FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A supervisor wants a framework that reflects the view that cyber incidents at financial institutions can become systemic. Which policy approach is most consistent with this macroprudential perspective?
The macroprudential approach maps common dependencies, such as shared cloud providers and market infrastructures, and runs sector-wide scenario exercises on disruption of critical functions. This captures contagion and concentration that standalone institution reviews miss, while uniform vendor mandates would worsen concentration risk.
- AAssessing each institution's IT controls solely on a standalone basis, ignoring interconnections
- BFocusing exclusively on penalties after an incident is reported
- CMapping common dependencies such as shared cloud providers and market infrastructures, and running sector-wide scenario exercises on impairment of critical functionsCorrect
- DRequiring all banks to adopt identical technology vendors to simplify oversight
Explanation
A macroprudential view looks at interconnections and concentration, such as shared third-party providers and infrastructures, and tests sector-wide responses. Standalone assessment misses contagion, and forcing a single vendor would increase concentration risk.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- An authority wants early warning of building systemic digital risk. Which indicator would be most useful for a macroprudential monitoring fr…
- A supervisor wants to reduce systemic risk from financial institutions' reliance on a few large cloud and ICT providers. Which policy tool m…
- During a severe cyber incident affecting a payment service provider used by many banks, authorities in several jurisdictions need to respond…
- A regional bank runs its core payments platform, fraud monitoring and customer app on a single cloud provider. The risk team notes that an o…
- A regional bank migrates its core payment processing to a single cloud provider to cut costs. Which feature of this change most directly rai…
- A regional bank's security team detects a new ransomware variant targeting payment systems. It wants to alert peers quickly without exposing…