FB pixel

Scottish Government emphasizes security of new platform for digital public services

Scottish Government emphasizes security of new platform for digital public services
 

Scotland is talking up the data security measures designed and built into ScotAccount, a single-sign on (SSO) service designed to streamline access to public services online. Laurie Brown, the digital information security officer for the Scottish Government, is spearheading efforts to provide strategic direction and governance for various digital public services, following the return of Scotland’s digital identity service.

According to a recent blog post, the ScotAccount digital identity service is intended to simplify the process of accessing public services by allowing users to sign in to multiple services with a single account. This system facilitates ease of use, and provides an option to verify and store personal information securely, which can be reused when applying for other services.

Brown’s strategy is built on three principles: privacy by design and default, security by design and default, and usability by design and default. The National Cyber Security Centre (NCSC) offers guidance to ScotAccount users, akin to the security practices required for banking, email, shopping, or social media.

The approach entails implementing both proactive and reactive security measures to safeguard information against cyber-attacks. This includes adhering to NCSC’s risk management guidance and establishing robust security governance and assurance protocols.

The ScotAccount platform follows Brown’s methodology for her security by design and default principle. The methodology, additionally, aligns with the UK’s Secure by Design Framework, embedding security measures and reactive capabilities in the service’s delivery and operation. The aim is to meet the public’s expectations for secure and private interactions with government services.

As ScotAccount approaches the final stages of its Beta phase, the blog post notes that the focus on “extrinsic assurance” — as per the NCSC model – is set to amplify. This involves external compliance and certification assessments, including the UK Government’s GovAssure scheme.

Additionally, ScotAccount is exploring compliance with the UK’s digital identity and attributes trust framework, potentially paving the way for future interoperability with the GOV.UK One Login service.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Opinions on UK Online Safety Act emphasize importance of enforcement

Online safety legislation is making headlines around the world. But in places where laws have taken effect, are they proving…

 

UK Home Office raises estimate for passport contract to 12 years, £576M

The UK Home Office has opened a third round of market engagement for its next major passport manufacturing and personalization…

 

US lawmakers move to restrict AI chatbots used by kids

A bipartisan pair of House and Senate bills would impose new federal restrictions on AI chatbots, including a ban on…

 

Utah age assurance law for VPN users takes effect this week

Privacy advocates and virtual private network (VPN) providers are up in arms over Utah’s Senate Bill 73 (SB 73), “Online…

 

CLR Labs wins ISO 17025 accreditation for biometrics testing across EU

Cabinet Louis Reynaud (CLR Labs) has been accredited for ISO/IEC 17025, the international standard for testing and calibration laboratories, in…

 

Leidos, Idemia PS advance checkpoint modernization with biometrics, CAT-2 systems

Leidos and Idemia Public Security have formed a strategic partnership to deploy biometric‑enabled eGates and integrated Credential Authentication Technology (CAT-2)…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events