The security models behind DORA and ISO 27001 compliance

DORA

Compliance teams at European financial institutions are under growing pressure to prove that their security controls do more than satisfy a checklist.

As regulators sharpen their focus under DORA, NIS2 and ISO 27001, understanding the theoretical models behind access control has become a practical necessity rather than an academic exercise.

RegTech firm Copla recently discussed information security models, and their types and how they work.

Information security models are formal frameworks that dictate how data is protected, translating principles such as confidentiality, integrity and availability into enforceable rules. Several established models now underpin modern compliance architecture.

Bell-LaPadula governs confidentiality through “no read up, no write down” rules, restricting data flow to prevent leakage from secure to less secure environments, though it leaves data integrity unaddressed. Biba was built to close that gap, blocking low-integrity processes from corrupting high-integrity systems, a principle that maps directly onto DORA’s change management requirements.

Clark-Wilson extends integrity into the operational realm, mandating well-formed transactions and segregation of duties, effectively the four-eyes principle demanded in financial transaction authorisation.

Brewer-Nash, known as the Chinese Wall model, addresses conflict of interest by dynamically restricting access once a user has touched data from a competing entity, a concept highly relevant to institutions managing information barriers between investment banking and asset management arms.

Role-Based Access Control (RBAC) remains the most widely deployed operational model, assigning permissions to roles rather than individuals so that access reviews and reassignments stay manageable at scale.

Meanwhile, Zero Trust, formalised in NIST SP 800-207, has reshaped security architecture over the past decade by removing default trust entirely, requiring continuous verification, least-privilege access and an assumption that breach has already occurred.

For EU financial institutions, the article argues that combining Zero Trust as the architecture, RBAC for access implementation, Defence in Depth for control layering, and Clark-Wilson for transaction integrity offers the most efficient route to satisfying ISO 27001, DORA and NIS2 simultaneously, without building separate compliance structures for each.

The underlying message for compliance professionals is one of substance over box-ticking: auditors and supervisory authorities are increasingly trained to distinguish between controls that merely exist and controls that genuinely satisfy the security objective behind them.

Read the full Copla post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.