FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alerts sat in an unmonitored queue and no one escalated them. Which control failure does this best illustrate?
This illustrates a failure in detection and response processes rather than tooling. The alerts were generated but nobody owned, triaged or escalated them, so the compromise continued for weeks. Clear ownership, monitoring staffing and escalation procedures are the missing controls.
- AWeakness in incident detection and response processes, not in toolingCorrect
- BInadequate encryption key length on stored data
- CInsufficient capital held against market risk
- DFailure of the bank's disaster recovery site to activate
Explanation
The technology detected the activity, but ineffective triage, ownership and escalation meant no response occurred. This is a process and governance failure. Encryption strength and market capital are unrelated, and no recovery site failure is described.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A payments firm sets a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for its card authorizatio…
- A bank estimates that a ransomware event has a 5% annual probability. If it occurs, expected loss is USD 20 million. A new offline-backup co…
- A bank's staff receive emails appearing to come from the CEO, urging an urgent wire transfer to a new supplier account and asking for secrec…
- After a cyber incident, a bank's post-incident review finds that the response playbook was sound but staff had never rehearsed it, causing d…
- A firm estimates that a data breach has a 10% annual probability. If it occurs, the loss is USD 20 million with probability 0.7 and USD 60 m…
- A bank's threat intelligence unit reports that a criminal group compromised a small software vendor and pushed a malicious update that was t…