HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF Domain 5-6: Response & Recovery + Situational Awareness (IR, Recovery, Threat Intel, Info Sharing)

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness: HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

HKMA C-RAF Domain 5 RESPONSE AND RECOVERY + Domain 6 SITUATIONAL AWARENESS. DOMAIN 5 RESPONSE AND RECOVERY (3 sub-areas): (1) INCIDENT RESPONSE PLANNING - documented IR plan + playbooks + runbooks + RACI + escalation criteria + decision trees + communication plan including HKMA cyber-incident reporting (24-hour + 48-hour SLAs per HKMA Circulars) + customer + media + regulatory communications + legal + law-enforcement + 3rd-party partner integration + retainer + tabletop exercises; (2) INCIDENT RESPONSE EXECUTION - SOC-coordinated detection + triage + containment + eradication + recovery + post-incident review + lessons learned + remediation + sharing learnings with sector via CISP + maintaining forensic chain of evidence + working with HKCERT + HK Police + threat-intel sharing + cross-jurisdiction coordination; (3) RECOVERY AND RESILIENCE - business continuity + DR + RTO/RPO + IT continuity + tested recovery procedures + critical services continuity + customer service restoration + post-recovery validation + AI Operational Resilience expectations. DOMAIN 6 SITUATIONAL AWARENESS (2 sub-areas): (a) CYBER THREAT LANDSCAPE MONITORING - ongoing threat-intel collection + analysis + sectoral context + emerging-threat tracking + ransomware + APT + insider + supply chain + AI/ML threats + quantum-readiness assessment + threat-modeling + scenario analysis; (b) INFORMATION SHARING - active participation in CISP + HKCERT + FS-ISAC + cross-sector threat sharing + cyber-incident communication + sectoral coordination + supervisory dialogue + multi-jurisdiction cooperation. HKMA INCIDENT REPORTING: AI must notify HKMA of significant cyber-security incidents per HKMA Cyber-Security Incident Reporting Requirements; initial notification + interim updates + final report; coordinates with broader supervisory + business impact reporting requirements; specific timelines + content requirements + escalation criteria.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.