FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A regional bank's board asks the risk function to explain how 'digital resilience' differs from traditional cybersecurity as discussed in policy literature on financial stability. Which statement best captures the distinction?
Digital resilience is the capacity to prevent, withstand, respond to and recover from digital disruptions while keeping critical services running. It is broader than cybersecurity, which centres on protection, because resilience assumes incidents will happen and emphasises continuity and recovery.
- ADigital resilience focuses only on preventing intrusions at the network perimeter, while cybersecurity covers recovery
- BDigital resilience concerns only the bank's own IT systems, excluding any third-party providers
- CDigital resilience is a regulatory term for data privacy compliance and has no link to operational continuity
- DDigital resilience covers the ability to prevent, withstand, respond to and recover from digital disruptions, extending beyond protection to continuity of critical servicesCorrect
Explanation
Digital resilience is broader than cybersecurity: it assumes disruptions will occur and stresses the capacity to absorb, respond and recover while maintaining critical services. The perimeter-only option describes a narrow protection view and reverses the roles.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A supervisor is designing a framework to limit systemic risk from the concentration of many banks on a single cloud provider. Which policy t…
- A supervisor argues that digitalisation makes operational disruptions a potential source of systemic risk, not only a firm-level concern. Wh…
- A regional bank suffers a ransomware attack and notices that attackers are using a technique that has not yet been publicly documented. The …
- A bank's critical payment processing runs on a single cloud service provider that also hosts the platforms of most of its peer banks in the …
- A major cloud provider used by many banks suffers a multi-day outage. Which crisis-coordination arrangement would most directly reduce the r…
- A regional bank's risk committee is debating why cyber risk can threaten financial stability and not just individual firms. Which feature of…