HKMA Cyber Resilience Assessment Framework (C-RAF)
HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

HKMA Cyber Resilience Assessment Framework (C-RAF) HKMA-CRAF-Implementation-Roles-Tooling-Assurance: HKMA C-RAF Implementation Roadmap, Organizational Roles, Tooling and Assurance

HKMA C-RAF implementation roadmap. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - C-RAF governance oversight + cyber-strategy + risk appetite + reporting; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - operational ownership + C-RAF program lead + Maturity Assessment + IRA + remediation; (c) CHIEF RISK OFFICER (CRO) / HEAD OF OPERATIONAL RISK - 2nd-line oversight + cyber-risk integration + reporting + Board engagement; (d) CHIEF TECHNOLOGY OFFICER (CTO) / CIO - IT + cloud + infrastructure + DevSecOps + asset management; (e) HEAD OF INTERNAL AUDIT (3rd line) - cyber audit + 3-year independent review oversight; (f) COMPLIANCE - HKMA supervisory relations + regulatory reporting; (g) BUSINESS LINE CYBER-RISK OWNERS - 1st-line accountability + cyber-risk acceptance; (h) HUMAN RESOURCES - cyber training + workforce + culture; (i) PROCUREMENT + 3rd-PARTY MANAGEMENT - vendor cyber risk; (j) LEGAL + REGULATORY - HKMA incident reporting + AML/CFT + breach notification + cross-border. PROGRAM ELEMENTS: (1) IRA EXECUTION - inherent risk assessment + scoring + tier determination; (2) MATURITY SELF-ASSESSMENT - 7-domain scoring against maturity scale; (3) GAP ANALYSIS + REMEDIATION ROADMAP - against target maturity level; (4) HKMA SUBMISSION - annual self-assessment + supervisory dialogue + remediation tracking; (5) iCAST EXECUTION (HIGH AIs) - 5-phase intelligence-led testing; (6) INDEPENDENT REVIEW (3-year cycle) - external assessor or internal audit + scope + reporting; (7) ONGOING MONITORING + INCIDENT-DRIVEN ENGAGEMENT; (8) WORKFORCE TRAINING + PDP - CCSO + Cyber Risk Management certifications + sectoral PDP. TOOLING: (a) GRC platforms (ServiceNow GRC + Archer + LogicGate + RSA + others) for C-RAF assessment + tracking; (b) Vulnerability + asset management (Tenable + Qualys + Rapid7); (c) SIEM/SOAR (Splunk + IBM QRadar + Microsoft Sentinel + ArcSight + Elastic Security); (d) Threat-intel (Recorded Future + Mandiant + CrowdStrike Falcon Intel + Anomali + ThreatConnect); (e) Penetration testing + Red Team services (CrowdStrike + Mandiant + IBM X-Force + KPMG + EY + PwC + Deloitte + Cyberhouses + Trustwave); (f) iCAST providers - HKMA-recognized firms; (g) Cyber-incident response retainers (Mandiant + CrowdStrike + Kroll + Coveware + Stroz Friedberg); (h) Cloud security (Wiz + Lacework + Prisma Cloud + Microsoft Defender for Cloud); (i) Identity + access (CyberArk + BeyondTrust + SailPoint + Okta + Microsoft Entra); (j) DLP + data security (Symantec + Forcepoint + Trend Micro + Microsoft Purview). METRICS: maturity level per domain + IRA tier + remediation closure rate + iCAST findings (HIGH AIs) + supervisory engagement frequency + workforce certifications + incident-response metrics + threat-intel feed utilization.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.