Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review notes that security findings are frequently deprioritised to meet project dates. Which governance change most directly addresses this conflict of interest?

Giving the CISO a direct line to the chief risk officer or a senior risk committee, independent of IT delivery, best resolves the conflict. It lets security challenge project timelines without being subordinate to the executive responsible for budgets and deadlines.

  1. AGive the CISO a direct reporting line to the CRO or senior risk committee, independent of IT deliveryCorrect
  2. BMove security staff into the IT project teams to work under the delivery managers
  3. CReplace periodic security reporting with ad hoc verbal updates to the CIO
  4. DOutsource the CISO role to the vendor that builds the bank's core systems

Explanation

The problem is that the security function is subordinate to the function whose objectives it must challenge. Independent reporting to risk leadership or a board-level committee restores a second line of defence view. Embedding staff under delivery managers or using the system vendor worsens the conflict, and verbal updates reduce accountability.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions