FB pixel

Scottish Government emphasizes security of new platform for digital public services

Scottish Government emphasizes security of new platform for digital public services
 

Scotland is talking up the data security measures designed and built into ScotAccount, a single-sign on (SSO) service designed to streamline access to public services online. Laurie Brown, the digital information security officer for the Scottish Government, is spearheading efforts to provide strategic direction and governance for various digital public services, following the return of Scotland’s digital identity service.

According to a recent blog post, the ScotAccount digital identity service is intended to simplify the process of accessing public services by allowing users to sign in to multiple services with a single account. This system facilitates ease of use, and provides an option to verify and store personal information securely, which can be reused when applying for other services.

Brown’s strategy is built on three principles: privacy by design and default, security by design and default, and usability by design and default. The National Cyber Security Centre (NCSC) offers guidance to ScotAccount users, akin to the security practices required for banking, email, shopping, or social media.

The approach entails implementing both proactive and reactive security measures to safeguard information against cyber-attacks. This includes adhering to NCSC’s risk management guidance and establishing robust security governance and assurance protocols.

The ScotAccount platform follows Brown’s methodology for her security by design and default principle. The methodology, additionally, aligns with the UK’s Secure by Design Framework, embedding security measures and reactive capabilities in the service’s delivery and operation. The aim is to meet the public’s expectations for secure and private interactions with government services.

As ScotAccount approaches the final stages of its Beta phase, the blog post notes that the focus on “extrinsic assurance” — as per the NCSC model – is set to amplify. This involves external compliance and certification assessments, including the UK Government’s GovAssure scheme.

Additionally, ScotAccount is exploring compliance with the UK’s digital identity and attributes trust framework, potentially paving the way for future interoperability with the GOV.UK One Login service.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Certification becoming trust signal for procurement and market positioning

One consequence of the explosion of synthetic media and AI-generated identities is that trusted identity infrastructure has become strategically valuable…

 

IAD testing set to take off as QTSP deadline passes, EUDI Wallet onboarding begins

Independent assessments of biometric injection attack detection (IAD) are about to become significantly more prominent, with the deadline for Qualified…

 

UK’s proposed OS-level age verification could eliminate part of DVS market

The UK government is mooting device-level restrictions on nude images that could usher in a new era of a kid-friendly…

 

UK promises age assurance for social media, device-level child safety controls

How many times can a head of government pledge to do something about harmful social media platforms before they’re obligated…

 

Aware upgrades biometric orchestration platform with ROC, Mitek integrations

Aware has added ROC and Mitek as biometric technology partners for its digital identity orchestration platform, Awareness, as part of…

 

Appeals board upholds 4 FaceTec biometric liveness detection patents

The U.S. Patent Trial and Appeal Board (PTAB) has ruled in a fight over intellectual property for biometric liveness detection between…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events