DORA asset management represents the strategic prerequisite for the security of critical infrastructures. The effectiveness of the security tests mandated by the Digital Operational Resilience Act depends on the precision in defining the asset perimeter. The identification and classification of assets are essential to ensure that critical live production systems are adequately protected and tested.
Asset inventory and testing: a regulatory link
Article 8 of DORA states that the identification and classification of assets constitute the fundamental and initial steps for operational resilience. The programs provided for in Articles 24 and 25 and vulnerability management must be based on an accurate classification of assets, as vulnerability scanning must be commensurate with the risk profile of the asset itself. Failure to classify or the exclusion of critical assets can lead to insufficient or incorrect testing.
Identification of critical or important functions (CIF)
- Total identification: The financial entity must map all operational and business functions.
- Criticality assessment: The criteria, to be met according to Art. 3(22) of DORA, include the impact on financial stability, importance for daily operations, and the difficulty of replacement in the event of failure.
Mapping of assets, owners, dependencies, and exposure
Delegated Regulation (EU) 2024/1774 requires the maintenance of detailed records for every ICT asset. Each asset must include:
- Unique identifier and physical/logical location
- Ownership: identity of the responsible party
- Support for CIFs: relationship with critical functions
- Interdependencies with other assets or business functions
- Exposure to external networks or the Internet
- End-of-Life date provided by third-party vendors
Classification errors impacting tests
A frequent error in the DORA ICT asset inventory concerns the failure to map technological dependencies on third parties. If an ICT provider subcontracts services relevant to critical functions, the entire technological value chain must be recorded in the register of information. A further risk arises from the use of test environments other than live ones; DORA establishes that live systems must be used for advanced testing (TLPT), making updated and precise information on the assets involved essential.
Minimum output required for VA/PT
Before performing Vulnerability Assessment (VA) or Penetration Testing (PT), it is necessary to have:
- Updated Register of Information (RoI) on contractual agreements and ICT services
- CIF documentation: approved list of critical functions and related assets
- Data flow mapping: details of network connections and flows to define the attack surface
FAQ on DORA asset management
- Is a CMDB enough?
- A standard CMDB is generally not sufficient, as DORA also requires linking to CIFs, business continuity requirements (RTO/RPO), and the management of interdependencies with third-party providers.
- How to classify cloud assets?
- Cloud assets must be classified according to the DORA taxonomy (IaaS, PaaS, SaaS) and included in the general inventory, clearly defining the responsibilities between the entity and the provider.
- Procedure for linking assets and critical functions?
- A “criticality assessment” must be carried out to evaluate the impact of the loss of confidentiality, integrity, or availability of the asset on the supported business function.
Plan your perimeter correctly: participate in our asset classification and test scoping workshop to align your inventory with DORA’s technical requirements.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
