Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A firm relies on a cloud provider that itself uses several subcontractors. In the cyber risk identification process, what is the most appropriate treatment of this arrangement?

The firm should map the cloud provider and its material subcontractors as dependencies and assess their cyber risk within its own framework, because accountability for critical services cannot be contracted away. Excluding them or assessing only finances leaves key exposures unidentified.

  1. AInclude the provider and material subcontractors in the dependency mapping and assess their cyber risk as part of the firm's own riskCorrect
  2. BExclude it because responsibility transfers fully to the provider under the contract
  3. CAssess only the provider's financial strength
  4. DReview it only if the provider reports a breach

Explanation

The firm remains accountable for its critical services even when outsourced, so third and fourth parties must be mapped and assessed. Contract terms do not remove the firm's operational and regulatory risk, and financial strength alone says nothing about cyber controls.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions