HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF Domain 1-2: Governance + Identification (Cyber Strategy, Risk Mgmt, Asset Mgmt, Threat Assessment)

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-Domain1-2-Governance-Identification: HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment

HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training; cyber-risk-committee or board-committee oversight + minutes + escalation; (2) CYBER RISK STRATEGY - documented + board-approved cyber strategy + alignment with business strategy + risk appetite + 3-5 year roadmap + investment + resource planning; (3) CYBER RISK CULTURE - tone-from-the-top + cyber-aware culture + accountability + non-punitive reporting + cross-business engagement + customer-protection orientation; (4) ROLES + RESPONSIBILITIES - clearly-defined cyber roles including CISO + Cyber Risk Officer + business-line cyber-risk owners + 3-lines-of-defense; (5) CYBER RISK REPORTING - regular + risk-based reporting to board + senior management + supervisory authorities including HKMA + incident escalation procedures. DOMAIN 2 IDENTIFICATION (2 sub-areas): (a) ASSET IDENTIFICATION + MANAGEMENT - comprehensive inventory of (i) IT assets (servers + workstations + network + applications + databases + cloud); (ii) information assets (PII + customer data + financial data + intellectual property); (iii) business processes + criticality + dependencies; (iv) third-party + service-provider dependencies; ongoing maintenance + change management; (b) RISK + THREAT ASSESSMENT - cyber risk register + risk assessment methodology + threat-landscape monitoring + scenario analysis + business-impact assessment + risk-treatment + residual-risk acceptance + alignment with HKMA risk-appetite. KEY EVIDENCE: governance documents + board minutes + strategy + roles charters + reporting templates + asset registers + risk assessments + threat-intelligence reports.

What else in your programme already covers this

This control maps to 197 controls across 88 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 29134:2023 · 5 controls

  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

ISO/IEC 27014:2020 · 4 controls

ISO/IEC 29147:2018 · 4 controls

  • 3.11 Encrypt Sensitive Data at Rest
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.3 Configure Data Access Control Lists
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports

API 1164 · 3 controls

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

FISMA · 3 controls

FedRAMP Rev 5 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 30111:2019 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • BB-DPA-2 Section 2 - Interpretation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

GLBA · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO/IEC 27031:2011 · 2 controls

  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage

Bahrain PDPL · 1 control

  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FDA 21 CFR Part 11 · 1 control

  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 197 it maps to, and the evidence behind each claim, over MCP and REST.