FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A firm's cyber risk team maps its framework to the standard functions of a cyber framework. It is building an inventory of critical business processes, systems and data flows and ranking them by importance to the firm. Which function does this activity primarily support?
This activity supports the Identify function. Cataloguing and ranking critical processes, systems and data flows establishes what must be protected and in what priority. Protect, Detect and Recover depend on that inventory but are different stages of the cyber framework.
- AIdentifyCorrect
- BProtect
- CDetect
- DRecover
Explanation
Inventorying and prioritizing assets, business processes and dependencies is the foundation of the Identify function. Protect applies safeguards, Detect finds events, and Recover restores services; none of those is primarily about building the asset and process inventory.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's cyber-resilience programme is reviewed. The review finds that the board approves a cyber risk appetite statement, but business line…
- A bank's cyber strategy states that it will tolerate no more than two high-severity incidents per year affecting critical services. Manageme…
- A bank's threat-intelligence function receives 400 indicator feeds from forums, vendors and peers. Analysts spend most time triaging low-val…
- A bank runs a critical service whose business-impact analysis shows losses of USD 2 million per hour of outage after the first 2 hours (no l…
- Which element is most important for a cyber-resilience strategy to be credible to the board and regulators?
- A bank wants its cyber risk assessment to reflect the threat landscape. Which approach is most consistent with good practice for incorporati…