FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?
The best approach combines sector-wide tools: oversight of critical third-party providers, coordinated incident response and testing, and information sharing. These address interconnected, shared vulnerabilities that firm-level controls or capital buffers alone cannot resolve.
- ARequiring each bank to raise its capital buffer and take no other action
- BRelying on market discipline alone to resolve cyber vulnerabilities
- CProhibiting all use of third-party technology providers
- DCombining sector-wide measures such as oversight of critical third parties, coordinated incident response and testing, and information sharingCorrect
Explanation
Because cyber risk is interconnected and shared, tools should operate at sector level: oversight of critical providers, coordinated response and testing, and information sharing. Capital alone cannot prevent disruption, and banning third parties is impractical.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A supervisor is concerned that many banks rely on the same cloud provider, so one outage could disrupt payments across the system at once. W…
- Which policy tool is most directly aimed at reducing systemic cyber risk arising from firms' reliance on critical third-party providers?
- A risk manager at a payments firm must set an impact tolerance for an important business service. Which statement best describes the purpose…
- A risk analyst compares two ways of modelling extreme cyber losses for the financial sector. Historical data are scarce and incidents are hi…
- A financial stability authority is designing a macroprudential framework for cyber risk. Which feature most distinguishes a macroprudential …
- A risk officer argues that digital resilience policy should move beyond capital buffers. Which reasoning best supports this view?