PURI: http://data.europa.eu/2sa/elap/security-by-design
Category: Digital Public Service Implementation
Scope: Business agnostic
Principle: Security by design
Statement: (Statement) Security by Design refers to the principle that security should be integrated into the design and development of IT systems and digital public services from the outset. This approach ensures that security measures are an inherent part of the system, rather than being added as an afterthought.
IoP Layer: Legal IoP, Organisational IoP, Technical IoP
Principle Source: Security and Privacy Underlying Principle (8) of the European Interoperability Framework (EIF)
About source: The European Interoperability Framework is part of the Communication (COM(2017)134) from the European Commission adopted on 23 March 2017. The framework gives specific guidance on how to set up interoperable digital public services.
PA Governance: Common
Influence in DPS Implementation life-cycle: Obligation
Influence in implemented DPS attribute: Obligation
|
|
| elap:PURI | http://data.europa.eu/2sa/elap/security-by-design |
| dct:title | Security by design |
| dct:description | (Statement) Security by Design refers to the principle that security should be integrated into the design and development of IT systems and digital public services from the outset. This approach ensures that security measures are an inherent part of the system, rather than being added as an afterthought. |
| dct:description | (Rationale) Security by design encompasses the protection of valuable assets by embedding security protocols throughout the entire lifecycle of IT systems and digital public services. This principle ensures that data and technology are safeguarded within organisational boundaries, considering asset ownership. By securing access to data assets and controlling their dissemination, organisations can protect sensitive information and maintain trust. This proactive approach minimises vulnerabilities, reduces long-term costs, and ensures compliance with regulatory requirements. Ultimately, Security by Design fosters a robust security posture that adapts to evolving threats and enhances overall system resilience. |
| dct:description | (Implications) Implementing Security by design implies a comprehensive and systematic approach to security across all stages of creating digital public services, from design to implementation. This approach has holistic implications across multiple layers: (I) Legal Level: Ensures compliance with data protection regulations and legal standards; (II)Organizational Level: Promotes a culture of security awareness and responsibility among all stakeholders; (III) Technical Level: Involves integrating security features such as encryption, access controls, and real-time monitoring into the system architecture. It also supports automation and data-driven decision-making to enhance security measures. |
| elap:scope | Business agnostic |
| elap:Category | Digital Public Service Implementation |
| dct:source | Security and Privacy Underlying Principle (8) of the European Interoperability Framework (EIF) |
| dct:source | https://interoperable-europe.ec.europa.eu/collection/nifo-national-interoperability-framework-observatory/2-underlying-principles-european-public-services#2.4 |
| rdfs:comment | The European Interoperability Framework is part of the Communication (COM(2017)134) from the European Commission adopted on 23 March 2017. The framework gives specific guidance on how to set up interoperable digital public services. |
| dcat:theme | Legal IoP, Organisational IoP, Technical IoP |
| elap:paGovernance | Common |
| elap:influenceInDPSLifecycle | Obligation |
| elap:influenceInDPSAttribute | Obligation |