FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A firm relies on a cloud provider that itself uses several subcontractors. In the cyber risk identification process, what is the most appropriate treatment of this arrangement?
The firm should map the cloud provider and its material subcontractors as dependencies and assess their cyber risk within its own framework, because accountability for critical services cannot be contracted away. Excluding them or assessing only finances leaves key exposures unidentified.
- AInclude the provider and material subcontractors in the dependency mapping and assess their cyber risk as part of the firm's own riskCorrect
- BExclude it because responsibility transfers fully to the provider under the contract
- CAssess only the provider's financial strength
- DReview it only if the provider reports a breach
Explanation
The firm remains accountable for its critical services even when outsourced, so third and fourth parties must be mapped and assessed. Contract terms do not remove the firm's operational and regulatory risk, and financial strength alone says nothing about cyber controls.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's last year of vulnerability scanning shows 400 critical vulnerabilities found; 300 were remediated within the 30-day policy window, …
- A bank has three critical services. Annualised expected losses from cyber events are: Service A USD 2.0m with inherent risk 10m, Service B U…
- A bank's cyber-resilience framework groups its controls into identification, protection, detection, response and recovery, and sustained lea…
- Under a three-lines model for cyber risk, which activity is the proper role of the second line of defence?
- A bank's business continuity plan was last tested by a tabletop walkthrough that assumed the failure of a single data center. The risk commi…
- A bank's board is reviewing its cyber-resilience framework based on the range of practices observed across large financial institutions. Whi…