In the United States, laws such as the Sarbanes-Oxley Act, HIPAA, GLBA, data security breach laws like California's SB-1386, and FISMA have made the adoption of many security practices a matter of regulatory compliance, rather than merely a measure to avoid worst-case security scenarios.