FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review notes that security findings are frequently deprioritised to meet project dates. Which governance change most directly addresses this conflict of interest?
Giving the CISO a direct line to the chief risk officer or a senior risk committee, independent of IT delivery, best resolves the conflict. It lets security challenge project timelines without being subordinate to the executive responsible for budgets and deadlines.
- AGive the CISO a direct reporting line to the CRO or senior risk committee, independent of IT deliveryCorrect
- BMove security staff into the IT project teams to work under the delivery managers
- CReplace periodic security reporting with ad hoc verbal updates to the CIO
- DOutsource the CISO role to the vendor that builds the bank's core systems
Explanation
The problem is that the security function is subordinate to the function whose objectives it must challenge. Independent reporting to risk leadership or a board-level committee restores a second line of defence view. Embedding staff under delivery managers or using the system vendor worsens the conflict, and verbal updates reduce accountability.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration te…
- A bank's board asks the CISO to explain how cyber-resilience differs from traditional cyber-security. Which description best captures the di…
- Which control is most effective at protecting sensitive customer data if an attacker gains access to a database server's storage?
- After a ransomware attack encrypts a payment processor's production systems, the firm restores from backups that were stored on the same net…
- A bank runs a cyber risk assessment and finds that a customer-facing payment application has a high-severity vulnerability. Threat intellige…
- A bank backs up its core ledger to an offsite site every 4 hours. A ransomware attack corrupts the primary system 3 hours after the last bac…