43. The representative of the United Kingdom of Great Britain and Northern Ireland, Co-Chair of the IWG on CS/OTA, presented (GRVA-20-25) the status of the group. He explained that the group met once since the last GRVA session and addressed the topics on: (a) Annex 7 to the Consolidated Resolution R.E.3., (b) Software Identification Number (RxSWIN) and (c) vehicle data access and privacy-by-design. On the latter, he detailed the activities of FIA, which had already presented its general intention and was requested to further develop its concepts. He added that, as the IWG did not desire to do that at the IWG level, so FIA established a group of volunteers. He concluded that the IWG was waiting for the outcome of this group.
44. He noted that the mandate of the IWG was going to expire and asked for an extension. He listed the following topics as possible items under the extended mandate: RxSWIN, categories of post-registration software updates and the FIA proposal. The GRVA Chair suggested that the group consider drafting a UN GTR on cybersecurity.
45. The representative of ITU invited GRVA to consider further issues, including cyberattack monitoring. He stated that if people could figure out how to blow a pager, they would certainly manage to hack vehicles (referring to the latest news before the session regarding pager explosions in Lebanon on 18 September 2024).
46. The representative of Canada responded to ITU that the cybersecurity activities of the group were not about addressing all possible edge cases but achieving a necessary resilience. He supported the mandate extension and invited GRVA to consider possible input that the IWG on CS/OTA could provide to the IWG on ADS.
47. The experts from France, Germany, European Commission and Japan also provided comments and supported the mandate extension.
48. GRVA agreed to request a mandate extension to WP.29 until November 2026 for the group and invited the experts to update the terms of reference of the group to include the tasks envisaged during the two years.