FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
Which statement best describes why a firm's cyber-resilience framework should be designed to evolve over time?
A framework must evolve because threats, technology and business models keep changing. Regular reassessment using threat intelligence, testing results and incident lessons keeps defences relevant. Freezing it, updating only on new regulation, or waiting for the firm's own breach leaves it exposed.
- AThreats, technology and business models change, so frameworks must be regularly reassessed against new intelligence, test results and incident lessonsCorrect
- BOnce approved by the board, a framework should remain fixed to maintain audit consistency
- CEvolution is needed only when a regulator issues a new rule
- DChanges should be made only after a successful attack on the firm itself
Explanation
Cyber threats and the firm's environment shift constantly, so frameworks must be continuously updated using intelligence, testing and lessons learned, not just regulatory prompts or own breaches.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- After a destructive malware attack, a bank's incident team wants to restore services from backups. Which practice best supports cyber-resili…
- A regional bank classifies its cyber defences into functions. Its security team installs firewalls and multi-factor authentication, runs a s…
- Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are …
- A regulator-style review of a firm's cyber resilience finds that its incident response plan has never been tested against a scenario in whic…
- A bank segments its network so that the payments environment sits in a separate zone with tightly restricted traffic from the corporate netw…
- A mid-sized bank's cyber team receives a threat indicator from an industry sharing forum about a new phishing campaign. Which use of this in…