FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A regional bank's risk committee wants a control framework that arranges cyber controls in sequence so that the failure of one control does not leave the asset exposed. The CISO proposes combining perimeter firewalls, network segmentation, endpoint detection and multi-factor authentication on critical systems. Which design principle does this proposal best illustrate?
The proposal illustrates defense in depth: multiple independent layers of controls, such as firewalls, segmentation, endpoint detection and multi-factor authentication, so that if one control fails others still protect the asset. It is not segregation of duties, least privilege or risk transfer.
- ADefense in depthCorrect
- BSegregation of duties
- CRisk transfer
- DLeast privilege
Explanation
Layering several independent preventive and detective controls so that a single failure does not expose the asset is defense in depth. Segregation of duties separates incompatible tasks among people, and least privilege limits access rights. Risk transfer concerns insurance or contracts, not control layering.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- During a cyber incident, a bank's legal and communications teams disagree over when to notify customers and regulators. Which feature of a m…
- A bank assesses a phishing-related risk scenario. Expected frequency without controls is 10 successful attacks per year, each with an averag…
- A bank estimates that a ransomware outage of its trading platform would cost USD 2.0 million per hour in lost revenue for the first 3 hours,…
- An analyst at an asset manager discovers that an unauthorised insider changed the settlement account numbers on several pending trade instru…
- A risk manager is reviewing the bank's exposure to a malicious insider, such as a database administrator with privileged access. Compared wi…
- A bank experienced a data breach in which attackers exfiltrated customer records over several months. The investigation shows that a known v…