FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's cyber risk team uses a three-lines model. An internal audit function reports that the IT security team both designs access controls and independently tests whether those controls work, with no separate review. Which finding is most appropriate?
The key finding is that independent assurance is lacking. The same team designs and tests the access controls, so no separate line challenges or validates their effectiveness. A three-lines model requires independent oversight and testing, regardless of how expert the security team is.
- AThe framework is sound because the team with most expertise performs testing
- BThe first line should be replaced by external consultants for all controls
- CIndependent assurance is lacking because control ownership and testing sit within the same lineCorrect
- DTesting should be removed since controls are already designed by experts
Explanation
Under a three-lines model, control owners (first line) should be challenged by independent oversight (second line) and assurance (third line). When the designers also test their own controls, independence is missing, so effectiveness assurance is weak. Expertise does not substitute for independence.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank's threat intelligence unit reports that a criminal group compromised a small software vendor and pushed a malicious update that was t…
- After an incident, a bank's investigation finds that a former employee's account was never deactivated and was used to download client files…
- A bank classifies its critical information assets and applies controls based on that classification. What is the primary risk management pur…
- A bank assesses an information asset's risk using inherent risk of 80 (on a 0-100 scale of loss exposure before controls). Preventive contro…
- A bank classifies four threat scenarios by actor motivation to prioritize controls. Which pairing of actor and primary motivation is most ac…
- A bank's security team discovers that a critical vulnerability patch was released by the software vendor four months ago but was never appli…