FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's board is reviewing how its approach to cyber risk should differ from a traditional information-security programme. Which statement best captures the idea of cyber-resilience as used in the BCBS/CPMI-style range-of-practices discussion?
Cyber-resilience is the ability to anticipate, withstand, contain and recover from cyber events while continuing to deliver critical operations. It assumes some attacks will succeed, so it goes beyond prevention, insurance or disclosure and focuses on keeping essential services running and restoring them.
- AThe ability to continue delivering critical operations despite adverse cyber events, including anticipating, withstanding, containing and recovering from themCorrect
- BA goal of preventing every cyber incident through perimeter controls so that recovery capability is unnecessary
- CA commitment to purchase cyber insurance so that all financial losses from attacks are transferred to insurers
- DA reporting framework under which all cyber incidents are disclosed to the public within a fixed number of hours
Explanation
Cyber-resilience goes beyond prevention: it emphasizes continuing critical operations and recovering when incidents occur, on the assumption that some attacks will succeed. Prevention-only approaches and insurance alone do not deliver operational continuity, and disclosure timing is a separate matter.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's cyber-resilience framework sets a recovery time objective (RTO) of two hours for its payments system. Which statement best describe…
- A bank's cyber-resilience framework sets a recovery time objective (RTO) for its payment-processing system. Which statement best describes w…
- A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration te…
- A bank has three critical services. Annualised expected losses from cyber events are: Service A USD 2.0m with inherent risk 10m, Service B U…
- A bank's cyber-resilience framework groups its controls into identification, protection, detection, response and recovery, and sustained lea…
- Which control is most effective at protecting sensitive customer data if an attacker gains access to a database server's storage?