Notes (alphabetical)
Search to quickly find notes, articles, guides, and resources across the site.
Search to quickly find notes, articles, guides, and resources across the site.
Cyber security is not just an issue for the IT department. It is a business risk that affects everybody. Report: Cyber and the CFO
The Cyber Assessment Framework was developed by the NCSC Related National Cyber Security Centre (NCSC)
Context For technology and risk professionals working within Hong Kong鈥檚 banking sector, the C-RAF is the inevitable baseline for cyber compliance. Understanding its structure is not just a regulatory requirement for the institution, but a core competency for those managing governance or operational risk. This note outlines the framework鈥檚 architecture and the regulator鈥檚 expectations. The Cyber Resilience Assessment Framework (C-RAF) is the mechanism by which the Hong Kong Monetary Authority (HKMA) measures the cyber maturity of Authorised Institutions (AIs). ...
Context For the technical specialist transitioning into management, the governance landscape can appear broad and fragmented. However, distinguishing between mere security controls and broader resilience is a fundamental competency for the modern leader. This article outlines the primary frameworks available to the Cyber practitioner, helping you select the appropriate structure to support both operational stability and regulatory compliance. It is no longer sufficient to focus solely on securing the organisation. The current operating environment requires a shift towards Cyber Resilience. ...