FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A regulator-style review of a firm's cyber resilience finds that its incident response plan has never been tested against a scenario in which a key third-party service provider is unavailable. Which action would best address this gap?
The firm should run scenario-based exercises that include severe but plausible third-party outages and use the lessons to update its response plan. Insurance, removing the risk from the register or merely reviewing documents does not demonstrate actual response and recovery capability.
- ARun scenario-based exercises, including severe but plausible third-party disruption, and feed lessons into the planCorrect
- BIncrease the cyber insurance limit and stop further testing
- CRemove the third-party dependency from the risk register
- DLimit testing to annual review of the plan document by the IT team
Explanation
Resilience requires testing response and recovery against severe but plausible scenarios, including dependencies on third parties, and updating plans from results. Insurance does not replace capability, deleting the risk hides it, and document review is not testing.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's cyber-resilience programme is reviewed. The review finds that the board approves a cyber risk appetite statement, but business line…
- A bank's cyber strategy states that it will tolerate no more than two high-severity incidents per year affecting critical services. Manageme…
- A bank's threat-intelligence function receives 400 indicator feeds from forums, vendors and peers. Analysts spend most time triaging low-val…
- A bank runs a critical service whose business-impact analysis shows losses of USD 2 million per hour of outage after the first 2 hours (no l…
- A bank wants its cyber risk assessment to reflect the threat landscape. Which approach is most consistent with good practice for incorporati…
- A bank scores four cyber scenarios by annual likelihood and loss per event. Expected annual loss = likelihood x loss. Scenario A: 0.50 x $1.…