Cyber Risk, Security and Resilience
Threats, vulnerabilities, controls, third parties, incident response, recovery and board reporting.
How to study CIMA Strategic Level
Secure E3, P3 and F3 knowledge before practising integrated long-term judgement and professional communication. Static study assets do not reproduce all objective-test interactions or the pre-seen, unseen information, locked written sections and human marking of the Strategic Case Study.
Core concepts
Concept 1
Assess cyber threats, assets, vulnerabilities and business impact.
Exam cue: Prioritise critical assets and business services.
Concept 2
Design layered technical, procedural and human controls.
Exam cue: Assume a control can fail and build defence in depth.
Concept 3
Govern incidents, third-party exposure, recovery and reporting.
Exam cue: Define incident decisions, evidence, communication and recovery objectives.
Risk pitfalls and guardrails
Treating cyber risk as an IT-only responsibility.
Guardrail: Check the applicable blueprint, task verb, assumptions, units, evidence provenance, stakeholder effects, residual risk and whether the conclusion follows.
Reporting control activity without business exposure.
Guardrail: Check the applicable blueprint, task verb, assumptions, units, evidence provenance, stakeholder effects, residual risk and whether the conclusion follows.
Restoring systems before confirming integrity and containment.
Guardrail: Check the applicable blueprint, task verb, assumptions, units, evidence provenance, stakeholder effects, residual risk and whether the conclusion follows.
Memory anchors
Cyber risk
Potential harm to objectives from digital threats, vulnerabilities and dependencies.
Defence in depth
Multiple complementary controls so one failure does not expose the entire service.
Recovery time objective
The target maximum time for restoring a service after disruption.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
The chief information security officer operates the cyber programme, but a prolonged outage could prevent the company serving customers. Who owns the enterprise cyber exposure?
A finance analyst needs to view supplier balances but can also create suppliers and release payments. Which least-privilege change is most appropriate?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 247 UK exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
