Topic module

Cyber Risk, Security and Resilience

Threats, vulnerabilities, controls, third parties, incident response, recovery and board reporting.

Long-form learning
Concept to Risk to Memory to Check-up

How to study CIMA Strategic Level

Secure E3, P3 and F3 knowledge before practising integrated long-term judgement and professional communication. Static study assets do not reproduce all objective-test interactions or the pre-seen, unseen information, locked written sections and human marking of the Strategic Case Study.

Core concepts

Concept 1

Assess cyber threats, assets, vulnerabilities and business impact.

Exam cue: Prioritise critical assets and business services.

Concept 2

Design layered technical, procedural and human controls.

Exam cue: Assume a control can fail and build defence in depth.

Concept 3

Govern incidents, third-party exposure, recovery and reporting.

Exam cue: Define incident decisions, evidence, communication and recovery objectives.

Risk pitfalls and guardrails

Treating cyber risk as an IT-only responsibility.

Guardrail: Check the applicable blueprint, task verb, assumptions, units, evidence provenance, stakeholder effects, residual risk and whether the conclusion follows.

Reporting control activity without business exposure.

Guardrail: Check the applicable blueprint, task verb, assumptions, units, evidence provenance, stakeholder effects, residual risk and whether the conclusion follows.

Restoring systems before confirming integrity and containment.

Guardrail: Check the applicable blueprint, task verb, assumptions, units, evidence provenance, stakeholder effects, residual risk and whether the conclusion follows.

Memory anchors

Cyber risk

Potential harm to objectives from digital threats, vulnerabilities and dependencies.

Defence in depth

Multiple complementary controls so one failure does not expose the entire service.

Recovery time objective

The target maximum time for restoring a service after disruption.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

The chief information security officer operates the cyber programme, but a prolonged outage could prevent the company serving customers. Who owns the enterprise cyber exposure?

A finance analyst needs to view supplier balances but can also create suppliers and release payments. Which least-privilege change is most appropriate?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 247 UK exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.