FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A bank's risk committee reviews a cyber incident scenario. The bank's critical payment service has a maximum tolerable outage of 4 hours. Testing shows recovery takes 6 hours when the main vendor is unavailable. Which conclusion and action are most consistent with a digital resilience approach?
The bank is outside its impact tolerance, since recovery takes 6 hours against a 4-hour limit. It should remediate through measures like alternative providers or quicker recovery, or escalate the gap, rather than relaxing the tolerance or relying on insurance.
- AResilience is adequate because recovery eventually happens, so no action is needed
- BReduce the tolerance to 6 hours to match current capability
- CThe bank is outside its impact tolerance and should invest in remediation such as alternative providers or faster recovery, or escalate the gapCorrect
- DTransfer the entire risk to insurance, which removes the need to meet the tolerance
Explanation
Impact tolerance is set based on harm to customers and stability, and then capability is tested against it. A 6-hour recovery exceeds the 4-hour tolerance by 2 hours, so remediation is needed. Loosening the tolerance to fit capability or relying on insurance does not restore the service.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- Which policy tool is most directly aimed at reducing systemic cyber risk arising from firms' reliance on critical third-party providers?
- A risk analyst compares two ways of modelling extreme cyber losses for the financial sector. Historical data are scarce and incidents are hi…
- Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?
- A financial stability authority is designing a macroprudential framework for cyber risk. Which feature most distinguishes a macroprudential …
- A risk officer argues that digital resilience policy should move beyond capital buffers. Which reasoning best supports this view?
- A regulator is designing a framework for operational resilience across the financial sector. Which design choice best reflects a sound macro…