Cloud Security Misconfigurations and Compliance: An Empirical Model for DORA Readiness in Financial Environments
Number of Authors: 42025 (English)In: SECURWARE 202: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 139-146Conference paper, Published paper (Refereed)
Abstract [en]
The increasing reliance of financial institutions on cloud infrastructures has amplified concerns surrounding regulatory compliance and cybersecurity, particularly in light of the EU’s Digital Operational Resilience Act (DORA). This paper presents an experimental, empirical model designed to assess security misconfigurations in Amazon Web Services (AWS) and evaluate their alignment with DORA compliance requirements. Leveraging a Python-based scanning script built with the AWS Boto3 SDK, the study programmatically inspects critical AWS services—S3, Elastic Compute Cloud (EC2), Identity and Access Management (IAM), and Virtual Private Cloud (VPC) —within a controlled environment configured with known vulnerabilities. Each misconfiguration is automatically mapped to relevant DORA articles (Articles 5, 9, and 10), and accompanied by actionable remediation strategies. The results, visualized through a Streamlit dashboard and exportable PDF reports, demonstrate the tool’s ability to detect compliance gaps in real-time. Unlike previous work based on theoretical models or manual audits, this research offers a replicable, data-driven approach that bridges the gap between technical vulnerabilities and regulatory mandates. By doing so, it empowers financial institutions to strengthen their operational resilience and proactively align with emerging regulatory standards in dynamic cloud ecosystems.
Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA) , 2025. p. 139-146
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords [en]
Cloud Security; DORA Compliance; Financial Institutions; AWS Misconfigurations; Operational Resilience; Regulatory Technology (RegTech); Cybersecurity Governance Identity and Access Management (IAM).
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
URN: urn:nbn:se:su:diva-250021ISBN: 9781685583064 (electronic)OAI: oai:DiVA.org:su-250021DiVA, id: diva2:2017163
Conference
SECURWARE 2025, The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, Barcelona, Spain, 26-30 October, 2025.
2025-11-272025-11-272025-12-03Bibliographically approved