INITIATIVES
THE PUBLIC SECTOR
PROTECTS DATA
DIGITAL IDENTITIES AND
RIGHTS MANAGEMENT
Systems and data must only be accessed by the
right people. This will be ensured through correct
assignment of digital identities (e-identities) and
rights. The common method to assign correct
digital identities to the public and businesses moving to Denmark, for example, will be improved.
The possibility to surrender digital power of attorney and consent will be made easier. Stricter
requirements from the EU for mutual acceptance
of e-identities across borders must also be met.
7.1
7.4
WELL-MANAGED INFORMATION
SECURITY IN ALL AUTHORITIES
NEW GENERATIONS OF NEMID,
NEMLOG-IN AND DIGITAL POST
Information security must be managed better by
central, regional and local governments. All public authorities will therefore have to commit to
the principles set out in the international information security standard ISO27001. Efforts against
hacking incidents will be intensified. Information
security should be an intrinsic part of design and
development of public IT solutions on the basis of
the principles of 'data protection by design' and
'data protection by default'.
NemID, NemLog-in and Digital Post are necessary
to ensure efficient and secure digital self-service
for citizens and businesses. New tendering procedures will be held for the three infrastructure
components in the strategy period. Among other
things, the tendering procedures will ensure continuous development of the systems so that they
are up-to-date, user-friendly, and secure, and so
that they meet the needs of authorities, citizens
and businesses.
7.2
7.5
COMMON STANDARDS FOR
SECURE EXCHANGE OF
INFORMATION
SECURE ID SOLUTIONS FOR
CHILDREN AND YOUNG PEOPLE
Exchange of information must be conducted
securely throughout the public sector. Therefore, the current and future common public sector
standards for secure exchange of information will
be disseminated throughout the public sector.
50
7.3
SECURITY AND CONFIDENCE MUST BE IN FOCUS AT ALL TIMES
The need for a more secure identification solution for children and young people has arisen in
line with the increasing use of digital solutions.
This need applies in particular to the group of
12-15-year-olds who do not yet have a NemID, but
have an increasing need for digital confidentiality
in connection with login to school intranets, for
example. Methods to develop an ID solution for
children and young people will be analysed.
Focus area 8
Robust digital infrastructure
Denmark has come a long way in establishing an up-to-date and robust basis for
eGovernment. In the years to come, the
public sector will strive to consolidate the
Danish digital foundation. A robust digital foundation is about ensuring common
frameworks for IT architecture, and a consistent IT infrastructure.
Common frameworks for IT architecture in the public sector
Effective sharing of data across authorities
and with citizens and businesses requires
possibilities to reuse relevant data. For IT
systems in one public authority to be able to
retrieve, understand and use data originating
from a system in another authority requires
a common framework for how authorities
describe and exchange such data. While
many authorities, within their respective
areas, have developed architecture patterns
for their IT systems, common architecture
principles and guidelines are necessary for
systems to be able to exchange and use data
easily and securely across authorities. Principles and guidelines are based in part on
the common public sector work on the Basic
Data Programme.
Consistent IT infrastructure
The common public sector digital infrastructure and digital platforms such as NemID,
NemLogin, NemKonto bank account, virk.dk,
Digital Post, The Civil Registration System
etc. are now just as important for Danish
society as the physical infrastructure such
as roads, railways, the electricity grid and
the telephone network. The individual infrastructure components and systems are
now so closely linked that a breakdown in
one system will impact many other systems
and solutions in the public sector as well as
in the private sector. For instance, if NemID
is down, users cannot read their digital post,
use a self-service solution, log on to their
online bank account or on to borger.dk.
WHAT DOES A COMMON PUBLIC SECTOR IT ARCHITECTURE MEAN
FOR DATA SHARING?
IT architecture to share data consists of common principles and guidelines to describe and
exchange data, and it helps authorities retrieve and use data from each other's IT systems. The
architecture makes it easier, simpler and more secure to integrate public IT systems with one
another and it forms the basis for more efficient data sharing in the public sector.
SECURITY AND CONFIDENCE MUST BE IN FOCUS AT ALL TIMES
51