DORA-Art25-P1

Article
25 (1)
Pillar
Digital Operational Resilience Testing
Regulation Ref
Regulation (EU) 2022/2554, Article 25(1)
Last Reviewed
2026-01-15

The digital operational resilience testing programme shall provide for the execution of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing.

Evidence Profiles

Vulnerability Assessment Report COMMON

Report documenting the results of vulnerability assessments and scans, including identified vulnerabilities, severity ratings, affected systems, and remediation recommendations as required by DORA Article 25.

Formats
PDF JSON
Evidence Class
vulnerability-assessment-report
Availability
COMMON
Update Frequency
quarterly
Typical Author
Security Testing Lead
Approval Chain
Security Testing Lead → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
VULNERABILITY ASSESSMENT REPORT
Nordvik Bank AG
Assessment ID: VA-2025-Q1-001
Assessment Date: 15 March 2025
Prepared by: Security Testing Lead
Reviewed by: Katrin Halvorsen, CISO
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

This report presents the findings of the Q1 2025 vulnerability assessment conducted
across Nordvik Bank AG's in-scope ICT infrastructure and applications. The assessment
was performed using a combination of automated scanning tools and manual validation,
covering 127 systems across all five security zones and the Bank's AWS cloud
environment.

Key Findings:
  — Total vulnerabilities identified: 89
  — Critical: 2 | High: 11 | Medium: 34 | Low: 42
  — Remediation rate from Q4 2024 assessment: 91%
  — New vulnerabilities since last assessment: 23
  — Recurring vulnerabilities: 7 (flagged for systemic review)

The two critical vulnerabilities relate to an unpatched Apache Struts component in
a legacy regulatory reporting module and an exposed administrative interface on a
development-adjacent network segment. Both have been escalated to the CISO for
immediate remediation within the 72-hour SLA.

Overall, the Bank's vulnerability posture has improved compared to Q4 2024, with
the total vulnerability count decreasing by 12% and the critical count remaining
stable. The remediation programme continues to address findings within defined SLAs.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

ASSESSMENT SCOPE

  Scope Element              Detail
  ─────────────────────────────────────────────────────────────────────────────
  Systems assessed           127 (of 143 total ICT assets)
  Network zones              DMZ, Production, Management, User, Cloud (AWS)
  Assessment type            Infrastructure vulnerability scan + web
                             application scan + cloud configuration review
  Tools used                 Qualys VMDR 10.x, Checkmarx SAST 9.6,
                             AWS Security Hub, Nessus Professional 10.7
  Scan window                10–14 March 2025
  Authenticated scanning     Yes (credentialed scans for all zones)
  Compliance benchmarks      CIS Benchmarks v8, DORA Art. 25, PCI DSS 4.0

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

METHODOLOGY

The assessment followed a four-phase methodology:

  Phase 1 — Discovery and Enumeration
    Network discovery scans to identify active hosts, open ports, and running
    services. Validated against the ICT asset inventory for completeness.

  Phase 2 — Automated Vulnerability Scanning
    Credentialed vulnerability scans using Qualys VMDR for infrastructure and
    Checkmarx for application code. AWS Security Hub for cloud configuration
    compliance. Scans executed during the approved maintenance window.

  Phase 3 — Manual Validation
    Manual verification of critical and high-severity findings to eliminate
    false positives. Includes contextual risk assessment considering the
    asset's criticality, network exposure, and existing compensating controls.

  Phase 4 — Reporting and Prioritisation
    Findings consolidated, deduplicated, and prioritised using the Bank's
    risk-based vulnerability scoring methodology (CVSS base score adjusted
    for asset criticality and threat intelligence).

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

FINDINGS SUMMARY

  Severity     Count    % of Total    Change vs Q4 2024
  ─────────────────────────────────────────────────────────────────────────────
  Critical       2        2.2%         0 (stable)
  High          11       12.4%        -3 (improved)
  Medium        34       38.2%        -5 (improved)
  Low           42       47.2%        -4 (improved)
  ─────────────────────────────────────────────────────────────────────────────
  Total         89      100.0%       -12 (improved)

Findings by Asset Category:

  Category                    Critical   High   Medium   Low    Total
  ─────────────────────────────────────────────────────────────────────────────
  Servers (Windows)              0        3       8       12      23
  Servers (Linux)                1        2       6        8      17
  Network Equipment              0        1       4        5      10
  Web Applications               1        3       7        6      17
  Databases                      0        1       3        4       8
  Cloud Configuration            0        1       4        5      10
  End-User Devices               0        0       2        2       4
  ─────────────────────────────────────────────────────────────────────────────
  Total                          2       11      34       42      89

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

DETAILED FINDINGS — CRITICAL

VULN-2025-001: Unpatched Apache Struts (CVE-2024-53677)
  Affected System:   SYS-005 (Regulatory Reporting — ABACUS)
  CVSS Score:        9.8 (Critical)
  Description:       Apache Struts 2.5.32 running on the ABACUS application
                     server is vulnerable to remote code execution via crafted
                     file upload parameters.
  Impact:            Full system compromise; potential access to regulatory
                     reporting data and connected database.
  Remediation:       Upgrade Apache Struts to version 6.4.0 or later.
                     Interim mitigation: restrict file upload functionality
                     and apply WAF rule.
  Deadline:          18 March 2025 (72-hour SLA)
  Owner:             IT Operations Team

VULN-2025-002: Exposed Administrative Interface
  Affected System:   SYS-014 (Firewall Management Interface)
  CVSS Score:        9.1 (Critical)
  Description:       Palo Alto firewall management interface accessible from
                     the User network zone due to misconfigured access rule.
                     Should be restricted to Management zone only.
  Impact:            Potential unauthorised access to firewall configuration;
                     could enable network segmentation bypass.
  Remediation:       Restrict management interface access to Management zone
                     IP ranges. Review all firewall access rules.
  Deadline:          18 March 2025 (72-hour SLA)
  Owner:             Network Operations Team

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RISK RATINGS

Overall Vulnerability Risk Rating: MEDIUM

  The Bank's vulnerability posture is assessed as Medium risk. While two critical
  vulnerabilities require immediate attention, the overall trend is positive with
  a 12% reduction in total findings and a 91% remediation rate from the previous
  quarter. The critical findings are isolated to specific systems and do not
  indicate a systemic control failure.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

REMEDIATION RECOMMENDATIONS

  Priority   Finding ID       Action                          Deadline
  ─────────────────────────────────────────────────────────────────────────────
  Immediate  VULN-2025-001    Patch Apache Struts              18 Mar 2025
  Immediate  VULN-2025-002    Restrict firewall mgmt access    18 Mar 2025
  High       VULN-2025-003    Update OpenSSL on 3 servers      29 Mar 2025
             through -013
  Medium     VULN-2025-014    Address medium findings          30 Jun 2025
             through -047
  Low        VULN-2025-048    Address low findings             30 Sep 2025
             through -089

Next scheduled assessment: Q2 2025 (June 2025)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Prepared by: Security Testing Lead
Reviewed by: Katrin Halvorsen, CISO
Date:        15 March 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

vulnerability_assessment_status — fs-vulnerability-assessment
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
  "evidenceClassId": "vulnerability-assessment-report",
  "factType": "vulnerability_assessment_status",
  "data": {
    "assessment_date": "2025-03-15",
    "total_vulnerabilities": 89,
    "critical_count": 2,
    "high_count": 11,
    "medium_count": 34,
    "low_count": 42,
    "remediation_in_progress": true,
    "remediated_count": 66,
    "next_assessment_date": "2025-06-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-20T09:00:00Z",
  "supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
  "evidenceClassId": "penetration-test-report",
  "factType": "penetration_test_results",
  "data": {
    "test_date": "2025-02-14",
    "tester_organisation": "CyberShield GmbH",
    "findings_count": 18,
    "critical_findings": 1,
    "high_findings": 3,
    "test_passed": false,
    "retesting_completed": false,
    "remediation_verified": false
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-20T09:00:00Z",
  "supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
  "evidenceClassId": "resilience-testing-programme",
  "factType": "basic_testing_coverage_status",
  "data": {
    "reporting_period_end": "2025-03-31",
    "vulnerability_assessments_performed": 4,
    "penetration_tests_performed": 1,
    "network_assessments_performed": 1,
    "gap_analyses_performed": 1,
    "source_code_reviews_performed": 2,
    "scenario_based_tests_performed": 1,
    "all_required_test_types_covered": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-04-05T09:00:00Z",
  "supersededBy": null
}

Penetration Test Report COMMON

Report documenting the results of penetration testing activities, including attack scenarios, findings, exploitation evidence, and remediation recommendations.

Formats
PDF
Evidence Class
penetration-test-report
Availability
COMMON
Update Frequency
annual
Typical Author
External Penetration Testing Firm
Approval Chain
Security Testing Lead → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
PENETRATION TEST REPORT
Nordvik Bank AG
Test ID: PT-2025-001
Test Date: 3–14 February 2025
Prepared by: CyberShield GmbH (External Penetration Testing Firm)
Reviewed by: Security Testing Lead, Nordvik Bank AG
Classification: Strictly Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

CyberShield GmbH was engaged by Nordvik Bank AG to conduct an annual penetration
test of the Bank's core banking platform, digital banking channels, and supporting
infrastructure. The test was performed between 3 and 14 February 2025 from both
external (internet-facing) and internal (assumed breach) perspectives.

Key Results:
  — Total findings: 18
  — Critical findings: 1
  — High findings: 3
  — Medium findings: 8
  — Low findings: 6
  — Overall assessment: The Bank's security posture is ADEQUATE with specific
    areas requiring remediation.

The single critical finding relates to an insecure direct object reference (IDOR)
vulnerability in the digital banking API that could allow an authenticated user to
access another customer's account summary data. This finding was reported to the
Bank's CISO immediately upon discovery on 5 February 2025 and a temporary mitigation
was applied within 6 hours.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SCOPE AND RULES OF ENGAGEMENT

  Scope Element              Detail
  ─────────────────────────────────────────────────────────────────────────────
  Target systems             Core Banking Platform (Temenos T24)
                             Digital Banking Portal (web application)
                             Mobile Banking API
                             Payment Gateway (SWIFT/SEPA interface)
                             Supporting infrastructure (AD, DNS, DB)
  Test type                  Black-box (external), Grey-box (internal)
  Network perspective        External: internet-facing services
                             Internal: assumed breach from User zone
  Social engineering         Included: phishing simulation (50 targets)
  Physical testing           Excluded (separate assessment)
  Testing window             Business hours: 08:00–18:00 CET
                             Active exploitation: maintenance window only
  Emergency contact          Katrin Halvorsen, CISO (+41 XX XXX XX XX)
  Data handling              No production customer data accessed or exfiltrated
                             Test accounts provided by the Bank

Rules of Engagement:
  — No denial-of-service testing against production systems
  — No modification or deletion of production data
  — Immediate notification to CISO for any Critical finding
  — All test traffic logged and identifiable by source IP range
  — Testing paused during any production incident

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

METHODOLOGY

The penetration test followed the OWASP Testing Guide v4.2 and PTES (Penetration
Testing Execution Standard) methodologies:

  Phase 1 — Reconnaissance (Days 1–2)
    Open-source intelligence gathering, DNS enumeration, service discovery,
    and technology fingerprinting of internet-facing assets.

  Phase 2 — Vulnerability Analysis (Days 3–5)
    Automated and manual vulnerability identification across web applications,
    APIs, network services, and infrastructure components.

  Phase 3 — Exploitation (Days 6–8)
    Controlled exploitation of identified vulnerabilities to assess real-world
    impact. Includes privilege escalation, lateral movement, and data access
    attempts.

  Phase 4 — Post-Exploitation (Days 9–10)
    Assessment of the extent of access achievable from compromised positions.
    Evaluation of detection and response capabilities.

  Phase 5 — Reporting (Days 11–12)
    Consolidation of findings, risk assessment, and remediation recommendations.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

ATTACK SCENARIOS

  Scenario 1: External Attacker — Internet-Facing Services
    Objective: Gain unauthorised access to customer data or internal systems
    via internet-facing services.
    Result: IDOR vulnerability in digital banking API exploited to access
    account summary data (Critical finding PT-001). Web application firewall
    bypassed for specific API endpoints.

  Scenario 2: Insider Threat — Assumed Breach from User Zone
    Objective: Escalate privileges and move laterally from a compromised
    workstation in the User zone.
    Result: Limited lateral movement achieved. Network segmentation effective
    in preventing direct access to Production zone. However, a misconfigured
    service account with excessive permissions was identified (High finding
    PT-004).

  Scenario 3: Phishing Simulation
    Objective: Assess employee susceptibility to targeted phishing attacks.
    Result: 8 of 50 targeted employees (16%) clicked the phishing link.
    3 employees (6%) entered credentials on the simulated phishing page.
    Results reported separately to HR and CISO for awareness training follow-up.

  Scenario 4: API Security Assessment
    Objective: Identify vulnerabilities in the mobile banking and payment APIs.
    Result: Rate limiting insufficient on authentication endpoint (High finding
    PT-002). JWT token validation weakness allowing token reuse after password
    change (High finding PT-003).

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

FINDINGS AND EVIDENCE

  ID        Severity   Title                                    CVSS
  ─────────────────────────────────────────────────────────────────────────────
  PT-001    Critical   IDOR in Digital Banking API               9.1
  PT-002    High       Insufficient Rate Limiting on Auth        7.5
  PT-003    High       JWT Token Reuse After Password Change     7.2
  PT-004    High       Excessive Service Account Permissions     7.0
  PT-005    Medium     Missing Security Headers (CSP, HSTS)      5.3
  PT-006    Medium     Verbose Error Messages in API             5.0
  PT-007    Medium     Outdated TLS Configuration (TLS 1.0)      5.5
  PT-008    Medium     Session Timeout Too Long (4 hours)        4.8
  PT-009    Medium     Missing Account Lockout on Admin Portal   5.8
  PT-010    Medium     Cross-Site Scripting (Stored) in CRM      6.1
  PT-011    Medium     SQL Injection (Blind) in Legacy Module    6.5
  PT-012    Medium     Insecure Cookie Attributes                4.3
  PT-013    Low        Information Disclosure in HTTP Headers     3.1
  PT-014    Low        Default Credentials on Test Instance       3.5
  PT-015    Low        Missing DNSSEC Configuration              2.8
  PT-016    Low        Weak Password Policy for Service Accts    3.8
  PT-017    Low        Unnecessary Open Ports on DB Server       3.2
  PT-018    Low        Outdated SSL Certificate on Internal Svc  2.5

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RISK ASSESSMENT

Overall Risk Rating: MEDIUM-HIGH

The critical IDOR vulnerability (PT-001) represents a significant risk to customer
data confidentiality. The three high-severity findings, if exploited in combination,
could enable an attacker to gain persistent access to internal systems. However, the
Bank's network segmentation, monitoring capabilities, and incident response readiness
provide meaningful compensating controls.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

REMEDIATION RECOMMENDATIONS

  Priority     Finding    Recommended Action                   Deadline
  ─────────────────────────────────────────────────────────────────────────────
  Immediate    PT-001     Implement proper authorisation        21 Feb 2025
                          checks on all API endpoints
  High         PT-002     Implement rate limiting and           14 Mar 2025
                          account lockout on auth endpoints
  High         PT-003     Invalidate JWT tokens on password     14 Mar 2025
                          change; reduce token lifetime
  High         PT-004     Review and restrict service account   14 Mar 2025
                          permissions; implement least privilege
  Medium       PT-005     Implement CSP, HSTS, and other        30 Apr 2025
               to PT-012  security headers; address remaining
                          medium findings
  Low          PT-013     Address low findings in next           30 Jun 2025
               to PT-018  scheduled maintenance cycle

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RETESTING PLAN

Retesting of critical and high-severity findings is scheduled for 28 March 2025.
CyberShield GmbH will verify that remediation actions have been effectively
implemented and that no regression has occurred.

  Retest Scope:  PT-001 through PT-004
  Retest Date:   28 March 2025
  Retest Type:   Targeted verification of remediated findings

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Prepared by: CyberShield GmbH
Lead Tester: [Lead Penetration Tester]
Reviewed by: Security Testing Lead, Nordvik Bank AG
Date:        14 February 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

vulnerability_assessment_status — fs-vulnerability-assessment
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
  "evidenceClassId": "vulnerability-assessment-report",
  "factType": "vulnerability_assessment_status",
  "data": {
    "assessment_date": "2025-03-15",
    "total_vulnerabilities": 89,
    "critical_count": 2,
    "high_count": 11,
    "medium_count": 34,
    "low_count": 42,
    "remediation_in_progress": true,
    "remediated_count": 66,
    "next_assessment_date": "2025-06-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-20T09:00:00Z",
  "supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
  "evidenceClassId": "penetration-test-report",
  "factType": "penetration_test_results",
  "data": {
    "test_date": "2025-02-14",
    "tester_organisation": "CyberShield GmbH",
    "findings_count": 18,
    "critical_findings": 1,
    "high_findings": 3,
    "test_passed": false,
    "retesting_completed": false,
    "remediation_verified": false
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-20T09:00:00Z",
  "supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
  "evidenceClassId": "resilience-testing-programme",
  "factType": "basic_testing_coverage_status",
  "data": {
    "reporting_period_end": "2025-03-31",
    "vulnerability_assessments_performed": 4,
    "penetration_tests_performed": 1,
    "network_assessments_performed": 1,
    "gap_analyses_performed": 1,
    "source_code_reviews_performed": 2,
    "scenario_based_tests_performed": 1,
    "all_required_test_types_covered": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-04-05T09:00:00Z",
  "supersededBy": null
}

Network Security Assessment Results PARTIAL

JSON-structured results of network security assessments including firewall rule reviews, network segmentation validation, and traffic analysis findings.

Formats
JSON
Evidence Class
network-security-assessment
Availability
PARTIAL
Update Frequency
semi-annual
Typical Author
Network Security Engineer
Approval Chain
Network Security Engineer → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

JSON — Inline Preview
{
  "assessmentId": "NSA-2025-H1-001",
  "assessmentDate": "2025-01-20",
  "institution": "Nordvik Bank AG",
  "assessedBy": "Network Security Engineer",
  "reviewedBy": "Katrin Halvorsen, CISO",
  "nextAssessmentDate": "2025-07-20",
  "scope": {
    "networksAssessed": 5,
    "networkZones": ["DMZ", "Production", "Management", "User", "Cloud (AWS VPC)"],
    "totalFirewallRules": 1247,
    "firewallRulesReviewed": 1247,
    "switchesAssessed": 34,
    "routersAssessed": 8
  },
  "complianceScore": 87.5,
  "complianceBenchmark": "CIS Benchmarks v8 — Network Devices",
  "segmentationAssessment": {
    "zonesValidated": 5,
    "segmentationEffective": true,
    "segmentationIssues": [
      {
        "issueId": "SEG-001",
        "severity": "Medium",
        "description": "Management zone accessible from User zone via legacy VPN tunnel configured for remote IT support. Tunnel should be restricted to specific source IPs.",
        "affectedZones": ["User", "Management"],
        "remediationAction": "Restrict VPN tunnel source IPs to IT support workstations only",
        "targetDate": "2025-03-15"
      },
      {
        "issueId": "SEG-002",
        "severity": "Low",
        "description": "Development zone has unrestricted outbound internet access. Should be proxied through the DMZ web proxy for logging and filtering.",
        "affectedZones": ["Development"],
        "remediationAction": "Route development zone internet traffic through DMZ proxy",
        "targetDate": "2025-06-30"
      }
    ]
  },
  "firewallRuleReview": {
    "totalRules": 1247,
    "activeRules": 1089,
    "disabledRules": 158,
    "shadowedRules": 23,
    "overpermissiveRules": 7,
    "expiredRules": 12,
    "findings": [
      {
        "findingId": "FW-001",
        "severity": "High",
        "description": "Seven firewall rules permit traffic from 'any' source to internal services. These rules were created as temporary exceptions during a migration in Q3 2024 and were not removed.",
        "affectedRules": ["FW-RULE-0892", "FW-RULE-0893", "FW-RULE-0894", "FW-RULE-0895", "FW-RULE-0896", "FW-RULE-0897", "FW-RULE-0898"],
        "remediationAction": "Replace 'any' source with specific IP ranges or remove rules if migration is complete",
        "targetDate": "2025-02-15"
      },
      {
        "findingId": "FW-002",
        "severity": "Medium",
        "description": "23 shadowed rules detected where a broader rule higher in the rule base renders a more specific rule ineffective. Indicates rule base complexity requiring cleanup.",
        "remediationAction": "Consolidate and reorder firewall rule base; remove shadowed rules",
        "targetDate": "2025-04-30"
      },
      {
        "findingId": "FW-003",
        "severity": "Low",
        "description": "12 rules reference expired temporary access grants (date-limited rules past their expiry). Rules are inactive but clutter the rule base.",
        "remediationAction": "Remove expired rules during next maintenance window",
        "targetDate": "2025-03-31"
      }
    ]
  },
  "openPortsAnalysis": {
    "totalOpenPorts": 342,
    "expectedOpenPorts": 328,
    "unexpectedOpenPorts": 14,
    "unexpectedPortDetails": [
      {
        "host": "prod-app-srv-07",
        "port": 8443,
        "service": "Apache Tomcat (debug)",
        "severity": "Medium",
        "description": "Debug port left open after deployment troubleshooting"
      },
      {
        "host": "prod-db-srv-02",
        "port": 1521,
        "service": "Oracle TNS Listener",
        "severity": "Low",
        "description": "Listener accessible from User zone; should be restricted to Production zone"
      }
    ]
  },
  "trafficAnalysis": {
    "analysisWindow": "2025-01-13 to 2025-01-19",
    "totalFlowsAnalysed": 4523891,
    "anomalousFlows": 127,
    "anomalyCategories": [
      {
        "category": "Unexpected cross-zone traffic",
        "count": 45,
        "severity": "Medium",
        "description": "Traffic from User zone to Management zone services not matching expected patterns"
      },
      {
        "category": "High-volume data transfers",
        "count": 12,
        "severity": "Low",
        "description": "Large data transfers during off-hours; verified as scheduled backup replication"
      },
      {
        "category": "Unencrypted internal traffic",
        "count": 70,
        "severity": "Medium",
        "description": "HTTP traffic between application servers in Production zone; should use TLS"
      }
    ]
  },
  "overallRiskRating": "Medium",
  "summary": "Network security posture is adequate with specific areas requiring attention. Firewall rule hygiene needs improvement, and two segmentation issues should be addressed. The network architecture provides effective zone separation for critical systems."
}

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

vulnerability_assessment_status — fs-vulnerability-assessment
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
  "evidenceClassId": "vulnerability-assessment-report",
  "factType": "vulnerability_assessment_status",
  "data": {
    "assessment_date": "2025-03-15",
    "total_vulnerabilities": 89,
    "critical_count": 2,
    "high_count": 11,
    "medium_count": 34,
    "low_count": 42,
    "remediation_in_progress": true,
    "remediated_count": 66,
    "next_assessment_date": "2025-06-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-20T09:00:00Z",
  "supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
  "evidenceClassId": "penetration-test-report",
  "factType": "penetration_test_results",
  "data": {
    "test_date": "2025-02-14",
    "tester_organisation": "CyberShield GmbH",
    "findings_count": 18,
    "critical_findings": 1,
    "high_findings": 3,
    "test_passed": false,
    "retesting_completed": false,
    "remediation_verified": false
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-20T09:00:00Z",
  "supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
  "evidenceClassId": "resilience-testing-programme",
  "factType": "basic_testing_coverage_status",
  "data": {
    "reporting_period_end": "2025-03-31",
    "vulnerability_assessments_performed": 4,
    "penetration_tests_performed": 1,
    "network_assessments_performed": 1,
    "gap_analyses_performed": 1,
    "source_code_reviews_performed": 2,
    "scenario_based_tests_performed": 1,
    "all_required_test_types_covered": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-04-05T09:00:00Z",
  "supersededBy": null
}

Resilience Testing Gap Analysis PARTIAL

CSV-structured gap analysis identifying areas where the institution's resilience testing programme falls short of DORA requirements, including coverage gaps and capability deficiencies.

Formats
CSV
Evidence Class
gap-analysis-report
Availability
PARTIAL
Update Frequency
annual
Typical Author
Compliance Officer
Approval Chain
Compliance Officer → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

CSV — Inline Preview
requirement_ref,requirement_description,current_status,gap_description,severity,remediation_action,target_date,responsible_owner
DORA Art.24(1),Establish comprehensive digital operational resilience testing programme,Compliant,No gap — programme established and approved by Board Risk Committee,N/A,N/A,N/A,CISO
DORA Art.24(2),Testing programme shall be proportionate to size and risk profile,Compliant,No gap — risk-based scope definition in place covering 88.8% of ICT assets,N/A,N/A,N/A,Security Testing Lead
DORA Art.24(3),Testing programme shall include range of tests and assessments,Partially Compliant,Source code reviews not yet integrated into CI/CD pipeline for all applications; currently manual and ad-hoc for legacy systems,Medium,Integrate SAST/DAST into CI/CD pipeline for all production applications,2025-06-30,AppSec Team Lead
DORA Art.24(4),Testing programme shall be reviewed and updated at least annually,Compliant,No gap — annual review completed January 2025,N/A,N/A,N/A,CISO
DORA Art.24(5),Testing shall be undertaken by independent parties,Partially Compliant,Internal vulnerability scans conducted by first-line IT team without formal independence attestation; external penetration tests properly independent,Medium,Establish formal independence attestation process for internal testing activities,2025-03-31,Head of Internal Audit
DORA Art.24(6),Maintain records of all testing activities for at least 5 years,Compliant,No gap — document retention policy covers all testing records with 5-year minimum,N/A,N/A,N/A,Compliance Officer
DORA Art.25(1),Perform vulnerability assessments and scans,Compliant,No gap — quarterly vulnerability assessments in place using Qualys VMDR,N/A,N/A,N/A,Security Testing Lead
DORA Art.25(1),Perform open-source analyses,Partially Compliant,Snyk deployed for new applications but legacy applications not yet onboarded for dependency scanning,Medium,Onboard all production applications to Snyk dependency scanning,2025-06-30,AppSec Team Lead
DORA Art.25(1),Perform network security assessments,Compliant,No gap — semi-annual network security assessments conducted,N/A,N/A,N/A,Network Security Engineer
DORA Art.25(1),Perform gap analyses,Compliant,No gap — this gap analysis fulfils the requirement,N/A,N/A,N/A,Compliance Officer
DORA Art.25(1),Perform physical security reviews,Partially Compliant,Physical security reviews conducted by Facilities team but not formally integrated into the resilience testing programme,Low,Integrate physical security review results into resilience testing programme reporting,2025-09-30,Security Testing Lead
DORA Art.25(1),Perform scenario-based tests,Compliant,No gap — quarterly tabletop exercises and annual simulation exercise conducted,N/A,N/A,N/A,Business Continuity Manager
DORA Art.25(1),Perform penetration testing,Compliant,No gap — annual external penetration testing by CyberShield GmbH,N/A,N/A,N/A,Security Testing Lead
DORA Art.25(1),Perform source code reviews,Non-Compliant,No formal source code review programme for legacy applications; only new development covered by automated SAST,High,Establish source code review programme covering all critical applications including legacy systems,2025-06-30,AppSec Team Lead
DORA Art.26(1),Carry out TLPT at least every 3 years,Non-Compliant,TLPT has not yet been performed; Bank is assessing whether it meets the designation criteria under Article 26(8),High,Complete TLPT designation assessment; if designated begin TLPT planning phase,2025-09-30,CISO
DORA Art.26(2),TLPT shall cover critical and important functions,Not Applicable,Pending TLPT designation assessment,N/A,Complete designation assessment first,2025-06-30,CISO
DORA Art.26(3),TLPT shall include threat intelligence phase,Not Applicable,Pending TLPT designation assessment,N/A,Complete designation assessment first,2025-06-30,CISO
DORA Art.27(1),Testers shall meet requirements for independence and expertise,Partially Compliant,External testers meet independence requirements; internal testing independence not formally attested,Medium,Implement formal tester independence attestation process,2025-03-31,Head of Internal Audit
DORA Art.27(2),Use external testers for TLPT,Not Applicable,Pending TLPT designation assessment,N/A,Identify qualified TLPT providers,2025-09-30,CISO
DORA Art.27(3),Ensure adequate resources for testing,Partially Compliant,Testing budget adequate for current programme but TLPT budget not yet allocated,Medium,Allocate TLPT budget in 2025 financial plan,2025-03-31,CFO

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

vulnerability_assessment_status — fs-vulnerability-assessment
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000003",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000003",
  "evidenceClassId": "vulnerability-assessment-report",
  "factType": "vulnerability_assessment_status",
  "data": {
    "assessment_date": "2025-03-15",
    "total_vulnerabilities": 89,
    "critical_count": 2,
    "high_count": 11,
    "medium_count": 34,
    "low_count": 42,
    "remediation_in_progress": true,
    "remediated_count": 66,
    "next_assessment_date": "2025-06-15"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-03-20T09:00:00Z",
  "supersededBy": null
}
penetration_test_results — fs-penetration-test-results
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000004",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000004",
  "evidenceClassId": "penetration-test-report",
  "factType": "penetration_test_results",
  "data": {
    "test_date": "2025-02-14",
    "tester_organisation": "CyberShield GmbH",
    "findings_count": 18,
    "critical_findings": 1,
    "high_findings": 3,
    "test_passed": false,
    "retesting_completed": false,
    "remediation_verified": false
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-20T09:00:00Z",
  "supersededBy": null
}
basic_testing_coverage_status — fs-basic-testing-coverage
{
  "factId": "c1d2e3f4-a5b6-7890-abcd-300000000005",
  "evidenceId": "d0e1f2a3-b4c5-6789-abcd-300000000001",
  "evidenceClassId": "resilience-testing-programme",
  "factType": "basic_testing_coverage_status",
  "data": {
    "reporting_period_end": "2025-03-31",
    "vulnerability_assessments_performed": 4,
    "penetration_tests_performed": 1,
    "network_assessments_performed": 1,
    "gap_analyses_performed": 1,
    "source_code_reviews_performed": 2,
    "scenario_based_tests_performed": 1,
    "all_required_test_types_covered": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-04-05T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

vulnerability_assessment_status

Schema ID
fs-vulnerability-assessment
Control
DORA-Art25-P1

Valid Ranges

assessment_date
within last 3 months for quarterly assessments
critical_count
should be 0 for compliant posture after remediation

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "critical_count": {
      "minimum": 0,
      "type": "integer"
    },
    "high_count": {
      "minimum": 0,
      "type": "integer"
    },
    "low_count": {
      "minimum": 0,
      "type": "integer"
    },
    "medium_count": {
      "minimum": 0,
      "type": "integer"
    },
    "next_assessment_date": {
      "format": "date",
      "type": "string"
    },
    "remediated_count": {
      "minimum": 0,
      "type": "integer"
    },
    "remediation_in_progress": {
      "type": "boolean"
    },
    "total_vulnerabilities": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "assessment_date",
    "total_vulnerabilities",
    "critical_count",
    "high_count",
    "remediation_in_progress"
  ],
  "type": "object"
}

penetration_test_results

Schema ID
fs-penetration-test-results
Control
DORA-Art25-P1

Valid Ranges

test_date
within last 12 months
critical_findings
should be 0 after remediation and retesting

Related Schemas

JSON Schema

{
  "properties": {
    "critical_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "findings_count": {
      "minimum": 0,
      "type": "integer"
    },
    "high_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "remediation_verified": {
      "type": "boolean"
    },
    "retesting_completed": {
      "type": "boolean"
    },
    "test_date": {
      "format": "date",
      "type": "string"
    },
    "test_passed": {
      "type": "boolean"
    },
    "tester_organisation": {
      "minLength": 1,
      "type": "string"
    }
  },
  "required": [
    "test_date",
    "tester_organisation",
    "findings_count",
    "critical_findings",
    "test_passed"
  ],
  "type": "object"
}

basic_testing_coverage_status

Schema ID
fs-basic-testing-coverage
Control
DORA-Art25-P1

Valid Ranges

reporting_period_end
within last 12 months
vulnerability_assessments_performed
at least 1 per year
penetration_tests_performed
at least 1 per year

Related Schemas

JSON Schema

{
  "properties": {
    "all_required_test_types_covered": {
      "type": "boolean"
    },
    "gap_analyses_performed": {
      "minimum": 0,
      "type": "integer"
    },
    "network_assessments_performed": {
      "minimum": 0,
      "type": "integer"
    },
    "penetration_tests_performed": {
      "minimum": 0,
      "type": "integer"
    },
    "reporting_period_end": {
      "format": "date",
      "type": "string"
    },
    "scenario_based_tests_performed": {
      "minimum": 0,
      "type": "integer"
    },
    "source_code_reviews_performed": {
      "minimum": 0,
      "type": "integer"
    },
    "vulnerability_assessments_performed": {
      "minimum": 0,
      "type": "integer"
    }
  },
  "required": [
    "reporting_period_end",
    "vulnerability_assessments_performed",
    "penetration_tests_performed",
    "network_assessments_performed"
  ],
  "type": "object"
}