FRM Part II · FRM Exam Part II
Cyber-resilience: Range of Practices: formula sheet
Key formulas
- CIA triad
- Confidentiality + Integrity + Availability
- The three security objectives. A cyber event breaches at least one of them.
- Cyber risk in Basel terms
- Cyber risk ⊂ Operational risk
- Operational risk is loss from inadequate or failed processes, people, systems or external events. It includes legal risk but excludes strategic and reputational risk in the Basel definition.
- Security vs resilience
- Resilience = Security (prevent) + Detect + Respond + Recover + Learn
- A memory aid, not a regulatory formula. Resilience assumes breaches will happen.
- Lifecycle of cyber resilience
- Govern → Identify → Protect → Detect → Respond → Recover → Learn
- Use as a checklist to place any control or action in the right phase.
- Board role
- Board = approve strategy and appetite + oversee + challenge
- The board does not design or operate technical controls.
- Appetite cascade
- Risk appetite → risk tolerances → limits and KRIs
- Appetite is broad; tolerances and KRIs are measurable and monitored.
- Three lines of defense
- 1st line = own and manage; 2nd line = oversee and challenge; 3rd line = independent assurance
- Internal audit is the third line and must stay independent of the first two.
- Risk tolerance test
- Actual metric ≤ tolerance → within appetite; actual > tolerance → escalate
- Applies when a higher value is worse, such as hours of downtime.
- Risk as a combination
- Cyber risk = Threat × Vulnerability × Impact (conceptual)
- A conceptual relationship, not a precise calculation. If any factor is near zero, risk is low.
- Frequency-severity annual loss
- Expected annual loss = Expected number of events per year × Average loss per event
- Valid as an expected value when frequency and severity are treated as independent.
- Residual risk
- Residual risk = Inherent risk − Effect of controls
- Conceptual. Inherent risk is before controls; residual is after controls.
- Preventive vs detective
- Preventive = before or during an attack (reduce likelihood); Detective = during or after (reduce dwell time and impact)
- Classify by what the control does at the moment it acts, not by the tool name.
- Penetration test vs red team
- Penetration test = scoped, specific systems, usually announced; Red team = goal-based, realistic adversary, tests people, process and technology and defender response
- Red teaming tests detection and response as well as technical weaknesses.
- Vulnerability scan vs penetration test
- Scan = automated, finds known weaknesses; Penetration test = manual exploitation to prove impact
- A scan does not show whether a weakness can actually be chained into a breach.
- Least privilege
- Access granted = minimum needed for the role, for the time needed
- Pair with periodic access recertification and privileged access management.
- Defence in depth
- Several independent layers, so one control failure does not cause a breach
- Use it to justify combining preventive and detective controls.
- Third-party risk lifecycle
- Due diligence → contract terms → ongoing monitoring → exit planning
- Accountability remains with the bank, not the provider.
- Recovery time objective (RTO)
- RTO = maximum acceptable time from disruption to restored service
- Measures downtime tolerance. Actual recovery time must be ≤ RTO.
- Recovery point objective (RPO)
- RPO = maximum acceptable data loss, measured as time between the last good copy and the incident
- Backup or replication interval must be ≤ RPO. It is about data, not time to restore.
- Response sequence
- Detect → Triage → Contain → Eradicate → Recover → Learn
- Containment comes before eradication and recovery. Do not restore into a still-compromised environment.
- Recovery must fit tolerance
- Time to restore critical service ≤ RTO ≤ impact tolerance
- Recovery objectives should sit inside the firm's tolerance for disruption of the critical operation.
Quick revision
- Cyber resilience is the ability to keep delivering critical services through and after a cyber incident.
- Prevention alone is not enough; assume some attacks will succeed and plan for recovery.
- Governance means the board and senior management set direction, risk appetite and accountability.
- Identify critical functions and the assets and data that support them before choosing controls.
- Risk assessment links threats, vulnerabilities and potential impact.
- Protection and detection controls work together; good protection without detection leaves breaches unseen.
- Defence in depth uses layered controls so one failure does not expose everything.
- Response plans need defined roles, escalation paths and communication to stakeholders.
- Recovery planning should be tested regularly, not only written down.
- Third-party and supply chain dependencies are part of your cyber risk.
- Information sharing with peers and authorities improves collective defence.
- Lessons from incidents and tests should feed back into strategy and controls.
Common mistakes
- Treating cyber resilience and cyber security as the same thing. Fix: Security prevents and protects. Resilience also covers detection, response, recovery and learning, and assumes breaches happen.
- Treating cyber risk as separate from operational risk. Fix: Under Basel it is a source of operational risk loss. Map it to event types such as external fraud or system failures.
- Giving the board day-to-day control responsibility. Fix: The board approves, oversees and challenges. Management and the first line operate controls.
- Treating internal audit as the second line. Fix: Audit is the third line and provides independent assurance. The second line sets the framework and challenges.
- Confusing threat with vulnerability Fix: A threat is the actor or event; a vulnerability is the weakness it exploits.
- Starting with all IT assets rather than critical services Fix: Begin with services the business cannot afford to lose, then map supporting assets.
- Calling monitoring or logging a preventive control. Fix: Monitoring finds activity; it is detective unless it is an automated blocking tool. Check what the question says the control does.
- Treating penetration testing and red teaming as the same thing. Fix: A penetration test is scoped and usually announced. Red teaming is goal-based, adversary-like and tests detection and response too.
- Mixing up RTO and RPO Fix: RTO is about downtime. RPO is about lost data. Think T for time to restore, P for the point in time you go back to.
- Restoring systems before containing the threat Fix: Contain and eradicate first, or the attacker may re-enter or destroy the restored data.
Exam tips
- Expect scenario questions that test the distinction between security and resilience. Look for words like 'recover', 'critical services' and 'continue'.
- Always link cyber to the Basel operational risk definition when asked about classification.
- Reject absolute answers such as 'eliminate' or 'fully prevent'.
- Remember why banks are targets: valuable assets, interconnection, technology dependence and systemic importance.
- Third-party and shared-vendor dependence often appears as the feature that distinguishes cyber from traditional operational risk.
- Memorise the three-line split and watch for options that blur independence.
- Expect scenarios where a measured metric exceeds a tolerance. The answer is usually escalation.
- Board answers are about approving, overseeing and challenging, not operating.