FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A regulator asks a bank how its cyber-resilience approach keeps pace with changing threats. Which practice would provide the strongest evidence of an evolving framework?
Regular review of threats, test results and incidents that leads to documented updates of strategy and controls is the strongest evidence. It shows a continuous learning cycle. A static strategy, budget increases without reprioritization, or vendor certificates do not demonstrate adaptation to evolving threats.
- AA static five-year cyber strategy approved once by the board
- BRegular review of the threat landscape, testing results, and incidents, leading to documented updates of strategy and controlsCorrect
- CA large increase in the security budget with no change in priorities
- DReliance on the vendor's annual certification of its security products
Explanation
Evolution is shown by a repeated cycle of monitoring threats, testing, and learning from incidents, then documenting adjustments. A static strategy, spending without direction, or vendor certification does not show adaptation to the firm's own risks.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A mid-sized bank hesitates to share cyber incident details with peers, citing concerns about confidentiality and reputational damage. Which …
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A firm runs annual red-team exercises, and the last three produced the same finding: slow escalation of suspected incidents to senior manage…
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…