Use case — Complying with DORA

DORA and Netwrix Endpoint Protector: stopping authorised data from leaving through a forbidden channel

A user may be perfectly entitled to view a piece of data without being entitled to copy it onto a USB stick, send it through an unauthorised service or transfer it to a personal device. DORA precisely distinguishes access to information from the way that information may then be stored, used or transferred.

Article 11 of Delegated Regulation (EU) 2024/1774 requires measures ensuring that only authorised storage media, systems and endpoints are used to transfer and store the financial entity's data. It also frames the use of removable media and explicitly requires measures to prevent data loss and leakage from systems and endpoints. Article 14 completes this requirement by asking for the prevention and detection of leakage during information transfers.

Netwrix Endpoint Protector addresses precisely this step: once access to the data has been authorised, it applies policies to devices and to certain exit channels in order to control what the user can actually transfer. The solution brings together Device Control, Content Aware Protection, eDiscovery and Enforced Encryption.

Controlling the media used to transfer data: DORA Article 11(2)(e)

DORA requirement

Article 11(2)(e)Only authorised storage media, systems and endpoints may be used to transfer or store data.

    Device Control

    • Detected devices
    • Rights per device type
    • Usage policies
    • Removable media control

    Article 11(2)(e) requires measures ensuring that only authorised storage media, systems and endpoints are used to transfer and store the organisation's data.

    This is the main role of Device Control. Endpoint Protector makes it possible to apply rights and policies to the different device categories and to the equipment detected on endpoints.

    Back to Claire. She legitimately holds the right to view a confidential financial report on her corporate workstation. If she plugs in a personal USB stick, her business entitlement has not changed: she can still read the report in the application. The endpoint policy, however, may consider that this device is not authorised to receive company data and prevent its use for that transfer.

    This difference is essential. IAM determines that Claire can access the document; Endpoint Protector controls whether the channel she wants to use to move it is acceptable.

    Framing removable media: DORA Article 11(2)(f)(iii)

    DORA requirement

    Article 11(2)(f)(iii)Frame the use of removable media according to accepted residual risk.

      Netwrix Endpoint Protector

      • Trusted Device
      • Enforced Encryption
      • Removable device control

      Contribution to this point, not full coverage of Article 11(2)(f).

      DORA also requires removable storage devices to be used only where the residual risk remains within the tolerance limits defined by the financial entity.

      Endpoint Protector makes it possible to distinguish authorised devices from other media and to apply appropriate control policies. Its Trusted Device function can in particular be associated with media meeting the criteria defined by the organisation.

      When data genuinely has to be carried on removable media, Enforced Encryption can complete this policy by encrypting the data on the device. Netwrix documents the use of Trusted Device with Enforced Encryption so that protected workstations accept only devices matching the configured trust level.

      This function must not be read as a complete answer to Article 11(2)(f). The same paragraph also requires other endpoint management and security mechanisms. Endpoint Protector must therefore not be presented as a substitute for an entire MDM or UEM strategy.

      Controlling content, not only the device: DORA Article 11(2)(i)

      DORA requirement

      Article 11(2)(i)Implement measures to prevent data loss and leakage from systems and endpoints.

        Content Aware Protection

        • Sensitive content detection
        • Policies per users / computers / groups / departments
        • Report / block / allow depending on policy

        Allowing or forbidding a USB stick is not enough when data can leave the company through many other channels. Article 11(2)(i) explicitly requires the identification and implementation of measures to prevent data loss and leakage for systems and endpoints.

        Endpoint Protector's Content Aware Protection module operates at this level. It makes it possible to create sensitive content detection policies applied to users, computers, groups or departments. The Netwrix documentation lists, among others, personal information, financial information, bank account numbers and various confidential documents among the content that policies can target.

        Depending on the configured policy, a transfer matching these criteria can be allowed, reported or blocked. This logic makes it possible to distinguish the right to access the file from the authorisation to exfiltrate it.

        In Claire's case, the rule therefore no longer needs to state that “all USB copies are forbidden”. It can address the content concerned, the user or the group they belong to and the channel used. Non-sensitive data may follow an authorised path while a report containing protected financial information triggers the control set out in the policy.

        The Netwrix documentation does, however, state an important limitation: Content Aware Protection cannot analyse files that are already encrypted, nor certain applications or communications that use encryption. Actual coverage therefore depends on the channels, applications and configurations effectively supported.

        Claire

        Is authorised to view a confidential financial report.

        Access to the data

        Authorised by IAM / AuthZ controls.

        Claire attempts a transfer

        • A. Personal USB stick
        • B. Channel covered by Content Aware Protection
        • C. Authorised removable media / Trusted Device

        Netwrix Endpoint Protector

        Device Control

        Is the device authorised?

        Content Aware Protection

        Does the content match a sensitive policy?

        Policy

        Depending on configuration

        • Allow
        • Report
        • Block

        For authorised media — Enforced Encryption

        If this policy is chosen.

        Ariovis conceptual diagram: control depends on the supported systems, operating systems, applications, modules, licences and channels.

        Preventing leakage during transfer: DORA Article 14(1)(b)

        DORA requirement

        Article 14(1)(b)Prevent and detect data leakage during information transfers.

          Content Aware Protection + Device Control

          • On the channels and endpoints effectively supported

          Article 14 specifically addresses the security of information in transit. Its paragraph 1(b) requires the prevention and detection of data leakage as well as the secure transfer of information between the financial entity and external parties. The corresponding policies must be defined according to the approved data classification and the ICT risk assessment.

          Endpoint Protector can contribute to this requirement when the transfer goes through a channel or an endpoint covered by its policies. Content Aware Protection monitors different exit points and can inspect sensitive content before transfer. Device Control handles in parallel the devices and media used to move the data.

          This capability does not turn Endpoint Protector into a universal solution for securing all company communications. Network exchanges, APIs, application interconnections, cloud services and other flows may require complementary controls. The value of endpoint DLP is precisely to control the area where a person holding legitimate access can still cause, deliberately or accidentally, an unauthorised data exit.

          Also identifying sensitive data present on endpoints

          Endpoint Protector also includes an eDiscovery module for searching sensitive data stored on endpoints and applying, depending on the configured functions and policies, remediation actions such as encryption, deletion or quarantine.

          This capability complements exit prevention without constituting a new DORA article on its own. It answers a prior problem: before deciding how to protect a file, it is useful to know where sensitive data sits on workstations.

          In a DORA approach, this visibility can help reconcile information classification with its actual location and determine the Device Control or Content Aware Protection policies required.

          Where Endpoint Protector fits into the DORA architecture

          Endpoint Protector comes after the first identity and access decisions. Netwrix Identity Manager can determine that Claire is legitimate to access the financial report; Ping verifies her identity; Axiomatics may decide that she is authorised to view that specific document. Endpoint Protector deals with another question: what can she then do with that data from her endpoint?

          In our example, Claire can therefore be perfectly authorised to read the report while being prevented from copying it to an unauthorised USB stick or transferring it through a channel covered by a DLP policy. If removable media are necessary for the business process, the organisation can apply specific requirements to them and, depending on the architecture, enforce their encryption.

          Netwrix Endpoint Protector is not a “DORA solution” and does not cover the whole of endpoint security addressed by Article 11. Its contribution is far more precise: controlling devices and certain exit channels, detecting sensitive content and preventing transfers that contradict the data protection policy.

          Going further

          Discuss DORA data leakage prevention

          Ariovis helps define data protection policies and implement controls on devices, sensitive content and the relevant exit channels.