolean operation that produces a 0 if its two Boolean inputs are the same (0 and 0 or 1 and 1) and that produces a 1 if its two inputs are different (1 and 0). In contrast, an inclusive-OR operator returns a value of TRUE if either or both of its operands are TRUE.
6
New cards
Executable code
The machine language code that is generally referred to as the object or load module.
7
New cards
Expert system
The most prevalent type of computer system that arises from the research of artificial intelligence.
8
New cards
Exposure
The potential loss to an area due to the occurrence of an adverse event.
9
New cards
Extended Binary-coded for Decimal Interchange Code (EBCDIC)
An 8-bit code representing 256 characters; used in most large computer systems
10
New cards
Extended enterprise
Describes an enterprise that extends outside its traditional boundaries. Such enterprise concentrate on the processes they do best and rely on someone outside the entity to perform the remaining processes.
11
New cards
eXtensible Access Control Markup Language (XACML)
A declarative online software application user access control policy language implemented in Extensible Markup Language (XML).
12
New cards
eXtensible Markup Language (XML)
Promulgated through the World Wide Web Consortium, XML is a web-based application development technique that allows designers to create their own customized tags, thus, enabling the definition, transmission, validation and interpretation of data between applications and enterprises.
13
New cards
External router
The router at the extreme edge of the network under control, usually connected to an Internet service provider (ISP) or other service provider; also known as border router.
14
New cards
External storage
The location that contains the backup copies to be used in case recovery or restoration is required in the event of a disaster.
15
New cards
Extranet
A private network that resides on the Internet and allows a company to securely share business information with customers, suppliers or other businesses as well as to execute electronic transactions.
16
New cards
Eavesdropping
Listening a private communication without permission
17
New cards
Egress
Network communications going out
18
New cards
Elliptical curve cryptography (ECC)
An algorithm that combines plane geometry with algebra to achieve stronger authentication with smaller keys compared to traditional methods, such as RSA, which primarily use algebraic factoring.
19
New cards
Encapsulation security payload (ESP)
Protocol, which is designed to provide a mix of security services in IPv4 and IPv6. ESP can be used to provide confidentiality, data origin authentication, connectionless integrity, an anti-replay service (a form of partial sequence integrity), and (limited) traffic flow confidentiality. (RFC 4303).
20
New cards
Encryption algorithm
A mathematically based function orcalculation that encrypts/decrypts data