HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training; cyber-risk-committee or board-committee oversight + minutes + escalation; (2) CYBER RISK STRATEGY - documented + board-approved cyber strategy + alignment with business strategy + risk appetite + 3-5 year roadmap + investment + resource planning; (3) CYBER RISK CULTURE - tone-from-the-top + cyber-aware culture + accountability + non-punitive reporting + cross-business engagement + customer-protection orientation; (4) ROLES + RESPONSIBILITIES - clearly-defined cyber roles including CISO + Cyber Risk Officer + business-line cyber-risk owners + 3-lines-of-defense; (5) CYBER RISK REPORTING - regular + risk-based reporting to board + senior management + supervisory authorities including HKMA + incident escalation procedures. DOMAIN 2 IDENTIFICATION (2 sub-areas): (a) ASSET IDENTIFICATION + MANAGEMENT - comprehensive inventory of (i) IT assets (servers + workstations + network + applications + databases + cloud); (ii) information assets (PII + customer data + financial data + intellectual property); (iii) business processes + criticality + dependencies; (iv) third-party + service-provider dependencies; ongoing maintenance + change management; (b) RISK + THREAT ASSESSMENT - cyber risk register + risk assessment methodology + threat-landscape monitoring + scenario analysis + business-impact assessment + risk-treatment + residual-risk acceptance + alignment with HKMA risk-appetite. KEY EVIDENCE: governance documents + board minutes + strategy + roles charters + reporting templates + asset registers + risk assessments + threat-intelligence reports.
This control maps to 197 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.