HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF Domain 3-4: Protection + Detection (Access, Data, Infrastructure, Application, Monitoring, Testing)

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-Domain3-4-Protection-Detection: HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding; (2) DATA SECURITY - data classification + encryption at rest + in transit + key management + DLP + tokenisation + de-identification + secure-data-destruction; (3) INFRASTRUCTURE SECURITY - network segmentation + firewall + IDS/IPS + endpoint protection + patch management + secure configuration + cloud security + hybrid + zero-trust network architecture; (4) APPLICATION SECURITY - secure SDLC + DevSecOps + code review + SAST + DAST + SCA + container + API + cloud-native security + WAF + bot protection; (5) SECURITY AWARENESS + TRAINING - workforce training + role-based + phishing simulation + awareness campaigns + cyber-skill development integrated with PDP; (6) THIRD-PARTY RISK MANAGEMENT - vendor risk assessment + due diligence + contractual cyber requirements + ongoing monitoring + audit rights + cloud + outsourcing risk + sub-processor management. DOMAIN 4 DETECTION (4 sub-areas): (a) SECURITY EVENT MONITORING - SIEM + SOC + 24x7 monitoring + log management + correlation + use cases + alert handling + escalation procedures; (b) THREAT INTELLIGENCE - tactical + operational + strategic threat intel + IOC management + CISP feed + commercial sources + integration with security tooling; (c) SECURITY TESTING - penetration testing + vulnerability scanning + red team + purple team + tabletop exercises + breach + attack simulation; (d) ANOMALY DETECTION - user/entity behavior analytics (UEBA) + insider threat detection + ML-driven anomaly + fraud detection. KEY EVIDENCE: access policies + DLP coverage + network architecture + secure SDLC + training records + vendor assessments + SIEM use cases + pen-test reports + IOC feeds.

What else in your programme already covers this

This control maps to 223 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 10 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-14 Vulnerability scanning and management
  • BSI-16 Threat intelligence integration
  • BSI-17 Continuous monitoring strategy
  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

API 1164 · 7 controls

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)
  • ASD37-37 Personnel management (Very Good)

ISO/IEC 27011:2024 · 6 controls

  • CJIS-19 Supply Chain Risk Management
  • CJIS-2 Security Awareness Training
  • CJIS-7 Configuration Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO/IEC 27400:2022 · 5 controls

  • 3.10 Encrypt Sensitive Data in Transit
  • 3.12 Segment Data Processing and Storage Based on Sensitivity
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following: • Coverage for all locations of stored account data.

OWASP ASVS · 5 controls

FedRAMP Rev 5 · 4 controls

  • FedRAMP-Baselines FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters
  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • FedRAMP-SupplyChain-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF)

ISO/IEC 29147:2018 · 4 controls

OWASP Top 10:2025 · 4 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components

APPI · 3 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A34 Request for Correction, Addition or Deletion
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

Bahrain PDPL · 3 controls

FDA 21 CFR Part 11 · 3 controls

  • Part11.10 Controls for closed systems (21 CFR §11.10)
  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

FISMA · 3 controls

  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

ISO/IEC 27010:2015 · 3 controls

ISO/IEC 30111:2019 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-4 Configuration Management and Change Control
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)

FIDO2 / WebAuthn · 1 control

  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP High · 1 control

  • CA-8 Penetration Testing

FedRAMP Moderate · 1 control

  • CA-8 Penetration Testing

GLBA · 1 control

HITECH Act · 1 control

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 27006:2024 · 1 control

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • CA-8 Penetration Testing
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AIGF-1.1 Risk Management and Internal Controls
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 223 it maps to, and the evidence behind each claim, over MCP and REST.