Skip to content

FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector

Which policy approach best addresses the systemic nature of cyber risk, as opposed to purely firm-level controls?

The best approach combines sector-wide tools: oversight of critical third-party providers, coordinated incident response and testing, and information sharing. These address interconnected, shared vulnerabilities that firm-level controls or capital buffers alone cannot resolve.

  1. ARequiring each bank to raise its capital buffer and take no other action
  2. BRelying on market discipline alone to resolve cyber vulnerabilities
  3. CProhibiting all use of third-party technology providers
  4. DCombining sector-wide measures such as oversight of critical third parties, coordinated incident response and testing, and information sharingCorrect

Explanation

Because cyber risk is interconnected and shared, tools should operate at sector level: oversight of critical providers, coordinated response and testing, and information sharing. Capital alone cannot prevent disruption, and banning third parties is impractical.

Did you get it right without looking?

One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.

More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions