1.
Introduction
One of the key projects of Prime Minister Juha Sipilä’s Government is the creation of a
growth environment for digital business operations in Finland. One of the principal measures
under this key project is the preparation and implementation of a national information security
strategy for increasing the level of trust in the Internet and in digital practices.
The main aims and principles for the strategy work are set out in the implementation plan for
the key projects. The national information security strategy is intended to focus on ensuring
competitiveness and suitable conditions for exports, developing the EU’s digital single market
and promoting and protecting privacy and other fundamental rights. The strategy aims to
bring about change whereby information security will be built into different systems, terminal
devices and services by design. The strategy also deals with matters that damage trust, such
as digital security incidents and large-scale invasions of privacy in communication networks.
One element of the strategy covers the implementation of the EU’s Network and Information
Security (NIS) Directive currently under negotiation. During this process an assessment will
be made of the impact of national legislation on the opportunities of citizens and businesses
to securely use digital services and business models while also managing the risks attached
to handling data.
The strategy is designed to increase the availability and use of commercial data encryption
and protection methods in the single market. The implementation of the strategy will also
serve to develop information security features in terminal devices, operating systems,
browsers, search engines, messaging applications, cloud services and other important
information and communications technology goods and services. The measures in the
strategy will also be used to improve the interoperability, transparency and verifiability of
security features in digital goods and services. At the same time, the ability to detect and
investigate information security anomalies will be strengthened. An assessment will be made
of the means which Finland could use to retain companies that provide information security
expertise and services that are critical for businesses in Finland.
Under the proposed EU Network and Information Security Directive, each Member State will
have to prepare a national strategy setting out the framework, vision, objectives and priorities
concerning network and information security at the national level. This strategy and its
implementation will take account of the requirements of the proposed Directive, which is
currently at the final stages of negotiation.
4