FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
Which information-sharing arrangement best supports macroprudential monitoring of digital risk?
Standardised, timely incident reporting to authorities that can be aggregated is best, because it reveals common vulnerabilities and emerging threats across the system. Secrecy or annual accounts give no system view, and broadcasting live vulnerabilities publicly would assist attackers.
- AEach firm keeps incident details confidential to protect its reputation
- BOnly annual financial statements are used to assess cyber exposure
- CStandardised, timely incident reporting to authorities that can be aggregated to identify common vulnerabilities and emerging threatsCorrect
- DPublic disclosure of every firm's technical vulnerabilities in real time
Explanation
Standardised and timely reporting lets authorities aggregate data and spot common vulnerabilities. Keeping details confidential or relying on annual accounts gives no system view, and publishing live vulnerabilities would help attackers and create risk.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- Which policy tool is most directly aimed at reducing systemic cyber risk arising from firms' reliance on critical third-party providers?
- A risk analyst compares two ways of modelling extreme cyber losses for the financial sector. Historical data are scarce and incidents are hi…
- Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?
- A financial stability authority is designing a macroprudential framework for cyber risk. Which feature most distinguishes a macroprudential …
- An asset manager considers a multi-cloud strategy, using two providers for its order management system, to reduce concentration risk. Which …
- A risk officer argues that digital resilience policy should move beyond capital buffers. Which reasoning best supports this view?