SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CRISC Information Systems Control
Start Test
Study First
Subjects
:
certifications
,
crisc
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Business process owner
The individual responsible for identifying process requirements - approving process design and managing process performance. Scope Note: Must be at an appropriately high level in the enterprise and have authority to commit resources to process-specif
commission
Standards standards published by: ISACA
A repository of the key attributes of potential and known IT risk issues. Attributes may include name - description - owner - expected/actual frequency - potential/actual magnitude - potential/actual business impact - disposition.
2. IT risk issue
1. An instance of IT risk 2. A combination of control - value and threat conditions that impose a noteworthy level of IT risk
A description of the overall (identified) IT risk to which the enterprise is exposed
The net effect - positive or negative - on the achievement of business objectives
A repository of the key attributes of potential and known IT risk issues. Attributes may include name - description - owner - expected/actual frequency - potential/actual magnitude - potential/actual business impact - disposition.
3. Access control
commission
Preserving authorized restrictions on access and disclosure - including means for protecting privacy and proprietary information
The processes - rules and deployment mechanisms that control access to information systems - resources and physical access to premises
statistical process control
4. EL
Carnegie Mellon University
Failure modes effects analysis
expected loss
Business Process Reengineering
5. Asset
A description of the overall (identified) IT risk to which the enterprise is exposed
Something of either tangible or intangible value that is worth protecting - including people - information - infrastructure - finances and reputation
The policies - procedures and activities designed to provide reasonable assurance that objectives relevant to a given automated solution (application) are achieved
Exists to detect and report when errors - omissions and unauthorized uses or entries occur
6. Enterprise Resource Planning (ERP)
Carnegie Mellon University
Software Engineering Institute
A enterprise to automate and integrate the majority of its planning. System packaged business software system that allows an business processes - share common data and practices across the entire enterprise - and produce and access information in a r
The process for systematically avoiding risk - constituting one approach to managing risk
7. Risk avoidance
expected loss
The process for systematically avoiding risk - constituting one approach to managing risk
Any event during which a threat element/actor acts against an asset in a manner that has the potential to directly result in harm
A repository of the key attributes of potential and known IT risk issues. Attributes may include name - description - owner - expected/actual frequency - potential/actual magnitude - potential/actual business impact - disposition.
8. cusum
A condition that can influence the frequency and/or magnitude and - ultimately - the business impact of IT-related events/scenarios
A measure of the rate by which events occur over a certain period of time
statistical process control
cumulative summary. each value is added for a cummulative total.
9. Key risk indicator (KRI)
A probable situation with uncertain frequency and magnitude of loss (or gain)
statistical process control
A subset of risk indicators that are highly relevant and possess a high probability of predicting or indicating important risk. Scope Note: See also Risk Indicator.
A measure that determines how well the process is performing in enabling the goal to be reached. Scope Note: A lead indicator of whether a goal will likely be reached - and a good indicator of capabilities - practices and skills. It measures an activ
10. Recovery time objective
Any event during which a threat event results in loss. Scope Note: From Jones - J.; 'FAIR Taxonomy -' Risk Management Insight - USA - 2008
The amount of time allowed for the recovery of a business function or resource after a disaster occurs
A group of people integrated at the enterprise with clear lines of reporting and responsibilities for standby support in case of an information systems emergency. This group will act as an efficient corrective control - and should also act as a singl
Guarding against improper information modification or destruction - and includes ensuring information non-repudiation and authenticity
11. SPC
The individual(s) and department(s) responsible for the storage and safeguarding of computerized data
statistical process control
1. The act of verifying identity (i.e. - user - system) Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data 2. The act of verifying the identity of a user and the user's eligibility to access computerized inform
Any event during which a threat event results in loss. Scope Note: From Jones - J.; 'FAIR Taxonomy -' Risk Management Insight - USA - 2008
12. treadway
Standards standards published by: ISACA
commission
The policies - procedures and activities designed to provide reasonable assurance that objectives relevant to a given automated solution (application) are achieved
The ability to exercise judgment - express opinions and present recommendations with impartiality
13. Control risk self-assessment
A method/process by which management and staff of all levels collectively identify and evaluate risk and controls with their business areas. This may be under the guidance of a facilitator such as an auditor or risk manager.
expected loss
The permission or privileges granted to users - programs or workstations to create - change - delete or view data and files within a system - as defined by rules established by data owners and the information security policy
Ensuring timely and reliable access to and use of information. Balanced scorecard (BSC) Developed by Robert S. Kaplan and David P. Norton as a coherent set of performance measures organized into four categories that includes traditional financial mea
14. IT risk register
risk management information systems
The remaining risk after management has implemented a risk response
A repository of the key attributes of potential and known IT risk issues. Attributes may include name - description - owner - expected/actual frequency - potential/actual magnitude - potential/actual business impact - disposition.
1. Information that proves or disproves a stated issue 2. Information that an auditor gathers in the course of performing an IS audit; relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it i
15. Capability
An aptitude - competency or resource that an enterprise may possess or require at an enterprise - business function or individual level that has the potential - or is required - to contribute to a business outcome and to create value
Business Process Reengineering
Anything (e.g. - object - substance - human) that is capable of acting against an asset in a manner that can result in harm. Scope Note: A potential cause of an unwanted incident (ISO/IEC 13335)
The remaining risk after management has implemented a risk response
16. Access rights
The permission or privileges granted to users - programs or workstations to create - change - delete or view data and files within a system - as defined by rules established by data owners and the information security policy
Any event during which a threat element/actor acts against an asset in a manner that has the potential to directly result in harm
Business Process Reengineering
business continuity planning
17. standards publisher of IT Audit and Assurance
Standards standards published by: ISACA
The management of risk through the use of countermeasures and controls
The phases deployed in the development or acquisition of a software system. Scope Note: SDLC is an approach used to plan - design - develop - test and implement an application system or a major modification to an application system. Typical phases of
Any event during which a material increase in vulnerability results. Note that this increase in vulnerability can result from changes in control conditions or from changes in threat capability/force.
18. Risk factor
An evaluation of the type - scope and nature of events or actions that can result in adverse consequences; identification of the threats that exist against enterprise assets Scope Note: The threat analysis usually defines the level of threat and the
operationally critical threat and vulnerability evaluation
A condition that can influence the frequency and/or magnitude and - ultimately - the business impact of IT-related events/scenarios
Something of either tangible or intangible value that is worth protecting - including people - information - infrastructure - finances and reputation
19. IT risk scenario
The process for systematically avoiding risk - constituting one approach to managing risk
critical success factor
The description of an IT-related event that can lead to a business impact IT-related incident An IT-related event that causes an operational - developmental and/or strategic business impact
A enterprise to automate and integrate the majority of its planning. System packaged business software system that allows an business processes - share common data and practices across the entire enterprise - and produce and access information in a r
20. Risk transfer
An aptitude - competency or resource that an enterprise may possess or require at an enterprise - business function or individual level that has the potential - or is required - to contribute to a business outcome and to create value
The discipline by which an enterprise in any industry assesses - controls - exploits - finances and monitors risk from all sources for the purpose of increasing the enterprise's short- and long-term value to its stakeholders
committee of sponsoring organizations
The process of assigning risk to another enterprise - usually through the purchase of an insurance policy or by outsourcing the service
21. Risk portfolio view
operationally critical threat and vulnerability evaluation
The amount of time allowed for the recovery of a business function or resource after a disaster occurs
1. Contains the essential elements of effective processes for one or more disciplines. It also describes an evolutionary improvement path from ad hoc - immature processes to disciplined - mature processes with improved quality and effectiveness. 2. C
1. A method to identify interdependencies and interconnections among risk - as well as the effect of risk responses on multiple types of risk 2. A method to estimate the aggregate impact of multiple types of risk (e.g. - cascading and coincidental th
22. Residual risk
The remaining risk after management has implemented a risk response
The individual(s) - normally a manager or director - who has responsibility for the integrity - accurate reporting and use of computerized data
A phase of a system development life cycle (SDLC) methodology that researches the feasibility and adequacy of resources for the development or acquisition of a system solution to a user need
enterprise risk management
23. System development life cycle (SDLC)
Any event during which a threat event results in loss. Scope Note: From Jones - J.; 'FAIR Taxonomy -' Risk Management Insight - USA - 2008
Failure modes effects analysis
The phases deployed in the development or acquisition of a software system. Scope Note: SDLC is an approach used to plan - design - develop - test and implement an application system or a major modification to an application system. Typical phases of
The process for systematically avoiding risk - constituting one approach to managing risk
24. Risk appetite
international organization for standards
A probable situation with uncertain frequency and magnitude of loss (or gain)
The amount of risk - on a broad level - that an entity is willing to accept in pursuit of its mission
The combination of strategic - managerial and operational activities involved in gathering - processing - storing - distributing and using information and its related technologies Scope Note: Information systems are distinct from information technolo
25. IT risk
A description of the overall (identified) IT risk to which the enterprise is exposed
The ability to exercise judgment - express opinions and present recommendations with impartiality
The business risk associated with the use - ownership - operation - involvement - influence and adoption of IT within an enterprise
A (graphic) tool for ranking and displaying risk by defined ranges for frequency and magnitude
26. Vulnerability
The processes - rules and deployment mechanisms that control access to information systems - resources and physical access to premises
Determined based on the acceptable data loss in case of a disruption of operations. It indicates the earliest point in time that is acceptable to recover the data. The RPO effectively quantifies the permissible amount of data loss in case of interrup
A weakness in the design - implementation - operation or internal control of a process that could expose the system to adverse threats from threat events
statistical process control
27. IEC
international electrotechnical commission
A probable situation with uncertain frequency and magnitude of loss (or gain)
A condition that can influence the frequency and/or magnitude and - ultimately - the business impact of IT-related events/scenarios
risk management information systems
28. FMEA
Failure modes effects analysis
risk control self assessment
The permission or privileges granted to users - programs or workstations to create - change - delete or view data and files within a system - as defined by rules established by data owners and the information security policy
A plan of action or set of procedures to be performed if a system implementation - upgrade or modification does not work as intended Scope Note: May involve restoring the system to its state prior to the implementation or change. Fallback procedures
29. Internal controls
Any event during which a threat event results in loss. Scope Note: From Jones - J.; 'FAIR Taxonomy -' Risk Management Insight - USA - 2008
The process of assigning risk to another enterprise - usually through the purchase of an insurance policy or by outsourcing the service
A group of people integrated at the enterprise with clear lines of reporting and responsibilities for standby support in case of an information systems emergency. This group will act as an efficient corrective control - and should also act as a singl
The policies - procedures - practices and organizational structures designed to provide reasonable assurance that business
30. Business goal
31. Risk map
The acceptable level of variation that management is willing to allow for any particular risk as the enterprise pursues its objectives
A (graphic) tool for ranking and displaying risk by defined ranges for frequency and magnitude
certified in risk and information systems control
The phases deployed in the development or acquisition of a software system. Scope Note: SDLC is an approach used to plan - design - develop - test and implement an application system or a major modification to an application system. Typical phases of
32. RCSA
Something that happens at a specific place and/or time
risk control self assessment
British Standards Institution
The discipline by which an enterprise in any industry assesses - controls - exploits - finances and monitors risk from all sources for the purpose of increasing the enterprise's short- and long-term value to its stakeholders
33. Evidence
The business risk associated with the use - ownership - operation - involvement - influence and adoption of IT within an enterprise
A measure of the rate by which events occur over a certain period of time
committee of sponsoring organizations
1. Information that proves or disproves a stated issue 2. Information that an auditor gathers in the course of performing an IS audit; relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it i
34. IT infrastructure
35. Inherent risk
Control Objectives for Information and Related Technology
1. The risk level or exposure without taking into account the actions that management has taken or might take (e.g. -implementing controls) 2. The risk that a material error could occur - assuming that there are no related internal controls to preven
critical success factor
committee of sponsoring organizations
36. SIE
A subset of risk indicators that are highly relevant and possess a high probability of predicting or indicating important risk. Scope Note: See also Risk Indicator.
Software Engineering Institute
The phases deployed in the development or acquisition of a software system. Scope Note: SDLC is an approach used to plan - design - develop - test and implement an application system or a major modification to an application system. Typical phases of
The amount of risk - on a broad level - that an entity is willing to accept in pursuit of its mission
37. BSI
British Standards Institution
Something of either tangible or intangible value that is worth protecting - including people - information - infrastructure - finances and reputation
The ability of a system or network to resist failure or to recover quickly from any disruption - usually with minimal recognizable effect
committee of sponsoring organizations
38. IT risk profile
A description of the overall (identified) IT risk to which the enterprise is exposed
An aptitude - competency or resource that an enterprise may possess or require at an enterprise - business function or individual level that has the potential - or is required - to contribute to a business outcome and to create value
Exists to detect and report when errors - omissions and unauthorized uses or entries occur
A plan of action or set of procedures to be performed if a system implementation - upgrade or modification does not work as intended Scope Note: May involve restoring the system to its state prior to the implementation or change. Fallback procedures
39. CRISC
A method/process by which management and staff of all levels collectively identify and evaluate risk and controls with their business areas. This may be under the guidance of a facilitator such as an auditor or risk manager.
certified in risk and information systems control
Business Process Reengineering
A repository of the key attributes of potential and known IT risk issues. Attributes may include name - description - owner - expected/actual frequency - potential/actual magnitude - potential/actual business impact - disposition.
40. Risk mitigation
A measure of the potential severity of loss or the potential gain from realized events/scenarios
enterprise risk management
The policies - procedures - practices and organizational structures designed to provide reasonable assurance that business
The management of risk through the use of countermeasures and controls
41. Data owner
The individual(s) - normally a manager or director - who has responsibility for the integrity - accurate reporting and use of computerized data
cumulative summary. each value is added for a cummulative total.
certified in risk and information systems control
1. A process by which frequency and magnitude of IT risk scenarios are estimated. 2. The initial steps of risk management: analyzing the value of assets to the business - identifying threats to those assets and evaluating how vulnerable each asset is
42. Application controls
Ensuring timely and reliable access to and use of information. Balanced scorecard (BSC) Developed by Robert S. Kaplan and David P. Norton as a coherent set of performance measures organized into four categories that includes traditional financial mea
The phases deployed in the development or acquisition of a software system. Scope Note: SDLC is an approach used to plan - design - develop - test and implement an application system or a major modification to an application system. Typical phases of
1. Contains the essential elements of effective processes for one or more disciplines. It also describes an evolutionary improvement path from ad hoc - immature processes to disciplined - mature processes with improved quality and effectiveness. 2. C
The policies - procedures and activities designed to provide reasonable assurance that objectives relevant to a given automated solution (application) are achieved
43. Threat
Anything (e.g. - object - substance - human) that is capable of acting against an asset in a manner that can result in harm. Scope Note: A potential cause of an unwanted incident (ISO/IEC 13335)
A weakness in the design - implementation - operation or internal control of a process that could expose the system to adverse threats from threat events
The amount of time allowed for the recovery of a business function or resource after a disaster occurs
An internal control that is used to avoid undesirable events - errors and other occurrences that an enterprise has determined could have a negative material effect on a process or end product
44. Reputation risk
45. Resilience
Any event during which a material increase in vulnerability results. Note that this increase in vulnerability can result from changes in control conditions or from changes in threat capability/force.
The ability of a system or network to resist failure or to recover quickly from any disruption - usually with minimal recognizable effect
British Standards Institution
The phases deployed in the development or acquisition of a software system. Scope Note: SDLC is an approach used to plan - design - develop - test and implement an application system or a major modification to an application system. Typical phases of
46. Key performance indicator (KPI)
The individual(s) and department(s) responsible for the storage and safeguarding of computerized data
Failure modes effects analysis
A measure that determines how well the process is performing in enabling the goal to be reached. Scope Note: A lead indicator of whether a goal will likely be reached - and a good indicator of capabilities - practices and skills. It measures an activ
Any event during which a material increase in vulnerability results. Note that this increase in vulnerability can result from changes in control conditions or from changes in threat capability/force.
47. Threat event
Documentation of the rationale for making a business investment - used both to support a business decision on whether to proceed with the investment and as an operational tool to support management of the investment through its full economic life cyc
risk management information systems
Any event during which a threat element/actor acts against an asset in a manner that has the potential to directly result in harm
The individual(s) and department(s) responsible for the storage and safeguarding of computerized data
48. Business impact
Documentation of the rationale for making a business investment - used both to support a business decision on whether to proceed with the investment and as an operational tool to support management of the investment through its full economic life cyc
A further development of the business goals into tactical targets and desired results and outcomes
1. The act of verifying identity (i.e. - user - system) Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data 2. The act of verifying the identity of a user and the user's eligibility to access computerized inform
The net effect - positive or negative - on the achievement of business objectives
49. Impact analysis
Description of the fundamental underlying design of the IT components of the business - the relationships among them - and the manner in which they support the enterprise's objectives
The amount of time allowed for the recovery of a business function or resource after a disaster occurs
A study to prioritize the criticality of information resources for the enterprise based on costs (or consequences) of adverse events In an impact analysis - threats to assets are identified and potential business losses determined for different time
The policies - procedures and activities designed to provide reasonable assurance that objectives relevant to a given automated solution (application) are achieved
50. Risk tolerance
Determined based on the acceptable data loss in case of a disruption of operations. It indicates the earliest point in time that is acceptable to recover the data. The RPO effectively quantifies the permissible amount of data loss in case of interrup
The acceptable level of variation that management is willing to allow for any particular risk as the enterprise pursues its objectives
The net effect - positive or negative - on the achievement of business objectives
The policies - procedures and activities designed to provide reasonable assurance that objectives relevant to a given automated solution (application) are achieved