Walte Fumy
This fellowship supports my engagement in ISO/IEC JTC 1 ‘Information technology’ is not on a working level (such as a contributor to specific standards) but on a strategic level.
This fellowship supports my engagement in ISO/IEC JTC 1 ‘Information technology’ is not on a working level (such as a contributor to specific standards) but on a strategic level.
My work aims to rationalise the resulting compliance efforts through a dedicated Technical Report (TR) under ETSI CYBER. This report will help reduce legal ambiguity, support standardisation across sectors, and ensure proportional and efficient compliance.
Through this fellowship, I am contributing to shape the standards around next-generation secure computing infrastructure. We are on the verge of a new paradigm where the security of the computing infrastructure is endorsed by hardware features and ensures protection of data at rest, in transit, and in use.
The use of digital identity wallets is foreseen to be the best appropriate solution to support an age verification method, which uses the date of birth of the individual without disclosing it.
There is currently no standard addressing the cybersecurity of AI systems. In ISO/IEC JTC1 SC27 WG4 27090 is under development; and I contribute directly to this work.
Annegrit's priority is the Convenorship of CEN CENELEC JTC21 WG 5, the organisation and project support to work on the AI Act standardisation request for Cybersecurity. This includes a close collaboration with other groups within JTC 21, JTC 13, ISO IEC SC 42 and SC 27 to collect all information of existing and work under development. The main challenge is that JTC 21 and also our WG5 has a diverse structure of experts and knowledge, which makes the work, the effort and efficiency very difficult. In this case, the challenge in addition is the collaboration with other existing standardisation groups within JTC 21 as well as with JTC 13 for Cyber Resilience Act, with ETSI and their view, with ISO IEC SC 27 and SC 42.
My work aims to develop robust frameworks for the verification of cryptographic protocols within the security of ICT products, services, and processes, thereby enhancing resilience against cyber threats.
Understanding how to work in international standardisation committees is vital, which implies going beyond IT asset management microcosm to deliver more value to related disciplines such as cybersecurity or sustainability.
Improving security is one of the most, if not the most, important priorities for the evolution and future development of the IoT.
This fellowship allows me to take part to all meetings concerning Cybersecurity, Privacy and Artificial Intelligence (even most are very early or very late in the day, as per rules for scheduling in SDO's), whilst being able to keep delivering standard based consulting especially for SMEs which need to comply for ISO 27001 certifications mostly.
My fellowship focuses on several priorities and key gaps related to AI and cybersecurity standards applied in education.
This technical report, resulting from my fellowship’s contributions, is an equitable analysis of the relationship between Quantum Key Distribution (QKD) and Post-quantum Cryptography (PQC) technologies. It describes the two technologies' complementary nature and highlights their potential advantages and benefits.