FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank wants its cyber risk assessment to reflect the threat landscape. Which approach is most consistent with good practice for incorporating threat intelligence into assessment?
Threat intelligence should feed scenario design and control testing, so the bank checks whether current controls would detect or stop the tactics real attackers use. Limiting assessment to internal history or post-breach updates leaves it backward-looking and blind to emerging threats.
- AUse intelligence on actors' tactics and techniques to inform scenario design and test whether existing controls would detect or stop those techniquesCorrect
- BCollect intelligence feeds but keep them within the security team and exclude them from enterprise risk assessments
- CUpdate the cyber risk assessment only after a successful breach at the bank itself
- DBase the assessment only on historical internal incidents, since external events are not relevant
Explanation
Good practice ties threat intelligence to scenario design and control testing, making assessment forward-looking. Using only internal history or waiting for a breach makes the assessment backward-looking and incomplete.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's cyber strategy is assessed by a supervisor. Which finding most clearly indicates that the strategy is not aligned with sound practi…
- A regional bank classifies its cyber defences into functions. Its security team installs firewalls and multi-factor authentication, runs a s…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) of two hours for its payments system. Which statement best describe…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) for its payment-processing system. Which statement best describes w…
- A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration te…
- Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are …