FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?
Cyber risk should be embedded in the enterprise risk taxonomy and assessed using the same framework as other operational risks, with the strategy aligned to business objectives. Treating it as an IT-only matter, reporting only after incidents, or funding it from discretionary budgets leaves it siloed and reactive.
- ATreating cyber risk as a purely technical issue managed solely within IT
- BReporting cyber risk to the board only after a significant incident
- CFunding cyber measures only from the IT department's discretionary budget
- DIncluding cyber risk in the enterprise risk taxonomy, assessing it with the same framework as other operational risks, and aligning the strategy with business objectivesCorrect
Explanation
Sound practice treats cyber as an enterprise-wide risk with business ownership, common taxonomy, assessment and reporting. The other options silo cyber within IT, make reporting reactive or make resourcing ad hoc.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are …
- A regulator-style review of a firm's cyber resilience finds that its incident response plan has never been tested against a scenario in whic…
- A bank segments its network so that the payments environment sits in a separate zone with tightly restricted traffic from the corporate netw…
- A mid-sized bank's cyber team receives a threat indicator from an industry sharing forum about a new phishing campaign. Which use of this in…
- A bank wants its cyber-resilience strategy to be integrated with enterprise risk management. Which approach best achieves this?
- Under a three-lines model for cyber risk, which activity is the proper role of the second line of defence?