FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's cyber control self-assessment rates a key control as effective, but a penetration test shows an attacker could bypass it in under an hour. Which action best aligns with sound cyber risk management?
The bank should reassess residual risk using the penetration test evidence and treat the control as ineffective until fixed. Objective testing outweighs an unsupported self-assessment, so reported residual cyber risk must reflect actual control performance rather than management's opinion or an arbitrary average.
- AKeep the self-assessment rating because it reflects management's view
- BReassess residual risk using the test evidence and treat the control as ineffective until remediatedCorrect
- CAverage the two results and report the control as partially effective
- DExclude the test result because penetration tests are not part of formal assessment
Explanation
Independent, evidence-based testing should override unsupported self-assessment ratings. Residual risk must be restated reflecting the control's actual performance until remediation. Averaging is arbitrary, and ignoring tests undermines the framework.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A retail bank discovers that attackers entered through a vendor's remote-access credentials, moved laterally across its flat internal networ…
- During a cyber incident, a bank's legal and communications teams disagree over when to notify customers and regulators. Which feature of a m…
- A bank assesses a phishing-related risk scenario. Expected frequency without controls is 10 successful attacks per year, each with an averag…
- A bank estimates that a ransomware outage of its trading platform would cost USD 2.0 million per hour in lost revenue for the first 3 hours,…
- A bank estimates that a phishing-led breach has an annual probability of 8% and a loss of USD 25 million if it occurs. A proposed control pa…
- A bank's board wants key risk indicators (KRIs) to give early warning of deteriorating cyber control health. Which of the following is the b…