Skip to content

FRM Part II · FRM Exam Part II · Case Study: Third-party Risk Management

Under the shared responsibility model for infrastructure-as-a-service cloud arrangements, which item generally remains the bank's responsibility?

The bank remains responsible for configuring access controls and encryption keys for its own workloads. The provider handles physical data-centre security, hardware and facilities, but customer-side misconfiguration stays with the bank under the shared responsibility model.

  1. APhysical security of the provider's data centres
  2. BConfiguration of access controls and encryption keys for the bank's own workloadsCorrect
  3. CMaintenance of the provider's underlying hypervisor hardware
  4. DPower and cooling of the provider's facilities

Explanation

The provider secures the underlying infrastructure, facilities and hardware, while the customer configures its own workloads, identity and access, and data protection. Misconfiguration by the customer is a common source of cloud breaches.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Third-party Risk Management shows your real accuracy, how long you take and where you lose marks.

More Case Study: Third-party Risk Management questions