HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations; (b) HKMA C-RAF v2.0 (verified separately) - HKMA Cybersecurity Fortification Initiative + Cyber Resilience Assessment Framework + IRA + Maturity + iCAST + CISP + PDP; coordinates with TM-G-1 + TM-G-3 (Information Technology Security and Cyber Risk) for cybersecurity-specific expectations; (c) HKMA TM-G-2 (Business Continuity Planning) + TM-G-4 (Public Cloud) + TM-E-1 (e-Banking) + TM-M (Monitoring) + TM-N (New Technology) + TM-S (Supervisory Expectations) - related TM module family; (d) HKMA OR-1 (Operational Risk Management) + OR-2 (Operational Resilience) + RR-1 (Recovery Planning) + SA-2 (Outsourcing) + IC-1 (Risk Management Framework) - adjacent modules; (e) HKMA SUPERVISORY COMMUNICATIONS + CIRCULARS - ongoing guidance supplementing modules. INTERNATIONAL COORDINATION: (1) BASEL III - BCBS Principles for Effective Banking Supervision + sound risk management + IT + operational risk; (2) FSB FINANCIAL STABILITY BOARD - Operational Resilience Principles + cybersecurity + cyber-incident response + cyber lexicon + Guidance on Cyber Incident Reporting (FIRE); (3) ISO/IEC 27001:2022 (Information Security Management System) + ISO 27002:2022 + ISO 27017 (cloud) + ISO 27018 (privacy in cloud) + ISO 27701 (PIMS) + ISO 27036 (supplier relationships) + ISO 22301 (BCM); (4) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - voluntary standard + HK AI adoption; (5) FFIEC IT EXAMINATION HANDBOOK + APRA CPS 234 + MAS TRMG + UK FCA Operational Resilience + Federal Reserve SR Letters + sectoral equivalents; (6) PCI DSS v4.0 - payment card industry; (7) SOC 2 Type II - service provider attestation. KEY 2024-2025+ PRIORITIES: (a) AI + ML + GENERATIVE AI GOVERNANCE - AI deployment + bias + transparency + adversarial ML + prompt injection + model poisoning + AI Risk Management Framework + Hong Kong AI Framework integration; (b) QUANTUM-RESISTANT CRYPTOGRAPHY - NIST FIPS 203/204/205 finalized 2024 + crypto-agility + transition planning + cryptographic asset inventory + 'harvest now decrypt later' threat; (c) CLOUD + MULTI-CLOUD + SOVEREIGN CLOUD - cloud risk management + outsourcing + concentration; (d) RANSOMWARE + DOUBLE-EXTORTION - sectoral response + cyber insurance + sanctions + business continuity + recovery; (e) SUPPLY CHAIN + 3rd-PARTY + SBOM - vendor cyber risk + open-source + sub-processor; (f) EU DORA COORDINATION (effective 17 January 2025) - cross-jurisdictional financial entity ICT risk; (g) GEOPOLITICAL CYBER + nation-state threats; (h) HYBRID + REMOTE WORK + zero trust + endpoint; (i) VIRTUAL BANKING + DIGITAL ASSETS + WEB3 + tokenization + e-HKD CBDC + sectoral cybersecurity. RECENT HKMA SUPERVISORY COMMUNICATIONS: ongoing Circulars + sectoral exercises + cyber wargames + thematic reviews + supervisory dialogue.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.