Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank's cyber control self-assessment rates a key control as effective, but a penetration test shows an attacker could bypass it in under an hour. Which action best aligns with sound cyber risk management?

The bank should reassess residual risk using the penetration test evidence and treat the control as ineffective until fixed. Objective testing outweighs an unsupported self-assessment, so reported residual cyber risk must reflect actual control performance rather than management's opinion or an arbitrary average.

  1. AKeep the self-assessment rating because it reflects management's view
  2. BReassess residual risk using the test evidence and treat the control as ineffective until remediatedCorrect
  3. CAverage the two results and report the control as partially effective
  4. DExclude the test result because penetration tests are not part of formal assessment

Explanation

Independent, evidence-based testing should override unsupported self-assessment ratings. Residual risk must be restated reflecting the control's actual performance until remediation. Averaging is arbitrary, and ignoring tests undermines the framework.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions