Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Cloud Security Misconfigurations and Compliance: An Empirical Model for DORA Readiness in Financial Environments
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.
Stockholm University, Faculty of Social Sciences, Department of Computer and Systems Sciences.ORCID iD: 0000-0002-9925-1592
Number of Authors: 42025 (English)In: SECURWARE 202: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 139-146Conference paper, Published paper (Refereed)
Abstract [en]

The increasing reliance of financial institutions on cloud infrastructures has amplified concerns surrounding regulatory compliance and cybersecurity, particularly in light of the EU’s Digital Operational Resilience Act (DORA). This paper presents an experimental, empirical model designed to assess security misconfigurations in Amazon Web Services (AWS) and evaluate their alignment with DORA compliance requirements. Leveraging a Python-based scanning script built with the AWS Boto3 SDK, the study programmatically inspects critical AWS services—S3, Elastic Compute Cloud (EC2), Identity and Access Management (IAM), and Virtual Private Cloud (VPC) —within a controlled environment configured with known vulnerabilities. Each misconfiguration is automatically mapped to relevant DORA articles (Articles 5, 9, and 10), and accompanied by actionable remediation strategies. The results, visualized through a Streamlit dashboard and exportable PDF reports, demonstrate the tool’s ability to detect compliance gaps in real-time. Unlike previous work based on theoretical models or manual audits, this research offers a replicable, data-driven approach that bridges the gap between technical vulnerabilities and regulatory mandates. By doing so, it empowers financial institutions to strengthen their operational resilience and proactively align with emerging regulatory standards in dynamic cloud ecosystems.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA) , 2025. p. 139-146
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords [en]
Cloud Security; DORA Compliance; Financial Institutions; AWS Misconfigurations; Operational Resilience; Regulatory Technology (RegTech); Cybersecurity Governance Identity and Access Management (IAM).
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
URN: urn:nbn:se:su:diva-250021ISBN: 9781685583064 (electronic)OAI: oai:DiVA.org:su-250021DiVA, id: diva2:2017163
Conference
SECURWARE 2025, The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, Barcelona, Spain, 26-30 October, 2025.
Available from: 2025-11-27 Created: 2025-11-27 Last updated: 2025-12-03Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Länk till publikationen

Authority records

Seid, EliasBlix, Fredrik

Search in DiVA

By author/editor
Ferzali, AliMengistu, NaolSeid, EliasBlix, Fredrik
By organisation
Department of Computer and Systems Sciences
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

isbn
urn-nbn

Altmetric score

isbn
urn-nbn
Total: 284 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf