CRO Cybersecurity Risk Management 2 — Questions and Answers
Question 1: A Chief Risk Officer is reviewing the organization's cyber risk appetite statement. Which element is most critical to include when defining cyber risk tolerance thresholds?
- The number of IT staff available for incident response
- Quantified maximum acceptable loss exposure tied to business objectives (Correct answer)
- The age of existing firewall infrastructure
- The number of security certifications held by employees
Correct answer: Quantified maximum acceptable loss exposure tied to business objectives
Cyber risk tolerance thresholds must be expressed as quantified maximum acceptable loss levels aligned with strategic business objectives to be operationally meaningful.
Question 2: An organization experiences a ransomware attack that encrypts critical data. Under the NIST Cybersecurity Framework, which function should have been used to establish offline backups as a control?
- Identify
- Protect
- Detect
- Recover (Correct answer)
Correct answer: Recover
The Recover function encompasses resilience planning including backup and restoration capabilities that enable return to normal operations after an incident.
Question 3: Which metric best enables a CRO to communicate cybersecurity risk to the board in financial terms?
- Mean time to detect (MTTD)
- Number of vulnerabilities patched per quarter
- Annualized Loss Expectancy (ALE) (Correct answer)
- Percentage of endpoints with antivirus installed
Correct answer: Annualized Loss Expectancy (ALE)
Annualized Loss Expectancy (ALE) expresses cyber risk as a dollar figure, making it directly comparable to other financial risks the board evaluates.
Question 4: A third-party vendor with access to sensitive customer data suffers a breach. What is the CRO's primary obligation under most US state data breach notification laws?
- Notify only the vendor's regulators
- Assess whether the organization must notify affected individuals and regulators (Correct answer)
- Immediately terminate the vendor contract
- Conduct an internal audit of all vendor relationships
Correct answer: Assess whether the organization must notify affected individuals and regulators
The organization that owns the customer data retains legal notification obligations regardless of where the breach originated, requiring assessment of applicable state law requirements.
Question 5: Which approach to cyber risk quantification assigns probability distributions to loss scenarios rather than single-point estimates?
- Qualitative heat map scoring
- FAIR (Factor Analysis of Information Risk) Monte Carlo analysis (Correct answer)
- CVSS vulnerability scoring
- Delphi method consensus ranking
Correct answer: FAIR (Factor Analysis of Information Risk) Monte Carlo analysis
FAIR combined with Monte Carlo simulation generates probability distributions across a range of loss outcomes, providing more statistically robust risk estimates than single-point values.
Question 6: An insider threat program identifies an employee downloading large volumes of intellectual property. Which risk treatment option is most appropriate as an immediate response?
- Accept the risk and monitor for 90 days
- Transfer the risk to a cyber insurance policy
- Mitigate by revoking access and initiating investigation (Correct answer)
- Avoid the risk by terminating all internal data transfers
Correct answer: Mitigate by revoking access and initiating investigation
Immediate access revocation stops ongoing data exfiltration while a formal investigation preserves evidence and determines the appropriate long-term response.
Question 7: The concept of 'defense in depth' in cybersecurity risk management refers to which risk control strategy?
- Relying on a single, highly effective perimeter firewall
- Layering multiple independent security controls so failure of one does not compromise the system (Correct answer)
- Prioritizing detection over prevention controls
- Outsourcing all security functions to a managed security service provider
Correct answer: Layering multiple independent security controls so failure of one does not compromise the system
Defense in depth implements multiple independent layers of security so that a single control failure does not result in complete system compromise.
A Chief Risk Officer is reviewing the organization's cyber risk appetite statement.
Which element is most critical to include when defining cyber risk tolerance thresholds?