Hong Kong

HKMA Cyber Resilience Assessment Framework (C-RAF)

11 controls. 101 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

11 controls 101 frameworks share controls with it Hong Kong verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORAHKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination0
HKMA-CRAF-CFI-3Pillars-Scope-MandatoryHKMA CFI 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope and Supervisory Framework0
HKMA-CRAF-Coord-SPM-TM-G-1-Singapore-UK-SectoralHKMA C-RAF Coordination with HKMA SPM TM-G-1, Singapore MAS TRMG, UK FCA Operational Resilience and Sectoral Cybersecurity0
HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBERHKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks0
HKMA-CRAF-Domain1-2-Governance-IdentificationHKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment85
HKMA-CRAF-Domain3-4-Protection-DetectionHKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel65
HKMA-CRAF-Domain5-6-Response-Recovery-SitAwarenessHKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing44
HKMA-CRAF-IRA-Maturity-TargetLevel-CycleHKMA C-RAF Inherent Risk Assessment (IRA), Cyber Maturity Assessment (MA), Target Maturity Level, Assessment Cycle0
HKMA-CRAF-Implementation-Roles-Tooling-AssuranceHKMA C-RAF Implementation Roadmap, Organizational Roles, Tooling and Assurance0
HKMA-CRAF-Status-Industry-Adoption-FutureRoadmapHKMA C-RAF Status, Industry Adoption, Hong Kong Banking Sector and Future Roadmap0
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLedHKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs0

Tell me when HKMA Cyber Resilience Assessment Framework (C-RAF) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Role inventory + RACI
  • Metrics + management review
  • Annual cycle documentation
  • Role inventory + RACI + DPO designation
  • Operational controls + tooling investment
  • Reporting process + content index
  • Pipeline tracking + impact assessment
  • Pipeline-tracking + implementation plan per rule
  • SEC Reg S-P readiness 2025-2026
  • Section 1033 readiness 2026-2030

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for HKMA Cyber Resilience Assessment Framework (C-RAF), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition