HKMA SPM: Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1 e-Banking) + Coordination with C-RAF
HKMA SPM HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord: HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF
HKMA SPM Technology Management (TM) module family + coordination with sectoral cybersecurity frameworks. TM MODULE FAMILY: (1) TM-G-1 General Principles for Technology Risk Management - foundational module on technology risk governance + framework + roles + IT strategy + policies + risk assessment + project management + system development + change management + IT operations + capacity + problem + incident + information security + access + privileged access + network + crypto + DLP + vulnerability + endpoint + monitoring + threat intel + IR; SEPARATELY TRACKED in this corpus as detailed module; ~26 sub-section codes (TM-G-1.2.1 through TM-G-1.7.3); (2) TM-G-2 Business Continuity Planning - sound BCP + DR + IT continuity + RTO/RPO + critical service identification + testing + crisis management + supplier dependency; (3) TM-G-3 Information Technology + Cyber Risk Management - cyber risk-specific module + supplements C-RAF expectations; (4) TM-G-4 Public Cloud Services - HKMA-specific cloud risk management expectations + due diligence + contractual + supervisory oversight + concentration + jurisdiction + outsourcing integration; (5) TM-E-1 Risk Management of e-Banking - e-banking governance + customer authentication (MFA) + transaction monitoring + fraud detection + customer protection + application security + sound e-banking risk management; (6) TM-M MONITORING + supervisory communications + reporting expectations; (7) TM-N NEW TECHNOLOGIES + emerging tech (AI + ML + cloud + DLT + virtual banking + cryptocurrency + tokenization) HKMA position + risk-based approach; (8) TM-S SUPERVISORY EXPECTATIONS + sectoral exercises + thematic reviews. COORDINATION WITH SECTORAL CYBERSECURITY FRAMEWORKS: HKMA C-RAF v2.0 (verified separately in this corpus) operationalises cybersecurity-specific expectations + 7-domain maturity model + IRA + iCAST; TM-G-1 + TM-G-3 provide foundational principles; CFI (Cybersecurity Fortification Initiative) + CISP + PDP + Professional Development complement; SUPERVISORY COMMUNICATIONS + CIRCULARS supplement modules with specific guidance (cloud + AI + ransomware + cyber-incident reporting + 24-hour SLA). COORDINATION WITH OTHER MODULES: OR-2 (Operational Resilience) + SA-2 (Outsourcing) + CG-2 (Systems of Control) + IC-1 (Risk Management) + RR-1 (Recovery) all integrate with TM modules for holistic operational + cyber resilience.
What else in your programme already covers this
This control maps to 200 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.