HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding; (2) DATA SECURITY - data classification + encryption at rest + in transit + key management + DLP + tokenisation + de-identification + secure-data-destruction; (3) INFRASTRUCTURE SECURITY - network segmentation + firewall + IDS/IPS + endpoint protection + patch management + secure configuration + cloud security + hybrid + zero-trust network architecture; (4) APPLICATION SECURITY - secure SDLC + DevSecOps + code review + SAST + DAST + SCA + container + API + cloud-native security + WAF + bot protection; (5) SECURITY AWARENESS + TRAINING - workforce training + role-based + phishing simulation + awareness campaigns + cyber-skill development integrated with PDP; (6) THIRD-PARTY RISK MANAGEMENT - vendor risk assessment + due diligence + contractual cyber requirements + ongoing monitoring + audit rights + cloud + outsourcing risk + sub-processor management. DOMAIN 4 DETECTION (4 sub-areas): (a) SECURITY EVENT MONITORING - SIEM + SOC + 24x7 monitoring + log management + correlation + use cases + alert handling + escalation procedures; (b) THREAT INTELLIGENCE - tactical + operational + strategic threat intel + IOC management + CISP feed + commercial sources + integration with security tooling; (c) SECURITY TESTING - penetration testing + vulnerability scanning + red team + purple team + tabletop exercises + breach + attack simulation; (d) ANOMALY DETECTION - user/entity behavior analytics (UEBA) + insider threat detection + ML-driven anomaly + fraud detection. KEY EVIDENCE: access policies + DLP coverage + network architecture + secure SDLC + training records + vendor assessments + SIEM use cases + pen-test reports + IOC feeds.
This control maps to 223 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 223 it maps to, and the evidence behind each claim, over MCP and REST.