HKMA TM-G-1
TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB and 2024-2025 Pipeline

HKMA TM-G-1 HKMA-TMG1-Implementation-Roles-Tooling-Status: TM-G-1 Implementation Roadmap, Roles, Tooling, Status and Future

HKMA TM-G-1 implementation roadmap + status. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - TM-G-1 governance oversight + Technology Risk Management Framework approval + Risk Appetite + Pillar 2; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - operational ownership + TM-G-1.6 information security + cybersecurity + sectoral expectations; (c) CHIEF TECHNOLOGY OFFICER (CTO) / CIO - IT + cloud + infrastructure + TM-G-1.3-5 strategy + policies + operations; (d) CHIEF RISK OFFICER (CRO) + HEAD OF OPERATIONAL RISK - 2nd-line oversight + Technology Risk Management Framework integration + sectoral reporting; (e) HEAD OF INTERNAL AUDIT (3rd line) - TM-G-1.8 independent audit + sectoral cybersecurity audit + remediation tracking; (f) COMPLIANCE - HKMA supervisory dialogue + regulatory reporting + sectoral cybersecurity coordination; (g) BUSINESS LINE OWNERS - 1st-line accountability + business-aligned technology risk; (h) HR - workforce + sectoral PDP integration; (i) PROCUREMENT + VENDOR MANAGEMENT - TM-G-1.9 outsourcing + 3rd-party + cloud risk; (j) LEGAL - HKMA supervisory engagement + Banking Ordinance interpretation. PROGRAM ELEMENTS: (1) Technology Risk Management Framework establishment + Board approval; (2) Module-by-module compliance assessment + gap analysis + remediation; (3) Information Security Programme + ISMS + ISO 27001 alignment + sectoral cybersecurity; (4) Project + Change Management + DevSecOps + secure SDLC; (5) Operations + Capacity + Incident Management + ITIL; (6) Independent Audit + 3rd-party assurance (SOC 2 + ISO 27001); (7) Outsourcing + 3rd-party + Cloud risk management; (8) BCP + DR + Operational Resilience; (9) e-Banking risk management + customer protection; (10) Ongoing HKMA supervisory dialogue + thematic reviews + sectoral exercises. TOOLING: (a) GRC platforms (ServiceNow GRC + Archer + LogicGate + RSA + others); (b) SIEM/SOAR (Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security); (c) Identity + PAM (CyberArk + BeyondTrust + SailPoint + Okta + Microsoft Entra); (d) Vulnerability management (Tenable + Qualys + Rapid7); (e) EDR/XDR (CrowdStrike + Microsoft Defender + SentinelOne + Carbon Black); (f) Cloud security (Wiz + Lacework + Prisma Cloud + Microsoft Defender for Cloud); (g) Network security (Palo Alto + Fortinet + Check Point + Cisco); (h) Cyber-incident retainer (Mandiant + CrowdStrike + Kroll); (i) ITSM (ServiceNow + BMC + Jira); (j) BCP/DR platforms (Fusion + Veoci + Everbridge + MetricStream). STATUS: ALL ~150 HKMA Authorised Institutions subject to TM-G-1 + module compliance + ongoing supervisory dialogue + sectoral cybersecurity + Cybersecurity Fortification Initiative + C-RAF v2.0 (verified separately) + sectoral evolution; HKMA TM-G-1 + adjacent modules form foundational HKMA technology risk supervisory framework; ongoing module revisions + AI + cybersecurity + cloud + recovery + sectoral cyber evolution.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB and 2024-2025 Pipeline

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.