Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?

Cyber risk should be embedded in the enterprise risk taxonomy and assessed using the same framework as other operational risks, with the strategy aligned to business objectives. Treating it as an IT-only matter, reporting only after incidents, or funding it from discretionary budgets leaves it siloed and reactive.

  1. ATreating cyber risk as a purely technical issue managed solely within IT
  2. BReporting cyber risk to the board only after a significant incident
  3. CFunding cyber measures only from the IT department's discretionary budget
  4. DIncluding cyber risk in the enterprise risk taxonomy, assessing it with the same framework as other operational risks, and aligning the strategy with business objectivesCorrect

Explanation

Sound practice treats cyber as an enterprise-wide risk with business ownership, common taxonomy, assessment and reporting. The other options silo cyber within IT, make reporting reactive or make resourcing ad hoc.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions