FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and competitive harm. Which measure would best address this barrier while preserving the benefits of sharing?
Sharing anonymized or trusted-community information under agreed confidentiality protocols best addresses the concern. It lowers legal, reputational and competitive risk while keeping intelligence timely and useful. Waiting until remediation, sharing raw customer data, or only receiving information either weakens value, breaches privacy, or undermines the exchange.
- AShare only after the incident has been fully remediated and publicly reported
- BShare anonymized or trusted-community information under agreed protocols that protect confidentialityCorrect
- CShare raw customer data so that peers can verify the threat
- DLimit participation to receiving information without ever contributing
Explanation
Trusted channels with confidentiality protocols and anonymization reduce legal and reputational concerns while allowing timely sharing. Delaying sharing reduces its value, raw customer data creates privacy breaches, and receive-only participation undermines the exchange.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- After a significant cyber incident is contained, a firm's CISO proposes a post-incident review. Which outcome of the review is most consiste…
- A bank's cyber risk team is building its inventory for cyber risk identification. Which step best reflects the range of practices observed f…
- A bank uses three lines of defence for cyber risk. The CISO's team designs controls and monitors threats, business units run systems daily, …
- A bank is deciding how to govern cyber risk. Which arrangement is most consistent with sound cyber-resilience practice?
- A bank's security operations centre receives thousands of alerts daily from separate tools, and analysts miss a slow data exfiltration that …
- A bank's cyber-resilience programme is reviewed. The review finds that the board approves a cyber risk appetite statement, but business line…