FRM Part II · FRM Exam Part II
Case Study: Cyberthreats and Information Security Risks: formula sheet
Key formulas
- CIA triad
- Confidentiality + Integrity + Availability
- Map each attack to the property it breaks. Ransomware: availability (and confidentiality if data is stolen). Data theft: confidentiality. Tampering with records: integrity. DDoS: availability.
- Actor to motive
- Criminals → profit; Nation-states → espionage/disruption; Hacktivists → ideology; Insiders → grievance, gain or error
- This is a general pattern, not a strict rule. Actors can overlap, and attribution is often uncertain.
- Phishing vs malware
- Phishing = deception of a person; Malware = malicious code
- Phishing often delivers malware, but the two are different things.
- Basel operational risk link
- Cyber event → external fraud / internal fraud / business disruption and system failures
- Which category fits depends on who acts and what is affected. An attack by an outsider is usually external fraud; a malicious employee is internal fraud.
- Confidentiality
- Confidentiality = only authorised access to information
- Breach examples: data theft, leaked customer records, phishing credential capture.
- Integrity
- Integrity = accuracy and completeness, no unauthorised change
- Breach examples: altered payment instructions, tampered ledgers, corrupted data.
- Availability
- Availability = authorised access when needed
- Breach examples: ransomware lockout, DDoS, system outage, failed recovery.
- Basel operational risk definition
- Operational risk = loss from inadequate or failed processes, people and systems, or from external events
- Includes legal risk. Excludes strategic and reputational risk.
- Expected operational loss (frequency-severity)
- Expected annual loss = expected number of events × average loss per event
- Use it to compare cyber scenarios. Assumes frequency and severity are independent.
- Kill chain order
- Reconnaissance → Initial access → Privilege escalation → Lateral movement → Data theft or disruption → Cover tracks or extort
- Use it to place each case fact at the right stage and pick a control for that stage.
- CIA triad
- Confidentiality, Integrity, Availability
- Data theft hits confidentiality, fraudulent payments hit integrity, ransomware hits availability.
- Control types
- Preventive, Detective, Corrective (response and recovery)
- Match the failed control to its type. Many cases show detection failing even when prevention is partly in place.
- Shared responsibility rule
- Provider secures the cloud; customer secures what it configures and deploys in the cloud
- Customer misconfiguration is not the provider's failure.
- Total incident loss
- Total loss = direct loss + response and remediation cost + legal and regulatory cost + reputational and business loss
- A conceptual breakdown. Reputational loss is hard to measure.
- NIST Cybersecurity Framework functions
- Identify → Protect → Detect → Respond → Recover
- Core functions. Newer versions add Govern. The functions run continuously, not as a strict one-time sequence.
- CIA triad
- Confidentiality, Integrity, Availability
- The three properties of information security that controls aim to protect.
- Three lines of defense
- 1st line: owns and manages risk | 2nd line: oversees and challenges | 3rd line: independent assurance
- Internal audit is the third line. Risk management is the second line, not the first.
- Control types
- Preventive (Protect) | Detective (Detect) | Corrective (Respond, Recover)
- A useful mapping to NIST functions, not a strict rule.
- Residual risk
- Residual risk = Inherent risk − Effect of controls
- Conceptual relationship used in risk assessment; controls reduce but rarely eliminate risk.
- Incident response lifecycle
- Prepare → Detect and analyse → Contain → Eradicate → Recover → Learn
- Order matters. Containment comes before eradication, and recovery only after the threat is removed.
- RTO
- RTO = maximum tolerable time to restore a service after disruption
- A time-to-restore target. It drives choices such as hot, warm or cold standby.
- RPO
- RPO = maximum tolerable data loss, measured as time back to the last good copy
- Backup or replication interval must be no longer than the RPO.
- Impact tolerance
- Impact tolerance = maximum disruption to a critical service the firm will accept
- A resilience concept. Recovery targets should sit inside it.
- Relationship check
- Backup interval ≤ RPO; actual restore time ≤ RTO ≤ impact tolerance
- Use to test whether a design meets its targets.
- Annualised loss expectancy
- Expected annual loss = Loss event frequency × Loss magnitude per event
- Use expected values per year. Frequency is events per year, magnitude is the average cost per event.
- FAIR loss event frequency
- Loss event frequency = Threat event frequency × Vulnerability
- Vulnerability is the probability that a threat event becomes a loss event, given the strength of controls.
- FAIR loss magnitude
- Loss magnitude = Primary loss + Secondary loss
- Secondary loss includes fines, legal costs and stakeholder reactions.
- Net loss after insurance
- Net loss = Gross loss − Insurance recovery, where recovery = min(max(Gross loss − Retention, 0), Policy limit)
- Apply the retention first, then cap at the limit. Check for exclusions and sub-limits.
- Residual risk
- Residual risk = Inherent risk − Effect of controls and risk transfer
- A conceptual relationship, not an exact arithmetic subtraction in every framework.
Quick revision
- Cyber risk is a type of operational risk: loss from people, processes, systems or external events.
- CIA triad: confidentiality (no unauthorised disclosure), integrity (no unauthorised change), availability (access when needed).
- Ransomware mainly attacks availability; data theft mainly attacks confidentiality; tampering mainly attacks integrity.
- Threat actors differ in motive: criminals seek money, state actors seek strategic goals, insiders may act from grievance or error.
- Preventive controls stop events, detective controls spot them, corrective controls limit damage and restore.
- Defence in depth uses several layers so one failure does not cause a breach.
- Weak access management and slow patching are repeated causes of control failure in cases.
- Third-party and supply chain links extend your risk beyond your own systems.
- Incident response runs from preparation and detection through containment, recovery and lessons learned.
- Recovery time objective is how fast service must return; recovery point objective is how much data loss is tolerable.
- Cyber loss estimates combine event frequency and severity, but limited data makes them uncertain.
- Good governance means board oversight and clear ownership of cyber risk, not only IT ownership.
Common mistakes
- Treating phishing as a type of malware. Fix: Phishing is social engineering aimed at a person. Malware is code. Phishing is a delivery route.
- Saying ransomware only affects availability. Fix: Remember double extortion: stolen data also breaches confidentiality.
- Treating cyber risk as a separate Basel risk category. Fix: Remember it is a cause of operational risk loss. Losses fall in event types such as external fraud or business disruption and system failures.
- Calling ransomware only a confidentiality breach. Fix: Locked systems are an availability failure. Add confidentiality only if data was also exfiltrated.
- Blaming the cloud provider for a customer misconfiguration. Fix: Apply shared responsibility: the customer owns its configuration, identity and access settings.
- Treating the breach as one event instead of a chain. Fix: Walk the kill chain and note which control would have broken each link.
- Placing internal audit in the second line or giving it control ownership. Fix: Audit is the third line and gives independent assurance. It must not own or run controls.
- Treating NIST functions as a strict one-time sequence. Fix: The functions run concurrently and continuously. Lessons from Recover feed back into Identify and Protect.
- Mixing up RTO and RPO. Fix: RTO is how long you can be down. RPO is how far back your data can go. Ask: restore time or lost data?
- Restoring systems before containing the threat. Fix: Contain and eradicate first. Restoring into a compromised environment lets the attacker return.
Exam tips
- Practise telling method from actor. Many wrong options swap the two.
- Link each scenario to a CIA property. It quickly removes options.
- Be wary of absolutes such as always, only or never about actors and motives.
- Expect cases that mention cloud, third parties or AI. Treat these as new routes for the same threat types.
- Connect threats to Basel operational risk event types when the question asks for classification.
- Name the CIA property first. Most options differ only by which property they pick.
- Watch for scenarios that breach two properties, such as ransomware with data theft.
- Remember that Basel operational risk includes legal risk but excludes reputational and strategic risk.