FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A regulator is designing a policy toolkit for digital resilience in the financial sector. It considers five tools: (1) mandatory incident reporting, (2) oversight of critical third-party providers, (3) threat-led penetration testing, (4) capital add-ons for operational risk, (5) cross-sector crisis simulation exercises. Which tool is most directly intended to address concentration risk from many institutions relying on the same cloud provider?
Direct oversight of critical third-party providers best addresses concentration risk from a shared cloud provider, because it targets the common dependency itself. Incident reporting, penetration testing and capital add-ons help with detection, defense or loss absorption but do not reduce the systemic reliance.
- AThreat-led penetration testing of each bank's own systems, because it exposes provider concentration
- BMandatory incident reporting, because it prevents provider outages
- COversight of critical third-party providers, because it targets the shared dependency directly rather than each institution separatelyCorrect
- DCapital add-ons, because capital eliminates the dependency on the provider
Explanation
Concentration in a shared provider is a systemic dependency that individual institutions cannot fully manage, so direct oversight of critical third parties is the tool aimed at it. Reporting aids detection, testing assesses defenses, and capital only absorbs losses without removing the dependency.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A regional bank suffers a ransomware attack and notices that attackers are using a technique that has not yet been publicly documented. The …
- A bank's critical payment processing runs on a single cloud service provider that also hosts the platforms of most of its peer banks in the …
- A major cloud provider used by many banks suffers a multi-day outage. Which crisis-coordination arrangement would most directly reduce the r…
- A regional bank's risk committee is debating why cyber risk can threaten financial stability and not just individual firms. Which feature of…
- During a severe cyber incident affecting a payment service provider used by many banks, authorities want a coordinated response. Which featu…
- A bank's board reviews its cloud outsourcing arrangement for a critical service. Which provision is most important for supporting operationa…