Home » Uncategorized » 5th Masterclass by International TPRM Alliance

News/Events@HB

5th Masterclass by International TPRM Alliance

0%
11

5th-TPRM Masterclass

5th TPRM Masterclass

Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.

1 / 18

Category: 4TPRMMasterclass

1. Please share your feedback on the event

  • What did you find most valuable?
  • What could be improved?
  • Any suggestions for future sessions?

2 / 18

Category: 5th-TPRM Masterclass

2. During an audit, an auditor notes that a bank has implemented several advanced threat detection systems but lacks a documented process to resume normal operations after an incident is resolved. Which domain or baseline does this gap violate?

3 / 18

Category: 5th-TPRM Masterclass

3. A CISO believes: 'The Statement of Applicability (SoA) is a one-time document that is only submitted during the initial CORF onboarding and does not need to be updated unless the Central Bank of Kuwait issues a formal audit notice.' What is the actual regulatory requirement?

4 / 18

Category: 4TPRMMasterclass

How would you rate the overall experience of the event?

  • 4. Highly insightful and engaging
  • Informative and valuable
  • Average / satisfactory
  • Lengthy but useful
  • Too long and less engaging
  • Not relevant / could be improved

5 / 18

Category: 5th-TPRM Masterclass

5. An auditor is assessing a bank's TPRM Business Continuity and Disaster Recovery domain. The bank has comprehensive documentation and regularly reviews its business impact analysis (BIA) to ensure alignment with regulations, but its processes are not yet automated or centralized. What maturity level does this represent?

6 / 18

Category: 5th-TPRM Masterclass

6. A Bank’s CISO decides that because the bank does not operate a neobank brand, the entire Emerging Technologies domain is 'Not Applicable' and plans to submit the SoA. What are the rules regarding such exclusions?

7 / 18

Category: 5th-TPRM Masterclass

7. A bank is filling out its Inherent Risk Profiling template. The IT Director asserts: 'We should implement compensating controls first to lower our risk inputs in the profiling sheet, which will lower our assigned Supervisory Tier.' Why is this approach incorrect under CORF?

8 / 18

Category: 5th-TPRM Masterclass

8. A bank's IT department argues that since they have robust firewalls and encryption, they have achieved 'operational resilience' for their payment systems. Why is this perspective incomplete under the CORF?

9 / 18

Category: 5th-TPRM Masterclass

9. A bank is mapping out its implementation lifecycle under CORF and aims to move from the 'Compliance and Maturity Assessment' step to 'CORF Baselines Implementation and Maturity Uplifting,' what intermediate step must be completed?

10 / 18

Category: 5th-TPRM Masterclass

10. Under the TPRM Data Protection and Confidentiality domain - a bank utilizes advanced threat modeling, real-time risk indicators and AI/ML models to dynamically adapt to business needs. What CORF maturity level does this bank demonstrate?

11 / 18

Category: 5th-TPRM Masterclass

11. A critical third-party technology vendor hosting a bank's main mobile application experiences a major ransomware attack, causing service disruption. Under the CORF TPRM Baselines, how should the bank's resilience BCP/DR plans have accounted for this?

12 / 18

Category: 4TPRMMasterclass

Which topics would you like to see covered in future roundtables or masterclasses?
e.g.,

  • 12. Third-Party Cyber Risk & Continuous Monitoring
  • AI Risk in Vendor Ecosystems
  • Cloud & SaaS Risk Management
  • Regulatory Compliance (e.g., outsourcing, data protection)
  • Fourth-Party / Concentration Risk
  • Incident & Breach Management involving vendors
  • Other (please specify): __________

13 / 18

Category: 5th-TPRM Masterclass

13. A major Bank’s Board of Directors asks the CISO to explain the core strategic shift of the new Cyber and Operational Resilience Framework (CORF). Which of the following best describes this shift?

14 / 18

Category: 5th-TPRM Masterclass

14. A Bank’s Executive management claims: 'If we outsource our IT administrative support and database management to an ISO 27001-certified third-party service provider, the bank's Board and management are no longer accountable for the cybersecurity and operational resilience risks of those systems.' How does CORF address this?

15 / 18

Category: 5th-TPRM Masterclass

15. Under the CORF Objectives, which of the following is NOT one of the four main objectives depicted in the framework's core design?

16 / 18

Category: 5th-TPRM Masterclass

16. A local bank is conducting its annual Cyber and Operational Resilience self-assessment. To ensure a standardized, objective evaluation, the bank must apply the 'dual-layered assessment methodology' defined in the CORF Toolkit. What are the two layers evaluated?

17 / 18

Category: 5th-TPRM Masterclass

IT Project Lead argues that: 'IT DRP and BCP are technical documents managed entirely within IT and 17. do not need to be aligned with business-defined recovery metrics like Maximum Tolerable Period of Disruption (MTPD) or RTO'. Under CORF Operational Resilience, what is the flaw in this statement?

18 / 18

Category: 5th-TPRM Masterclass

18. During vendor offboarding, a bank is finalizing its disengagement process. According to the CORF TPRM Exit Strategy domain, which of the following is a key requirement for a structured, secure exit process?

Your score is

0%

Exit