QuestionQ422

Information Security Risk Management

A financial institution's management accepted an operational risk that consequently resulted in the temporary deactivation of a critical monitoring process. Which of the following should be the information security manager's GREATEST concern in this situation?

  • A Deviation from risk management best practices
  • B Impact on the risk culture
  • C Inability to determine short-term impact
  • D Impact on compliance risk
Explanation

Financial institutions must maintain monitoring and control processes that support compliance with applicable regulatory obligations. Temporarily deactivating a critical monitoring process can leave violations undetected and undermine required ongoing compliance controls, creating immediate regulatory, legal, financial, and reputational exposure. Risk acceptance does not eliminate those obligations; banks are expected to monitor operational risk and material exposures.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!