Here is the honest situation. The HKMA Cyber Resilience Assessment Framework guides authorized institutions through assessing and strengthening cyber resilience: an inherent risk assessment that sets the target maturity, a maturity assessment across domains including governance, identification, protection, detection, response and recovery, situational awareness and third-party risk, and intelligence-led attack simulation testing for higher maturity levels. An institution that runs good security but cannot show its inherent risk rating, its maturity assessment against the target or its testing is exactly where institutions fall short.
This Kit removes the guesswork. It is the C-RAF written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.
What you get, the moment you buy
Grounded in the HKMA Cyber Resilience Assessment Framework, with the inherent risk assessment, the target maturity, the maturity domains of governance, identification, protection, detection, response and recovery, situational awareness and third-party risk, and intelligence-led testing called out. Editable Word and Excel files.
What one control looks like
This is adopting the C-RAF assessment, where the framework begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A maturity claim you cannot evidence will not stand. This tells you what an assessor examines and where institutions fall short, for every part of the framework.
- Inherent risk, maturity and testing built in. The inherent risk assessment, the maturity domains and intelligence-led testing are written into the controls, the substance the C-RAF requires.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The C-RAF aligns with your wider cyber and NIST-based program, so this work feeds your broader resilience.
Who buys this
Authorized institutions in Hong Kong and their cyber resilience, risk and compliance leads. Whether it is a first C-RAF assessment or a re-assessment, you save weeks and walk in with the inherent risk, maturity domains and testing structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this an official C-RAF assessment? No. It is an implementation toolkit grounded in the framework. It gets your controls and evidence in order fast so the assessment goes smoothly.
Does it cover the inherent risk assessment? Yes. The inherent risk assessment and setting the target maturity are built as controls.
Does it cover intelligence-led testing? Yes. Intelligence-led cyber attack simulation testing is built as a control for higher maturity levels.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com