Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank's cyber-resilience team is building its inventory of assets that support critical business functions. Which activity best reflects sound cyber risk identification under the range-of-practices approach?

The best practice is mapping information assets, their interconnections and dependencies to the business functions they support, and keeping that map current. Excluding third-party systems, ignoring software or updating only every few years leaves blind spots in the bank's view of its cyber risk.

  1. AMapping information assets, their interconnections and dependencies to the business functions they support, and keeping the map currentCorrect
  2. BLimiting the inventory to assets owned by the bank so that third-party systems are excluded from scope
  3. CCataloguing only hardware assets because software is covered by patch management
  4. DUpdating the asset inventory once every three years alongside the strategic plan

Explanation

Sound identification requires an up-to-date inventory of information assets and their interconnections, tied to the business functions they support. Excluding third-party systems leaves dependencies unseen, which is why that option is wrong. Ignoring software or updating rarely also leaves gaps.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions