Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A firm's cyber risk team maps its framework to the standard functions of a cyber framework. It is building an inventory of critical business processes, systems and data flows and ranking them by importance to the firm. Which function does this activity primarily support?

This activity supports the Identify function. Cataloguing and ranking critical processes, systems and data flows establishes what must be protected and in what priority. Protect, Detect and Recover depend on that inventory but are different stages of the cyber framework.

  1. AIdentifyCorrect
  2. BProtect
  3. CDetect
  4. DRecover

Explanation

Inventorying and prioritizing assets, business processes and dependencies is the foundation of the Identify function. Protect applies safeguards, Detect finds events, and Recover restores services; none of those is primarily about building the asset and process inventory.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions