WEBIST 2023

The International Conference on Web Information Systems and Technologies (WEBIST) will be held from 15 until 17 November 2023 in Rome, Italy.

WEBIST aims to bring together experts including researchers and engineers who are interested in technological advances and business applications of web-based information systems. The conference will have four main focusing on Web Information Systems, namely Internet Technology, Web Intelligence and Semantic Web, Social Network Analytics, HCI in Mobile Systems and Web Interfaces.

For more information, please visit the event page.

IoT Tech Expo Global 2023

The seventh annual Internet of Things (IoT) Tech Expo Global will be held from 30 November until 1 December 2023 in London, UK.

It is one of the 5 co-located events that will take place during these two days, among Cyber Security & Cloud, Blockchain, AI & Big Data, and Digital Transformation. The key topics that will be covered include digital Transformation, Data Analytics, IIoT & Smart Manufacturing, Connected Environments, Developing for the IoT, Process Optimisation, Sensor Deployment, Connectivity Considerations, 5G & Future Connectivity, Security & Standards, Cloud Computing, Autonomous Transportation, and  Device & Asset Management, among others.

For more information, please visit the event page

World Economic Forum issues ‘State of the Connected World 2023’ report

The World Economic Forum and the Council on the Connected World published the State of the Connected World 2023 report exploring governance gaps related to the internet of things (IoT). The report outlines the findings of a survey conducted with 271 experts worldwide to understand the state of IoT affairs. The COVID-19 pandemic has increased IoT demand in health, manufacturing, and consumer IoT. However, there is a lack of confidence when it comes to matters such as privacy and security.

Two main governance gaps are identified: (1) a lack of governmental regulation and implementation of industry standards and (2) IoT users are more susceptible to cyber threats and cyberattacks.

One recommendation is for businesses and governments to develop and implement practices to improve privacy and security and create a more inclusive and accessible IoT ecosystem. The need to improve equal access to technology and its benefits is also underscored.

The US publishes medical IoT cybersecurity regulations

The 2023 Federal spending bill includes cybersecurity requirements for IoT medical devices. According to the law, manufacturers of medical IoT devices will be obligated to (1) submit a plan on how to monitor post-market cybersecurity vulnerabilities that includes a coordinated vulnerability disclosure; (2) design and maintain processes and procedures to assure that the device and its related systems are secure, and provide updates and patches on a regular base and in critical events outside of regular cycles (3) provide a software bill of materials, including commercial, open-source, and off-the-shelf software components. The legislation also allows the FDA to take action against existing devices that were not submitted
for pre-market approval if they are found to be insecure.

Microsoft’s Cyber Signals report highlights a rise in cyber risks to critical infrastructure

The third edition of Cyber Signals, a yearly report which highlights security trends and insights from Microsoft’s 8,500 security experts and 43 trillion daily security signals, was recently launched. In this edition, experts present new information on broader threats to critical infrastructure posed by converging information technologies, the Internet of Things (IoT), and operational technology (OT) systems. 

Some of the report’s highlights include:

  • Unpatched, high-security vulnerabilities identified in 75% of the most common industrial controllers in customer OT networks.
  • Over one million connected devices publicly visible on the internet running Boa, an outdated and unsupported software widely used in IoT devices and software development kits.
  • An 78% increase in disclosures of high-severity vulnerabilities from 2020 to 2022 in industrial control equipment produced by popular vendors.

US National Institute of Standards and Technology issues draft guide for trusted IoT onboarding and lifecycle management

The US National Institute of Standards and Technology (NIST) and its National Cybersecurity Center of Excellence (NCCoE) published a draft practice guide for trusted internet of things (IoT) onboarding and lifecycle management. This guide demonstrates how organisations can protect their IoT devices and networks. It details standards, practices, and technology to demonstrate mechanisms for trusted network-layer onboarding of IoT devices. The guide also shows how to provide network credentials to IoT devices in a trusted manner and maintain a secure posture throughout the device lifecycle.

Egypt held its first IoT forum

The National Telecommunications Regulatory Authority of Egypt (NTRA), together with the Information Technology Industry Development Agency (ITIDA), held Egypt’s first forum for internet of things (IoT) services. The forum aims to promote and disseminate IoT services within Egypt’s market, particularly across national projects. Representatives of 36 public and private entities, technology manufacturers, and operators participated in the forum. The forum approved two main agendas. The first agenda concerns securing data, establishing regulatory and legislative frameworks, and raising awareness. The second agenda relates to using IoT services in public utilities such as health, education, environment, transportation, tourism, energy, industry, agriculture, irrigation, and smart cities sectors.

World Economic Forum

WEF is a not-for-profit foundation whose membership is composed of large corporations from around the world. We engage political, business, academic, and other leaders of society in collaborative efforts to shape global, regional, and industry agendas. Together with other stakeholders, we work to define challenges, solutions, and actions in the spirit of global citizenship. The Forum also serves and builds sustained communities through an integrated concept of high-level meetings, research networks, task forces, and digital collaboration.

Digital activities

The Fourth Industrial Revolution is one of the Forum’s key areas of work. Under this focus, we carry out a wide range of activities covering digital policy issues, from telecom infrastructure and cybersecurity to the digital economy and the future of work. We have set up multiple platforms and global forums focused on bringing together various stakeholders and initiatives to advance debates and foster cooperation on the issues explored. We also publish reports, studies, and white papers on our focus areas, and feature discussions on the policy implications of digital technologies in the framework of the Forum’s annual meeting in Davos and other events organised around the world.

Digital policy issues

Telecommunications infrastructure

The Forum’s work in the area of telecom/digital infrastructure is broadly dedicated to shedding light on the need to advance connectivity and evolve towards new network technologies as a way to support the transition to the fourth industrial revolution and support the growth of digital economies. For instance, the Global Future Council of New Network Technologies, active between 2018 and 2020, explored, among others, incentives for network development and the role of new network systems in driving value and innovation. The Forum also promotes the role of digital public infrastructures in enabling digital inclusion and advancing sustainable development. 

A specific focus area for the Forum is 5G. We have identified 5G as an issue of global importance and work on analysing the impacts of 5G on industry and society. In our report titled The impact of 5G: Creating new value across industries and society, we note that 5G will be critical because it will enable unprecedented levels of connectivity, allowing for superfast broadband, ultra-reliable low latency communication, massive machine-type communications, and high reliability/availability and efficient energy usage, all of which will transform many sectors, such as manufacturing, transportation, public services, and health. In another example, the 5G Outlook Series: Enabling inclusive long-term opportunities looks at what can be done to ensure that 5G is a technology that benefits people, businesses, and society. The role of satellites in delivering connectivity and the challenges associated with growing competition in Earth orbit are other areas explored by the Forum. The Global Future Council on the Future of Space explores ways in which international cooperation and public-private partnerships can drive sustainable and inclusive use of space resources.

Artificial intelligence

The Forum is carrying out multiple activities in the field of artificial intelligence (AI). The AI Governance Alliance brings together industry leaders, governments, academic institutions, and civil society to shape the future of AI governance. In April 2023, the Forum hosted the Responsible AI Leadership: A Global Summit on Generative AI event, which resulted in the Presidio Recommendations on Responsible Generative AI – a set of recommendations for responsible AI development, open innovation, and social progress. In addition, the Global Future Council on the Future of AI focuses on exploring the opportunities and risks associated with strong forms of AI.  

Examples of publications issued by the Forum with a focus on AI include a Blueprint for equity and inclusion in AI, a briefing paper on Data Equity: Foundational Concepts for Generative AI, and a guidebook on Harnessing the AI Revolution in Industrial Operations

The Forum also explores issues related to AI safety, security, and standards; AI ethics and values; and machine learning and predictive systems in relation to global risks and international security. We publish articles on the need to build a new social contract to ensure that technological innovation, in particular AI, is deployed safely and aligned with the ethical needs of a globalising world. We are also assisting policymakers in devising appropriate AI-related policies. For instance, we published a Framework for Developing a National Artificial Intelligence Strategy to guide governments in their efforts to elaborate strategies for the development and deployment of AI. 

In recent years, AI and its impact on national and international policy spaces have featured highly on the agenda of our annual meetings in Davos. AI is also the focus of dedicated events such as the AI Governance Summit organised in November 2023. 

Blockchain and cryptocurrencies

The Forum works on governance issues related to the equity, interoperability, security, transparency, and trust of blockchain and distributed ledger technology (DLT). We also analyse the relationship between blockchain and cybersecurity and international security, as well as the future of computing. We publish papers on issues such as blockchain data storage, the challenges blockchain faces and its role in security, as well as guides such as the Blockchain Development Toolkit to guide organisations through the development and deployment of blockchain solutions.

Internet of things

The Forum’s Centre for Urban Transformation explores various issues related to the implications of connected devices and smart technologies. For example, the Council on the Connected World focuses on strengthening innovation and the global governance of connected technologies to maximise the positive benefits and minimise harm for all. One specific area of work for the Council is the security of IoT devices; in 2022, the Forum facilitated a joint Statement of Support on consumer IoT device security outlining key security requirements for consumer-facing devices. In 2023, the Council published the State of the Connected World report, which tracks governance gaps related to IoT. 

The Global New Mobility Coalition explores issues related to sustainable mobility, including when it comes to the governance of shared, electric, and automated mobility. 

Other IoT-related issues that the Forum has been exploring through various publications and initiatives include the industrial internet, the safety of smart home products, and challenges associated with the concept of the internet of bodies. In cooperation with the Massachusetts Institute of Technology (MIT), we published a report on Realizing the Internet of Things – a Framework for Collective Action outlining five pillars for the development of IoT: architecture and standards, security and privacy, shared value creation, organisational development, and ecosystem governance. 

We also lead the G20 Global Smart Cities Alliance on Technology Governance, dedicated to promoting the responsible and ethical use of smart city technologies.

Emerging technologies

Virtual reality

The Forum’s Global Future Council on Virtual and Augmented Reality focuses on raising awareness of the positive and negative aspects of the widespread adoption of VR/AR technologies. We carry out policy research and analysis related to the impact of VR/AR on society and its security implications in publications on issues such as immersive media technologies, AR innovation in manufacturing, and privacy in the context of VR use.

The Forum also pays attention to developments related to the metaverse and issues various publications on this topic. For instance, Exploring the Industrial Metaverse: A Roadmap to  the Future provides a framework for discussing steps towards a valuable ecosystem for the industrial metaverse, while the reports on Social Implications of the Metaverse and Privacy and Safety in the Metaverse explore the implications of metaverse adoptions for individuals and society at large. These and similar publications are issued in the context of the Defining and Building the Metaverse Initiative, whose focus is on ‘guiding the development of a safe, interoperable, and economically viable metaverse’.  

Quantum computing

The Forum has created the Global Future Council on the Future of Quantum Economy, which looks into how various actors (governments, businesses, etc.) can take action to maximise the potential offered by quantum technologies. In addition, the Quantum Economy Network offers a platform for governments, businesses, and academia to shape the development of quantum technologies and prepare for their introduction into the economy. The Quantum Security initiative brings together stakeholders from governments, the private sector, academia, and non-profit organisations to exchange ideas and cooperate on issues related to promoting the secure adoption of quantum technologies. 

The Forum publishes regularly on matters related to quantum computing and quantum technologies. A few examples include the State of Quantum Computing: Building a Quantum Economy, Quantum Computing Governance Principles, and Transitioning to a Quantum-Secure Economy.

Cybercrime

Under its Centre for Cybersecurity, the Forum runs the Partnership against Cybercrime project, focused on advancing public-private partnerships (e.g. between law enforcement agencies, international organisations, cybersecurity companies, and other actors) to combat cybercrime. Outputs of the partnership include, for instance, the Recommendations for Public-Private Partnership against Cybercrime and the Cybercrime Prevention Principles for Internet Service Providers

We host a Cybercrime Atlas Initiative dedicated to strengthening coordination between the private sector and law enforcement in fighting cybercrime. 

Cybercrime also constitutes the focus of various studies and articles we have published, which delve into issues such as emerging threats and ways to tackle them. 

Network security/critical infrastructure/cybersecurity

The Forum has launched a Centre for Cybersecurity dedicated to ‘fostering international dialogues and collaboration between the global cybersecurity community both in the public and private sectors’. Multiple projects are run under this platform, such as the Cybersecurity Learning Hub and the Digital Trust initiative. The cyber resilience of critical sectors, such as electricity and the oil and gas industry, is also a focus area for us. 

The Centre also issues reports and other publications covering various cybersecurity topics. Examples include the Global Cybersecurity Outlook; the insight report on Cybersecurity, Emerging Technology, and Systemic Risks; and the Principles for Board Governance of Cyber Risk.

The Forum hosts a Global Future Council on the Future of Cybersecurity, which explores modalities for strengthening cyber risk management across economies and societies. Quantum security and digital trust are among the Council’s focus areas. 

Every year, we bring together actors from the public and private sectors to foster collaboration on making cyberspace safer and more resilient, in the framework of the Annual Meeting on Cybersecurity

Data governance

The Forum has established a Data Policy Platform under our Centre for the Fourth Industrial Revolution, dedicated to developing innovative approaches to enable the responsible use of data.  Within this platform, the Data for Common Purpose Initiative aims to support the creation of flexible data governance models, oriented around common purposes. Examples of white papers published by the initiative include Data for Common Purpose: Leveraging Consent to Build Trust and Towards a Data Economy: An Enabling Framework

The Cross-Border Data Flows project under the Forum’s Digital Trade Initiative looks at how policymakers can advance data transfer governance arrangements while ensuring policy interoperability for data flows. 

The Forum regularly publishes reports and papers on data governance issues such as restoring trust in data, cross-border data flows, data protection and security, among others.

E-commerce and trade and digital business models

Several activities and projects run by the Forum focus on e-commerce and broader digital economy-related issues. Under our Digital Trade initiative (part of the Centre for Regions, Trade and Geopolitics), we have been exploring opportunities and challenges associated with digital trade, while also engaging in the shaping of global, regional, and industry agendas on digital trade. Projects run within the initiative include, among others, the Digital Economy Agreement Leadership Group – which aims to contribute to the growth of inclusive and sustainable digital economies, and the TradeTech project – which facilitates dialogue on public policy and regulatory practices related to digital trade. The Digital Payments for Trade and Commerce Advisory Committee – also part of the Digital Trade initiative – is dedicated to fostering interoperability, inclusivity, and coherent regulatory reforms for digital payments.

E-commerce is also tackled in studies, white papers, and events we produce, which address issues such as e-commerce in emerging markets, the impact of e-commerce on prices, and digital currencies. 

Under the Centre for the New Economy and Society, we bring together various stakeholders to promote new approaches to competitiveness in the digital economy, with a focus on issues such as education and skills, equality and inclusion, and improved economic opportunities for people.

Future of work

The future of work is a topic that spans multiple Forum activities. For instance, under the Centre for the New Economy and Society, several projects focus on issues such as education, skills, upskilling and reskilling, and equality and inclusion in the world of work. We have also launched a Reskilling Revolution Initiative, aimed at contributing to providing better jobs, education, and skills to one billion people by 2030. Projects under this platform include, among others, Education 4.0 (focused on mapping needed reforms to primary and secondary education systems), Education and Skills Country Accelerators (dedicated to advancing gender parity, promoting upskilling and reskilling, and improving education systems), and Skills-first (focused on transforming adult education and workforce skills). Also part of the Reskilling Revolution is the Future Skills Alliance, whose main objective is to facilitate the adoption of skills-first management practices and give workers a fair and equal opportunity to excel in the labour market. 

The Forum publishes regular reports on the Future of Jobs, exploring the evolution of jobs and skills and how technology and socio-economic trends shape the workplace of the future. Other notable publications and tools developed by the Forum include the white paper on Putting Skills First: A Framework for Action and the Global Skills Taxonomy.  

Digital access

The Forum’s EDISON Alliance brings together governments, businesses, academia, and civil society to advance equitable access to the digital economy and bridge digital divides. Part of the Forum’s Centre for the Fourth Industrial Revolution, the Alliance fosters collaboration to drive digital inclusion and accelerate the delivery of digital solutions to unserved and underserved communities, with a focus on health, education, and financial inclusion. It also provides policymakers with guidance to make informed decisions that drive financial inclusions. Tools developed by the Alliance include principles for digital health inclusion, a guidebook for digital inclusion bond financing, and a Digital Inclusion Navigator that provides access to case studies and best practices related to bridging digital divides.

Cryptocurrencies

The Forum is also active on issues related to digital currencies and their policy implications. For instance, its Digital Currency Governance Consortium focuses on exploring the macroeconomic impacts of digital currencies and informing approaches to regulating digital currencies. The Central Bank Digital Currency (CBDC) Policy-Makers Toolkit, published in 2020, is intended to serve as a possible framework to ensure that the deployment of CBDCs takes into account potential costs and benefits. Various publications have been issued that explore topics such as the macroeconomic impact of cryptocurrency and stablecoins, cryptocurrency regulation, and the links between stablecoins and financial inclusion

Digital tools

Digital platforms

Strategic Intelligence: The Forum’s platform provides access to transformation maps – mappings of ‘hundreds of global issues and their interdependencies’.

Social media channels

Facebook @worldeconomicforum

Flipboard @WEF

Instagram @worldeconomicforum

LinkedIn @ World Economic Forum

TikTok @worldeconomicforum

X @wef

YouTube @World Economic Forum

United Nations Economic Commission for Europe

UNECE is one of five regional commissions of the UN. Its major aim is to promote pan-European economic integration. To do so, it brings together 56 countries in Europe, North America, and Central Asia, which discuss and cooperate on economic and sectoral issues.

UNECE works to promote sustainable development and economic growth through policy dialogue, negotiation of international legal instruments, development of regulations and norms, exchange and application of best practices, economic and technical expertise, and technical cooperation for countries with economies in transition. It also sets out norms, standards, and conventions to facilitate international cooperation.

Digital activities

UNECE’s work touches on several digital policy issues, ranging from digital standards (in particular in relation to electronic data interchange for administration, commerce, and transport) to the internet of things (IoT) (e.g. intelligent transport systems). Its activities on connected vehicles and automated driving systems are essential to seize the benefits of technical progress and disruptions in that field and to operationalise new mobility concepts such as Mobility as a Service (MaaS). Its UN/CEFACT develops trade facilitation recommendations and electronic business standards, covering both commercial and government business processes. UNECE also carries out activities focused on promoting sustainable development, in areas such as sustainable and smart cities for all ages; sustainable mobility and smart connectivity; and measuring and monitoring progress towards the sustainable development goals (SDGs).

UNECE’s work in the field of statistics is also relevant for digital policy issues. For example, the 2019 Guidance on Modernizing Statistical Legislation– which guides countries through the process of reviewing and revising statistical legislation – covers issues such as open data, national and international data exchanges, and government data management.

UNECE carries out extensive work in the area of sustainable transport leading on several UN Conventions. Accession to the conventions continues to increase as more and more member states realise the benefits in the time taken and associated costs in the movement of goods. Numerous digitised systems have been developed, and are maintained, hosted, and administered under the auspices of UNECE. For a number of other tools and mechanisms, work is underway.

Digital policy issues

Digital standards

UNECE’s intergovernmental body UN/CEFACT continues making great strides in the area of digital standards. In a recent collaboration with the International Federation of Freight-Forwarders Associations (FIATA), it developed the electronic FIATA Multimodal Bill of Lading (eFBL) data standard. The basis of the mapping of the Negotiable FIATA Multimodal Transport Bill of Lading (FBL) with the UN/CEFACT Multimodal Transport (MMT) reference data model, allows the exchange of BL data in a standardised way, facilitating interoperability between all modes of transport and industry stakeholders. Similar to other data standards developed by UN/CEFACT, the data standard is offered as open-source for all software providers and industry stakeholders to implement. UNECE’s standardisation work builds on a family of reference data models in alignment with its strategy to become the next generation of global standards for trade and transport information exchange. Other digital standards in the areas of supply chain management, agriculture, and travel and tourism (e.g. Buy Ship Pay Reference Data Model, Textile and Leather Data Model (Part 1 and Part 2), and Travel and Tourism Experience Programme Data Model) are a great step toward paperless trade and benefit all actors of the supply chain by reducing costs, increasing security, and gaining efficiency.

Artificial intelligence

As the UN centre for inland transport, UNECE hosts international regulatory platforms in the field of automated driving and intelligent transport systems. It hosts multilateral agreements and conventions ruling the requirements and the use of these technologies (such as the UN agreements on vehicle regulations and the Vienna Convention on Road Traffic). Its activities (e.g. facilitating policy dialogue and developing regulations and norms) contribute to enabling automated driving functionalities and ensuring that the benefits of these technologies can be captured without compromising safety and progress achieved in areas such as border crossing and interoperability. It also collaborates with other interested stakeholders, including the automotive and information and communications technology (ICT) industries, consumer organisations, governments, and international organisations.

Another area of work for UNECE is related to harnessing smart technologies and innovation for sustainable and smart cities. In this regard, it promotes the use of ICTs in city planning and service provision and it has developed (together with ITU) a set of key performance indicators for smart sustainable cities. UNECE also works to facilitate connectivity through sustainable infrastructure. For instance, it assists countries in developing smart grids for more efficient energy distribution, and it administers international e-roads, e-rail, and e-waterway networks.

UNECE launched the Advisory Group on Advanced Technology in Trade and Logistics (AGAT) in 2020 on topics, such as distributed ledger technologies (DLT) including blockchain, IoT, and AI.

The UNECE High-Level Group on Modernisation of Official Statistics (HLG-MOS) has been at the forefront of modernisation initiatives in the field of official statistics. These initiatives include innovative areas such as big data, synthetic data, and machine learning (ML). A UNECE guide, Machine Learning for Official Statistics, can help national and international statistical organisations to harness the power of ML to modernise the production of official statistics. Responding to the growing interest in LLM, HLG-MOS is working on a white paper to establish a common understanding of LLM’s potential within the statistical community by exploring implications and opportunities for official statistics.

In trade, the newly released UN/CEFACT JSON-LD Web Vocabulary complements and enhances the capabilities of AI systems for trade-related exchanges. It aims to support the interoperability of trade by allowing supply chain actors to more easily integrate a common vocabulary in their business tools (e.g. software applications, AI algorithms) to ensure that data shared between different entities (e.g. suppliers, manufacturers, distributors, transporters, financiers, and regulators) is consistent and easily interpretable, reducing errors and misunderstandings.

Artificial intelligence for energy

AI and other technologies are inspiring energy suppliers, transmission and distribution companies, and demand sectors (buildings, industry, transport) to establish new business models to generate, deliver, and consume energy in a more sustainable way.

UNECE established a task force on digitalization in energy to offer a platform for cross-industry experts from the energy sector and digital innovation to develop a unified voice on digitalisation in energy.

The group found that AI and digitalisation have the potential to reduce residential and commercial buildings’ energy use by as much as 10% globally by 2040 if applied throughout a building’s value chain and life cycle. In particular, applications of AI may help optimise a building’s orientation for solar heat gain and predict power and heat needs, thus increasing overall energy security and maximising the integration of renewable energy sources.

The group also found that AI and digitalisation could help achieve energy savings of at least 10%–20% in the industrial sector (which consumes around 38% of global final energy and produces 24% of greenhouse gasses).

UNECE has partnered with the University of Zürich to develop an AI-powered tool that will offer a real-time interactive compendium of information and data resources on the resilience of energy systems. The platform will equip policymakers with a cutting-edge tool that will inform their policy decisions by facilitating knowledge management and dissemination capabilities. It is also meant to help identify technology and policy breakthroughs and mobilise financial flows for resilience. The European Investment Bank, the International Atomic Energy Agency, the International Energy Agency, the International Telecommunication Union, the Organization for Security and Co-operation in Europe, the World Meteorological Organization, the World Bank, and other organisations contribute their knowledge base to support and shape this tool.

Automated driving

Blockchain

UNECE’s subsidiary body UN/CEFACT has been exploring the use of blockchain for trade facilitation. For instance, work carried out within the Blockchain White Paper Project has resulted in two white papers: One looking at the impact of blockchain on the technical standards work of UN/CEFACT and another looking at how blockchain could facilitate trade and related business processes. The ongoing Chain Project is focused on developing a framework/mechanism for the development and implementation of blockchain services infrastructure, and creating a whitepaper on strategy for the development and implementation of interoperable global blockchain technology infrastructure. Another blockchain-related project looks into the development of a standard on the creation of a cross-border inter-customs ledger using blockchain technology.

Critical infrastructure

UNECE achieved a transformative milestone with regard to cybersecurity in the broad automotive sector with the adoption of UN Regulation No. 155 (Cyber Security and CSMS) and UN Regulation No. 156 (Software Updates).

Before that, cyber risks related to connected vehicles were apparent but not systematically addressed. Security researchers alerted the public of them by revealing various vulnerabilities. There were only narrow standards and guidelines for securing vehicles, such as standards for secure communication among Electronic Control Units (ECUs) and for hardware encryption.

UNECE’s World Forum for Harmonization of Vehicle Regulations (Working Party on Automated/Autonomous and Connected Vehicles (GRVA) WP.29) adopted two important new regulations on cybersecurity and over-the-air software updates and led to the situation where cybersecurity became non-negotiable for securing market access via type approval for those countries applying this regime. GRVA also developed recommendations on uniform provisions concerning cybersecurity and software updates for countries applying the self-certification regime.

Under the 1958 Agreement (binding to 54 countries)

Data governance

UNECE carries out multiple activities of relevance for the area of data governance.

First, its work on trade facilitation also covers data management issues. For example, it has issued a white paper on data pipeline concept for improving data quality in the supply chain and a set of Reference Data Model Guidelines. Several projects carried out in the framework of UNECE’s subsidiary UN/CEFACT also cover data-related issues.  Examples include the  Buy-Ship-Pay  Reference Data Model (BSP-RDM), the Supply Chain Reference Data Model (SCRDM), the Multi-Modal Transport Reference Data Model (MMT-RDM), the Cross-border Management Reference Data Model Project (to provide a regulatory reference data model within the UN/CEFACT semantic library in order to assist authorities to link this information to the standards of other organisations), the Sustainable Development and Circular Economy Reference Data Model Project, and the Accounting and Audit Reference Data Model Project.

Second, UNECE has a statistical division, which coordinates international statistical activities between UNECE countries and helps to strengthen, modernise, and harmonise statistical systems under the guidance of the Conference of European Statisticians. Its activities in this area are guided by the Fundamental Principles of Official Statistics, adopted in 1992 and later endorsed by the ECOSOC and the UNGA. Areas of work include economic statistics, statistics on population, gender and society, statistics related to sustainable development and the environment, and modernisation of official statistics. In 2019, UNECE published a Guidance on Modernizing Statistical Legislation to guide countries through the process of reviewing and revising statistical legislation. The guidance covers issues such as open data, national and international data exchanges, and government data management.

Third, UNECE keeps abreast of external developments, (e.g. in Europe or an Organisation for Economic Co-operation and Development (OECD) country), related to challenges related to AI, privacy, and human rights. This is the case for example with the activities on transport and automated vehicles. The GRVA is reflecting on the impact of general AI policies in its activities and developed possible ways to add layers in its multi-pillar approach to validate the performance of the Automated Driving System, and therefore to integrate considerations on data management in the context of AI agent training, support features, and functions of automated driving, and collaborate with the automotive sector on this matter.

E-commerce and trade

UNECE’s subsidiary, UN/CEFACT, serves as a focal point (within ECOSOC) for trade facilitation recommendations and electronic business standards, covering both commercial and government business processes. In collaboration with the Organization for the Advancement of Structured Information Standards (OASIS), UNECE developed the Electronic business using eXtensible Mark-up Language (ebXML). Another output of UNECE is represented by the UN rules for Electronic Data Interchange for Administration, Commerce and Transport (UN/ EDIFACT), which include internationally agreed upon standards, directories, and guidelines for the electronic interchange of structured data between computerized information systems. UNECE has also issued recommendations on issues such as Single Window, electronic commerce agreements, and e-commerce self-regulatory instruments. In addition, UN/CEFACT works on supporting international, regional, and national e-government efforts to improve trade facilitation and e-commerce systems.

Recommendation 33 – Single Window Recommendation

In addition, UN/CEFACT is reviewing its mandates and developing white papers analyzing how AI can be used to facilitate trade processes. This includes examining how AI technology could be used to facilitate trade and related processes in the international supply chain including the study of areas such as data privacy, AI-based trade policies, the use of AI in e-Commerce and payments; how existing UN/CEFACT deliverables could be used in AI applications; and possible changes to existing UN/CEFACT deliverables, or new deliverables, that could be considered  to support AI trade facilitation applications.

Digital and environment

UNECE’s work in the area of environmental policy covers a broad range of issues, such as air pollution, transboundary water cooperation,  industrial safety,  environmental democracy, the green economy, environmental monitoring and impact assessment, and education for sustainable development. Much of this work is carried out by the Committee on Environmental Policy, which, among other tasks, supports countries in their efforts to strengthen their environmental governance and assesses their efforts to reduce their pollution burden, manage natural resources, and integrate environmental and socio-economic policies. UNECE has put in place an Environmental Monitoring and Assessment Programme to assist member states in working with environmental data and information and enable informed decision-making processes. As part of this programme, it promotes the use of electronic tools for accessing information and knowledge on environmental matters and is supporting the continued development of a Shared Environmental Information System across the UNECE region. The system is intended to enable countries to connect databases and make environmental data more accessible.

The INForest database offers the most up-to-date source of information about the size of the forest area in the UNECE region, how it has changed over decades, the structure of forests, the goods and services forests provide, as well as their contribution to the economy, society and the environment.

UNECE has developed policy guidance to support the digital inclusion of older people. In the Rome Ministerial Declaration on Ageing, adopted in June 2022, Ministers pledged to ‘promote age-friendly digitalisation, products and services, and support innovation for the silver economy’.

Recognising the importance of environmental, social, and governance (ESG) traceability in achieving SDG 12 and considering the rich body of expertise and standards already available through UNECE, UNECE broadened the focus of the Team of Specialists (ToS) on sustainable fisheries to (ESG) traceability of sustainable value chains in the circular economy.

UNECE Environmental Conventions and Protocols (not necessarily covering digital issues directly, but relevant):

Sustainable development

UNECE assists countries in its region to address sustainable development challenges (in areas such as environment, connectivity, and urbanisation) through offering policy advice; leveraging its norms, standards, and conventions; and building capacities. It focuses on driving progress towards the following SDGs: good health and well-being (SDG 3), clean water and sanitation (SDG 6), affordable and clean energy (SDG 7), decent work and economic growth (SDG 8), industry, innovation and infrastructure (SDG 9), sustainable cities and communities (SDG 11), responsible consumption and production (SDG 12), climate action (SDG 13), and life on land (SDG 15). Gender equality (SDG 5) and partnerships (SDG 17) are overarching for all UNECE activities. Activities undertaken by UNECE concerning these SDGs converge under four high-impact areas: sustainable use of natural resources; sustainable and smart cities for all ages; sustainable mobility and smart connectivity; and measuring and monitoring progress towards the SDGs.

UNECE has developed a series of tools and standards to support countries in measuring and monitoring progress towards the SDGs. It has also put in place an Innovation Policy Outlook, which assesses the scope, quality, and performance of policies, institutions, and instruments promoting innovation for sustainable development.

Privacy and data protection

The World Forum for Harmonization of Vehicle Regulations has included guidelines on cybersecurity and data protection in its consolidated resolution on the construction of vehicles, including principles of lawful, fair, and transparent processing of personal data: (1) respecting the identity and privacy of the data subject; (2) not discriminating against data subjects based on their personal data; (3) paying attention to the reasonable expectations of the data subjects with regard to the transparency and context of the data processing; (4) maintaining the integrity and trustworthiness of information technology systems and in particular not secretly manipulating data processing; (5) taking into account the benefit of data processing depending on the free flow of data, communication and innovation, as far as data subjects have to respect the processing of personal data with regard to the overriding general public interest; and (6) ensuring the preservation of individual mobility data according to necessity and purpose.

These guidelines were referred to in the Resolution on Data Protection in Automated and Connected Vehicles adopted during the 39th International Conference of Data Protection and Privacy Commissioners Hong Kong, 25–29 September 2017.

Digital tools

UNECE hosts several portals, applications, and digitalised conventions.

eTIR International System Application

The Customs Convention on the International Transport of Goods under Cover of TIR (Transports Internationaux Routiers) Carnets (TIR Convention, 1975) is one of the most successful international transport conventions. It is the only universal customs transit system in existence.

The TIR system, used by over 34,000 transport and logistics companies in its 77 contracting parties, has already reduced cross-border transport time by up to 80%, and costs by up to 38%. The eTIR international system aims to ensure the secure exchange of data between national customs systems related to the international transit of goods, vehicles, or containers according to the provisions of the TIR Convention and to allow customs to manage the data on guarantees, issued by guarantee chains to holders authorised to use the TIR system.

ITDB: International TIR Data Bank

The ITDB is an international online repository of information for all those authorised by contracting parties to use the TIR procedure. It is an integral part of the eTIR International system since only users approved in ITDB can use the eTIR system. The main goal of the ITDB is to foster the exchange of information between competent authorities of contracting parties and national associations.

eCPD

The Carnet de Passages en Douane (CPD) system (i.e. a passport card for your vehicle) facilitates the temporary importation of private and commercial vehicles. The CPD system is based on two international conventions: the 1954 Customs Convention on the Temporary Importation of Private Road Vehicles and the 1956 Customs Convention on the Temporary Importation of Commercial Road Vehicles. Hosted by UNECE, the conventions combined have 96 contracting parties. Work has started to prepare the appropriate amendments to the 1954 and 1956 conventions describing the eCPD; prepare the high-level architecture including the concepts and functional and technical specifications of the future eCPD application; and develop the eCPD system based on these specifications.

eCMR

The eCMR is based on the provisions of the Convention on the Contract for the International Carriage of Goods by Road (CMR) (1956) and especially on the provisions of the Additional Protocol to CMR Concerning the Electronic Consignment Note (2008). UNECE, which administers the CMR Convention, has been mandated by governments to administer the eCMR protocol and to establish a formal group of experts on the operationalisation of the eCMR procedure.

Digital visualisation

International Transport Infrastructure Observatory (ITIO)

The observatory will be developed on a geographic information systems (GIS) platform with three main pillars of services: it offers an electronic repository of UNECE inland transport conventions, an innovative tool to finance transport infrastructure, and a way to promote sustainable regional and interregional connectivity.

ITIO GIS Platform

Climate Change Adaptation and Transport Infrastructure Tool – The ITIO GIS platform assists in the analysis of possible future impacts of climate change on transport networks. The tool enables experts to identify sections of transport networks potentially exposed to the effects of climate change.

Digital enabler

SITCIN: Sustainable Inland Transport Connectivity Indicators tool

The SITCIN tool allows countries to measure their degree of transport connectivity, both domestically and bilaterally/sub-regionally, as well as in terms of soft and hard infrastructure.

UNECE Dashboard of SDG Indicators

UNECE digital tools facilitating access to statistical information:

UNECE online platforms and observatories gather updates and policy resources to help member states respond to the COVID-19 crisis:

Social media channels

Facebook @UNECE

Flickr @UNECE

Instagram @un_ece

LinkedIn @ United Nations Economic Commission for Europe

X @UNECE

YouTube @UNECE

Sign up for the monthly newsletter on digital issues to receive updates.

International Organization for Standardization

ISO is the International Organization for Standardization, the world’s largest developer of international standards. It consists of a global network of 170 national standards bodies – our members. Each member represents ISO in its country. The organisation brings together global experts to share knowledge and develop voluntary, consensus-based, market-relevant International Standards. It is best known for its catalogue of almost 25,000 standards spanning a wide range of sectors, including technology, food, and healthcare.

Digital activities

A large number of the international standards and related documents developed by ISO are related to information and communication technologies (ICTs), such as the Open Systems Interconnection (OSI) that was created in 1983 to establish a universal reference model for communication protocols. The organisation is also active in the field of emerging technologies including blockchain, the Internet of Things (IoT), and AI. The standards are developed by various technical committees dedicated to specific areas including information security, cybersecurity, privacy protection, AI, and intelligent transport systems.

Digital policy issues

Artificial intelligence

The joint technical committee of ISO and the International Electrotechnical Commission (IEC) for AI is known as ISO/IEC JTC1/SC 42 Artificial intelligence and is responsible for the development of standards in this area. To date, it has published 20 standards specifically pertaining to AI with 35 others in development. ISO/IEC 42001 is the flagship AI Management System Standard, which provides requirements for establishing, implementing, maintaining, and continually improving an AI management system within the context of an organisation. ISO/IEC TR 24028 provides an overview of trustworthiness in AI systems, detailing the associated threats and risks and addresses approaches on availability, resiliency, reliability, accuracy, safety, security, and privacy. The standards under development include those that cover concepts and terminology for AI (ISO/IEC 22989); bias in AI systems and AI-aided decision-making (ISO/IEC TR 24027); AI risk management (ISO/IEC 23894); a framework for AI systems using machine learning (ISO/IEC 23053); and the assessment of machine learning classification performance (ISO/IEC TS 4213). Up-to-date information on the technical committee (e.g. scope, programme of work, contact details) can be found on the committee page.

Cloud computing

ISO and IEC also have a joint committee for standards related to cloud computing which currently has 27 published standards and a further 5 in development. Of those published, two standards of note include ISO/IEC 19086-1, which provides an overview, foundational concepts, and definitions for a cloud computing service level agreement framework, and ISO/IEC 22123-3, which specifies the cloud computing reference architecture.Standards under development include those on health informatics (ISO/TR 21332); the audit of cloud services (ISO/IEC 22123-2); and data flow, categories, and use (ISO/IEC 19944 series). Up-to-date information on the technical committee (e.g. scope, programme of work, contact details) can be found on the committee page.

Internet of things

Recognising the ongoing developments in the field of IoT, ISO has a number of dedicated standards both published and in development, including those for intelligent transport systems (ISO 19079), future networks for IoT (ISO/IEC TR 29181 series), unique identification for IoT (ISO/IEC 29161), Internet of Media Things (ISO/IEC 23093-3), the trustworthiness of IoT (ISO/IEC 30149), and industrial IoT systems (ISO/IEC 30162). IoT security is addressed in standards such as ISO/IEC 27001 and ISO/IEC 27002, which provide a common language for governance, risk, and compliance issues related to information security. In addition, there are 26 standards under development, some of which provide a methodology for the trustworthiness of an IoT system or service (ISO/IEC 30147); a trustworthiness framework (ISO/IEC 30149); the requirements of an IoT data exchange platform for various IoT services (ISO/IEC 30161); and a real-time IoT framework (ISO/IEC 30165). Up-to-date information on the ISO and IEC joint technical committee for IoT (e.g. scope, programme of work, contact details) can be found on the committee page

Telecommunication infrastructure

ISO’s standardisation work in the field of telecommunications infrastructure covers areas such as planning and installation of networks (e.g. ISO/IEC 14763-2), corporate telecommunication networks (e.g. ISO/IEC 17343), local and metropolitan area networks (e.g. ISO/IEC/IEEE 8802-A), private integrated telecommunications networks (e.g. ISO/IEC TR 14475), and wireless networks. Next-generation networks – packet-based public networks able to provide telecommunications services and use multiple quality-of-service-enabled transport technologies – are equally covered (e.g. ISO/IEC TR 26905). ISO also has standards for the so-called future networks, which are intended to provide futuristic capabilities and services beyond the limitations of current networks, including the internet. Up-to-date information on the joint ISO and IEC technical committee that develops these standards (e.g. scope, programme of work, contact details ) can be found on the committee page.

Blockchain

ISO has published 11 standards on blockchain and distributed ledger technologies: ISO/TR 23455 gives an overview of smart contracts in blockchain and distributed ledger technologies; ISO/TR 23244 tackles privacy and personally identifiable information protection; and ISO 22739 covers fundamental blockchain terminology respectively. ISO also has a further eight standards on blockchain in development. These include those related to:  security management of digital asset custodians (ISO/TR 23576); taxonomy and ontology (ISO/TS 23258); and guidelines for governance (ISO/TS 23635). Up-to-date information on the technical committee (e.g. scope, programme of work, contact details, etc.) can be found on the committee page.

Emerging technologies

ISO develops standards in the area of emerging technologies. 

Dozens of standards in the area of emerging technologies are those related to robotics. ISO has more than 40 different standards either published or in development that cover issues such as collaborative robots (e.g. ISO/TS 15066); safety requirements for industrial robots (e.g. ISO 10218 series); and personal care robots (e.g. ISO 13482). Autonomous or so-called intelligent transport systems (ITS) standards are developed by ISO’s ITS Technical Committee and include those for forward vehicle collision warning systems (ISO 15623) and secure connections between trusted devices (ISO/TS 21185). Standards are also being developed to address the use of virtual reality in learning, education, and training (e.g. ISO/IEC 23843).

Network security

ISO and IEC standards also address information security and network security . The ISO and IEC 27000 family of standards covers information security management systems and are used by organisations to secure information assets such as financial data, intellectual property, and employee information. For example,ISO/IEC 27031 and ISO/IEC 27035 are specifically designed to help organisations respond, diffuse, and recover effectively from cyberattacks. ISO/IEC 27701 is an extension of ISO/IEC 27001 and ISO/IEC 27002 for privacy information management, and details requirements and guidance for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS).Network security is also addressed by standards on technologies such as the IoT, smart community infrastructures, medical devices, localisation and tracking systems, and future networks. Up-to-date information on the joint ISO and IEC technical committee (e.g. scope, programme of work, contact details) can be found on the committee page.

Encryption

As more and more information (including sensitive personal data) is stored, transmitted, and processed online, the security, integrity, and confidentiality of such information becomes increasingly important. To this end, ISO has a number of standards for the encryption of data. For example, ISO/IEC 18033-1, currently under development, addresses the nature of encryption and describes certain general aspects of its use and properties. Other standards include ISO/IEC 19772 which covers authenticated encryption, ISO/IEC 18033-3 which specifies encryption systems (ciphers) for the purpose of data confidentiality, and ISO 19092 which allows for encryption of biometric data used for authentication of individuals in financial services for confidentiality or other reasons. ISO also has standards that focus on identity-based ciphers, symmetric and asymmetric encryption, public key infrastructure, and many more related areas. 

Data governance

Big data is another area of ISO standardisation; around 80% of related standards are developed by the ISO/IEC AI committee. The terminology for big-data-related standards is outlined in ISO/IEC 20546, while ISO/IEC 20547-3 covers big data reference architecture. ISO/IEC TR 20547-2 provides examples of big data use cases with application domains and technical considerations and ISO/IEC TR 20547-5 details a roadmap of existing and future standards in this area. Up-to-date information on the technical committee (e.g. scope, programme of work, contact details) can be found on the committee page.

Digital identities

Digital signatures that validate digital identities help to ensure the integrity of data and authenticity of particulars in online transactions. This, therefore, contributes to the security of online applications and services. Standards to support this technology cover elements such as anonymous digital signatures (e.g. ISO/IEC 20008 series); digital signatures for healthcare documents (e.g. ISO 17090-4 and ISO 17090-5); and blind digital signatures, which is where the content of the message to be signed is disguised, used in contexts where, for example, anonymity is required. Examples of such standards are ISO 18370-1 and ISO/IEC 18370-2.

Privacy and data protection

Privacy and data protection in the context of ICTs is another area covered by ISO’s standardisation activities. One example is ISO/IEC 29101 which describes a privacy architecture framework. Others include those for privacy-enhancing protocols and services for identification cards (ISO/IEC 19286); privacy protection requirements pertaining to learning, education, and training systems employing information technologies (ISO/IEC 29187-1); privacy aspects in the context of intelligent transport systems (ISO/TR 12859); and security and privacy requirements for health informatics (ISO/TS 14441).

Digital tools

ISO has developed an online browsing platform that provides up-to-date information on ISO standards, graphical symbols, publications, and terms and definitions.

Social media channels

Facebook @isostandards

Instagram @isostandards

LinkedIn @isostandards

X @isostandards

YouTube @iso