FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
During a cyber risk self-assessment, a bank's business units rate their own control effectiveness as strong, yet internal audit finds repeated unresolved access-management findings. What is the most appropriate response by the second line?
The second line should independently challenge the ratings and calibrate them using objective evidence such as audit findings, control testing and incident data. Self-assessments tend to be optimistic, so accepting them, removing the scope or relying on one vulnerability count would leave known access-management weaknesses unreflected.
- AAccept the self-assessments since business units know their processes best
- BChallenge the ratings independently, using audit findings, testing results and incident data to calibrate the assessmentCorrect
- CRemove access management from the assessment scope to avoid conflict
- DReplace all qualitative assessment with a single vulnerability count
Explanation
Self-assessments are subject to optimism bias and need independent challenge, using objective evidence such as audit findings, control testing and incidents. Accepting them or dropping the scope leaves known weaknesses unreflected, and a single count oversimplifies.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's board is reviewing its cyber-resilience framework based on the range of practices observed across large financial institutions. Whi…
- A bank's board sets a cyber risk appetite statement. Which of the following is the most appropriate form of the statement for it to be effec…
- After a significant cyber incident is contained, a firm's CISO proposes a post-incident review. Which outcome of the review is most consiste…
- After a destructive cyberattack, a bank's recovery plan relies on restoring from backups held on the same network as production systems. Whi…
- A global bank's cyber strategy is aligned with the three lines model. The first-line technology team has reported that all controls tested a…
- A bank is deciding how to govern cyber risk. Which arrangement is most consistent with sound cyber-resilience practice?