Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

Which statement best describes why a firm's cyber-resilience framework should be designed to evolve over time?

A framework must evolve because threats, technology and business models keep changing. Regular reassessment using threat intelligence, testing results and incident lessons keeps defences relevant. Freezing it, updating only on new regulation, or waiting for the firm's own breach leaves it exposed.

  1. AThreats, technology and business models change, so frameworks must be regularly reassessed against new intelligence, test results and incident lessonsCorrect
  2. BOnce approved by the board, a framework should remain fixed to maintain audit consistency
  3. CEvolution is needed only when a regulator issues a new rule
  4. DChanges should be made only after a successful attack on the firm itself

Explanation

Cyber threats and the firm's environment shift constantly, so frameworks must be continuously updated using intelligence, testing and lessons learned, not just regulatory prompts or own breaches.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions