Quarter 2, 2025 means that we’re already halfway through a busy year. The highlights for this quarter include, input by JTC 1/SC 27 (subcommittee on Cybersecurity and privacy) on Gender responsive standards initiative, a workshop on Cybersecurity, an example of successful and timely collaboration, key takeaways from the JTC 1 May 2025 plenary in Singapore and the SC 32 plenary in Australia, and finally, JTC 1’s new revised logo with a link to an accessible file for everyone’s use.

Gender Responsive Standards (GRS)

As part of the ongoing initiative from ISO and IEC, following the signing of the UNECE Declaration of Gender Responsive Standards and Standards Development, JTC 1 continues to play its part in ensuring that international standards provide equal benefit to all different genders, and for technical committees to determine the extent of potential gender implications.

The 41st plenary and synchronized working group meetings of Information security, cybersecurity and privacy protection (SC 27)

included sessions on GRS, the SC 27 Gender Action Plan (GAP) and SC 27 gender study report.  Rachel Miller, Program Manager for Capacity building from the ISO Central Secretariate along with Jane Fuller, ISO Gender Consultant announced the sessions at the SC 27 plenary and the SC 27/WG plenaries respectively.

The underlying message urging SC 27 members to incorporate gender diversity at all stages of the standards development process was well received.

All members were invited to respond to the SC 27 Survey 2.0, where the survey intends to learn about any differences in experiences in standards development in SC 27 based on gender, obtain indicators for tailoring the GRS training to cater to the needs of SC 27, and better understand what is required to get more women to the table.

The results will be presented at the SC 27 plenary in September 2025. The snapshot of progress of SC 27 Gender Responsive Standards Initiative (GRSI) activities, captured in a poster had a significant role in socialising the SC 27 GAP, drawing attention to the present gender balance in SC 27 and its working groups, and reiterating the available GRS resources e.g. GRS training, guidance on the use of inclusive terminology and JSAG case studies.
A pilot GRS workshop by WG 5; Identity management and privacy triggered discussions on the GRS assessment form and encouraged many to approach the GRSI team for in-depth discussions.  Preliminary results of the application of a GRS lens to a standard undergoing a systematic review initiated conversations on gender blind and gender neutral standards.

The SC 27 tradition of an informal networking “Ladies night” was renamed as ‘Gender diversity night’, throwing it open for all to participate.

[1] https://www.iso.org/files/live/sites/isoorg/files/store/en/PUB100474.pdf

Gargi Keeni

JTC 1 May 2025 Plenary meeting – Singapore

During the week of May 5th 2025, JTC 1, the joint technical committee of ISO and IEC and home for developing international standards related to information technology (IT), gathered at the York Hotel, Singapore, hosted by Singapore standards (SST), to work through the agenda for the 46th JTC 1 plenary. As always, the meeting had over one hundred delegates from twenty-two national bodies, meeting together to discuss issues and topics that affect them. The meeting also included active participation by Liaison representatives like ECMA International’s Secretary General Samina Husain and COPOLCO Chair Dr. Eunsook Moon, on behalf of ISO.

The week-long meeting featured several engaging discussions and noteworthy developments. Among them was the introduction of opportunities to engage consumers via Subcommittee 44 on Consumer Protection in Privacy. Additionally, the publication of JTC 1’s Consumer Engagement paper demonstrates how various national bodies are actively working to involve local consumer groups in standards development. These efforts were further reinforced by a compelling presentation from the Chair of ISO COPOLCO, lending strong support to the initiative. Furthermore there were reports presented and additional discussions on succession planning and ongoing work by ISO and IEC reviewing JTC 1’s work, processes and governance.

There are lots of discussions taking place in relation to the ever-growing alignment of the Directives between ISO and IEC, and although decisions are far from agreed yet, further

discussions will help to shape a common ground, and we can expect to see decisions and output by early 2026.

Also watch out for the JTC 1 Emerging Technologies Initiative (JETI) survey, which will be with you very soon and will run through the summer months.

JTC 1/AG 1 Communications

Design, development, use and maintenance of biometric identification systems involving passive capture subjects

JTC 1’s Biometrics subcommittee (SC 37) show here that collaboration works. We often hear people say that standards development is too slow and this is often true.  But we need to recognize that it is a challenge to achieve global consensus on a new technical topic with a process that is fair to all participants and with a result that is high quality. Quality takes time.

However, with planning and cooperation, standards can be developed and produced on time, in line with other needs. An example of this is the newly published standard Information technology — Design, development, use and maintenance of biometric identification systems involving passive capture subjects (ISO/IEC 9868:2025), by the Biometrics subcommittee.

Before the European Commission released their draft of the AI Directive in 2021, they initiated discussions with JTC 1 on their perceived need for a standard that would establish requirements for systems that perform passive biometric scanning, for example in surveillance systems.  The EC submitted a proposal for a new project soon after the draft Directive was released, that was 2021.  Subsequent to that the Directive has now been approved by Council and Parliament, and the standard they initiated is also finished and published. This shows that with cooperation timely results can be achieved.

Neither regulations nor standards are created instantaneously.  Standards organizations and regulators benefit from working together from an early stage to facilitate having standards available when needed, to support regulatory requirements.  By working together, it is possible to effectively meet the needs of the market.

This is how the timelines matched up:

Phil Wennblom, Brian McAuliffe, SC 37

IEC Academy Cybersecurity Webinars

The IEC Academy in cooperation with JTC 1’s subcommittee on Cybersecurity, SC 27 have been running a series of public webinars on Zoom covering different aspects of cybersecurity.  The first of these was held last  November, 2024, and covered the use of ISO/IEC 27001.  The leader of the webinars, Dr Humphreys, remarked that this first webinar attracted over 1900 registrants, reflecting the global interest and influence the standard has had on business and trade, whilst acknowledging the importance of this standard in managing information security risks.

The second webinar was held in January this year and covered Cloud Security based on the standard ISO/IEC 27017. This was followed in February with a webinar on IoT security, based on the ISO/IEC 27400 series of standards.  Finally, a fourth webinar was held in May that touched upon cybersecurity-risks (organizational, people and technology).  These webinars also attracted a large number of participants, from a diverse range of market sectors.

The webinars are aimed at sharing real-world experiences of cybersecurity issues between the on-line participants representing a diverse range of sectors and a Panel of cybersecurity professionals.  The webinars also involved on-line surveys to enhance participant contributions and engagement.  The sessions were informative two-way dialogues exploring how the real-world application of international standards have improved and secured business, opened up new opportunities and provided economic growth.

Following feedback from attendees for more of these cyber webinars, a number are being planned for later this year including (i) Cybersecurity and SMEs, (ii) Cyber skills and competence and (iii) Future cybersecurity challenges.

Dr Edward Humphreys

Database Languages plenary -SC 32/WG 3 – Australia

The international standards working group for Database Languages (ISO/IEC JTC 1/

SC 32/WG 3) held its June 2025 meeting from the 2nd – 6th of June 2025 in Sydney, Australia.

The following were some of the accomplishments of the meeting, and don’t forget to look out for the separate paper from WG 3 with more details.

  • Reviewed and approved new functionality for the SQL/JSON capabilities with a JSON_TRANSFORM function.
  • Approved a draft for descriptive statistical functions for a new Functions standard (ISO 29075); devised a plan to complete and approve probability distribution and hypothesis testing statistical functions by September.
  • Discussed future enhancements of the SQL and GQL languages.
  • Initiated an ongoing effort to better inform interested parties about the work of the Database Languages standards working group and to encourage their involvement.

Joern Bartels

New JTC 1 logo for 2025

Following work by ISO, and of course by IEC, acknowledging ISO’s logo and colours, these have now been merged into a new JTC 1 logo, which is rolling out across media channels and documentation. You can download the .png file here: https://tinyurl.com/JTC1Logo-2025.

JTC 1/AG 1 Communications

 

As always, thanks goes out to all our contributors to this quarter’s newsletter, the AG 1 team for getting it ready, and don’t forget that you can submit articles to be included in the next quarterly newsletter by emailing us directly or by using the online submission form at JTC1info.org, we’d love to hear from you.

Deadline for the contributions to the next newsletter is September 12th 2025.

Tags