HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains; many AIs use NIST CSF as supplementary framework + crosswalk to C-RAF for ease + interoperability. (b) ISO/IEC 27001:2022 (Information Security Management System) + ISO 27002:2022 implementation guide + 27017 (cloud) + 27018 (privacy in cloud) + 27701 (PIMS) + 27036 (supplier relationships) - widely adopted by HK AIs alongside C-RAF; ISO 27001 certified AIs typically map ISO 27001 controls to C-RAF maturity levels. (c) FFIEC CYBERSECURITY ASSESSMENT TOOL (CAT) - similar tiered cyber-maturity assessment used by US banks; C-RAF + FFIEC CAT methodologically aligned + complementary; some HK AIs with US operations use both. (d) FFIEC IT EXAMINATION HANDBOOK - US banking sectoral IT supervisory expectations; complementary to HKMA SPM modules. (e) BANK OF ENGLAND CBEST (Cyber Threat Intelligence Based Ethical Red Teaming) - iCAST methodology derived from CBEST; conceptual + operational alignment. (f) ECB TIBER-EU (Threat Intelligence-Based Ethical Red Teaming European Union, VERIFIED SEPARATELY in this corpus) - parallel EU central bank framework + 5 phases + iCAST methodologically aligned. (g) SINGAPORE MAS TRMG (Technology Risk Management Guidelines) - parallel sectoral framework + 7-pillar maturity + mandatory + supervisory oversight; cross-Asia bank coordination. (h) AUSTRALIA APRA CPS 234 Information Security - regulatory cyber requirements + similar reporting + sectoral cyber. (i) US FEDERAL RESERVE SR LETTERS + OCC Heightened Standards + FDIC IT Risk Examination - parallel US banking sectoral cybersecurity. (j) DTCC + SWIFT + ISDA + sectoral financial-market-infrastructure cybersecurity standards. (k) PCI DSS v4.0 - payment card industry; applicable to AI payment processing + merchant + service-provider operations. (l) SOC 2 Type II - third-party assurance + service-provider attestation. (m) HKMA SPM TM-G-1 (General Principles for Technology Risk Management, verified separately) + GS-1 + TM-G-3 + IC-1 + others - adjacent HKMA supervisory expectations. (n) EU DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554, separately tracked) effective 17 January 2025 - parallel EU sectoral cybersecurity + ICT-risk + 5 pillars + financial-entity coordination + cross-border AI operations. (o) MITRE ATT&CK Framework - tactics + techniques + procedures used in iCAST + threat-intel + red team scenarios.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.