INITIATIVES THE PUBLIC SECTOR PROTECTS DATA DIGITAL IDENTITIES AND RIGHTS MANAGEMENT Systems and data must only be accessed by the right people. This will be ensured through correct assignment of digital identities (e-identities) and rights. The common method to assign correct digital identities to the public and businesses moving to Denmark, for example, will be improved. The possibility to surrender digital power of attorney and consent will be made easier. Stricter requirements from the EU for mutual acceptance of e-identities across borders must also be met. 7.1 7.4 WELL-MANAGED INFORMATION SECURITY IN ALL AUTHORITIES NEW GENERATIONS OF NEMID, NEMLOG-IN AND DIGITAL POST Information security must be managed better by central, regional and local governments. All public authorities will therefore have to commit to the principles set out in the international information security standard ISO27001. Efforts against hacking incidents will be intensified. Information security should be an intrinsic part of design and development of public IT solutions on the basis of the principles of 'data protection by design' and 'data protection by default'. NemID, NemLog-in and Digital Post are necessary to ensure efficient and secure digital self-service for citizens and businesses. New tendering procedures will be held for the three infrastructure components in the strategy period. Among other things, the tendering procedures will ensure continuous development of the systems so that they are up-to-date, user-friendly, and secure, and so that they meet the needs of authorities, citizens and businesses. 7.2 7.5 COMMON STANDARDS FOR SECURE EXCHANGE OF INFORMATION SECURE ID SOLUTIONS FOR CHILDREN AND YOUNG PEOPLE Exchange of information must be conducted securely throughout the public sector. Therefore, the current and future common public sector standards for secure exchange of information will be disseminated throughout the public sector. 50 7.3 SECURITY AND CONFIDENCE MUST BE IN FOCUS AT ALL TIMES The need for a more secure identification solution for children and young people has arisen in line with the increasing use of digital solutions. This need applies in particular to the group of 12-15-year-olds who do not yet have a NemID, but have an increasing need for digital confidentiality in connection with login to school intranets, for example. Methods to develop an ID solution for children and young people will be analysed. Focus area 8 Robust digital infrastructure Denmark has come a long way in establishing an up-to-date and robust basis for eGovernment. In the years to come, the public sector will strive to consolidate the Danish digital foundation. A robust digital foundation is about ensuring common frameworks for IT architecture, and a consistent IT infrastructure. Common frameworks for IT architecture in the public sector Effective sharing of data across authorities and with citizens and businesses requires possibilities to reuse relevant data. For IT systems in one public authority to be able to retrieve, understand and use data originating from a system in another authority requires a common framework for how authorities describe and exchange such data. While many authorities, within their respective areas, have developed architecture patterns for their IT systems, common architecture principles and guidelines are necessary for systems to be able to exchange and use data easily and securely across authorities. Principles and guidelines are based in part on the common public sector work on the Basic Data Programme. Consistent IT infrastructure The common public sector digital infrastructure and digital platforms such as NemID, NemLogin, NemKonto bank account, virk.dk, Digital Post, The Civil Registration System etc. are now just as important for Danish society as the physical infrastructure such as roads, railways, the electricity grid and the telephone network. The individual infrastructure components and systems are now so closely linked that a breakdown in one system will impact many other systems and solutions in the public sector as well as in the private sector. For instance, if NemID is down, users cannot read their digital post, use a self-service solution, log on to their online bank account or on to borger.dk. WHAT DOES A COMMON PUBLIC SECTOR IT ARCHITECTURE MEAN FOR DATA SHARING? IT architecture to share data consists of common principles and guidelines to describe and exchange data, and it helps authorities retrieve and use data from each other's IT systems. The architecture makes it easier, simpler and more secure to integrate public IT systems with one another and it forms the basis for more efficient data sharing in the public sector. SECURITY AND CONFIDENCE MUST BE IN FOCUS AT ALL TIMES 51

Select target paragraph3