1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|---|---|---|---|---|---|---|---|---|
Document Title | Cybersecurity: Proposal for amendments to the draft UN Regulation | ||||||||
Reference Number | GRVA-05-05/Rev.1 | ||||||||
Date |
14 Feb 2020
|
||||||||
Summary | Draft text for a new UN Regulation on the certification of cybersecurity management systems and the approval of vehicles with regarding to cybersecurity. This draft will be considered during the 6th GRVA session. | ||||||||
Rulemaking Area(s) | UN R155 Cybersecurity | ||||||||
Proposal Status | Superseded | ||||||||
Meeting(s) | |||||||||
Related Documents | |||||||||
GRVA-06-08/Rev.1 | Cybersecurity: Explanations for the suggested amendments to GRVA-05-05-Rev.1 | ||||||||
GRVA-06-07 | Cybersecurity: Suggestion for amendments to GRVA-05-05-Rev.1 | ||||||||
GRVA-06-15 | Cybersecurity: Proposal for amendments to document GRVA-05-05-Rev.1 | ||||||||
GRVA-06-17 | Cybersecurity: Proposal for amendments to the draft UN Regulation | ||||||||
GRVA-06-18 | Cybersecurity: Proposal for amendments to GRVA-05-05/Rev.1 | ||||||||
GRVA-06-19/Rev.1 | Cybersecurity: Draft proposal for a new UN Regulation (superseded) | ||||||||
Downloads | |||||||||
UNECE server | .pdf format | .docx format | |||||||
Excerpts from session reports related to this document | |||||||||
GRVA | Session 5 | 10-14 Feb 2020 |
25. The expert from the United Kingdom and Northern Ireland, Co-Chair of the Task Force (TF) on Cyber Security and Over-The-Air issues (CS/OTA), presented the outcome of the TF. He introduced the proposed draft UN Regulation on Cyber Security and Cyber Security Management System (ECE/TRANS/WP.29/GRVA/2020/2 (withdrawn), ECE/TRANS/WP.29/GRVA/2020/3 amended by GRVA-05-05). He mentioned that the revised proposal entailed a recent proposal from Germany and the European Commission (paragraphs 5.3.1.-5.3.3.) in square brackets. He recalled that the TF was planning to deliver further documents accompanying the UN Regulation: a resolution and an interpretation document. He stated that these documents would be further elaborated during the next session of the TF and would distillate the learnings of the test phase in 2019. He informed GRVA that the work on a UN Global Technical Regulation (GTR) had to start. 26. The expert from Japan introduced GRVA-05-20 proposing amendments to paragraph 7.3.8. on the use of cryptographic modules. 27. The expert from the European Commission introduced GRVA-05-22, aimed at clarifying the consequences of the Cyber Security Management System certificate expiration. 28. The expert from Japan introduced GRVA-05-13, expressing strong objections to the proposed paragraphs 5.3.1.-5.3.3. establishing prerequisites to the granting of type approvals not in line with the 1958 Agreement and posing a sovereignty risk. The expert from the Russian Federation expressed a similar position and proposed to draft an alternative proposal. 29. The expert from France introduced, GRVA-05-29 proposing an alternative to the proposed paragraphs 5.3.1.-5.3.3. as well as amendments proposal for paragraph 7.4 and Annex 5. 30. The expert from the European Commission introduced a compromise proposal (GRVA-05-42) for paragraphs 5.3.1.-5.3.3. aimed at addressing the proposals from Japan and France. 31. The expert from OICA introduced GRVA-05-33. He stated that the test phase’s general outcome was the confirmation of the applicability of the former draft. He explained their major concerns with the current text. He mentioned their concerns from the industry point of view regarding the major type approval procedure modifications introduced by paragraphs 5.3.1.-5.3.3. and the major delay associated risks. 32. He stated that insufficient considerations were given to existing vehicle architectures and requested the introduction of transitional provisions. He also stated that the reporting provisions were excessive. He called on GRVA to consider these concerns and to resolve them on a consensus basis. 33. The expert from FIGIEFA introduced GRVA-05-15, proposing a process flow for national/regional authorities to define objective minimum compliance criteria for the UNECE cybersecurity regulation and a way forward for aftermarket issues. 34. GRVA reviewed in detail GRVA-05-05, having in mind the presentations received (paragraphs 26-32 above).
35. The Secretary produced a consolidation of the draft Regulation based on the input received during the session (GRVA-05-05/Rev.1). GRVA agreed to use this consolidation as a basis for further work until the next GRVA session. |
||||||||
GRVA | Session 6 | 3-4 Mar 2020 |
16. GRVA worked on the basis of GRVA-05-05-Rev.1 prepared by the Secretary at the end of the fifth session of GRVA. 19. The expert from OICA presented GRVA-06-08-Rev.1 introducing GRVA-06-07 proposing amendments to the scope, clarifications in para. 5.1.3., paras. 7.2.2.2-7.2.2.4. and para. 7.3.7., a proposed way forward for the resolution of the discussion on paras. 5.3.1-5.3.4, transitional provisions in para. 7.3.1. and the deletion to the reference to Part. C in Annex 5. 20. The expert from Germany introduced an alternative amendment proposal to the transitional provision para. 7.3.1.. 21. The expert from the European Commission introduced GRVA-06-17 and GRVA-06-17-Rev.1, aimed at resolving the Contracting Parties discussion on paras. 5.3.1.-5.3.4. GRVA could not reach consensus on the proposal. GRVA agreed to make further progress until the June 2020 session of WP.29 along the following agreed principles:
22. The expert from Spain introduced GRVA-06-18 aimed at specifying security definition requirements for the vehicle type. GRVA agreed to consider a revised proposal at its September 2020 session. 23. GRVA adopted GRVA-06-19-Rev.1 and requested the secretariat to submit it (without paras 5.3.1.-5.3.4.) as draft UN Regulation on Cyber Security and Cyber Security Management Systems to WP.29 and AC.1 for consideration and vote at their June 2020 session. |
||||||||