Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank runs a cyber risk assessment and finds that a customer-facing payment application has a high-severity vulnerability. Threat intelligence shows active exploitation of this flaw in the industry, but the application is only reachable through a segmented network behind multi-factor authentication. Which approach to rating the risk is most consistent with sound practice?

Sound practice combines vulnerability severity with threat likelihood, asset criticality and the effectiveness of compensating controls such as segmentation and multi-factor authentication. A technical score alone ignores context, dismissing industry threat intelligence understates likelihood, and waiting for a breach is purely reactive.

  1. ARate it by the vulnerability's technical severity score alone, since the score is objective
  2. BRate it as low because the threat intelligence concerns other firms
  3. CCombine the vulnerability severity with threat likelihood, the asset's criticality and the effectiveness of compensating controlsCorrect
  4. DDefer rating until an actual breach confirms exploitability

Explanation

Cyber risk assessment combines threat, vulnerability, asset criticality and existing controls. Using the severity score alone ignores segmentation and MFA, and ignoring industry intelligence understates likelihood. Waiting for a breach is reactive and not acceptable.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions