HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF: Cybersecurity Fortification Initiative (CFI), 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-CFI-3Pillars-Scope-Mandatory: HKMA CFI 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope and Supervisory Framework

HKMA CYBERSECURITY FORTIFICATION INITIATIVE (CFI) - announced May 2016 + ongoing evolution + C-RAF v2.0 issued 6 May 2020 (Circular 20200506e1a1). CFI 3 PILLARS: (1) CYBER RESILIENCE ASSESSMENT FRAMEWORK (C-RAF) - mandatory tiered self-assessment of cybersecurity maturity vs inherent risk; (2) PROFESSIONAL DEVELOPMENT PROGRAMME (PDP) - workforce certifications (Certified Cyber Security Officer CCSO + Cyber Risk Management); (3) CYBER INTELLIGENCE SHARING PLATFORM (CISP) - HKMA-operated sectoral intelligence-sharing platform + threat-intel feeds + IOC distribution + integration with HKCERT + commercial providers. SCOPE: C-RAF applies to ALL HKMA AUTHORISED INSTITUTIONS (AIs) - approximately 150+ entities including (a) LICENSED BANKS (mainstream commercial banks); (b) RESTRICTED LICENCE BANKS (RLBs - investment banks + private banks); (c) DEPOSIT-TAKING COMPANIES (DTCs - finance companies); all AIs must complete C-RAF assessment cycle on annual + 3-year independent review basis. SUPERVISORY FRAMEWORK: HKMA Banking Supervision Department + Cybersecurity + Technology Risk Supervision divisions oversee C-RAF + Cybersecurity Fortification + sectoral cybersecurity; HKMA Supervisory Policy Manual (SPM) Modules including TM-G-1 (General Principles for Technology Risk Management) + GS-1 (General Principles for Risk Management) + others provide adjacent supervisory expectations. C-RAF v2.0 MAJOR ENHANCEMENTS over v1.0: (a) refined 7-domain structure + sub-domain scoring; (b) iCAST framework integrated; (c) Inherent Risk Assessment (IRA) refined; (d) Target Maturity Level alignment; (e) supervisory dialogue + remediation expectations clarified; (f) third-party + supply chain risk emphasis; (g) post-COVID + hybrid + cloud + emerging tech considerations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.