3.3
Finnish companies will benefit from international
standards and there will be digital goods and services
with inbuilt information security available on the market
Goods and services with inbuilt security features will be developed, made available and used
in Finland. Finland will be able to offer terminal devices, operating systems, browsers, search
engines, messaging applications, cloud services and other key digital goods and services
whose information security features are so comparable that their transparency, efficiency and
verifiability will be easy to assess. Finland will have the world’s most advanced commercial
services for enabling companies to measure and reduce (including underwriting) information
security risks that could cause financial loss to their business. Finland and the EU will adopt
standards that make it easier to choose a reliable contractual partner in terms of information
security. These objectives will also be extended to developing the Internet of Things (IoT),
both nationally and internationally.
MEASURES:
Trust in digital services and electronic transactions will be enhanced by launching a
nationwide trust network for electronic identification. The aim is that the different
operators can more easily use strong electronic identification and trust the
identification data transmitted by others in the network. As part of the National Service
Architecture Programme for the public sector, the State will develop a centralised
service for the electronic identification of citizens.11
Conditions favourable for the creation of anonymisation services will be developed in
cooperation between the public and private sector to help businesses manage the
information security risks related to personal data processing.12
A study will be made of the user terms and data protection features of the most
common terminal devices, operating systems, Internet browsers, search engines and
messaging applications in regard to the ability of users to protect the data within their
own business activities or in other activities.13
A study will be made of the need – from the user’s perspective – for certification of
various data security and protection features and the impact of such certification on
the trust placed in digital goods and services. The importance of certification and
standardisation bodies to hardware and service providers in the ICT sector and their
customers will be also studied.14
11
Responsibility: Ministry of Transport and Communications, Ministry of Finance, Population Register Centre
Responsibility: Ministry of Transport and Communications, Ministry of Finance, Population Register Centre,
Data Protection Ombudsman
13
Responsibility: Finnish Communications Regulatory Authority, Data Protection Ombudsman, Ministry of
Finance
14
Responsibility: Ministry of Transport and Communications, Finnish Communications Regulatory Authority,
Finnish Standards Association SFS
12
9