> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/law-and-compliance/sector-legislation.md).

# Sector Legislation

Some business sectors may be concerned with specific legislation or regulations that affect them, and therefore must be conisdered when planning  an engagement. Examples include:

* **Financial Services and Markets Act**

The Financial Services and Markets Act 200 regulates the financial services sector, covering aspects like conduct of business, regulation of financial markets, and financial products. It includes provisions relevant to security and operational risk management.

* **Payment  Services Regulations**

The Payment Services Regulations 2017 governs payment services and sets security requirements for providers of payment services, including fraud prevention and data protection.

* **Health and Social Care Act**

Health and Social Care Act 2012 governs the delivery of health and social care services and includes provisions for the protection and confidentiality of patient data.

* **Digital Operational Resilience Act**

The Digital Operational Resilience Act (DORA) is and EU regulation that aims to strengthen the IT security of financial entities such as banks, insurance companies and investment firms. This act covers "digital operational resilience testing".

The address these types of requirements, several frameworks exist to provide a structured and consistent approach to security testing<br>

* **CBEST**

CBEST is a framework developed by the Bank of England that is particularly relevant for financial institutions such as banks, insurers, and payment service providers. It aligns with various regulatory requirement (such as FSMA).

* **TIBER-EU**

The Threat Intelligence-Based Ethical Red Teaming Framework is an EU-wide framework for conducting Threat Intelligence-led ethical red teaming designed to test the cybersecurity of critical infrastructure and financial institutions.
