DORA vulnerability assessment and scanning for financial entities

DORA vulnerability assessment e scanning per entità finanziarie

The Digital Operational Resilience Act (DORA) and Delegated Regulation (EU) 2024/1774 have elevated vulnerability assessment to an essential regulatory requirement for all financial entities. Implementing a DORA vulnerability assessment and scanning program is essential to validate the resilience of ICT systems against dynamic and evolving threats.

DORA definition of vulnerability assessment

Vulnerability assessment, according to DORA, is a fundamental component of a transparent, consistent, and accountable ICT management framework. This activity includes procedures to identify, validate, and record weaknesses in ICT assets that could be exploited by malicious actors. The focus is not limited to detection but extends to analyzing the potential impact on the entity’s operational resilience.

Difference between assessment and scanning

  • Vulnerability Scanning: Automated activity using specialized software to systematically cover the widest range of ICT assets.
  • Vulnerability Assessment: A more extensive process that integrates scanning, critical evaluation of results, root cause analysis, and the definition of the best mitigation measures.

Correct scope: systems, apps, cloud, endpoints, and third-party libraries

  • Total ICT assets: All assets must be verified according to their classification and risk profile.
  • Third-party libraries: It is mandatory to monitor security versions and updates, including for open-source components.
  • Applications and software: Analysis and testing of source code and proprietary software provided by third parties.
  • Endpoints and infrastructure: Control over portable endpoints and network configurations to reduce exposure to threats.

Frequencies: when weekly, when risk-based

  • Weekly frequency: Automated scans at least once a week for ICT assets that support critical or important functions.
  • Risk-based frequency: For non-critical assets, the frequency is determined by classification and risk profile.
  • Emergency situations: Frequency must increase in the presence of high threats or newly discovered vulnerabilities.

Documentary evidence: findings, severity, owner, remediation, retest

  • Identification and Severity: Every vulnerability must be recorded with quantitative or qualitative values regarding impact and probability of occurrence.
  • Remediation prioritization: Remediation plans must prioritize patches based on the criticality detected and the risk profile.
  • Verification and monitoring: Control and verification of the effective resolution of identified vulnerabilities.
  • Third-party control: Obligation for ICT providers to manage and promptly report critical vulnerabilities related to their services.

Useful KPIs for audit and management

  • Mean Time to Detect and Resolve (MTTR) vulnerabilities.
  • Percentage of critical assets scanned within weekly deadlines.
  • Number of vulnerabilities open beyond the tolerance times defined in the mitigation plan.
  • Statistics and trends on vulnerabilities managed by third-party providers.

FAQ

  • Is a vulnerability scan sufficient?
  • No. Scanning is only an automated component. DORA requires a comprehensive management framework that includes root cause analysis, risk prioritization, and remediation verification.
  • Does the weekly scan apply to all assets?
  • No. The weekly obligation only concerns assets that support critical or important functions. For others, a risk-based approach applies.
  • How should the activity be documented?
  • It is necessary to adopt written procedures for recording findings, assigning owners, tracking patches, and securely storing reports for competent authorities.

Avoid penalties and disruptions: request a complete Gap Analysis of your vulnerability management process today to align it with DORA’s technical requirements.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!