Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank allocates its cyber risk governance responsibilities under a three lines model. Which arrangement is most consistent with that model?

The consistent arrangement has business and IT units owning and managing cyber risk, the security risk function setting policy and challenging, and internal audit giving independent assurance. Mixing operation of controls with assurance breaks independence, and the board must still oversee the framework.

  1. ABusiness and IT units own and manage cyber risk, the information security risk function sets policy and challenges, and internal audit independently assuresCorrect
  2. BInternal audit designs and operates the security controls and also tests them
  3. CThe CISO both operates all controls and provides independent assurance to the board
  4. DThe business units own the risk but the board has no role in oversight

Explanation

In the three lines model, the first line owns and manages risk, the second line sets frameworks and provides challenge, and the third line (internal audit) gives independent assurance. Having audit operate controls or the CISO self-assure compromises independence.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions