FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's cyber-resilience team is building its inventory of assets that support critical business functions. Which activity best reflects sound cyber risk identification under the range-of-practices approach?
The best practice is mapping information assets, their interconnections and dependencies to the business functions they support, and keeping that map current. Excluding third-party systems, ignoring software or updating only every few years leaves blind spots in the bank's view of its cyber risk.
- AMapping information assets, their interconnections and dependencies to the business functions they support, and keeping the map currentCorrect
- BLimiting the inventory to assets owned by the bank so that third-party systems are excluded from scope
- CCataloguing only hardware assets because software is covered by patch management
- DUpdating the asset inventory once every three years alongside the strategic plan
Explanation
Sound identification requires an up-to-date inventory of information assets and their interconnections, tied to the business functions they support. Excluding third-party systems leaves dependencies unseen, which is why that option is wrong. Ignoring software or updating rarely also leaves gaps.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- During a cyber risk self-assessment, a bank's business units rate their own control effectiveness as strong, yet internal audit finds repeat…
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…
- Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?