HKMA TM-G-1 adjacent modules covered in this framework's scope. TM-G-2 BUSINESS CONTINUITY PLANNING: (a) Business Continuity Governance (TM-G-2.2.1) - Board oversight + BCP committee + crisis management + RACI + ownership; (b) Business Impact Analysis (TM-G-2.3.1) - critical process + service identification + dependency mapping + RTO/RPO + financial + operational + customer + reputational impact; (c) Recovery Strategy and Plans (TM-G-2.3.2) - documented recovery strategies per critical service + IT continuity + work area continuity + supplier continuity + alternate site + recovery procedures; (d) Backup and Restoration (TM-G-2.3.3) - data + system backups + retention + offsite + immutable + ransomware-resistant + restoration testing + integrity verification; (e) BCP Testing and Exercising (TM-G-2.4.1) - annual + scenario-based + tabletop + live + sectoral cyber wargames + lessons learned + remediation. TM-E-1 RISK MANAGEMENT OF E-BANKING: (a) Governance of E-banking (TM-E-1.2.1) - Board oversight + e-banking strategy + customer protection + regulatory compliance; (b) Customer Authentication for E-banking (TM-E-1.3.1) - MFA + biometric + behavioural + adaptive authentication + risk-based + customer journey; (c) Transaction Monitoring and Fraud Detection (TM-E-1.3.2) - real-time monitoring + ML/AI fraud detection + UEBA + suspicious activity + sanctions + AML integration + customer dispute resolution; (d) Customer Protection and Awareness (TM-E-1.3.3) - phishing + scam awareness + customer education + sectoral cyber-safety campaigns + transparency + consent + customer complaints; (e) Application Security for E-banking (TM-E-1.4.1) - secure SDLC + DAST + SAST + WAF + bot protection + mobile app security + API security + open banking + OAuth + PSD2-style API security alignment. OR-2 OPERATIONAL RESILIENCE: (a) Operational Resilience Framework (OR-2.2.1) - HKMA OR-2 + Important Business Services + Impact Tolerances + Mapping + Testing + Self-Assessment + aligned with FSB Operational Resilience Principles + UK PRA + APRA CPS 230; (b) Severe but Plausible Scenario Testing (OR-2.3.1) - reverse stress test + cyber + ransomware + supply chain + regulatory + scenario design + tabletop + live exercises; (c) Third Party and Concentration Risk for Resilience (OR-2.4.1) - 3rd-party concentration + cloud concentration + sectoral concentration + critical service provider monitoring + SBOM + sub-processor visibility + cross-jurisdiction supplier risk + recovery.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.