Software Dependency Management and DORA Open Source Analysis

Gestione dipendenze software e open source analysis DORA

The increasing complexity of IT infrastructures in the financial sector requires an in-depth assessment of software dependencies. With the Digital Operational Resilience Act (DORA), the management of third-party libraries and open source analysis have become central elements in ensuring operational resilience and the security of digital assets, as provided for by Article 25 of the regulation.

Open source analysis required by DORA

DORA establishes that open source software analyses must be included in the digital operational resilience testing program. The goal is to manage risks related to the software supply chain: a vulnerability in a shared library can compromise the entire infrastructure of a financial entity. According to regulatory requirements, open source analysis allows for the proactive identification of security flaws in third-party components to maintain control over operational risks.

Software dependencies and Delegated Regulation (EU) 2024/1773

Delegated Regulation (EU) 2024/1773 requires financial entities to analyze source code and proprietary software from third parties or open source projects before production deployment, searching for vulnerabilities and malicious code. Static and dynamic tests, anomaly detection, and the adoption of remediation plans are required.

Dependency inventory and CVE vulnerability monitoring

Effective dependency management requires systematic tracking of third-party libraries, version monitoring, timely updates, and accurate logging of every vulnerability impacting ICT systems. Procedures must include:

  • Constant monitoring and tracking of libraries, including open source ones, with related update management.
  • Registration of each detected vulnerability.
  • Prioritization of patch deployment based on the criticality of the vulnerability and the risk profile of the affected assets.
  • For critical or relevant assets, monitoring must be stringent; for non-critical off-the-shelf assets, tracking must still be guaranteed where possible.

SBOM: state of the art for compliance

Although DORA and the RTS do not explicitly mention the SBOM (Software Bill of Materials), the need to track libraries and versions makes the SBOM the most effective and widely used technical standard to ensure compliance. An SBOM acts as a complete inventory of software components, facilitating proactive monitoring and timely response to new public vulnerabilities (CVEs) involving specific libraries used by the entity.

Integration into the SDLC and patch management

The open source analysis required by DORA must be integrated into the Software Development Life Cycle (SDLC). Entities are required to protect the integrity of source code—both internal and third-party—and to link these activities with patch management. Software updates must be tested and implemented in representative staging environments before deployment to production to avoid operational disruptions. If an open source vulnerability is not covered by a patch, it is mandatory to identify and activate other mitigation measures.

FAQ

  • Does DORA mandate the SBOM?
  • The regulation requires tracking the use of third-party and open source libraries, monitoring their versions and updates. Although it does not use the term “SBOM,” creating a software bill of materials represents the most effective technical solution to meet this requirement.
  • How to manage libraries in legacy applications?
  • Entities must monitor whether ICT assets are still supported by vendors or developers. For legacy or unsupported assets, a risk management plan that mitigates their obsolescence is essential.
  • Does open source analysis replace pentesting?
  • No. Open source analysis focuses on dependencies and code and is part of the ordinary resilience tests provided for by Article 25. Such activities must be integrated with vulnerability assessments and penetration tests to evaluate the overall security of the systems.

Govern your software supply chain: request a review of software risk and critical dependencies to align your development with DORA’s security requirements.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!