FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Under a three-lines model for cyber risk, which activity is the proper role of the second line of defence?
The second line independently challenges and monitors the first line's cyber risk management and reports on it to senior management. Running controls and patching belongs to the first line, while independent assurance to the audit committee is the internal audit's third-line role.
- AIndependently challenging and monitoring the first line's cyber risk management and reporting on it to senior managementCorrect
- BOperating daily access controls and patching systems
- CProviding independent assurance to the audit committee through audits of the whole framework
- DDeveloping and coding the bank's applications
Explanation
The second line (risk and compliance) sets policy, monitors and challenges the first line. Operating controls and patching is first-line work, and independent audit assurance to the audit committee is the third line's role.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- After a ransomware attack encrypts a payment processor's production systems, the firm restores from backups that were stored on the same net…
- A bank's cyber risk team is building an inventory as the first step of its cyber risk identification process. Which activity best reflects t…
- A bank runs a cyber risk assessment and finds that a customer-facing payment application has a high-severity vulnerability. Threat intellige…
- A bank backs up its core ledger to an offsite site every 4 hours. A ransomware attack corrupts the primary system 3 hours after the last bac…
- A bank performs a cyber risk assessment of its payments platform. Inherent risk is rated 'High'. Existing controls are assessed as reducing …
- During a cyber incident, a bank's crisis team debates when to notify regulators and customers. Which practice is most consistent with sound …