FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank allocates its cyber risk governance responsibilities under a three lines model. Which arrangement is most consistent with that model?
The consistent arrangement has business and IT units owning and managing cyber risk, the security risk function setting policy and challenging, and internal audit giving independent assurance. Mixing operation of controls with assurance breaks independence, and the board must still oversee the framework.
- ABusiness and IT units own and manage cyber risk, the information security risk function sets policy and challenges, and internal audit independently assuresCorrect
- BInternal audit designs and operates the security controls and also tests them
- CThe CISO both operates all controls and provides independent assurance to the board
- DThe business units own the risk but the board has no role in oversight
Explanation
In the three lines model, the first line owns and manages risk, the second line sets frameworks and provides challenge, and the third line (internal audit) gives independent assurance. Having audit operate controls or the CISO self-assure compromises independence.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank classifies threat actors by motivation. Which pairing of actor and typical primary motivation is most accurate?
- After a breach, a review finds that attackers who compromised one employee's credentials moved freely from the corporate network into the pa…
- After a ransomware incident, a bank finds that attackers first sent employees emails mimicking an internal HR notice, harvested credentials,…
- A regional bank's security team observes a group that has quietly maintained access to its payment-switch network for eleven months, exfiltr…
- Which feature of cyber risk most complicates its quantification relative to other operational risk categories?
- A bank estimates that a phishing-led breach occurs with annual frequency 0.4 and an average loss of USD 5 million per event. A proposed cont…