1. Model Risk Management advanced

    An independent validator asks you to reproduce a model's training run from eight months ago. Can you? What is needed?

    2 min answer mlreproducibilitygovernance
  2. Model Risk Management advanced

    An organisation deploys machine learning models in decisions affecting customers. What does model risk management require?

    1 min answer model-riskvalidationmonitoringgovernance
  3. Risk Appetite advanced

    A board sets an appetite of at most two customer-visible material incidents a year. Engineering ships about 3000 production changes a year with a change failure rate near 15%. Roughly how many material incidents does that imply, and which lever actually closes the gap?

    3 min answer risk-appetitechange-failure-rateblast-radiuserror-budget
  4. Risk Appetite advanced

    A board's risk appetite statement allows at most four hours of customer-visible unavailability per year for the payments API. The service currently runs as two VMs in a single Azure availability set behind a load balancer, with a managed database in the same region. Roughly what availability does the appetite imply and does the design fit?

    2 min answer risk-appetiteavailabilityslaazure
  5. Risk Appetite advanced

    An organisation states a risk appetite and teams still make inconsistent decisions. What is missing?

    2 min answer coinswitchrisk-appetitethresholdsdecisions
  6. Risk Appetite advanced

    An organisation states a risk appetite. How does that become something engineers can act on?

    1 min answer risk-appetitethresholdsdecision-rightsslo
  7. Risk Assessment Methods advanced

    Which risk assessment approach fits a technical architecture review, and where do the common methods go wrong?

    1 min answer risk-assessmentthreat-modellingscoringcalibration
  8. Risk Assessment Methods advanced

    Your main transactional database runs a version that goes out of vendor support in four months. Upgrading needs an estimated eight engineer-weeks and a maintenance window the business does not want to give. The CTO asks you to recommend whether to accept the risk for another twelve months. Talk me through how you would decide.

    2 min answer riskend-of-lifedecision-makingquantification
  9. Security Design Review advanced

    A developer-tools company of JetBrains' shape has six security engineers for 200 developers shipping desktop IDEs, a plugin marketplace and a hosted build service. It replaces mandatory pre-launch security review with a self-service threat-modelling questionnaire plus a trigger list, keeping deep review for triggered changes. What has it given up, and when does that bill arrive?

    3 min answer security-design-reviewthreat-modellingtriggerssampling
  10. Security Design Review advanced

    A security team of six supports two hundred engineers. Design reviews are a bottleneck. What do you do?

    1 min answer security-reviewscalingtriagepaved-road
  11. Segregation of Duties advanced

    A financial platform must demonstrate segregation of duties. What is the concrete test, and where does it usually fail?

    2 min answer brexrampsegregationcredentials
  12. Segregation of Duties advanced

    A team owns its service end to end, including deploying to production. How is segregation of duties satisfied?

    1 min answer segregation-of-dutiesdevopspipelineapproval