Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A mid-sized bank's cyber team receives a threat indicator from an industry sharing forum about a new phishing campaign. Which use of this information best reflects the purpose of participating in cyber information-sharing arrangements?

The best use is to apply the shared indicator to strengthen detection and defenses before the campaign hits the bank. Sharing arrangements exist so firms learn from peers' experience and act early. They complement internal monitoring and do not wait for regulators or require premature public disclosure.

  1. APublishing the bank's own incident details to customers before investigating the cause
  2. BUsing the indicator to strengthen detection and defenses before the campaign reaches the bankCorrect
  3. CReplacing the bank's internal monitoring with the forum's alerts
  4. DDelaying any response until regulators confirm the threat

Explanation

Information sharing lets firms learn from others' experience and improve defenses proactively. It supplements, not replaces, internal monitoring, and does not require waiting for regulators. Public disclosure before investigation is not the aim of sharing arrangements.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions