Skip to main content

The Ísland.is App

Digital Iceland Frontpage
Digital Iceland Frontpage

Digital Iceland

Security audits and cyber security issues

Responsible and secure handling of information and data is fundamental in the services of Digital Iceland, which main objective is to help public institutions improve digital services by making the service more accessible, simple, and faster. Security management of Ísland.is is based on the policies of Digital Iceland, the Ministry of Finance and Economic Affairs and the Government of Iceland.

Information security is incorporated into the objectives and design of every service offered by Ísland.is. International information security standards and criteria are taken into consideration as well as into all service agreements that Digital Iceland enters into with developers and web teams.

In accordance with established requirements, Digital Iceland conducts regular security audits on its products and status assessments on the overall security of the website Ísland.is. The Cyber Security Committee of Digital Iceland reviews the security manager's annual audit plan. A regular reassessment of risks is conducted in addition to security audits. This includes reviewing regulations and standards pertaining to Digital Iceland's information security framework, while considering changes in operations, the legislative framework, technology, and/or network threats.

Public entities with websites within Ísland.is do not need to perform security audits or take measures regarding their institutional websites within Ísland.is but are responsible for the security of their data and other systems related to them.

Digital Iceland works in collaboration with Defend Iceland. Among the things Defend Iceland’s bug bounty platform screens are all of Digital Iceland’s core services, including My pages, the Application system and the Digital Mailbox, as well as the Ísland.is app and code repository on Github.

Further reading:
Cloud Policy of the Icelandic Public Sector
Policy on the security classification of data of the Icelandic state (Icelandic)
Data Protection Policy - Ísland.is
Information security policy - Ísland.is