FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank runs a cyber risk assessment and finds that a customer-facing payment application has a high-severity vulnerability. Threat intelligence shows active exploitation of this flaw in the industry, but the application is only reachable through a segmented network behind multi-factor authentication. Which approach to rating the risk is most consistent with sound practice?
Sound practice combines vulnerability severity with threat likelihood, asset criticality and the effectiveness of compensating controls such as segmentation and multi-factor authentication. A technical score alone ignores context, dismissing industry threat intelligence understates likelihood, and waiting for a breach is purely reactive.
- ARate it by the vulnerability's technical severity score alone, since the score is objective
- BRate it as low because the threat intelligence concerns other firms
- CCombine the vulnerability severity with threat likelihood, the asset's criticality and the effectiveness of compensating controlsCorrect
- DDefer rating until an actual breach confirms exploitability
Explanation
Cyber risk assessment combines threat, vulnerability, asset criticality and existing controls. Using the severity score alone ignores segmentation and MFA, and ignoring industry intelligence understates likelihood. Waiting for a breach is reactive and not acceptable.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- During a cyber risk self-assessment, a bank's business units rate their own control effectiveness as strong, yet internal audit finds repeat…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…
- Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?