HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style alignment with ISO 27001 + sectoral expectations + Cybersecurity Fortification Initiative; CISO leadership + Board reporting + Risk Committee oversight; (2) ACCESS CONTROL + IDENTITY MANAGEMENT (TM-G-1.6.2) - identity + access management + provisioning + de-provisioning + access reviews + role-based + attribute-based + segregation of duties + ZTNA + identity governance; (3) PRIVILEGED ACCESS MANAGEMENT (PAM) (TM-G-1.6.3) - privileged credential vault + just-in-time access + session recording + monitoring + PAM tooling (CyberArk + BeyondTrust + Delinea + others); (4) NETWORK SECURITY (TM-G-1.6.4) - segmentation + firewall + IDS/IPS + WAF + DDoS protection + zero trust network + cloud network + east-west + north-south + secure remote access + VPN + ZTNA + SASE + macro/micro segmentation; (5) CRYPTOGRAPHIC CONTROLS (TM-G-1.6.5) - encryption at rest + in transit + key management + HSM + crypto-agility + quantum-resistant transition planning (NIST FIPS 203/204/205 finalized 2024) + secure key lifecycle + certificate management; (6) DATA LOSS PREVENTION + DATA PROTECTION (TM-G-1.6.6) - DLP + tokenization + de-identification + classification + secure-data-handling + customer data protection + cross-border data flow + sovereign cloud + data residency + PDPO compliance (Cap. 486 separately tracked); (7) VULNERABILITY + PATCH MANAGEMENT (TM-G-1.6.7) - vulnerability scanning + Tenable + Qualys + Rapid7 + patch management + change management integration + emergency patches + CVSS + risk-based prioritization + zero-day response; (8) ENDPOINT + MOBILE SECURITY (TM-G-1.6.8) - EDR/XDR + MDM + Mobile Application Management (MAM) + zero trust endpoint + macOS + Windows + iOS + Android + BYOD policy + remote work hardening.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.