Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A regional bank's risk committee wants a control framework that arranges cyber controls in sequence so that the failure of one control does not leave the asset exposed. The CISO proposes combining perimeter firewalls, network segmentation, endpoint detection and multi-factor authentication on critical systems. Which design principle does this proposal best illustrate?

The proposal illustrates defense in depth: multiple independent layers of controls, such as firewalls, segmentation, endpoint detection and multi-factor authentication, so that if one control fails others still protect the asset. It is not segregation of duties, least privilege or risk transfer.

  1. ADefense in depthCorrect
  2. BSegregation of duties
  3. CRisk transfer
  4. DLeast privilege

Explanation

Layering several independent preventive and detective controls so that a single failure does not expose the asset is defense in depth. Segregation of duties separates incompatible tasks among people, and least privilege limits access rights. Risk transfer concerns insurance or contracts, not control layering.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions