ANALYSIS OF THE IMPACT OF DIGITAL OPERATIONAL RESILIENCE ACT (DORA) REQUIREMENTS ON THE PROCESS OF SECURE SOFTWARE DEVELOPMENT

Authors

DOI:

https://doi.org/10.28925/2663-4023.2025.28.852

Keywords:

DORA; Secure SDLC; cyberresilience; ICT risk management; financial institutions; monitoring; incident response.

Abstract

The article provides a comprehensive analysis of the impact of the European Union’s Digital Operational Resilience Act (DORA) Regulation on the Secure Software Development Life Cycle (Secure SDLC) in the financial sector. In the context of the rapid digital transformation of banking, insurance and investment services, the DORA forms a new mandatory regulatory framework for digital operational resilience, covering a wide range of areas, including information and communication technology (ICT) risk management, mandatory reporting of serious cyber incidents, regular security testing, control of IT service providers, and coordination of threat information exchange between financial market participants. The paper discusses in detail the five key DORA requirements defined in the text of the Regulation, with an emphasis on their consistent integration into all stages of the Secure SDLC - from initialization, planning, requirements analysis, and architecture design to implementation, testing, deployment, technical support, modernization, and decommissioning. Particular attention is paid to the implementation of automated security testing tools (SAST, DAST, IAST), the use of abnormal activity detection systems (SIEM, UEBA), the implementation of Software Bill of Materials (SBOM) to increase component transparency, as well as the development and implementation of incident response plans (IRP) and business continuity plans (BCP). A table of alignment of the key DORA articles with the relevant phases of the SDLC life cycle is proposed, which allows identifying critical compliance points, reducing security gaps and optimizing the implementation of digital resilience requirements. The study examines modern approaches to integrating security practices into CI/CD processes, the importance of raising employees’ awareness of current cyber threats, and the formation of a security culture focused on proactive protection even after software deployment. It is noted that compliance with DORA requirements should not be viewed solely as a response to regulatory pressure, but as a basis for the long-term transformation of corporate digital security in financial institutions. The results of the study are of interest to software developers, information security professionals, risk management professionals, regulators, and internal and external auditors seeking to ensure compliance with new regulatory requirements and strengthen the digital resilience of organizations in a high-risk environment.

Downloads

Download data is not yet available.

References

The Digital Operational Resilience Act (DORA) - Regulation (EU) 2022/2554. (n. d.). https://www.digital-operational-resilience-act.com/

Preparing for DORA: 5 Pillars of DORA and How to Achieve Compliance. (n. d.). https://sigma.software/about/media/preparing-for-dora-5-pillars-of-dora-and-how-to-achieve-complia nce

Navigating DORA Compliance: Software Development Requirements for Financial Services Companies. (n. d.). https://jfrog.com/blog/navigating-dora-compliance-software-development-requirements-for-financialservices-companies/

Digital Operational Resilience Act (DORA) - Central Bank of Ireland. (n. d.). https://www.centralbank.ie/regulation/digital-operational-resilience-act-dora

What is DORA? - Microsoft Learn. (n. d.). https://learn.microsoft.com/en-us/compliance/dora/dora-what-is-dora

DORA Regulation: Summary, Compliance Checklist + Training – Hoxhunt. (n. d.). https://hoxhunt.com/blog/dora-regulation

Secure Software Development Lifecycle (SSDLC) - Security-as-a-Service.io. (n. d.). https://security-as-a-service.io/en/it-security-solutions/secure-software-development-lifecycle-ssdlc-how-companies-integrate-security-into-the-development-process-with-iso-27001-and-c5/

Third-Party Risk Management under DORA - SAP LeanIX. (n. d.). https://www.leanix.net/en/wiki/trm/third-party-risk-management-under-dora

Art. 6 ICT risk management framework - dora-info.eu. (n. d.). https://www.dora-info.eu/dora/article-6/

DORA: EU regulation on digital operational resilience of financial institutions – Deloitte. (n. d.). https://www.deloitte.com/cz-sk/en/services/consulting/perspectives/eu-dora-digital-operational-resilience-act-fo r-financial-services.html

Implementing DORA: EU Financial Entities, Here’s What You Should Know – Sprinto. (n. d.). https://sprinto.com/blog/dora-implementation/

Reporting Major ICT-related Incidents and Significant Cyber Threats under DORA - Central Bank of Ireland. (n. d.). https://www.centralbank.ie/regulation/digital-operational-resilience-act-dora/reporting-major-ict-related-inciden ts-and-significant-cyber-threats

Downloads


Abstract views: 0

Published

2025-06-26

How to Cite

Kurii, Y., Susukailo, V., Yerofeieva, A., & Nesteriuk, M. (2025). ANALYSIS OF THE IMPACT OF DIGITAL OPERATIONAL RESILIENCE ACT (DORA) REQUIREMENTS ON THE PROCESS OF SECURE SOFTWARE DEVELOPMENT. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 4(28), 400–412. https://doi.org/10.28925/2663-4023.2025.28.852