Back to Frameworks

HKMA Cyber Resilience Assessment Framework (C-RAF)

Hong Kong
v2.0 (2020)
7 domains
11 controls

HKMA Cyber Resilience Assessment Framework (C-RAF) is the Hong Kong Monetary Authority (HKMA) MANDATORY cybersecurity assessment + supervisory framework for all Authorised Institutions (AIs) in Hong Kong + part of the broader HKMA CYBERSECURITY FORTIFICATION INITIATIVE (CFI) launched 2016. KEY HISTORY: (a) CFI announced May 2016; (b) C-RAF v1.0 issued December 2016; (c) C-RAF v2.0 issued 6 May 2020 (Circular 20200506e1a1) - major revision incorporating lessons learned + international best practice + iCAST framework; (d) ongoing 2024-2025 enhancements + supervisory communications + threat-landscape evolution. CFI 3 PILLARS: (1) CYBER RESILIENCE ASSESSMENT FRAMEWORK (C-RAF) - tiered + risk-based self-assessment of cybersecurity maturity against inherent risk profile; mandatory for ALL AIs (~150+ banks + RLBs + DTCs); 7 domains; produces Cyber Maturity Profile + Target Maturity Level + remediation roadmap. (2) PROFESSIONAL DEVELOPMENT PROGRAMME (PDP) - industry workforce capability building + Certified Cyber Security Officer (CCSO) + Cyber Risk Management certifications + ongoing professional development; supports Hong Kong banking sector cyber talent pipeline. (3) CYBER INTELLIGENCE SHARING PLATFORM (CISP) - HKMA-operated intelligence-sharing platform + sectoral threat-sharing + indicator-of-compromise (IOC) distribution + tactical + operational + strategic intel + integration with HKCERT + commercial threat-intel feeds. C-RAF ASSESSMENT MODEL: 2-axis maturity model - INHERENT RISK ASSESSMENT (IRA) x CYBER MATURITY ASSESSMENT (CMA). IRA SCORES AI inherent cyber risk based on (a) technology footprint + online services + customer-facing channels; (b) data + transaction volumes + sensitivity; (c) third-party + service-provider dependence + interconnectedness; (d) deposits + scale; (e) cybersecurity threat-environment + history of incidents; result: LOW + MEDIUM + HIGH inherent risk tier. CMA assesses AI cybersecurity maturity across 7 DOMAINS each scored on 5-level scale (Baseline + Evolving + Intermediate + Advanced + Innovative). 7 DOMAINS: (1) GOVERNANCE - cyber strategy + risk management + reporting + culture; (2) IDENTIFICATION - asset management + risk + threat assessment; (3) PROTECTION - access control + data security + infrastructure + application security + training + 3rd-party risk; (4) DETECTION - monitoring + threat intelligence + testing + anomaly detection; (5) RESPONSE AND RECOVERY - incident response planning + execution + recovery + resilience; (6) SITUATIONAL AWARENESS - threat landscape + information sharing; (7) ICAST - intelligence-led cyber attack simulation testing (mandatory for HIGH inherent risk AIs). TARGET MATURITY LEVEL: each AI must achieve target maturity matched to its inherent risk tier (HIGH tier requires Intermediate-to-Advanced + iCAST; MEDIUM Intermediate; LOW Evolving-to-Intermediate); gaps trigger remediation roadmap submitted to HKMA. ICAST INTELLIGENCE-LED CYBER ATTACK SIMULATION TESTING: mandatory for HIGH inherent risk AIs + optional for medium; red team + threat-intelligence + scope + threat scenarios + execution + purple team replay + findings + remediation; modeled on UK CBEST + EU TIBER-EU (separately verified) + intelligence-led red team testing. ASSESSMENT CYCLE: annual self-assessment + 3-year independent + supervisory dialogue + remediation + ongoing monitoring. SUPERVISORY DIALOGUE: HKMA reviews submissions + may impose remediation requirements + escalate findings + monitor through ongoing supervision. COORDINATION: HKMA Supervisory Policy Manual (SPM) Module TM-G-1 (General Principles for Technology Risk Management, verified separately if tracked) + GS-1 + TM-G-3 + others; Singapore MAS TRMG; UK FCA Operational Resilience + ECB TIBER-EU (verified separately) + various banking sectoral cybersecurity. 2024-2025 PIPELINE: ongoing v2.0 enhancements + threat-landscape evolution + AI cybersecurity + quantum-readiness + cloud + DORA-coordination + new SPM modules + ransomware response + post-COVID hybrid + supply chain.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

HKMA C-RAF Domain 1-2: Governance + Identification (Cyber Strategy, Risk Mgmt, Asset Mgmt, Threat Assessment)

1 controls
Controls in the HKMA C-RAF Domain 1-2: Governance + Identification (Cyber Strategy, Risk Mgmt, Asset Mgmt, Threat Assessment) domain of HKMA Cyber Resilience Assessment Framework (C-RAF)1 controls
CodeTitle
HKMA-CRAF-Domain1-2-Governance-IdentificationHKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment

HKMA C-RAF Domain 3-4: Protection + Detection (Access, Data, Infrastructure, Application, Monitoring, Testing)

1 controls
Controls in the HKMA C-RAF Domain 3-4: Protection + Detection (Access, Data, Infrastructure, Application, Monitoring, Testing) domain of HKMA Cyber Resilience Assessment Framework (C-RAF)1 controls
CodeTitle
HKMA-CRAF-Domain3-4-Protection-DetectionHKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

HKMA C-RAF Domain 5-6: Response & Recovery + Situational Awareness (IR, Recovery, Threat Intel, Info Sharing)

1 controls
Controls in the HKMA C-RAF Domain 5-6: Response & Recovery + Situational Awareness (IR, Recovery, Threat Intel, Info Sharing) domain of HKMA Cyber Resilience Assessment Framework (C-RAF)1 controls
CodeTitle
HKMA-CRAF-Domain5-6-Response-Recovery-SitAwarenessHKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline

4 controls
Controls in the HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline domain of HKMA Cyber Resilience Assessment Framework (C-RAF)4 controls
CodeTitle
HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORAHKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination
HKMA-CRAF-Coord-SPM-TM-G-1-Singapore-UK-SectoralHKMA C-RAF Coordination with HKMA SPM TM-G-1, Singapore MAS TRMG, UK FCA Operational Resilience and Sectoral Cybersecurity
HKMA-CRAF-Implementation-Roles-Tooling-AssuranceHKMA C-RAF Implementation Roadmap, Organizational Roles, Tooling and Assurance
HKMA-CRAF-Status-Industry-Adoption-FutureRoadmapHKMA C-RAF Status, Industry Adoption, Hong Kong Banking Sector and Future Roadmap

HKMA C-RAF: Cybersecurity Fortification Initiative (CFI), 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope

1 controls
Controls in the HKMA C-RAF: Cybersecurity Fortification Initiative (CFI), 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope domain of HKMA Cyber Resilience Assessment Framework (C-RAF)1 controls
CodeTitle
HKMA-CRAF-CFI-3Pillars-Scope-MandatoryHKMA CFI 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope and Supervisory Framework

HKMA C-RAF: Inherent Risk Assessment (IRA), Maturity Assessment (MA), Target Maturity Level, Assessment Cycle

1 controls
Controls in the HKMA C-RAF: Inherent Risk Assessment (IRA), Maturity Assessment (MA), Target Maturity Level, Assessment Cycle domain of HKMA Cyber Resilience Assessment Framework (C-RAF)1 controls
CodeTitle
HKMA-CRAF-IRA-Maturity-TargetLevel-CycleHKMA C-RAF Inherent Risk Assessment (IRA), Cyber Maturity Assessment (MA), Target Maturity Level, Assessment Cycle

HKMA C-RAF: iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

2 controls
Controls in the HKMA C-RAF: iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs domain of HKMA Cyber Resilience Assessment Framework (C-RAF)2 controls
CodeTitle
HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBERHKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLedHKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

Your Compliance Coverage

If you comply with HKMA Cyber Resilience Assessment Framework (C-RAF), you already cover:

Maps to 170 other frameworks

11 total controls
Ghana Cybersecurity Act
3 source controls mapped|6 target controls covered
27%
GLBA
3 source controls mapped|4 target controls covered
27%
ISO/IEC 27011:2024
3 source controls mapped|10 target controls covered
27%
FISMA
3 source controls mapped|3 target controls covered
27%
ISO/IEC 30111:2019
3 source controls mapped|6 target controls covered
27%
FTC GLBA Safeguards Rule (16 CFR Part 314)
3 source controls mapped|6 target controls covered
27%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|12 target controls covered
27%
Bahrain PDPL
3 source controls mapped|6 target controls covered
27%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|9 target controls covered
27%
TNFD Recommendations
3 source controls mapped|4 target controls covered
27%
AASB S2 Climate-related Disclosures
3 source controls mapped|4 target controls covered
27%
BSI IT-Grundschutz
3 source controls mapped|15 target controls covered
27%
API 1164
3 source controls mapped|11 target controls covered
27%
OWASP ASVS
3 source controls mapped|10 target controls covered
27%
APPI
3 source controls mapped|6 target controls covered
27%
FedRAMP Rev 5
3 source controls mapped|5 target controls covered
27%
Azure Security Benchmark
3 source controls mapped|9 target controls covered
27%
ISO/IEC 27400:2022
3 source controls mapped|8 target controls covered
27%
APRA CPS 230 Operational Risk Management
3 source controls mapped|7 target controls covered
27%
ISO/IEC 29147:2018
3 source controls mapped|7 target controls covered
27%
Privacy Act 1988 (Australia)
3 source controls mapped|6 target controls covered
27%
APRA CPS 234
3 source controls mapped|14 target controls covered
27%
Family Educational Rights and Privacy Act (FERPA)
3 source controls mapped|1 target controls covered
27%
Switzerland FADP
3 source controls mapped|6 target controls covered
27%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
3 source controls mapped|4 target controls covered
27%
NIST AI Risk Management Framework (AI RMF 1.0)
3 source controls mapped|6 target controls covered
27%
NIST AI 600-1: Generative AI Profile
3 source controls mapped|6 target controls covered
27%
27%
AWS Well-Architected Security Pillar
3 source controls mapped|9 target controls covered
27%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|3 target controls covered
27%
GAMP 5 - Good Automated Manufacturing Practice
3 source controls mapped|3 target controls covered
27%
BS 65000:2014 - Guidance on Organizational Resilience
3 source controls mapped|3 target controls covered
27%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|5 target controls covered
27%
ISO/IEC 38500:2024 - Governance of IT
3 source controls mapped|5 target controls covered
27%
ISO/IEC 27010:2015
2 source controls mapped|4 target controls covered
18%
ISO/IEC 27031:2011
2 source controls mapped|6 target controls covered
18%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|6 target controls covered
18%
ISO/IEC 27007:2020
2 source controls mapped|2 target controls covered
18%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
2 source controls mapped|3 target controls covered
18%
Serbia Law on Personal Data Protection (2018)
2 source controls mapped|3 target controls covered
18%
HITECH Act
2 source controls mapped|2 target controls covered
18%
South Korea Cloud Security Assurance Program (CSAP)
2 source controls mapped|2 target controls covered
18%
New Zealand Information Security Manual (NZISM)
2 source controls mapped|1 target controls covered
18%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
2 source controls mapped|1 target controls covered
18%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
2 source controls mapped|1 target controls covered
18%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|13 target controls covered
18%
OWASP Top 10:2025
2 source controls mapped|5 target controls covered
18%
Barbados Data Protection Act 2019
2 source controls mapped|2 target controls covered
18%
COBIT 2019
2 source controls mapped|2 target controls covered
18%
FIRST CSIRT Services Framework and Standards
2 source controls mapped|2 target controls covered
18%
Kuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive)
2 source controls mapped|4 target controls covered
18%
Laos Law on Prevention and Combating Cybercrime (2015)
2 source controls mapped|2 target controls covered
18%
LGPD
2 source controls mapped|2 target controls covered
18%
NIS2 Directive
2 source controls mapped|5 target controls covered
18%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
2 source controls mapped|5 target controls covered
18%
US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants
2 source controls mapped|1 target controls covered
18%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
18%
ISO 19011
2 source controls mapped|4 target controls covered
18%
18%
ISO 31000:2018
2 source controls mapped|2 target controls covered
18%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|8 target controls covered
18%
FBI CJIS Security Policy
2 source controls mapped|6 target controls covered
18%
FDA 21 CFR Part 11
2 source controls mapped|4 target controls covered
18%
AML/CTF Act 2006 (Australia)
2 source controls mapped|2 target controls covered
18%
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
2 source controls mapped|2 target controls covered
18%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|8 target controls covered
18%
Singapore Model AI Governance Framework (2nd Edition)
2 source controls mapped|1 target controls covered
18%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
2 source controls mapped|3 target controls covered
18%
ISO 20000-1
2 source controls mapped|3 target controls covered
18%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|1 target controls covered
18%
IEC 60601-1 - Medical Electrical Equipment Safety
2 source controls mapped|4 target controls covered
18%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|10 target controls covered
18%
AS9100D - Aerospace Quality Management System
2 source controls mapped|1 target controls covered
18%
ISO/IEC 27003:2017
2 source controls mapped|1 target controls covered
18%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|6 target controls covered
18%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|2 target controls covered
18%
GLI-33 - Gaming Laboratories International Event Wagering Systems
2 source controls mapped|1 target controls covered
18%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
2 source controls mapped|3 target controls covered
18%
ISO/IEC 29134:2023
2 source controls mapped|6 target controls covered
18%
Aged Care Quality Standards (Australia)
2 source controls mapped|1 target controls covered
18%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|3 target controls covered
18%
FedRAMP High
2 source controls mapped|2 target controls covered
18%
NIST SP 800-53 Revision 5.1 HIGH
2 source controls mapped|2 target controls covered
18%
IRS Publication 1075
2 source controls mapped|2 target controls covered
18%
FedRAMP Moderate
2 source controls mapped|2 target controls covered
18%
German Supply Chain Due Diligence Act (LkSG)
2 source controls mapped|2 target controls covered
18%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|2 target controls covered
18%
NIST SP 800-171
1 source controls mapped|1 target controls covered
9%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
9%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
9%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
9%
OWASP API Security Top 10 - 2023
1 source controls mapped|2 target controls covered
9%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
9%
ISO 27005
1 source controls mapped|1 target controls covered
9%
FIDO2 / WebAuthn
1 source controls mapped|1 target controls covered
9%
WCO Authorised Economic Operator (AEO) Framework
1 source controls mapped|1 target controls covered
9%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
9%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|5 target controls covered
9%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|3 target controls covered
9%
Saudi PDPL
1 source controls mapped|2 target controls covered
9%
Korea PIPA
1 source controls mapped|1 target controls covered
9%
Japan APPI
1 source controls mapped|1 target controls covered
9%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
9%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
9%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|2 target controls covered
9%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
9%
ISO 14001
1 source controls mapped|1 target controls covered
9%
ISO 45001:2018
1 source controls mapped|1 target controls covered
9%
ISO 9001:2015
1 source controls mapped|2 target controls covered
9%
ISO/IEC 27014:2020
1 source controls mapped|4 target controls covered
9%
ILO Nursing Personnel Convention C149 (1977)
1 source controls mapped|1 target controls covered
9%
IFRS 17 - Insurance Contracts
1 source controls mapped|1 target controls covered
9%
9%
South Korea Personal Information Protection Act (PIPA)
1 source controls mapped|4 target controls covered
9%
Science Based Targets initiative (SBTi) Corporate Standard
1 source controls mapped|2 target controls covered
9%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|2 target controls covered
9%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|3 target controls covered
9%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
9%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
9%
FATF Recommendation 16 - Virtual Asset Travel Rule
1 source controls mapped|1 target controls covered
9%
Paraguay Law on Protection of Personal Data (Law No. 6534/2020)
1 source controls mapped|1 target controls covered
9%
Jordan Draft Personal Data Protection Law (2022)
1 source controls mapped|1 target controls covered
9%
Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
1 source controls mapped|2 target controls covered
9%
Portugal Law No. 58/2019 - Data Protection Implementation Act
1 source controls mapped|3 target controls covered
9%
Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)
1 source controls mapped|3 target controls covered
9%
Montenegro Law on Personal Data Protection (2023)
1 source controls mapped|3 target controls covered
9%
Law on Personal Data Protection (Official Gazette No. 42/2020)
1 source controls mapped|3 target controls covered
9%
Japan Act on Specified Commercial Transactions (ASCT) - Digital Services
1 source controls mapped|3 target controls covered
9%
Uruguay Personal Data Protection Act (Law No. 18.331)
1 source controls mapped|3 target controls covered
9%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
1 source controls mapped|1 target controls covered
9%
MiFID II / MiFIR
1 source controls mapped|1 target controls covered
9%
Turkey Personal Data Protection Law (KVKK - Law No. 6698)
1 source controls mapped|1 target controls covered
9%
Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
9%
Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
1 source controls mapped|1 target controls covered
9%
Uzbekistan Law on Personal Data (No. ZRU-547)
1 source controls mapped|1 target controls covered
9%
Panama Law on Personal Data Protection (Law No. 81 of 2019)
1 source controls mapped|1 target controls covered
9%
Lithuania Law on Legal Protection of Personal Data (2018)
1 source controls mapped|1 target controls covered
9%
Malta Data Protection Act (Cap. 586, 2018)
1 source controls mapped|1 target controls covered
9%
Oman Personal Data Protection Law (Royal Decree 6/2022)
1 source controls mapped|1 target controls covered
9%
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)
1 source controls mapped|1 target controls covered
9%
UNCITRAL Model Law on Electronic Commerce (1996, updated 2005)
1 source controls mapped|1 target controls covered
9%
SWIFT CSCF
1 source controls mapped|2 target controls covered
9%
SWIFT CSCF v2024
1 source controls mapped|3 target controls covered
9%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|3 target controls covered
9%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
9%
Union Customs Code (UCC) - Regulation (EU) No 952/2013
1 source controls mapped|3 target controls covered
9%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
9%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|2 target controls covered
9%
Telecommunications Sector Security Reforms (TSSR)
1 source controls mapped|2 target controls covered
9%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|2 target controls covered
9%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
9%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
9%
ISO 13485
1 source controls mapped|1 target controls covered
9%
ISO 13485:2016
1 source controls mapped|1 target controls covered
9%
FSSC 22000 - Food Safety System Certification
1 source controls mapped|1 target controls covered
9%
Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018)
1 source controls mapped|1 target controls covered
9%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
9%
South Korea Credit Information Act
1 source controls mapped|1 target controls covered
9%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
9%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
9%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
1 source controls mapped|1 target controls covered
9%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
9%

Frequently Asked Questions

What is HKMA Cyber Resilience Assessment Framework (C-RAF)?

HKMA Cyber Resilience Assessment Framework (C-RAF) is a compliance framework from Hong Kong with 7 domains and 11 controls. HKMA Cyber Resilience Assessment Framework (C-RAF) is the Hong Kong Monetary Authority (HKMA) MANDATORY cybersecurity assessment + supervisory framework for all Authorised Institutions (AIs) in Hong Kong + part of the broader HKMA CYBERSECURITY FORTIFICATION INITIATIVE (CFI) launched 2016. KEY HISTORY: (a) CFI announced May 2016; (b) C-RAF v1.0 issued December 2016; (c) C-RAF v2.0 issued 6 May 2020 (Circular 20200506e1a1) - major revision incorporating lessons learned + international best practice + iCAST framework; (d) ongoing 2024-2025 enhancements + supervisory communications + threat-landscape evolution. CFI 3 PILLARS: (1) CYBER RESILIENCE ASSESSMENT FRAMEWORK (C-RAF) - tiered + risk-based self-assessment of cybersecurity maturity against inherent risk profile; mandatory for ALL AIs (~150+ banks + RLBs + DTCs); 7 domains; produces Cyber Maturity Profile + Target Maturity Level + remediation roadmap. (2) PROFESSIONAL DEVELOPMENT PROGRAMME (PDP) - industry workforce capability building + Certified Cyber Security Officer (CCSO) + Cyber Risk Management certifications + ongoing professional development; supports Hong Kong banking sector cyber talent pipeline. (3) CYBER INTELLIGENCE SHARING PLATFORM (CISP) - HKMA-operated intelligence-sharing platform + sectoral threat-sharing + indicator-of-compromise (IOC) distribution + tactical + operational + strategic intel + integration with HKCERT + commercial threat-intel feeds. C-RAF ASSESSMENT MODEL: 2-axis maturity model - INHERENT RISK ASSESSMENT (IRA) x CYBER MATURITY ASSESSMENT (CMA). IRA SCORES AI inherent cyber risk based on (a) technology footprint + online services + customer-facing channels; (b) data + transaction volumes + sensitivity; (c) third-party + service-provider dependence + interconnectedness; (d) deposits + scale; (e) cybersecurity threat-environment + history of incidents; result: LOW + MEDIUM + HIGH inherent risk tier. CMA assesses AI cybersecurity maturity across 7 DOMAINS each scored on 5-level scale (Baseline + Evolving + Intermediate + Advanced + Innovative). 7 DOMAINS: (1) GOVERNANCE - cyber strategy + risk management + reporting + culture; (2) IDENTIFICATION - asset management + risk + threat assessment; (3) PROTECTION - access control + data security + infrastructure + application security + training + 3rd-party risk; (4) DETECTION - monitoring + threat intelligence + testing + anomaly detection; (5) RESPONSE AND RECOVERY - incident response planning + execution + recovery + resilience; (6) SITUATIONAL AWARENESS - threat landscape + information sharing; (7) ICAST - intelligence-led cyber attack simulation testing (mandatory for HIGH inherent risk AIs). TARGET MATURITY LEVEL: each AI must achieve target maturity matched to its inherent risk tier (HIGH tier requires Intermediate-to-Advanced + iCAST; MEDIUM Intermediate; LOW Evolving-to-Intermediate); gaps trigger remediation roadmap submitted to HKMA. ICAST INTELLIGENCE-LED CYBER ATTACK SIMULATION TESTING: mandatory for HIGH inherent risk AIs + optional for medium; red team + threat-intelligence + scope + threat scenarios + execution + purple team replay + findings + remediation; modeled on UK CBEST + EU TIBER-EU (separately verified) + intelligence-led red team testing. ASSESSMENT CYCLE: annual self-assessment + 3-year independent + supervisory dialogue + remediation + ongoing monitoring. SUPERVISORY DIALOGUE: HKMA reviews submissions + may impose remediation requirements + escalate findings + monitor through ongoing supervision. COORDINATION: HKMA Supervisory Policy Manual (SPM) Module TM-G-1 (General Principles for Technology Risk Management, verified separately if tracked) + GS-1 + TM-G-3 + others; Singapore MAS TRMG; UK FCA Operational Resilience + ECB TIBER-EU (verified separately) + various banking sectoral cybersecurity. 2024-2025 PIPELINE: ongoing v2.0 enhancements + threat-landscape evolution + AI cybersecurity + quantum-readiness + cloud + DORA-coordination + new SPM modules + ransomware response + post-COVID hybrid + supply chain. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does HKMA Cyber Resilience Assessment Framework (C-RAF) have?

HKMA Cyber Resilience Assessment Framework (C-RAF) has 11 controls organised across 7 domains. The largest domains are HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline (4 controls), HKMA C-RAF: iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs (2 controls), HKMA C-RAF Domain 1-2: Governance + Identification (Cyber Strategy, Risk Mgmt, Asset Mgmt, Threat Assessment) (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does HKMA Cyber Resilience Assessment Framework (C-RAF) map to?

HKMA Cyber Resilience Assessment Framework (C-RAF) maps to 170 other compliance frameworks. The top mapping partners are Ghana Cybersecurity Act (27% coverage), GLBA (27% coverage), ISO/IEC 27011:2024 (27% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with HKMA Cyber Resilience Assessment Framework (C-RAF) compliance?

Start your HKMA Cyber Resilience Assessment Framework (C-RAF) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HKMA Cyber Resilience Assessment Framework (C-RAF) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 11 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required