FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are sometimes deprioritised to meet project launch dates. Which governance change most directly addresses this conflict of interest in line with sound cyber-resilience practice?
Giving the CISO an independent reporting line to senior management or the board addresses the conflict, because security findings can then be escalated without being suppressed by the IT head whose delivery targets compete with them. Testing, training or outsourcing leave the flawed reporting structure unchanged.
- AIncrease the number of penetration tests performed each year
- BGive the CISO an independent reporting line to senior management or the board, separate from IT deliveryCorrect
- CTransfer all security tooling to an external vendor
- DRequire IT staff to complete additional annual security training
Explanation
The problem is structural: the security function's escalation is controlled by a party with competing incentives. Independence of the cyber/information security function, with direct access to senior management or the board, resolves this. More tests, training or outsourcing do not change who can override findings.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A mid-sized bank hesitates to share cyber incident details with peers, citing concerns about confidentiality and reputational damage. Which …
- A bank's board is reviewing its cyber strategy. Management proposes to focus only on preventing every intrusion at the perimeter. Which stat…
- A bank's cyber risk officer reviews the access management programme for its core payment platform. Several system administrators hold perman…
- Which approach best strengthens a bank's identification of emerging cyber threats?
- A bank's cyber-resilience team is building its inventory of assets that support critical business functions. Which activity best reflects so…
- A bank's security team wants to reduce the damage an attacker can do if a single employee's credentials are stolen. Which protective control…