FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank scores three cyber controls on design effectiveness (D) and operating effectiveness (O), each as a percentage of risk reduction, and applies them in sequence to an inherent annual loss of USD 10 million. Control residual effectiveness is the product D x O. Control A: D 90%, O 80%. Control B: D 80%, O 75%. Control C: D 50%, O 60%. If each control independently removes its effectiveness share of the remaining loss, what is the residual expected loss?
Residual expected loss is USD 0.784 million. Combined effectiveness per control is 72%, 60% and 30%, leaving 28%, 40% and 70% of loss. Multiplying gives 7.84% of the USD 10 million inherent loss.
- AUSD 0.784 million
- BUSD 1.568 millionCorrect
- CUSD 1.960 million
- DUSD 2.352 million
Explanation
Effectiveness: A = 0.72, B = 0.60, C = 0.30. Remaining fractions: 0.28, 0.40, 0.70. Product = 0.28 x 0.40 = 0.112; x 0.70 = 0.0784. Residual = 10 x 0.0784 = USD 0.784 million. Key is therefore USD 0.784 million; the 1.568 figure doubles it erroneously.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A regional bank's customer-statement database is altered by an attacker who changes several account balances without being detected. Which e…
- A payments firm sets a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for its card authorisatio…
- A post-incident review of a major retailer breach found that attackers entered through credentials stolen from an HVAC contractor that had n…
- After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alert…
- A bank's risk team is deciding which control best supports confidentiality of customer data held on laptops that may be lost while staff tra…
- A regional bank's security team observes that a group has gained access to its payment-messaging environment, remained undetected for severa…