开发者:上海品职教育科技有限公司 隐私政策详情

应用版本:4.2.11(IOS)|3.2.5(安卓)APP下载

啊柚子熟了 · 2025年04月18日

没看懂什么意思

NO.PZ2023102301000022

问题如下:

The CRO at a bank wants to strengthen the bank’s capability to defend itself against emerging cyber-threats. To help achieve this goal, the CRO is assessing the current range of practices regarding the sharing of cyber-security information between different types of institutions, as well as the potential benefits from sharing information. Which of the following statements would be most appropriate for the CRO to make?

选项:

A.The sharing of cyber-security information among banks is less frequently observed and generally considered to be less effective than other cyber-security information-sharing practices.

B.The scope and depth of information-sharing practices among banks may significantly vary between financial markets, depending on the level of trust among participating banks.

C.Information-sharing among different national regulators has evolved significantly over the past several years and is now a widespread practice at a large majority of jurisdictions.

D.Existing peer-sharing mechanisms among banks focus on the exchange of information related to cyber-security incidents, but such information is generally not shared from banks to regulators.

解释:

B is correct. Sharing of information and collaboration among banks depends on the financial industry’s culture and level of trust among participants. Experience shows that a two-level information-sharing structure through which information would be first shared on the interpersonal level with a closer group and then be exchanged at the company level with a broader group of banks helps build trust into the system. A is incorrect. Sharing of information among banks is one of the most widely observed practices across jurisdictions and a relatively wider range of information, such as knowledge about cyber threats / cyber intelligence is typically shared among banks. C is incorrect. Sharing amongst regulators is one of the least observed practices and a majority of jurisdictions do not currently allow it. D is incorrect. Banks typically do not share information about cyber-incidents with each other, but they do share this information with regulators at times when required by regulatory reporting practices.

没有懂这道题什么意思

1 个答案

李坏_品职助教 · 2025年04月18日

嗨,爱思考的PZer你好:


题目问你,关于网络信息安全问题,以及信息分享,下列叙述正确的哪一项?


A选项说: 与其他行业的网络信息共享相比,银行间的网络安全信息共享频率较低且效果较差。

这个明显错误。金融机构是最有这个动力和财力去更新网络设施,提高信息共享效率的。选项A与当前行业实践相悖,银行间信息共享已成为主流防御策略之一。


B选项说银行间信息共享的深度和范围因金融市场信任水平的不同而呈现出显著的差异。选项B准确反映了当前全球银行业信息共享的现状,是CRO需重点评估的内容,所以本题选B。


C说的是:不同国家监管机构间的信息共享已成为大多数司法管辖区的普遍实践。这个主要错在“大多数”,跨国监管信息共享现在并非主流趋势,所以不能说大多数都已经采用。


D说的是:银行间现有共享机制仅聚焦网络安全事件信息,且不向监管机构披露。选项D仅适用于少数未建立强制报告制度的地区,不符合当前主流监管要求。

----------------------------------------------
就算太阳没有迎着我们而来,我们正在朝着它而去,加油!

  • 1

    回答
  • 0

    关注
  • 4

    浏览
相关问题