FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
Which policy tool is most directly aimed at reducing systemic cyber risk arising from firms' reliance on critical third-party providers?
Direct oversight and incident-reporting requirements for critical third-party providers, together with sector-wide cyber crisis exercises, target systemic cyber risk from shared dependencies. Capital buffers, mortgage limits and deposit insurance address credit-cycle or run risks, not operational concentration.
- ARaising the countercyclical capital buffer
- BDirect oversight and incident-reporting requirements for critical service providers, combined with sector-wide cyber stress or crisis exercisesCorrect
- CTightening loan-to-value limits on mortgages
- DIncreasing deposit insurance coverage limits
Explanation
Oversight of critical providers, incident reporting and joint sector exercises address common dependencies and coordination in a crisis. The countercyclical buffer, LTV limits and deposit insurance target credit-cycle or run risks rather than operational concentration.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A regional bank's board asks the risk function to explain how 'digital resilience' differs from traditional cybersecurity. Which statement b…
- A bank tests its resilience using a threat-led penetration test in which ethical hackers mimic real attacker tactics against live production…
- A reinsurer models a cyber catastrophe pool of 10 banks, each with a 2% annual probability of a vendor-driven loss of 50 million. Losses are…
- A bank defines an impact tolerance for its payments service: the maximum tolerable disruption is 4 hours. A scenario test shows the service …
- A financial stability authority is weighing capital buffers against operational-resilience requirements as a response to systemic cyber risk…
- A regulator considers using capital requirements as a tool against cyber risk. Which is the strongest argument that capital alone is an insu…