ANALYSIS OF THE IMPACT OF DIGITAL OPERATIONAL RESILIENCE ACT (DORA) REQUIREMENTS ON THE PROCESS OF SECURE SOFTWARE DEVELOPMENT
DOI:
https://doi.org/10.28925/2663-4023.2025.28.852Keywords:
DORA; Secure SDLC; cyberresilience; ICT risk management; financial institutions; monitoring; incident response.Abstract
The article provides a comprehensive analysis of the impact of the European Union’s Digital Operational Resilience Act (DORA) Regulation on the Secure Software Development Life Cycle (Secure SDLC) in the financial sector. In the context of the rapid digital transformation of banking, insurance and investment services, the DORA forms a new mandatory regulatory framework for digital operational resilience, covering a wide range of areas, including information and communication technology (ICT) risk management, mandatory reporting of serious cyber incidents, regular security testing, control of IT service providers, and coordination of threat information exchange between financial market participants. The paper discusses in detail the five key DORA requirements defined in the text of the Regulation, with an emphasis on their consistent integration into all stages of the Secure SDLC - from initialization, planning, requirements analysis, and architecture design to implementation, testing, deployment, technical support, modernization, and decommissioning. Particular attention is paid to the implementation of automated security testing tools (SAST, DAST, IAST), the use of abnormal activity detection systems (SIEM, UEBA), the implementation of Software Bill of Materials (SBOM) to increase component transparency, as well as the development and implementation of incident response plans (IRP) and business continuity plans (BCP). A table of alignment of the key DORA articles with the relevant phases of the SDLC life cycle is proposed, which allows identifying critical compliance points, reducing security gaps and optimizing the implementation of digital resilience requirements. The study examines modern approaches to integrating security practices into CI/CD processes, the importance of raising employees’ awareness of current cyber threats, and the formation of a security culture focused on proactive protection even after software deployment. It is noted that compliance with DORA requirements should not be viewed solely as a response to regulatory pressure, but as a basis for the long-term transformation of corporate digital security in financial institutions. The results of the study are of interest to software developers, information security professionals, risk management professionals, regulators, and internal and external auditors seeking to ensure compliance with new regulatory requirements and strengthen the digital resilience of organizations in a high-risk environment.
Downloads
References
The Digital Operational Resilience Act (DORA) - Regulation (EU) 2022/2554. (n. d.). https://www.digital-operational-resilience-act.com/
Preparing for DORA: 5 Pillars of DORA and How to Achieve Compliance. (n. d.). https://sigma.software/about/media/preparing-for-dora-5-pillars-of-dora-and-how-to-achieve-complia nce
Navigating DORA Compliance: Software Development Requirements for Financial Services Companies. (n. d.). https://jfrog.com/blog/navigating-dora-compliance-software-development-requirements-for-financialservices-companies/
Digital Operational Resilience Act (DORA) - Central Bank of Ireland. (n. d.). https://www.centralbank.ie/regulation/digital-operational-resilience-act-dora
What is DORA? - Microsoft Learn. (n. d.). https://learn.microsoft.com/en-us/compliance/dora/dora-what-is-dora
DORA Regulation: Summary, Compliance Checklist + Training – Hoxhunt. (n. d.). https://hoxhunt.com/blog/dora-regulation
Secure Software Development Lifecycle (SSDLC) - Security-as-a-Service.io. (n. d.). https://security-as-a-service.io/en/it-security-solutions/secure-software-development-lifecycle-ssdlc-how-companies-integrate-security-into-the-development-process-with-iso-27001-and-c5/
Third-Party Risk Management under DORA - SAP LeanIX. (n. d.). https://www.leanix.net/en/wiki/trm/third-party-risk-management-under-dora
Art. 6 ICT risk management framework - dora-info.eu. (n. d.). https://www.dora-info.eu/dora/article-6/
DORA: EU regulation on digital operational resilience of financial institutions – Deloitte. (n. d.). https://www.deloitte.com/cz-sk/en/services/consulting/perspectives/eu-dora-digital-operational-resilience-act-fo r-financial-services.html
Implementing DORA: EU Financial Entities, Here’s What You Should Know – Sprinto. (n. d.). https://sprinto.com/blog/dora-implementation/
Reporting Major ICT-related Incidents and Significant Cyber Threats under DORA - Central Bank of Ireland. (n. d.). https://www.centralbank.ie/regulation/digital-operational-resilience-act-dora/reporting-major-ict-related-inciden ts-and-significant-cyber-threats
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Євгеній Курій, Віталій Сусукайло, Анна Єрофеєва, Марта Нестерюк

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.