Network Security Assessment in DORA for financial infrastructures

Network Security Assessment in DORA per infrastrutture finanziarie

The DORA Regulation requires financial entities to perform rigorous and constant verification of their network infrastructure, demanding in-depth assessments to ensure that the architecture can withstand, detect, and contain cyber threats. The digital operational resilience testing program, according to Article 25, must include structured network security assessments to ensure the continuity and security of critical or important functions.

What is a network security assessment under DORA

A network security assessment in the DORA context is a technical and analytical process that validates the effectiveness of network security policies, procedures, and tools. The objective is not only to identify software vulnerabilities but to verify the robustness of the network configuration and design to prevent unauthorized access, ensure the confidentiality and integrity of data in transit, and protect the continuity of critical functions.

Segmentation, remote access, firewalling, IAM, PAM, and logging

  • Segregation and Segmentation: The network must be segmented based on the criticality of the supported functions and the risk profile of ICT assets, limiting the lateral movement of attackers.
  • Firewalling and Connection Filters: Roles and responsibilities must be identified for the approval and review of firewall rules. In systems supporting critical functions, the review of rule adequacy is mandatory at least every six months.
  • Access Management (IAM and PAM): The implementation of network access controls is mandatory to prevent the connection of unauthorized devices. For the administration of critical assets, a separate and dedicated network is required.
  • Logging and Monitoring: It is necessary to record events related to network traffic and performance, with a level of detail proportional to the criticality of the asset. Logs must be protected against tampering and deletion.
  • Encryption in transit: All network connections, whether corporate, public, or wireless, must be encrypted according to the classification of the data being processed.

Hardening and Exposure Review for exposed assets

  • Network Hardening: Secure configuration baselines must be implemented for all network components, following vendor instructions and industry leading practices.
  • Exposure Management: Direct access from the Internet to devices used for the administration of information systems is prohibited.
  • Session Termination: Procedures must provide for the automatic closure of remote sessions after a predetermined period of inactivity.
  • Temporary Isolation: The network must be designed to allow the temporary isolation of subnets or components in the event of an incident.

Relationship with vulnerability assessment and pentest

The network security assessment sits between a vulnerability assessment and a penetration test. The vulnerability assessment is limited to an automated scan of known flaws, while the penetration test performs an active simulation of attacks. The network assessment focuses on configuration and architecture analysis to identify logical errors and points of failure that scans might not detect. It serves to map data flows and define the correct scope for vulnerability assessment and penetration test activities.

Evidence and remediation

  • The documentation produced must include the mapping and visual representation of networks and data flows.
  • The results of annual network architecture reviews must be reported.
  • A remediation plan must be provided that links the identified deficiencies to their root cause through a root cause analysis, assigning priority based on the risk to critical functions.

FAQ

  • Is it the same thing as a pentest?
  • No. The penetration test attempts to breach defenses; the network security assessment verifies that defenses (segmentation, firewalls, hardening) are configured according to policies and best practices.
  • Does it include the cloud?
  • Yes. DORA applies to all ICT assets, including cloud infrastructures and third-party services.
  • How to demonstrate the proportionality of the control?
  • According to Article 4, the complexity of the assessment depends on the entity’s size and risk profile, but the minimum requirements for segregation and semi-annual review for critical systems cannot be bypassed.

Protect your infrastructure: request a DORA-oriented Network Security Assessment to validate your segmentation and hardening before the authorities’ inspection.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!