
Ultimate access to all questions.
The CRO at a bank wants to strengthen the bank's capability to defend itself against emerging cyber-threats. To help achieve this goal, the CRO is assessing the current range of practices regarding the sharing of cybersecurity information between different types of institutions, as well as the potential benefits from sharing information. Which of the following statements would be most appropriate for the CRO to make?
A
The sharing of cybersecurity information among banks is less frequently observed and generally considered to be less effective than other cyber-security information-sharing practices.
B
The scope and depth of information-sharing practices among banks may significantly vary between financial markets, depending on the level of trust among participating banks.
C
Information-sharing among different national regulators has evolved significantly over the past several years and is now a widespread practice at a large majority of jurisdictions.
D
Existing peer-sharing mechanisms among banks focus on the exchange of information related to cyber-security incidents, but such information is generally not shared from banks to regulators.