FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
After a significant cyber incident is contained, a firm's CISO proposes a post-incident review. Which outcome of the review is most consistent with a cyber-resilience framework that evolves over time?
The review should feed root-cause findings back into controls, response playbooks and testing scenarios. Cyber-resilience depends on continuous learning and adaptation. Closing the record at restoration, assigning blame, or hiding findings within one team prevents the framework from improving after the incident.
- AClosing the incident record once systems are restored to service
- BAssigning individual blame to the staff member who clicked the malicious link
- CFeeding root-cause findings into updates of controls, response playbooks, and testing scenariosCorrect
- DKeeping the findings within the security team to limit reputational exposure
Explanation
Resilience practices stress learning from incidents and tests, and then adapting the framework, playbooks and scenarios. Closing the record at restoration forfeits the lessons. Blame and secrecy undermine learning and sharing.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- After a destructive malware attack, a bank's incident team wants to restore services from backups. Which practice best supports cyber-resili…
- A regional bank classifies its cyber defences into functions. Its security team installs firewalls and multi-factor authentication, runs a s…
- A firm runs annual red-team exercises, and the last three produced the same finding: slow escalation of suspected incidents to senior manage…
- Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are …
- A regulator-style review of a firm's cyber resilience finds that its incident response plan has never been tested against a scenario in whic…
- A bank segments its network so that the payments environment sits in a separate zone with tightly restricted traffic from the corporate netw…