HKMA TM-G-1
TM-G-1 Cyber: Security Monitoring + SIEM + Threat Intel + Cyber IR + Audit + Outsourcing + Cloud

HKMA TM-G-1 HKMA-TMG1-Cyber-Monitoring-Threat-Intel-IR-Audit-Outsource-Cloud: TM-G-1 Security Monitoring + SIEM + Threat Intel + Cyber IR + Audit + Outsourcing + Cloud Computing Risk

HKMA TM-G-1 Cyber + Audit + Outsourcing + Cloud. (1) SECURITY MONITORING AND SIEM (TM-G-1.7.1) - SIEM + SOC + 24x7 monitoring + log management + correlation + use cases + alert handling + escalation + UEBA + behavior analytics + SOAR automation + threat detection + Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security + ArcSight; (2) CYBER THREAT INTELLIGENCE (TM-G-1.7.2) - tactical + operational + strategic threat intel + IOC management + CISP (HKMA Cyber Intelligence Sharing Platform separately tracked) + commercial threat-intel feeds (Recorded Future + Mandiant + CrowdStrike + Anomali) + threat-modeling + scenario analysis + emerging-threat tracking + sectoral threat-intelligence sharing; (3) CYBER INCIDENT RESPONSE (TM-G-1.7.3) - documented IR plan + playbooks + runbooks + IR team + escalation procedures + breach response retainers (Mandiant + CrowdStrike + Kroll + Coveware + Stroz Friedberg) + cyber-incident communication procedures + HKMA mandatory cyber-incident reporting + customer notification + regulatory + law-enforcement coordination + sectoral coordination + lessons learned + post-incident review; (4) INDEPENDENT AUDIT OF TECHNOLOGY RISK (TM-G-1.8.1) - sound 3rd line (internal audit) function + scope + independence + competence + quality assurance + scenario-based audits + thematic reviews + remediation tracking + 3rd-party assurance (SOC 2 + ISO 27001 + sectoral); aligned with IIA standards + sectoral expectations; (5) OUTSOURCING + 3rd PARTY RISK (TM-G-1.9.1) - sound outsourcing risk management + materiality + due diligence + contract + ongoing monitoring + concentration risk + business continuity + termination + sub-contractor risk + SA-2 (Outsourcing module) alignment + sectoral coordination; (6) CLOUD COMPUTING RISK MANAGEMENT (TM-G-1.9.2) - HKMA TM-G-4 Public Cloud module + cloud risk taxonomy + cloud security posture (CSPM) + cloud workload protection (CWPP) + cloud-native application protection (CNAPP) + sovereign cloud + data localization + cross-border + hyperscaler concentration + sectoral concentration + multi-cloud + hybrid + outsourcing integration.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.