Skip to content

FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

A supervisor wants a framework that reflects the view that cyber incidents at financial institutions can become systemic. Which policy approach is most consistent with this macroprudential perspective?

The macroprudential approach maps common dependencies, such as shared cloud providers and market infrastructures, and runs sector-wide scenario exercises on disruption of critical functions. This captures contagion and concentration that standalone institution reviews miss, while uniform vendor mandates would worsen concentration risk.

  1. AAssessing each institution's IT controls solely on a standalone basis, ignoring interconnections
  2. BFocusing exclusively on penalties after an incident is reported
  3. CMapping common dependencies such as shared cloud providers and market infrastructures, and running sector-wide scenario exercises on impairment of critical functionsCorrect
  4. DRequiring all banks to adopt identical technology vendors to simplify oversight

Explanation

A macroprudential view looks at interconnections and concentration, such as shared third-party providers and infrastructures, and tests sector-wide responses. Standalone assessment misses contagion, and forcing a single vendor would increase concentration risk.

Did you get it right without looking?

One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.

More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions