3.3 Finnish companies will benefit from international standards and there will be digital goods and services with inbuilt information security available on the market Goods and services with inbuilt security features will be developed, made available and used in Finland. Finland will be able to offer terminal devices, operating systems, browsers, search engines, messaging applications, cloud services and other key digital goods and services whose information security features are so comparable that their transparency, efficiency and verifiability will be easy to assess. Finland will have the world’s most advanced commercial services for enabling companies to measure and reduce (including underwriting) information security risks that could cause financial loss to their business. Finland and the EU will adopt standards that make it easier to choose a reliable contractual partner in terms of information security. These objectives will also be extended to developing the Internet of Things (IoT), both nationally and internationally. MEASURES:  Trust in digital services and electronic transactions will be enhanced by launching a nationwide trust network for electronic identification. The aim is that the different operators can more easily use strong electronic identification and trust the identification data transmitted by others in the network. As part of the National Service Architecture Programme for the public sector, the State will develop a centralised service for the electronic identification of citizens.11  Conditions favourable for the creation of anonymisation services will be developed in cooperation between the public and private sector to help businesses manage the information security risks related to personal data processing.12  A study will be made of the user terms and data protection features of the most common terminal devices, operating systems, Internet browsers, search engines and messaging applications in regard to the ability of users to protect the data within their own business activities or in other activities.13  A study will be made of the need – from the user’s perspective – for certification of various data security and protection features and the impact of such certification on the trust placed in digital goods and services. The importance of certification and standardisation bodies to hardware and service providers in the ICT sector and their customers will be also studied.14 11 Responsibility: Ministry of Transport and Communications, Ministry of Finance, Population Register Centre Responsibility: Ministry of Transport and Communications, Ministry of Finance, Population Register Centre, Data Protection Ombudsman 13 Responsibility: Finnish Communications Regulatory Authority, Data Protection Ombudsman, Ministry of Finance 14 Responsibility: Ministry of Transport and Communications, Finnish Communications Regulatory Authority, Finnish Standards Association SFS 12 9

Select target paragraph3