Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A mid-sized bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's primary responsibility under sound cyber risk governance practices?

The board's primary cyber governance responsibility is to approve the cyber risk appetite and strategy and oversee management's implementation. Technical tasks such as firewall configuration, forensics and choosing encryption algorithms are delegated to management and technology specialists rather than performed by the board.

  1. AApproving the cyber risk appetite and strategy and overseeing management's implementation of itCorrect
  2. BConfiguring firewall rules and intrusion detection thresholds
  3. CPerforming the technical forensic analysis after each security incident
  4. DSelecting the encryption algorithms used on customer databases

Explanation

The board sets direction: it approves the cyber risk appetite and strategy and holds senior management accountable for implementation. Technical configuration, forensics and algorithm selection are operational tasks delegated to management and specialist functions, so they are not the board's primary role.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions