1. Introduction One of the key projects of Prime Minister Juha Sipilä’s Government is the creation of a growth environment for digital business operations in Finland. One of the principal measures under this key project is the preparation and implementation of a national information security strategy for increasing the level of trust in the Internet and in digital practices. The main aims and principles for the strategy work are set out in the implementation plan for the key projects. The national information security strategy is intended to focus on ensuring competitiveness and suitable conditions for exports, developing the EU’s digital single market and promoting and protecting privacy and other fundamental rights. The strategy aims to bring about change whereby information security will be built into different systems, terminal devices and services by design. The strategy also deals with matters that damage trust, such as digital security incidents and large-scale invasions of privacy in communication networks. One element of the strategy covers the implementation of the EU’s Network and Information Security (NIS) Directive currently under negotiation. During this process an assessment will be made of the impact of national legislation on the opportunities of citizens and businesses to securely use digital services and business models while also managing the risks attached to handling data. The strategy is designed to increase the availability and use of commercial data encryption and protection methods in the single market. The implementation of the strategy will also serve to develop information security features in terminal devices, operating systems, browsers, search engines, messaging applications, cloud services and other important information and communications technology goods and services. The measures in the strategy will also be used to improve the interoperability, transparency and verifiability of security features in digital goods and services. At the same time, the ability to detect and investigate information security anomalies will be strengthened. An assessment will be made of the means which Finland could use to retain companies that provide information security expertise and services that are critical for businesses in Finland. Under the proposed EU Network and Information Security Directive, each Member State will have to prepare a national strategy setting out the framework, vision, objectives and priorities concerning network and information security at the national level. This strategy and its implementation will take account of the requirements of the proposed Directive, which is currently at the final stages of negotiation. 4

Select target paragraph3