FB pixel

Scottish Government emphasizes security of new platform for digital public services

Scottish Government emphasizes security of new platform for digital public services
 

Scotland is talking up the data security measures designed and built into ScotAccount, a single-sign on (SSO) service designed to streamline access to public services online. Laurie Brown, the digital information security officer for the Scottish Government, is spearheading efforts to provide strategic direction and governance for various digital public services, following the return of Scotland’s digital identity service.

According to a recent blog post, the ScotAccount digital identity service is intended to simplify the process of accessing public services by allowing users to sign in to multiple services with a single account. This system facilitates ease of use, and provides an option to verify and store personal information securely, which can be reused when applying for other services.

Brown’s strategy is built on three principles: privacy by design and default, security by design and default, and usability by design and default. The National Cyber Security Centre (NCSC) offers guidance to ScotAccount users, akin to the security practices required for banking, email, shopping, or social media.

The approach entails implementing both proactive and reactive security measures to safeguard information against cyber-attacks. This includes adhering to NCSC’s risk management guidance and establishing robust security governance and assurance protocols.

The ScotAccount platform follows Brown’s methodology for her security by design and default principle. The methodology, additionally, aligns with the UK’s Secure by Design Framework, embedding security measures and reactive capabilities in the service’s delivery and operation. The aim is to meet the public’s expectations for secure and private interactions with government services.

As ScotAccount approaches the final stages of its Beta phase, the blog post notes that the focus on “extrinsic assurance” — as per the NCSC model – is set to amplify. This involves external compliance and certification assessments, including the UK Government’s GovAssure scheme.

Additionally, ScotAccount is exploring compliance with the UK’s digital identity and attributes trust framework, potentially paving the way for future interoperability with the GOV.UK One Login service.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Meta’s smart glasses privacy defense falters when AI can use camera without recording light

Meta has spent months defending its rapidly expanding line of AI glasses by pointing to a small white light. The…

 

EU lets 9 Schengen countries delay full EES biometric checks 

The European Union has allowed at least nine Schengen countries to postpone full enforcement of its new Entry/Exit System (EES)….

 

Why organizations are supporting more authentication technologies — and how to do it

By Ashish Jain, CTO, OneSpan For almost a decade, the security industry’s conversations focused on what would replace traditional passwords….

 

ITL’s biometric age assurance offerings obtain ISO/IEC certification

UK biometrics firm Innovative Technology (ITL) has achieved ISO/IEC 27566-1:2025 certification across its full biometric age estimation range (MyCheckr, MyCheckrMini…

 

Philippines eyes privacy-preserving age checks for social media

The Philippines seems like it’s following through on its stronger rhetoric on social media platforms as it now focuses on…

 

Digital inclusion for refugee women must go beyond connectivity: GSMA

New GSMA research argues that digital inclusion efforts for refugee women must go beyond basic measures such as connectivity, mobile…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events