FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank wants its cyber-resilience strategy to be integrated with enterprise risk management. Which approach best achieves this?
Cyber strategy should be aligned with the enterprise risk framework, using common appetite, taxonomy and reporting, and linked to business objectives and critical services. A siloed IT document, a perimeter-only focus, or exclusive cyber-team ownership prevents consolidated oversight and business accountability.
- AMaintain the cyber strategy as a separate IT document with its own unrelated risk scales
- BAlign cyber risk appetite, taxonomy and reporting with the enterprise framework, and link the strategy to business objectives and critical servicesCorrect
- CLimit the strategy to perimeter controls and exclude business continuity planning
- DHave the cyber team own all risk decisions independently of business lines
Explanation
Integration means using a common taxonomy, appetite and reporting, and tying cyber objectives to business services. Separate scales, perimeter-only scope and cyber-team-only ownership prevent a consolidated view and weaken accountability by business lines.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration te…
- A bank's cyber risk team is building its inventory for cyber risk identification. Which step best reflects the range of practices observed f…
- A bank uses three lines of defence for cyber risk. The CISO's team designs controls and monitors threats, business units run systems daily, …
- Which control is most effective at protecting sensitive customer data if an attacker gains access to a database server's storage?
- A bank's cyber-resilience programme is reviewed. The review finds that the board approves a cyber risk appetite statement, but business line…
- A bank's cyber strategy states that it will tolerate no more than two high-severity incidents per year affecting critical services. Manageme…