FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A risk officer argues that digital resilience policy should move beyond capital buffers. Which reasoning best supports this view?
Capital absorbs financial losses but cannot restore disrupted services or confidence, so policy also needs tools like recovery time objectives, resilience testing and incident response to keep critical functions operating. Capital alone is an incomplete defense against operational and cyber shocks that threaten stability.
- ACyber losses are always small, so capital is unnecessary
- BCapital absorbs losses but does not by itself restore services, so tools such as operational recovery requirements, testing and incident response are needed to keep critical functions runningCorrect
- CCapital requirements cannot be applied to any bank
- DResilience tools only matter for non-bank firms
Explanation
A cyber event's main stability harm is service disruption and loss of trust, which capital cannot fix directly. Hence complementary tools such as recovery objectives, scenario testing and incident response are emphasized. The other statements are false or overbroad.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- Which policy tool is most directly aimed at reducing systemic cyber risk arising from firms' reliance on critical third-party providers?
- A risk manager at a payments firm must set an impact tolerance for an important business service. Which statement best describes the purpose…
- A risk analyst compares two ways of modelling extreme cyber losses for the financial sector. Historical data are scarce and incidents are hi…
- Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?
- A financial stability authority is designing a macroprudential framework for cyber risk. Which feature most distinguishes a macroprudential …
- A supervisor reviewing digital resilience notes that a cyber incident at one bank could spread to others. Which transmission channel is MOST…