HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-Coord-SPM-TM-G-1-Singapore-UK-Sectoral: HKMA C-RAF Coordination with HKMA SPM TM-G-1, Singapore MAS TRMG, UK FCA Operational Resilience and Sectoral Cybersecurity

HKMA C-RAF coordination with HKMA SPM Modules + international banking sectoral cybersecurity + 2024-2025 pipeline. HKMA SUPERVISORY POLICY MANUAL (SPM) MODULES: (a) TM-G-1 General Principles for Technology Risk Management (verified separately) - foundational technology risk management expectations + 7 modules; (b) GS-1 General Principles for Risk Management - enterprise-wide risk management; (c) TM-G-3 General Principles for Information Technology Risk Management - earlier TI module; (d) IC-1 Risk-Based Approach to Inspection - supervisory approach; (e) other SPM Modules covering BCM + operational risk + AML + outsourcing + cloud. SINGAPORE MAS TRMG (Technology Risk Management Guidelines, June 2021) - parallel framework for Singapore-licensed financial institutions; similar 7-pillar structure + maturity assessment + mandatory + supervisory oversight; cross-Asia banking coordination. UK FCA OPERATIONAL RESILIENCE - PRA + FCA joint policy statement March 2021 + effective March 2022 + Important Business Services + Impact Tolerances + Mapping + Testing + Self-Assessment; complementary supervisory framework. BANK OF ENGLAND CBEST - UK intelligence-led red team testing; iCAST inspired by CBEST methodology + threat-intel + red team + replay. ECB TIBER-EU (Threat Intelligence-Based Ethical Red Teaming - European Union, verified separately) - parallel EU central bank framework + threat intel + red team + 5 phases + purple team replay; iCAST methodologically aligned + sectoral interoperability potential. AUSTRALIA APRA CPS 234 + RBI India Cyber Security Framework + Federal Reserve SR Letters + OCC Heightened Standards + similar sectoral cybersecurity supervisory frameworks. 2024-2025 PIPELINE + EMERGING ISSUES: (1) AI + MACHINE LEARNING + GENERATIVE AI cyber risk + governance + bias + transparency + DPO/CISO collaboration; (2) QUANTUM-RESISTANT CRYPTOGRAPHY readiness + NIST post-quantum standards (FIPS 203/204/205 finalized 2024) + crypto-agility + planning; (3) CLOUD + HYBRID + MULTI-CLOUD security + outsourcing risk + sovereign cloud + data localization; (4) RANSOMWARE + EXTORTION + Crypter + double-extortion + payment policy + insurance + sanctions; (5) SUPPLY CHAIN + 3rd-PARTY RISK + SBOM + open-source + sub-processor visibility; (6) DORA COORDINATION - EU DORA effective January 2025 + cross-jurisdictional financial entity coordination; (7) GEOPOLITICAL CYBER + nation-state threats + sanctions; (8) POST-COVID HYBRID + remote work + zero trust + endpoint security; (9) FINTECH + VIRTUAL BANKING + DECENTRALIZED FINANCE (DeFi) cybersecurity; (10) RECENT HONG KONG CYBER INCIDENTS + sectoral learning + HKMA supervisory communications. RECENT HKMA SUPERVISORY COMMUNICATIONS: Circulars on cyber-incident reporting + cloud + AI + ransomware + supervisory expectations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.