FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Which element is most important for a cyber-resilience strategy to be credible to the board and regulators?
A credible strategy defines risk appetite with measurable metrics, assigns clear ownership, and aligns resources to critical business services. Promising zero incidents is unrealistic, vendor lists are not strategy, and a policy never revisited cannot keep pace with changing cyber threats.
- AA defined risk appetite with measurable metrics, assigned ownership, and resources aligned to critical business servicesCorrect
- BA commitment that no cyber incident will ever occur
- CA list of security vendors under contract
- DA policy approved once and not revisited unless a breach occurs
Explanation
Credible strategy needs measurable appetite, clear ownership and adequate resources tied to critical services, and it should be reviewed regularly. Promising zero incidents is unrealistic, vendor lists are not strategy, and static policies fail to adapt to evolving threats.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…
- Which approach to cyber strategy best reflects the practice of integrating cyber risk into the bank's broader enterprise risk management?
- A bank's board is reviewing how its approach to cyber risk should differ from a traditional information-security programme. Which statement …