# CBEST Threat Intelligence-Led Penetration Testing

Framework id: `cbest`. Threat-Led Testing. Publisher: Bank of England. Version: 2021. Region: UK. Mapping licence: CC BY-SA 4.0.
Source text: https://www.bankofengland.co.uk/financial-stability/financial-sector-continuity

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (10, average coverage 62%)
- CBEST.1 Governance and Oversight: PM-01, PM-02, PM-09, PM-14, PM-29, PL-01, PL-02, CA-01, CA-06 (65%)
- CBEST.2 Threat Intelligence Phase: PM-16, RA-03, RA-05, RA-10, PM-15, SI-05 (48%)
- CBEST.3 Penetration Testing Scope: CA-08, PM-11, PM-08, RA-09, RA-02, CM-08, CM-12 (68%)
- CBEST.4 Red Team Execution: CA-08, SC-26, SC-35, RA-06, RA-10 (45%)
- CBEST.5 Blue Team Assessment: SI-04, AU-06, AU-13, IR-04, IR-05, CA-07, PM-14, SC-07 (75%)
- CBEST.6 Findings and Remediation: CA-05, PM-04, RA-05, RA-07, SI-02, PM-31 (72%)
- CBEST.7 Assurance and Reporting: CA-02, CA-05, CA-07, PM-06, PM-14 (55%)
- CBEST.8 Provider Qualification: SA-04, SA-09, SA-21, PS-03, PS-07, SR-06 (38%)
- CBEST.9 Data Handling and Confidentiality: SC-08, SC-12, SC-13, SC-28, MP-01, MP-04, MP-05, MP-06, PT-01, PT-02, SI-12, AC-03 (80%)
- CBEST.10 Continuous Improvement: PM-31, CA-02, CA-05, CA-07, IR-03, AT-06, PM-06, PM-14 (72%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=cbest
- Control-to-clause mappings as JSON: /api/v1/frameworks/cbest?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/cbest.json
- Page for people: /frameworks/cbest/
