HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA: HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk management; emerging governance + bias + transparency + adversarial ML + AI-specific attack vectors (prompt injection + model extraction + data poisoning); HKMA supervisory communications on AI cyber risk. (2) QUANTUM-RESISTANT CRYPTOGRAPHY READINESS - NIST FIPS 203 (ML-KEM) + FIPS 204 (ML-DSA) + FIPS 205 (SLH-DSA) finalized 2024; cryptographic asset inventory + crypto-agility + transition planning + 'harvest now decrypt later' threat mitigation; HKMA supervisory expectations + sectoral working groups. (3) CLOUD + MULTI-CLOUD + HYBRID SECURITY - increased cloud adoption + sovereign cloud requirements + outsourcing risk + sub-processor visibility + cloud security posture management (CSPM) + cloud-native application protection (CNAPP); ongoing HKMA cloud guidance. (4) RANSOMWARE + DOUBLE-EXTORTION + PAYMENT POLICY - sectoral ransomware response procedures + cyber insurance + sanctions + law-enforcement coordination + business continuity + recovery + customer communications. (5) SUPPLY CHAIN + 3rd-PARTY + SBOM - vendor cyber risk + open-source software vulnerabilities + SBOM management + sub-processor visibility + supply chain attack scenarios + 3rd-party iCAST scope. (6) EU DORA COORDINATION (effective 17 January 2025) - cross-jurisdictional financial entity ICT risk + 5 pillars + cross-border AI coordination + DORA-aligned reporting + ICT third-party risk + threat-led penetration testing (TLPT) + register of contractual arrangements. (7) GEOPOLITICAL CYBER + NATION-STATE THREATS - China-US tensions + Russia-Ukraine + APT + sectoral targeting + HK as cross-border financial center + state-actor cybersecurity. (8) POST-COVID HYBRID + REMOTE WORK + ZERO TRUST - permanent hybrid + endpoint security + remote access + identity + ZTNA + SASE. (9) VIRTUAL BANKING + DIGITAL ASSETS + FINTECH - virtual bank (VB) cybersecurity + digital asset platform + Web3 + DeFi + tokenization + stablecoin sectoral cybersecurity. (10) RECENT SUPERVISORY COMMUNICATIONS - HKMA Circulars + advisory + sectoral exercises + cyber wargames + table-top + sectoral threat-intel sharing via CISP. (11) ASEAN + APAC SECTORAL COORDINATION - cross-jurisdiction information sharing + bilateral arrangements + MAS + APRA + BSP + Bank Indonesia + State Bank of Vietnam cooperation. ONGOING C-RAF EVOLUTION: HKMA periodically reviews + updates C-RAF + supervisory communications + sectoral consultation; potential v3.0 + further enhancements 2025-2027.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.