27% of HKMA Cyber Resilience Assessment Framework (C-RAF) you already have
NIST SP 800-171A Rev 3 already covers about 27% of HKMA Cyber Resilience Assessment Framework (C-RAF), leaving
8 of 11 controls as genuinely new work.
Already covered 3
Likely covered 0
New work 8
What is genuinely new work
Nothing in NIST SP 800-171A Rev 3 reaches these. This is the list to scope.
HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORAHKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination
HKMA-CRAF-CFI-3Pillars-Scope-MandatoryHKMA CFI 3 Pillars (C-RAF + PDP + CISP), Mandatory Scope and Supervisory Framework
HKMA-CRAF-Coord-SPM-TM-G-1-Singapore-UK-SectoralHKMA C-RAF Coordination with HKMA SPM TM-G-1, Singapore MAS TRMG, UK FCA Operational Resilience and Sectoral Cybersecurity
HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBERHKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks
HKMA-CRAF-IRA-Maturity-TargetLevel-CycleHKMA C-RAF Inherent Risk Assessment (IRA), Cyber Maturity Assessment (MA), Target Maturity Level, Assessment Cycle
HKMA-CRAF-Implementation-Roles-Tooling-AssuranceHKMA C-RAF Implementation Roadmap, Organizational Roles, Tooling and Assurance
HKMA-CRAF-Status-Industry-Adoption-FutureRoadmapHKMA C-RAF Status, Industry Adoption, Hong Kong Banking Sector and Future Roadmap
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLedHKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs
Show the 3 you already have
HKMA-CRAF-Domain1-2-Governance-IdentificationHKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment
HKMA-CRAF-Domain3-4-Protection-DetectionHKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
HKMA-CRAF-Domain5-6-Response-Recovery-SitAwarenessHKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-171A Rev 3 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition