FB pixel

One Login 18 steps short of complying with UK national cybersecurity framework

One Login 18 steps short of complying with UK national cybersecurity framework
 

Gov.uk One Login is struggling to satisfy the cybersecurity expectations the Government Digital Service says it is underpinned by, a new report states, calling into question the wisdom of expanding the program into new use cases, like private sector digital identity interactions.

The One Login system was introduced in 2021 as a single sign-on (SSO) digital identity platform for access to public services. A 2022 business case said it was underpinned by the Cyber Assessment Framework managed by the National Cyber Security Centre (NCSC). The government set aside 330 million pounds to bring the system to production.

The Framework specifies 39 outcomes that national services should comply with to make them resilient against cyber attacks. But One Login complies with only 21, according to a Computer Weekly report based on a review by national cybersecurity auditor GovAssure.

That is an improvement on 5 out of 39 met as of 2024, Computer Weekly says.

The 39 outcomes the CAF specifies as contributing to cyber resilience are broken down into “indicators of good practice,” each of which must be present to satisfy the desired outcome.

The report details a history of warnings about the system’s security, and notes that the GDS has pushed back the completion target for its implementation of Secure by Design Principles from January to October.

The 2025 response from GDS to the One Login cybersecurity risk report shows that of five “extremely high” risks assessed in 2023, three have been downgraded to “medium” risks, one is rated “high,” and one remains unchanged. Of 12 high risk areas, seven have been reduced to “medium,” while the other five are unchanged.

The introduction of the Gov.uk digital wallet and the certification of One Login under the Digital Identity and Attributes Trust Framework has sparked concern among private sector digital ID and biometrics providers, and calls for the project’s scope to be limited.

GovAssure and the targeted improvement plan

Cybersecurity assurance scheme GovAssure was launched in 2023 to replace and extend the functions of the Departmental Security Health check, according to a promotional video produced by the Cabinet Office the year of its launch.

The video describes the outcomes-based approach of GovAssure, and the five stage assessment process it uses. The independent assurance review is the fourth step in the process, and is carried out by an accredited independent assessor. The final step is the production of a final technical report with a “targeted improvement plan.”

“This plan will be a useful tool for organizations to make the case for more resources, for vital improvements and to track progress,” says Government Security Group Cyber Assurance and Engagement Lead Lucy Dobson.

Perhaps One Login needs more resources.  Perhaps it needs more time.  Perhaps it needs more focus.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Leidos wins $130M FBI contract to support CJIS biometric services program

The Federal Bureau of Investigation (FBI) has awarded Leidos a five-and-a-half year $129.7 million contract to support its Criminal Justice…

 

Deepfakes are testing the limits of American governance

Under the looming omnipresence of AI, the United States finds itself at a crossroads in determining how best to regulate…

 

Move in House to block state AI laws draws bipartisan fire; Senate support questionable

The U.S. House of Representatives this week passed a sweeping budget reconciliation package that includes a controversial provision that would…

 

Mom sues porn sites for noncompliance with Kansas age assurance law

You can mess with the law – but don’t mess with the moms who catch their sons in compromising acts….

 

Spike in first party fraud could presage raging storm of generative AI

The latest version of LexisNexis Risk Solutions’ annual Cybercrime Report shows what a release calls “a significant swing in the…

 

Digital ID, payments providers are trying to solve eIDAS ambiguities

The EU has been busy building a regulatory foundation for its European Digital Identity (EUDI), which will be offered to…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events