FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
After a ransomware incident that was contained within hours, a bank's CISO wants the event to improve long-term resilience. Which action best reflects a mature post-incident learning process?
The best practice is a root-cause review whose findings update controls, scenarios and training, with remediation tracked to completion. Merely restoring systems, restricting the review to a few staff, or waiting for the annual assessment fails to turn the incident into lasting improvement.
- AClose the incident ticket once systems are restored and report only the recovery time to the board
- BConduct a root-cause review, feed findings into control, scenario and training updates, and track remediation actions to completionCorrect
- CLimit the review to the IT staff directly involved to avoid disclosing weaknesses
- DWait for the next scheduled annual risk assessment to consider any lessons
Explanation
Mature learning goes beyond restoration: root cause analysis, updating controls, scenarios and training, and tracking actions. Narrow or deferred reviews let the same weaknesses persist.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…
- Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?
- A bank's board is reviewing how its approach to cyber risk should differ from a traditional information-security programme. Which statement …