FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A mid-sized bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's primary responsibility under sound cyber risk governance practices?
The board's primary cyber governance responsibility is to approve the cyber risk appetite and strategy and oversee management's implementation. Technical tasks such as firewall configuration, forensics and choosing encryption algorithms are delegated to management and technology specialists rather than performed by the board.
- AApproving the cyber risk appetite and strategy and overseeing management's implementation of itCorrect
- BConfiguring firewall rules and intrusion detection thresholds
- CPerforming the technical forensic analysis after each security incident
- DSelecting the encryption algorithms used on customer databases
Explanation
The board sets direction: it approves the cyber risk appetite and strategy and holds senior management accountable for implementation. Technical configuration, forensics and algorithm selection are operational tasks delegated to management and specialist functions, so they are not the board's primary role.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- Which element is most important for a cyber-resilience strategy to be credible to the board and regulators?
- A bank's cyber risk team is building an inventory as the first step of its cyber risk identification process. Which activity best reflects t…
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…