HKMA Cyber Resilience Assessment Framework (C-RAF)
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
HKMA C-RAF Domain 1-2: Governance + Identification (Cyber Strategy, Risk Mgmt, Asset Mgmt, Threat Assessment)
HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training; cyber-risk-committee or board-committee oversight + minutes + escalation; (2) CYBER RISK STRATEGY - documented + board-approved cyber strategy + alignment with business strategy + risk appetite + 3-5 year roadmap + investment + resource planning; (3) CYBER RISK CULTURE - tone-from-the-top + cyber-aware culture + accountability + non-punitive reporting + cross-business engagement + customer-protection orientation; (4) ROLES + RESPONSIBILITIES - clearly-defined cyber roles including CISO + Cyber Risk Officer + business-line cyber-risk owners + 3-lines-of-defense; (5) CYBER RISK REPORTING - regular + risk-based reporting to board + senior manage
- Governance documents + board records
- Asset inventory + dependency mapping
- Threat-landscape monitoring evidence
- Governance documents incomplete
- Asset inventory gaps
- Threat assessment weak
HKMA C-RAF Domain 3-4: Protection + Detection (Access, Data, Infrastructure, Application, Monitoring, Testing)
HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding; (2) DATA SECURITY - data classification + encryption at rest + in transit + key management + DLP + tokenisation + de-identification + secure-data-destruction; (3) INFRASTRUCTURE SECURITY - network segmentation + firewall + IDS/IPS + endpoint protection + patch management + secure configuration + cloud security + hybrid + zero-trust network architecture; (4) APPLICATION SECURITY - secure SDLC + DevSecOps + code review + SAST + DAST + SCA + container + API + cloud-native security + WAF + bot protection; (5) SECURITY AWARENESS + TRAINING - workforce training + role-based + phishing simulation + awareness campaigns + cyber-skill developmen
- Protection control evidence per sub-area
- SIEM + SOC + threat-intel coverage
- Pen-test + red team reports + remediation
- Protection gaps
- Detection coverage weak
- Testing program inadequate
HKMA C-RAF Domain 5-6: Response & Recovery + Situational Awareness (IR, Recovery, Threat Intel, Info Sharing)
HKMA C-RAF Domain 5 RESPONSE AND RECOVERY + Domain 6 SITUATIONAL AWARENESS. DOMAIN 5 RESPONSE AND RECOVERY (3 sub-areas): (1) INCIDENT RESPONSE PLANNING - documented IR plan + playbooks + runbooks + RACI + escalation criteria + decision trees + communication plan including HKMA cyber-incident reporting (24-hour + 48-hour SLAs per HKMA Circulars) + customer + media + regulatory communications + legal + law-enforcement + 3rd-party partner integration + retainer + tabletop exercises; (2) INCIDENT RESPONSE EXECUTION - SOC-coordinated detection + triage + containment + eradication + recovery + post-incident review + lessons learned + remediation + sharing learnings with sector via CISP + maintaining forensic chain of evidence + working with HKCERT + HK Police + threat-intel sharing + cross-jurisdiction coordination; (3) RECOVERY AND RESILIENCE - business continuity + DR + RTO/RPO + IT continu
- IR plan + playbooks + tabletop exercises
- BCP/DR + RTO/RPO + recovery testing
- CISP/HKCERT/FS-ISAC participation
- IR plan weak + not tested
- Recovery procedures untested
- Threat-intel sharing not done
HKMA C-RAF: Coordination with HKMA SPM TM-G-1, Sectoral Coordination, 2024-2025 Pipeline
HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk management; emerging governance + bias + transparency + adversarial ML + AI-specific attack vectors (prompt injection + model extraction + data poisoning); HKMA supervisory communications on AI cyber risk. (2) QUANTUM-RESISTANT CRYPTOGRAPHY READINESS - NIST FIPS 203 (ML-KEM) + FIPS 204 (ML-DSA) + FIPS 205 (SLH-DSA) finalized 2024; cryptographic asset inventory + crypto-agility + transition planning + 'harvest now decrypt later' threat mitigation; HKMA supervisory expectations + sectoral working groups. (3) CLOUD + MULTI-CLOUD + HYBRID SECURITY - increased cloud adoption + sovereign cloud requirements + outsourcing risk + sub-processor visi
- Pipeline tracking + impact assessment
- Emerging risk readiness + roadmap
- Multi-jurisdictional + DORA coordination
- Pipeline not tracked
- Emerging risk readiness gaps
- Multi-jurisdictional coordination weak
HKMA C-RAF coordination with HKMA SPM Modules + international banking sectoral cybersecurity + 2024-2025 pipeline. HKMA SUPERVISORY POLICY MANUAL (SPM) MODULES: (a) TM-G-1 General Principles for Technology Risk Management (verified separately) - foundational technology risk management expectations + 7 modules; (b) GS-1 General Principles for Risk Management - enterprise-wide risk management; (c) TM-G-3 General Principles for Information Technology Risk Management - earlier TI module; (d) IC-1 Risk-Based Approach to Inspection - supervisory approach; (e) other SPM Modules covering BCM + operational risk + AML + outsourcing + cloud. SINGAPORE MAS TRMG (Technology Risk Management Guidelines, June 2021) - parallel framework for Singapore-licensed financial institutions; similar 7-pillar structure + maturity assessment + mandatory + supervisory oversight; cross-Asia banking coordination. UK F
- Multi-framework alignment + crosswalk
- Sectoral cybersecurity engagement
- 2024-2025 emerging risk readiness
- Multi-framework alignment ad-hoc
- Sectoral engagement weak
- Emerging risk readiness gap
HKMA C-RAF implementation roadmap. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - C-RAF governance oversight + cyber-strategy + risk appetite + reporting; (b) CHIEF INFORMATION SECURITY OFFICER (CISO) - operational ownership + C-RAF program lead + Maturity Assessment + IRA + remediation; (c) CHIEF RISK OFFICER (CRO) / HEAD OF OPERATIONAL RISK - 2nd-line oversight + cyber-risk integration + reporting + Board engagement; (d) CHIEF TECHNOLOGY OFFICER (CTO) / CIO - IT + cloud + infrastructure + DevSecOps + asset management; (e) HEAD OF INTERNAL AUDIT (3rd line) - cyber audit + 3-year independent review oversight; (f) COMPLIANCE - HKMA supervisory relations + regulatory reporting; (g) BUSINESS LINE CYBER-RISK OWNERS - 1st-line accountability + cyber-risk acceptance; (h) HUMAN RESOURCES - cyber training + workforce + culture; (i) PROCUREMENT + 3rd-PARTY MANAGEMENT - vendor cyber risk
- Role inventory + RACI
- Tooling adoption + integration
- Annual + 3-year cycle execution
- Workforce certifications
- Roles undefined
- Tooling fragmented
- Program execution gaps
- Workforce gaps
HKMA C-RAF status + Hong Kong banking sector adoption. ADOPTION: ALL ~150+ HKMA AUTHORISED INSTITUTIONS (AIs) mandated to participate in CFI + C-RAF + complete annual self-assessment + 3-year independent review + ongoing supervisory dialogue; major participants include local banks (HSBC + Hang Seng Bank + Standard Chartered Hong Kong + Bank of China Hong Kong + DBS Hong Kong + Citi + UBS + Goldman Sachs + Morgan Stanley + many more); RLBs + DTCs + foreign banks operating in Hong Kong; ~100 percent participation as mandated. CYBER MATURITY PROGRESS: significant industry maturity improvement since 2016 launch; most AIs at Intermediate (Level 3) or higher maturity; HIGH-inherent-risk AIs typically Intermediate-to-Advanced (Level 3-4); v2.0 raised maturity expectations + added iCAST requirement. iCAST EXECUTION: significant industry experience executing iCAST + remediation; sectoral lessons
- AI participation + maturity evidence
- CISP + PDP engagement
- Supervisory dialogue + roadmap
- Adoption monitoring weak
- CISP + PDP gaps
- Supervisory engagement weak
HKMA C-RAF: Cybersecurity Fortification Initiative (CFI), 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope
HKMA CYBERSECURITY FORTIFICATION INITIATIVE (CFI) - announced May 2016 + ongoing evolution + C-RAF v2.0 issued 6 May 2020 (Circular 20200506e1a1). CFI 3 PILLARS: (1) CYBER RESILIENCE ASSESSMENT FRAMEWORK (C-RAF) - mandatory tiered self-assessment of cybersecurity maturity vs inherent risk; (2) PROFESSIONAL DEVELOPMENT PROGRAMME (PDP) - workforce certifications (Certified Cyber Security Officer CCSO + Cyber Risk Management); (3) CYBER INTELLIGENCE SHARING PLATFORM (CISP) - HKMA-operated sectoral intelligence-sharing platform + threat-intel feeds + IOC distribution + integration with HKCERT + commercial providers. SCOPE: C-RAF applies to ALL HKMA AUTHORISED INSTITUTIONS (AIs) - approximately 150+ entities including (a) LICENSED BANKS (mainstream commercial banks); (b) RESTRICTED LICENCE BANKS (RLBs - investment banks + private banks); (c) DEPOSIT-TAKING COMPANIES (DTCs - finance companies)
- AI status confirmation + scope evidence
- C-RAF + PDP + CISP participation
- Supervisory dialogue records
- Scope unclear
- CFI 3 Pillars participation gaps
- Supervisory engagement weak
HKMA C-RAF: Inherent Risk Assessment (IRA), Maturity Assessment (MA), Target Maturity Level, Assessment Cycle
HKMA C-RAF Inherent Risk Assessment (IRA) + Maturity Assessment (MA) methodology + assessment cycle. INHERENT RISK ASSESSMENT (IRA): scoring AI inherent cyber risk based on multiple factors including (a) TECHNOLOGY FOOTPRINT - on-premise + cloud + hybrid + complexity + interconnectivity; (b) ONLINE SERVICES - internet banking + mobile + API + open banking + customer-facing channels; (c) DATA + TRANSACTIONS - volumes + sensitivity + PII + financial + cross-border; (d) THIRD-PARTY DEPENDENCIES - service providers + cloud + outsourcing + sub-processors + interconnectedness; (e) SCALE + DEPOSITS - asset size + customer base + transaction volume + balance sheet size; (f) CYBERSECURITY THREAT-ENVIRONMENT - geopolitical + sectoral + historical incidents + targeted-attack history; (g) SECTORAL ROLE - systemically important + cross-border + interconnection with other AIs. IRA RESULT: LOW + MEDIUM
- IRA submission + validation
- MA self-assessment + independent review
- Remediation roadmap tracking + closure
- IRA methodology unclear
- MA scoring inconsistent
- Roadmap not tracked
HKMA C-RAF: iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs
HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains; many AIs use NIST CSF as supplementary framework + crosswalk to C-RAF for ease + interoperability. (b) ISO/IEC 27001:2022 (Information Security Management System) + ISO 27002:2022 implementation guide + 27017 (cloud) + 27018 (privacy in cloud) + 27701 (PIMS) + 27036 (supplier relationships) - widely adopted by HK AIs alongside C-RAF; ISO 27001 certified AIs typically map ISO 27001 controls to C-RAF maturity levels. (c) FFIEC CYBERSECURITY ASSESSMENT TOOL (CAT) - similar tiered cyber-maturity assessment used by US banks; C-RAF + FFIEC CAT methodologically aligned + complementary; some HK AIs with US operations use both. (d) FFIEC IT EXAMINATION HANDBOOK - US ba
- Multi-framework crosswalk + certification
- Sectoral cybersecurity coordination
- DORA + cross-jurisdictional readiness
- Multi-framework alignment ad-hoc
- Sectoral coordination weak
- Cross-jurisdictional gaps
HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology. iCAST OBJECTIVES: (a) test AI cyber defenses against realistic + threat-intelligence-informed attack scenarios; (b) assess people + processes + technology resilience against simulated APT + ransomware + insider + supply-chain attacks; (c) provide actionable findings + remediation recommendations; (d) build sectoral threat-intelligence + lessons-learned. iCAST 5 PHASES: (1) SCOPE DEFINITION - critical services + critical functions + scope of testing + risk acceptance + ground rules + RoE + HKMA coordination + executive sponsorship; AI engages Threat Intelligence Provider + Red Team Service Provider both pre-approved by HKMA; (2) THREAT
- iCAST execution + reports + remediation
- TI + RT provider engagement
- Sectoral coordination evidence
- iCAST not done for HIGH AIs
- Provider selection issues
- Remediation tracking weak
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the HKMA Cyber Resilience Assessment Framework (C-RAF) framework page.