Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank's cyber-resilience programme is reviewed. The review finds that the board approves a cyber risk appetite statement, but business lines set their own recovery time targets for critical services, many of which exceed the tolerance for disruption set at enterprise level. Which weakness is most directly indicated?

The weakness is misalignment between enterprise-level risk tolerance and operational recovery objectives. When business lines set recovery times longer than the board's tolerance for disruption, the cyber risk appetite has not been cascaded into practice, so governance does not actually control the firm's exposure to disruption.

  1. AInadequate encryption of data in transit
  2. BA lack of alignment between enterprise-level risk tolerance and operational recovery objectivesCorrect
  3. CExcessive investment in intrusion detection tools
  4. DOverreliance on a single external auditor

Explanation

Recovery targets that exceed the board's tolerance for disruption show that governance and risk appetite are not cascaded into operational objectives. Nothing in the facts concerns encryption, detection tooling or audit reliance. Effective frameworks tie recovery objectives to the tolerance set at the top.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions