FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's cyber-resilience programme is reviewed. The review finds that the board approves a cyber risk appetite statement, but business lines set their own recovery time targets for critical services, many of which exceed the tolerance for disruption set at enterprise level. Which weakness is most directly indicated?
The weakness is misalignment between enterprise-level risk tolerance and operational recovery objectives. When business lines set recovery times longer than the board's tolerance for disruption, the cyber risk appetite has not been cascaded into practice, so governance does not actually control the firm's exposure to disruption.
- AInadequate encryption of data in transit
- BA lack of alignment between enterprise-level risk tolerance and operational recovery objectivesCorrect
- CExcessive investment in intrusion detection tools
- DOverreliance on a single external auditor
Explanation
Recovery targets that exceed the board's tolerance for disruption show that governance and risk appetite are not cascaded into operational objectives. Nothing in the facts concerns encryption, detection tooling or audit reliance. Effective frameworks tie recovery objectives to the tolerance set at the top.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's risk committee notes that cyber risk differs from many other operational risks. Which feature most strongly supports treating cyber…
- A firm defines its cyber risk appetite as tolerating no more than 4 hours of unavailability for its payments platform. Testing shows recover…
- A bank's cyber team joins an industry forum in which members exchange indicators of compromise and attack techniques shortly after detecting…
- A firm runs annual red-team exercises, and the last three produced the same finding: slow escalation of suspected incidents to senior manage…
- After a destructive malware attack, a bank's incident team wants to restore services from backups. Which practice best supports cyber-resili…
- A regional bank classifies its cyber defences into functions. Its security team installs firewalls and multi-factor authentication, runs a s…