---
title: "Strengthening financial software security: A holistic approach to compliance and operational resilience"
description: Discover how financial institutions can enhance security and compliance by adopting robust software composition analysis and managing vulnerabilities in open source dependencies.
image: https://www.finos.org/hubfs/sonatype%20blog%20post%20sep%2024.png
---

[![FINOS](https://www.finos.org/hs-fs/hubfs/sofin%20assets/SOFIN%20LOGOS/finos-logo.png?width=543&height=126&name=finos-logo.png "FINOS")](https://finos.org)

- [Projects](https://www.finos.org/projects) 
    - [Artificial Intelligence (AI)](https://ai.finos.org/)
    - [Common Domain Model (CDM)](https://www.finos.org/common-domain-model)
    - [FDC3](https://www.finos.org/fdc3)
    - [Fluxnova](https://fluxnova.finos.org)
    - [FINOS Common Cloud Controls](https://www.finos.org/common-cloud-controls-project)
    - [High Performance Computing (HPC)](https://hpc.finos.org)
    - [OSERA](https://osera.finos.org/)
    - [Open Source Readiness Initiative](https://www.finos.org/open-source-readiness)
    - [OS-Climate](https://www.finos.org/os-climate)
    - [Try our Projects](https://www.finos.org/project-sandbox)
    - [All Projects Landscape](https://landscape.finos.org/)
- [Community](https://www.finos.org/engage-with-our-community) 
    - [FINOS Community Calendar](https://www.finos.org/calendar)
    - [Community Quickstart](https://www.finos.org/get-involved)
    - [FINOS Community Site](https://community.finos.org/)
    - [Contribute](https://community.finos.org/docs/governance/Software-Projects/contribution)
    - [Unable to Contribute?](https://www.finos.org/open-source-readiness)
    - [Join our Slack channel](https://finos-lf.slack.com/messages/finos-community/)
    - [Recognize a contributor](https://github.com/finos/community/issues/new?assignees=mcleo-d&labels=community-recognition&template=Community-Recognition.md&title=FINOS+Community+Recognition)
    - [Ambassador Program](https://www.finos.org/ambassador-program)
- [Membership](https://www.finos.org/membership-benefits) 
    - [Members](https://www.finos.org/members)
    - [Inquire](https://www.finos.org/membership-benefits#become-a-member)
    - [Join](https://joinnow.platform.linuxfoundation.org/?project=finos)
    - [Member ROI Summary & Calculator](https://www.finos.org/roi-report-calculator)
    - [Dependency Consumption Analysis](https://www.finos.org/dependency-consumption-analysis)
- Resources 
    - [2025 Mission & Vision](https://www.finos.org/2024-in-review-2025-vision)
    - [Research & Case Studies](https://www.finos.org/research-case-studies)
    - [Training](https://training.linuxfoundation.org/finos/)
    - [Open Source Maturity Model](https://osr.finos.org/docs/bok/OSMM/Introduction)
    - [Contributions Live Dashboard](https://metrics.finos.org)
    - [Our Github Organization](https://github.com/finos/)
    - [Our Developer Toolchain](https://odp.finos.org/)
    - [FINOS Store](https://store-finos.myshopify.com/)
- News & Events 
    - [This Week At FINOS](https://www.finos.org/this-week-at-finos)
    - [Community Blog](https://www.finos.org/blog)
    - [Newsletter](https://www.finos.org/newsletter)
    - [Podcast: Open Source in Finance](https://www.finos.org/open-source-in-finance-podcast)
    - [Press Releases](https://www.finos.org/press)
    - [FINOS Events](https://www.finos.org/hosted-events)
    - [Community Events](https://www.finos.org/featured-events)
    - [Community Spotlight](https://www.finos.org/community-spotlight)
    - [Stay Informed](https://www.finos.org/sign-up)
- [About](https://www.finos.org/about-us) 
    - [Stay Informed](https://www.finos.org/sign-up)
    - [FAQs](https://www.finos.org/faq)
    - [Contact Us](https://www.finos.org/contact-us)
    - [Governing Board](https://www.finos.org/governing-board)
    - [Technical Oversight Committee](https://www.finos.org/technical-oversight-committee)
    - [Team](https://www.finos.org/team)
    - [Governance](https://www.finos.org/governance)
    - [Code of Conduct](https://www.finos.org/code-of-conduct)
- [OSFF + Videos](https://events.linuxfoundation.org/open-source-finance-forum) 
    - [OSFF 2026](https://events.linuxfoundation.org/open-source-finance-forum/)
    - [OSFF Toronto 2026 Videos](https://www.finos.org/osff-toronto-2026-videos)
    - [OSFF New York 2025 Videos](https://www.finos.org/osff-nyc-2025-videos)
    - [OSFF London 2026 Videos](https://www.finos.org/osff-london-2026-videos)
    - [apidays Paris 2025 Videos](https://www.finos.org/apidays)

- [Projects](https://www.finos.org/projects) 
    - [Artificial Intelligence (AI)](https://ai.finos.org/)
    - [Common Domain Model (CDM)](https://www.finos.org/common-domain-model)
    - [FDC3](https://www.finos.org/fdc3)
    - [Fluxnova](https://fluxnova.finos.org)
    - [FINOS Common Cloud Controls](https://www.finos.org/common-cloud-controls-project)
    - [High Performance Computing (HPC)](https://hpc.finos.org)
    - [OSERA](https://osera.finos.org/)
    - [Open Source Readiness Initiative](https://www.finos.org/open-source-readiness)
    - [OS-Climate](https://www.finos.org/os-climate)
    - [Try our Projects](https://www.finos.org/project-sandbox)
    - [All Projects Landscape](https://landscape.finos.org/)
- [Community](https://www.finos.org/engage-with-our-community) 
    - [FINOS Community Calendar](https://www.finos.org/calendar)
    - [Community Quickstart](https://www.finos.org/get-involved)
    - [FINOS Community Site](https://community.finos.org/)
    - [Contribute](https://community.finos.org/docs/governance/Software-Projects/contribution)
    - [Unable to Contribute?](https://www.finos.org/open-source-readiness)
    - [Join our Slack channel](https://finos-lf.slack.com/messages/finos-community/)
    - [Recognize a contributor](https://github.com/finos/community/issues/new?assignees=mcleo-d&labels=community-recognition&template=Community-Recognition.md&title=FINOS+Community+Recognition)
    - [Ambassador Program](https://www.finos.org/ambassador-program)
- [Membership](https://www.finos.org/membership-benefits) 
    - [Members](https://www.finos.org/members)
    - [Inquire](https://www.finos.org/membership-benefits#become-a-member)
    - [Join](https://joinnow.platform.linuxfoundation.org/?project=finos)
    - [Member ROI Summary & Calculator](https://www.finos.org/roi-report-calculator)
    - [Dependency Consumption Analysis](https://www.finos.org/dependency-consumption-analysis)
- Resources 
    - [2025 Mission & Vision](https://www.finos.org/2024-in-review-2025-vision)
    - [Research & Case Studies](https://www.finos.org/research-case-studies)
    - [Training](https://training.linuxfoundation.org/finos/)
    - [Open Source Maturity Model](https://osr.finos.org/docs/bok/OSMM/Introduction)
    - [Contributions Live Dashboard](https://metrics.finos.org)
    - [Our Github Organization](https://github.com/finos/)
    - [Our Developer Toolchain](https://odp.finos.org/)
    - [FINOS Store](https://store-finos.myshopify.com/)
- News & Events 
    - [This Week At FINOS](https://www.finos.org/this-week-at-finos)
    - [Community Blog](https://www.finos.org/blog)
    - [Newsletter](https://www.finos.org/newsletter)
    - [Podcast: Open Source in Finance](https://www.finos.org/open-source-in-finance-podcast)
    - [Press Releases](https://www.finos.org/press)
    - [FINOS Events](https://www.finos.org/hosted-events)
    - [Community Events](https://www.finos.org/featured-events)
    - [Community Spotlight](https://www.finos.org/community-spotlight)
    - [Stay Informed](https://www.finos.org/sign-up)
- [About](https://www.finos.org/about-us) 
    - [Stay Informed](https://www.finos.org/sign-up)
    - [FAQs](https://www.finos.org/faq)
    - [Contact Us](https://www.finos.org/contact-us)
    - [Governing Board](https://www.finos.org/governing-board)
    - [Technical Oversight Committee](https://www.finos.org/technical-oversight-committee)
    - [Team](https://www.finos.org/team)
    - [Governance](https://www.finos.org/governance)
    - [Code of Conduct](https://www.finos.org/code-of-conduct)
- [OSFF + Videos](https://events.linuxfoundation.org/open-source-finance-forum) 
    - [OSFF 2026](https://events.linuxfoundation.org/open-source-finance-forum/)
    - [OSFF Toronto 2026 Videos](https://www.finos.org/osff-toronto-2026-videos)
    - [OSFF New York 2025 Videos](https://www.finos.org/osff-nyc-2025-videos)
    - [OSFF London 2026 Videos](https://www.finos.org/osff-london-2026-videos)
    - [apidays Paris 2025 Videos](https://www.finos.org/apidays)

![Community Blog](https://www.finos.org/hubfs/10.04.19.FINOS_WebsiteBanners_3.png)

# Community Blog

# Strengthening financial software security: A holistic approach to compliance and operational resilience

 September 10, 2024

[FINOS Team](https://www.finos.org/blog/author/finos-team)

Financial services institutions worldwide are facing increasingly stringent regulations, with added complexity for those operating in multiple regions.

Those operating in Europe will be keenly aware of DORA, the [Digital Operational Resilience](https://www.digital-operational-resilience-act.com/) [Act](https://www.digital-operational-resilience-act.com/). This regulation emphasizes a comprehensive approach to managing cybersecurity risks, especially those related to [software supply chains](https://www.sonatype.com/resources/articles/what-is-software-supply-chain).

As active contributors and members of [FINOS](https://www.finos.org/), Sonatype has observed a rising energy in the community to create value for its members and consumers of its projects — especially regarding security and compliance for regulations. To better understand the value being created by the community, let’s take a closer look at the complexities of recent regulatory changes.

*Author: Aaron Linskens, Technical Writer, Sonatype*

![sonatype blog post sep 24](https://www.finos.org/hs-fs/hubfs/sonatype%20blog%20post%20sep%2024.png?width=823&height=461&name=sonatype%20blog%20post%20sep%2024.png)

## Navigating DORA and U.S. cybersecurity regulations

Put forth in the European Union, DORA sets high standards for [ensuring operational resilience](https://www.sonatype.com/resources/guides/dora-compliance-guide) [across the financial sector](https://www.sonatype.com/resources/guides/dora-compliance-guide). It aims to ensure financial entities can withstand, respond to, and recover from [all types of information and communications technology disruptions and threats](https://www.sonatype.com/blog/dora-ict-risk-management-framework-what-to-know).

DORA emphasizes vulnerability management in software systems and mandates financial institutions regularly assess and address vulnerabilities, focusing on those threatening critical infrastructure integrity.

In the U.S., [executive orders and new regulations](https://www.sonatype.com/resource-hub/regulations-and-compliance) increasingly push for cybersecurity incident disclosures and operational resilience. Although regulations are fragmented, high-level directives demand greater transparency in cybersecurity practices. U.S. financial institutions must comply with cybersecurity incident disclosure requirements, promptly reporting breaches and vulnerabilities to regulators and affected parties.

As regulations increasingly emphasize enhanced security via vulnerability management, Sonatype believes this goal can be achieved with better [software composition analysis (SCA)](https://www.sonatype.com/blog/software-composition-analysis-sca-a-beginners-guide) and better management of [software dependencies](https://www.sonatype.com/blog/software-dependencies-a-beginners-guide).

## Securing open source dependencies

As a unique value for FINOS members, Sonatype is working with the FINOS Board of Directors to create a custom-tailored dependency consumption analysis for members.

Drawing on exclusive insights gained from [Maven Central](https://central.sonatype.com/), participating members will receive a report on when, where, and how their software teams are ingesting open source dependencies. In many cases, report recipients will find that additional processes and tools will be needed to bring their organization into compliance with regulations that they previously expected were met.

Following this effort, members have been invited by FINOS to aggregate findings into a comprehensive report that can be used by [Tidelift](https://tidelift.com/) in a special effort led by FINOS Staff. This initiative aims to make targeted security improvements to the most widely used open source packages, making supply chain security regulation compliance easier.

 

## Automated support for financial software security

Guided by FINOS staff and its Technical Oversight Committee, the community increasingly incorporates industry best practices into open source software production.

Efficient vulnerability management relies on automation, where SCA tools are crucial for managing vulnerabilities in open source software.

As institutions of all sizes [depend on open source](https://www.linuxfoundation.org/blog/blog/a-summary-of-census-ii-open-source-software-application-libraries-the-world-depends-on), SCA is now a cornerstone of effective cybersecurity, helping identify and manage vulnerabilities in their dependencies, especially in open source libraries and frameworks.

By implementing robust SCA tools, financial institutions can:

- Monitor open source components in their software supply chain.
- Identify known vulnerabilities in those components.
- Prioritize vulnerabilities based on their impact and exploitability.
- Track and manage software licenses to ensure compliance with licensing obligations.

## Transforming project security with Morphir

While many security advisories and insights are provided to projects by the Linux Foundation’s [LFX](https://lfx.linuxfoundation.org/tools/security/) platform, the FINOS [Morphir](https://morphir.finos.org/) project has recently brought advanced SCA tooling into its CI/CD pipelines.

SCA tools can be seamlessly integrated into [a financial institution’s software development life](https://www.sonatype.com/solutions/banking-and-financial-services) [cycle](https://www.sonatype.com/solutions/banking-and-financial-services), offering ongoing surveillance of vulnerabilities in open source components. By incorporating SCA with a policy-based approach, FINOS staff and maintainers are able to control the noise levels by selecting which elements are most important for the foundation.

 

![results](https://www.finos.org/hs-fs/hubfs/results.jpg?width=2046&height=419&name=results.jpg)

 

More FINOS projects are adopting this comprehensive SCA tooling in a single dashboard, enabling FINOS Staff to support maintainers in protecting their projects from open source malware. This initiative delivers value to users of FINOS open source software, reducing the steps needed to mitigate risks when using applications or systems like Morphir.

 

 

## Centralizing compliance for cloud services

Parallel to the discussion of open source package use is the topic of cloud services consumption, an equally critical element of enterprise supply chain security.

Through the [Common Cloud Controls](https://github.com/finos/common-cloud-controls) (CCC) project and related initiatives, Sonatype is part of a community effort working to create a standard to boost cloud adoption, security, and compliance.

![ccc](https://www.finos.org/hs-fs/hubfs/ccc.jpg?width=300&height=71&name=ccc.jpg)

 

The community has made significant progress in defining a common taxonomy for cloud services, a crucial step often overlooked due to the wide array of similar services each Cloud Service Provider offers. This evolving taxonomy highlights the essential features required for a service to be considered “portable” or equivalent within its category. The project aims to facilitate true hybrid-cloud adoption by certifying service interoperability.

Building on this progress, the community will release threat and control artifacts linked to features of each service category. These threats are mapped to standards like [MITRE ATT&CK](https://attack.mitre.org/), providing quick references for financial services GRC teams. Similarly, CCC’s controls align with mitigations from frameworks like [CCM](https://cloudsecurityalliance.org/research/cloud-controls-matrix), [ISO 27001](https://www.iso.org/standard/27001), and [NIST 800-53](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final). In collaboration with

FS-ISAC members, the FINOS community is developing infrastructure as code for secure-by-default deployment, enabling rapid deployment by teams. This collaboration also involves creating plugin-based validation tests to ensure CCC compliance.

 

## Building operational resilience and compliance

As cybersecurity regulations evolve globally, financial institutions face pressure to boost digital resilience. Frameworks like DORA in Europe, alongside global regulations, require a proactive approach to managing vulnerabilities, especially in open source.

By implementing SCA along with vulnerability management strategies, financial institutions ensure compliance and enhance security. Robust SCA tools help monitor and manage software supply chain vulnerabilities, keeping them compliant and resilient against cybersecurity threats.

Adopting these practices allows financial institutions to confidently navigate complex regulations, safeguarding systems and contributing to a secure global financial ecosystem.

 

[JOIN US AT THE OPEN SOURCE IN FINANCE FORUM (OSFF) THIS YEAR](https://events.linuxfoundation.org/open-source-finance-forum/)

[![Register to attend OSFF now!](https://no-cache.hubspot.com/cta/default/2419532/interactive-177336953712.png)](https://www.finos.org/hs/cta/wi/redirect?encryptedPayload=AVxigLI0T%2FSzNWheT%2FiqqNin92VIi5i3tHjfa75m0eS14lx%2Fh8iRibwVbd88lacA7CDpySr4aqIK1Oys4paa6H2VRzhrz1fHjUZplVkJW2qdygjHmIZY0q5r5nTIDpMmmx9yTV57sB0zh%2FNUwjpDKxn5%2BkCqsltA%2FrJEXotylANIrLNIma%2FtRTA3xu20olnyu9u5slN24iynZu1xLTSeBdV2wD8%3D&webInteractiveContentId=177336953712&portalId=2419532)

 

### Share this:

- [Tweet](https://twitter.com/share)

<https://www.finos.org/blog/strengthening-financial-software-security-sonatype>

[← Preview CNCF’s Track at OSFF NY 2024](https://www.finos.org/blog/preview-cncfs-track-at-osff-ny-2024)

[FINOS Q3 2024 All Community Call →](https://www.finos.org/blog/finos-q3-2024-all-community-call)

[![FINOS Logo](https://www.finos.org/hs-fs/hubfs/sofin%20assets/SOFIN%20LOGOS/FINOS_Icon_Wordmark_White.png?width=689&height=971&name=FINOS_Icon_Wordmark_White.png "FINOS Logo")](https://www.finos.org/)

[![Twitter logo](https://finos.org/hubfs/2419532/FINOS/website/logos/social-logos/twitter-blue-social-panel.png)](https://twitter.com/finosfoundation) [![GitHub logo](https://finos.org/hubfs/2419532/FINOS/website/logos/social-logos/github-black-social-panel.png)](https://finos.github.io) [![LinkedIn logo](https://finos.org/hubfs/2419532/FINOS/website/logos/social-logos/linkedin-blue-social-panel.png)](https://www.linkedin.com/company/finosfoundation) [![SlideShare logo](https://finos.org/hubfs/2419532/FINOS/website/logos/social-logos/Homepage%20Social%20Panel/slideshare-logo.png)](https://www.slideshare.net/finosfoundation) [![YouTube logo](https://finos.org/hubfs/2419532/FINOS/website/logos/social-logos/Homepage%20Social%20Panel/youtube_logo-1.png)](https://www.youtube.com/channel/UCfJAdRALzJ7J7snubrb_Y-Q)

[Contact Us](https://www.finos.org/contact-us)  
[info@finos.org](mailto:info@finos.org)  
+1 (650) 665-9773

[Privacy | ](https://www.finos.org/privacy-policy)[Terms of Service |](https://www.finos.org/terms-of-service)[Community Code of Conduct |](https://www.finos.org/code-of-conduct)[Email Preferences](https://www.finos.org/hs/manage-preferences/unsubscribe-simple)

![](https://px.ads.linkedin.com/collect/?pid=537250&fmt=gif)