CBEST Threat Intelligence-Led Penetration Testing
Bank of England framework for intelligence-led penetration testing of UK financial infrastructure. Prescribes threat intelligence gathering, red team execution, blue team assessment, and remediation for systemically important financial institutions. Requires accredited threat intelligence providers (TIPs) and penetration testing providers (PTPs). Complementary to PRA operational resilience requirements.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| CBEST.1 | Governance and Oversight | |
| CBEST.2 | Threat Intelligence Phase | |
| CBEST.3 | Penetration Testing Scope | |
| CBEST.4 | Red Team Execution | |
| CBEST.5 | Blue Team Assessment | |
| CBEST.6 | Findings and Remediation | |
| CBEST.7 | Assurance and Reporting | |
| CBEST.8 | Provider Qualification | |
| CBEST.9 | Data Handling and Confidentiality | |
| CBEST.10 | Continuous Improvement |