Security
Ensuring that digital products, platforms, services, and infrastructure are protected from unauthorised access, tampering, and failure – safeguarding the integrity, availability, and resilience of systems and the data they hold
Security means ensuring that public-serving digital systems remain trustworthy, resilient, and protected against unauthorised access, tampering, disruption, or loss.
We believe a person should be able to rely on the integrity and availability of the services they use, and trust that the information held by those services has not been altered, exposed, destroyed, or misused without authorisation.
For a public-serving entity, Security means protecting systems, records, and data through appropriate technical, operational, and organisational safeguards. It means controlling access to sensitive systems, securing communications and stored information, monitoring for intrusion or misuse, and maintaining clear procedures for responding to incidents, failures, or breaches.
It means designing systems that can recover from disruption without loss of integrity or continuity, maintaining secure backups and audit trails, and ensuring that important public records remain authentic, accessible, and protected over time. It means assigning clear responsibility for security oversight and reviewing protections regularly as systems, threats, and technologies change.
Example requirements (illustrative)
These example requirements are grounded in established international standards, regulations, and laws, which are listed in full in the section below.
-
Organisations maintain documented security policies covering access control, incident response, continuity, and recovery.
-
Access to sensitive systems and data is restricted to authorised individuals with appropriate authentication controls.
-
Encrypted connections are used for all public-facing services and administrative access.
-
Interoperability between systems is secured through documented authentication, authorisation, encryption, and audit mechanisms.
-
Security vulnerabilities and incidents are documented, assessed, and addressed within defined response timeframes.
-
Services are designed to remain operational and recoverable during technical failures, cyber incidents, or external disruption.
-
Digital records are stored and maintained in ways that preserve evidential integrity, authenticity, and chain of custody.
Standards, regulations, and laws informing this work
- EU | European Digital Identity Framework Regulation (eIDAS 2.0) 2024
- EU | Network and Information Security Directive (NIS2) 2022
- European Telecommunications Standards Institute (ETSI) | Securing Artificial Intelligence (SAI) Baseline Cyber Security Requirements for AI Models and Systems (EN 304 223) 2021
- Institute of Electrical and Electronics Engineers Standards Association (IEEE SA) | Standard for Local and Metropolitan Area Networks: Port-Based Network Access Control (IEEE 802.1X) 2020
- Internet Engineering Task Force (IETF) | Security and Privacy Standards
- International Organization for Standardization (ISO) | Guidelines for Digital Evidence (ISO/IEC 27037) 2012
- UK | Data (Use and Access) Act 2025
- UK | Data Protection Act 2018
- UK | Freedom of Information Act (FOI Act) 2000
- UK | National Cyber Security Centre (NCSC) Cyber Essentials Standard
- UK | Public Records Act 1958
Organisations working in this area
- Access Now | US-based nonprofit
- Center for Internet Security (CIS) | US-based nonprofit
- Chaos Computer Club | Germany-based nonprofit
- Citizen Lab | Canada-based research organisation
- CyberPeace Institute | Switzerland-based nonprofit
- Digital Security Lab (Лабораторія цифрової безпеки)| Ukraine-based nonprofit
- eQualitie | Canada-based nonprofit
- European Telecommunications Standards Institute (ETSI) | France-based standards organisation
- European Union Agency for Cybersecurity (ENISA) | Greece-based EU body
- European Cyber Security Organisation (ECSO) | Belgium-based membership organisation
- Institute of Electrical and Electronics Engineers Standards Association (IEEE SA) | US-based standards organisation
- Internet Engineering Task Force (IETF) | US-based standards organisation
- International Organization for Standardization (ISO) | Switzerland-based standards organisation
- Kantara Initiative | US-based standards organisation
- National Cyber Security Centre (NCSC) | UK government body
- OpenID Foundation | US-based standards organisation
- OpenSSL | Global project
- Qurium | Sweden-based nonprofit
- UK Cyber Security Council | UK-based membership organisation
- Wau Holland Stiftung (Wau Holland Foundation) | Germany-based nonprofit