Connecting the world and beyond

Dec25-summary


Executive Summary

Meeting of ITU-T SG17 'Security', Geneva, 3-11 December 2025

1         Hot topics of this meeting (summarizing both input & output)

  • agentic AI: security, trust framework and identity management
  • identity management and trust management framework
  • security of generative AI systems, AI applications and AI cloud
  • computing power network security
  • intelligent transport system and autonomous driving security
  • Quantum readiness and new essential Quantum Key Distribution work
  • Intelligent Transport System security
  • Public key and privilege management Infrastructure as foundation for digital trust
  • Digital Emblems
  • Parental control
  • Year 2000 problem is back in 2036 and 2038
2         Meeti​ng Output (meeting statistics see Annex E below)

–     Output standards (46, see Annex A): 

    • TAP approval (10): Details are in Annex A a).
    • TAP not approved (0): Details are in Annex A b).
    • TAP determined (12): 11 new and 1 revised Recommendations. Details are in Annex A c).
    • AAP consented (12): 10 new and 2 revised Recommendations for AAP Last Call. Details are in Annex A d).
    • Agreed (12): 1 new Supplement, 1 new erratum, 7 Technical Reports and 3 SG17 documents. Details are in Annex A e).

–    New work items (55, see Annex B) were established, one work item was discontinued (see Annex C)

–    New OID registration authority for Senegal: {joint-iso-itu-t(2) country(16) sn(686)}

–    SG17 Correspondence Groups

  • Terminated:
    • CG-SECAPA (Correspondence Group on Security Capability and Architecture),
    • CG-AISEC-STRAT (Correspondence group on Strategy for AI security in Telecommunication/ICTs).
  • Continued:
    • CG-COP (Child online protection): continued existing ToR (ref. Annex G of SG17-R1).
    • CG-RES-MODERN (Correspondence group to SG17 restructuring and modernization): continued with slightly modified ToR in TD185/P

    Agreement on SG17 Content Week format (see section 3)

    SG17 structure updates (pending TSAG endorsement)

    • Creation of new Question 16/17 on AI Security
    • Merge of Question 3 and Question 10
    • Amendment of Question 7
    • Termination of JCA-COP
    • Creation of JRG-CQR

    ​SG17 Modernization (outcome since the last meeting)

  • Efficiency: new SG17 plenary format with reinforcement of Working Party roles
    • WP openings in parallel,
    • Questions closing in sequence within their WP,
    • Plenary sessions to process LS/o helped gained nearly 2x4 hours of WP and SG17 closing plenary meetings times
  • Quality:
    • 55 new work items established out of 65 proposed (85%),
    • all WP4 first interim meeting 8 decisions were approved without reopening the texts.
  • Coordination:
    • CEN/CENELEC, IETF, ETSI, FIRST, OIDF relationships reinforced
  • Visibility:
    • SG17 workshop for newcomers in demand by 2 member states after first success in the United States
    • TSB Communications team engaged
    • much improved newcomer's session
  • Industry Engagement:
    • 37 engaged invited experts vs 9 at the last meeting leading to 5 formal requests for membership and around 10-15 leads in progress
    • New type of industries as end-users attended
      • especially from finance sector: Statestreet, AXA, JP Morgan
      • this is strategic in the long term to help establishing standardization in the field of security
    • Net new sector members: Thales, Cognizant, Amazon, Zscaler
    • Net new associate members: Metomic, Logically AI, ServiceNow

​​​​3     ​​ ​   Future SG17 meetings

3.1        WP/SG/workshop events,

date​VenueeventScope
6 Feb 2026MyWorkspaceSG17 virtual plenaryTAP approval of common text
X.1058rev | ISO/IEC 29151. See Col 5/17
30-31 March 2026GenevaSG17 1st content weekworkshop Trustable and interoperable digital identities for humans and AI agents
1 April 2026GenevaRGMs (see 3.2 below)
2 April 2026GenevaWP1, 2, 3, 4/17 meetings
9 April 2026MyWorkspaceSG17 virtual plenaryTAP approval of common text
X.1901 (ex X.aas) | ISO/IEC 27566-1. See Col 6/17
14 May 2026 1300-1800Geneva5th ITU X.509 Day eventOrganize with GSMA, physical + remote
June 2026 (during SG17 meeting) GenevaWorkshop on globally interoperable digital identity 
Tue 2 – Thu 11 June 2026GenevaSG17 meeting SG17 plenary meeting in 2025-2028 Study Period
10 July 2026 (during AI4Good 2026)GenevaAgentic AI security workshop 

7-11 Sept 2026

 

Chongqing, China (TBC)SG17 2nd content weekWorkshop, RGMs, and WP meetings. (Planning)

3.2        Interim RGMs

12 Questions plan to hold the following 18 RGMs in the interregnum period before  SG17 June 2026 meeting:

#

Q
DatePlace/HostSubject/objective
1.     1/174 March 2026MyWorkspaceDiscussion on trust and ongoing WIs
2.     1/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteDiscussion on trust
3.     2/1730 March – 1 April 2026 (SG17 content week)Geneva+remote
  • prepare texts for action in the next SG17 meeting: XSTR.FMSC-IMT2030, X.ztmc, XSTR.sa-ran, XSTR.sec-int-cpc and XSTR.srsec
  • review all work items and identify future topics for Q2/17
4.     3/17

13:00-14:00 CET 2 February 2026

MyWorkspaceX.1058rev TAP consultation result
5.     3/17

13:00-14:00 CET 4 February 2026

MyWorkspaceDiscussion on X.cdc-csirt
6.     4/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteDiscuss ongoing WIs
7.     6/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteJCG-IoTSec related issues
8.     7/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteApplication security including  AI security.
9.     7/17May 2026 MyWorkspaceProgress on AI security strategy
10.  8/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteProgress on WIs for action and potential new work items
11.  10/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteX.srm-ssc, and all other Q10 work items
12.  10/17May 2026MyWorkspaceall Q10 work items
13.  11/1713-17 April 2026Seoul (Republic of Korea)Joint ISO/IEC/JTC 1/SC 6/WG 10 and ITU-T Q11/17 meeting, see TD 131/1
14.  13/1730 March – 1 April 2026 (SG17 content week)Geneva+remote

- Finalization of X.idse, X.af-sec, X.evpnc-sec, X.fod-sec

- Progress on on-going items 

- Initial discussion on new work items

15.  13/17

8 - 9 July 2026

 

Seoul+remote

- Progress on on-going items 

- Initial discussion on new work items

16.  14/1730 March – 1 April 2026 (SG17 content week)Geneva+remoteProgress on WIs for action and potential new work items
17.  15/1730 March – 1 April 2026 (SG17 content week)Geneva+remote

-   Review documents for agreement on TR.kdc_qkdn, TR.QKDN-SP

-   Review potential new WI on XSTR.FMSC-SP

18.  15/1727-30 April 2026Japan/TTC

-   Finalize for agreement on TR.kdc_qkdn, TR.QKDN-SP

-   Progress on going Wis

-   Other input contributions


Annex A
Actions taken on Recommendations, and other texts at SG17 closing plenary on 11 December 2025

a)    TAP Recommendations approved (WTSA-24 Resolution 1) (10)

#​Q/17AcronymTitleNew / RevisedBase text

 Equivalent

e.g., ISO/IEC

1.       Q3/17X.1062 (ex X.shcd)*Framework for Security Human Capability DevelopmentNewTD128/3 
2.       Q4/17X.1238 (ex X.sgc-rcs)*Guidelines for countering spam over rich communication service (RCS) messagingNewTD135/3 
3.       Q6/17X.1128 (ex X.mt-feature)*Security features to assess mobile terminal securityNewTD105/2 
4.       Q6/17X.1129 (ex X.mt-integrity)*Security guidelines for mobile terminal integrity protectionNewTD106/2 
5.       Q7/17X.1130 (ex X.tg-fdma)*Technical guidelines for fraud detection of malicious applications in mobile devicesNewTD140/4 
6.       Q7/17X.1457 (ex X.str-irs)*Security threats and requirements for information recommendation serviceNewTD143/4 
7.       Q8/17X.1649 (ex X.sgmc)*Security guidelines for multi-cloudNewTD142/4 
8.       Q8/17X.1753 (ex X.gdsml)*Guidelines for data security using machine learning in big data infrastructureNewTD190/4 
9.       Q8/17X.1631revInformation security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud servicesRev.TD147/4ISO/IEC 27017
10.    Q10/17X.1250rev*Baseline capabilities for enhanced identity management and interoperabilityRev.TD149/1 

 

b)    TAP Recommendations not approved (WTSA-24 Resolution 1)

None.

c)     TAP Recommendations determined (WTSA-24 Resolution 1) (12)

 #Q/17AcronymTitleNew / RevisedBase text

Equivalent

e.g., ISO/IEC

1.       Q2/17X.1821
(ex X.5Gsec-asra)
Guidelines and Technical Requirements for Analysis of 5G Network Asset Security Risk NewTD103/2  
2.       Q4/17X.2105
(ex X.st-ssc)
Security threats of software supply chainNewTD101/3 
3.       Q6/17X.1350
(ex X.sr-iiot)
Security requirements for the industrial Internet of things based smart manufacturing reference modelNewTD112/2 
4.       Q7/17X.2210
(ex X.ig-dw)
Implementation guidelines for digital watermarkingNewTD171/4 
5.       Q7/17X.1910
(ex X.tc-ifd)
Technical capabilities of interactive deception risk detectionNewTD172/4 
6.       Q8/17X.1607
(ex X.asm-cc)
Requirements of attack surface management for cloud computingNewTD103/4  
7.       Q8/17X.1651
(ex X.soar-cc)
Framework of security orchestration, automation and response for cloud computingNewTD105/4  
8.       Q10/17X.1280revFramework for out-of-band mutual authentication using mobile devicesRevTD114/1 
9.       Q10/17X.1901
(ex X.aas)
Information security, cybersecurity and privacy protection — Age assurance systems — Part 1: FrameworkNewTD83R5/1 ISO/IEC 27566-1
10.    Q10/17X.1286
(ex X.accsadlt)
Access security authentication based on DLTNewTD115/1 
11.    Q14/17X.1418
(ex X.sg-dcs)
Security guidelines for DLT-based digital collection servicesNewTD156/4 
12.    Q14/17X.1417
(ex X.sr-dpts)
Security requirements for DLT data on permissioned DLT-based distributed power trading systemsNewTD155/4 

 

d)    AAP Recommendations consented (Recommendation ITU-T A.8) (12)

#Q/17AcronymTitleNew / RevisedBase text

Equivalent

e.g., ISO/IEC

1.       Q3/17X.1060revFramework for the creation and operation of a cyber defence/security centreRevTD129/3 
2.       Q4/17X.2014
(ex X.dtns)
Guidelines of using digital twin of network for network securityNewTD94/3  
3.       Q4/17X.1560
(ex X.nspam)
Security framework for network storage protection against malware attacksNewTD93/3  
4.       Q8/17X.1416
(ex X.mbaas-cs-sec)
Security requirements and framework of collaboration service for multiple blockchain-as-a- service platformsNewTD146/4 
5.       Q14/17X.1400revTerms and definitions for distributed ledger technologyRev.TD193/4 
6.       Q10/17X.1096
(ex X.bvm)
Requirements for biometric variability managementNewTD117/1  
7.       Q10/17X.1268
(ex X.oob-pacs)
Framework for out-of-band physical access control systems using beacon-initiated mutual authenticationNewTD123/1  
8.       Q10/17X.2310
(ex X.srdidm)
Security requirements for decentralized identity management systems using distributed ledger technologyNewTD94/1  
9.       Q10/17X.1097
(ex X.tas)
Telebiometric authentication using speaker recognitionNewTD109/1  
10.    Q10/17X.1098
(ex X.tis)
Telebiometric authentication based on information splittingNewTD147/1  
11.    Q15/17X.1711
(ex X.sec_QKD_profr)
Framework of quantum key distribution (QKD) protocols in QKD networkNewTD86/1  
12.    Q15/17X.1718
(ex X.sec_QKDNi)
Security requirements for Quantum Key Distribution Network interworking (QKDNi)NewTD87/1  

 

e)     Non-normative texts (Technical Report, Supplement, Implementers' Guide, etc) agreed (12)

      #

Q/17AcronymTitleNew / RevisedBase text

1.       

Q1/17Security CompendiumICT Security CompendiumRev.TD97/3

2.       

Q1/17Security standards roadmapICT Security standards roadmapRev.TD98/3

3.       

Q1/17SG17 implementation of WTSA ResSG17 activities and achievements in support of the most recent Resolutions of the WTSARev.TD141/P

4.       

Q2/17XSTR.sd-cncTechnical report: Security guidelines for data of coordination of networking and computingNewTD102/2

5.       

Q2/17XSTR.sg-lmcsTechnical report: Security guidelines for DLT-based lifecycle management of computing servicesNewTD108/2

6.       

Q6/17XSTR.trust-metaverseTechnical Report: Technical challenges to achieving trustworthy metaversesNewTD139/2

7.       

Q7/17XSTR.AIsecTechnical Report: Artificial intelligence security standardization strategyNewTD145/4

8.       

Q7/17XSTR.dpamaTechnical Report on "Landscape analysis for data protection of avatars in metaverse applications"NewTD188/4

9.       

Q7/17XSTR.saAIoTTechnical Report: Security Threat Analysis for Artificial Intelligence of Things on DevicesNewTD180/4

10.    

Q7/17XSTR.se-AITechnical Report: Security Evaluation on Artificial Intelligence Technology in ICTNewTD149/4

11.    

Q10/17X.sup-divs (ex TR.divs)Supplement to X.1403: Rationale and initial approach of decentralized identity verification system (DIVS) based on verifiable dataQ10NewTD132/1

12.    

Q14/17

X.1408 erratum

 
 New
TD194/4


 

Annex B
New work items

The following new work items were agreed to be added to the SG17 Work Programme:

Q#
(total# of NWIs)
#WI abbreviationTitleTD#
1/17
(6)
1.       

XSTR.diem-assets**

incubated

Technical Report: Digital emblems as a key solution in resolving the issue of inappropriately exposed OT assets in the cyber spaceTD113/3
2.       XSTR.CRAMMS**Technical Report: SG17 Cyber Security Reference Architectures, Methodologies, Models and Strategies (CRAMMS) RoadmapTD115/3
3.       

X.crta*

incubated

Framework for Cyber Resilience Testing and AssuranceTD111/3
4.       

X.PARCEP*

Incubated

Interoperable Parental Control Enforcement Policies (PARCEP) for Child Online ProtectionTD114/3
5.       

XSTR.diem**

incubated

Technical Report: Digital International Humanitarian Law EmblemsTD112/3
6.       X.te-consent*Framework for Trust Enhancing Consent ManagementTD121/3
2/17
(4)
7.       X.fast*Functional Architecture of Security Testbed for Telecommunication OperatorsTD127/2
8.       X.5Gsec-CNC*Security requirements and guidelines for Coordination of networking and computing in IMT-2020 networks and beyondTD117/2
9.       X.cpn-tp-sec*Security requirements and capabilities of computing power network transaction platformTD111/2
10.    X.cpn-gw-sec*Security requirements and security-enhanced architecture of the CPN gatewayTD113/2
3/17
(1)
11.    XSTR.AIsmf**Technical Report: Artificial Intelligence Security Management FrameworkTD131/3
4/17
(5)
12.    XSTP.epoch**Technical Paper: Global Coordination Requirements for 2038-class rollover events (including but not limited to 2036, 2038, 2106)TD122/3
13.    X.SecaaS-ReqSecurity requirements in the domain of security as a serviceTD99/3
14.    X.sim-gAI*Guidelines for security incident management of generative artificial intelligence servicesTD103/3
15.    XSTR.da-AIcsp**Technical Report: Development and Analysis of an AI-Based Cybersecurity Simulation PlatformTD119/3
16.    XSTR.cfscgap**Technical Report: Impact of client-facing servers and content delivery networks  on  centralizationTD125/3
6/17
(5)
17.    X.tdu-mv*Requirements for components of trusted data use in building a trustworthy metaverseTD126/2
18.    X.sr-ppgs*Cybersecurity requirements for photovoltaic power generation systemTD110/2
19.    XSTR.sec-Dba-eSIM**Technical Report: Security considerations for DLT-based authentication of IoT devices with eSIMTD109/2
20.    XSTR.MVDTsecRM**Technical Report: Metaverse and digital twin security standardization roadmapTD116/2
21.    XSTR.IoTsecRM**Technical Report: IoT security standardization roadmapTD115/2
7/17
(11)
22.    XSTR.AI-GSB**Technical Report: Guidelines of security benchmark for foundation modelsTD158/4
23.    X.LLMCC*Guidelines for Large Language Model data security based on Confidential ComputingTD165/4
24.    XSTR.ltf-AAI**Technical Report: Landscape of Trust Framework for Agentic AITD179/4
25.    X.rg-dis*Requirements for guidelines for Data Interaction Security in Training and Inference Stages of Generative Artificial IntelligenceTD164/4
26.    XSTR.sem-AIA**Technical Report: Security evaluation methods for artificial intelligence agentTD181/4
27.    X.gavd-mas Guidelines for application vulnerability detection based on multi-agent systemTD183/4
28.    X.sr-taimasSecurity requirements for terminal-based artificial intelligence multi-agent systemTD182/4
29.    X.srg-AIgisSecurity requirements and guidelines for artificial intelligence-based image generation system  TD113/4
30.    X.sg-eAISecurity requirements and guidelines for embodied artificial intelligence systemsTD114/4
31.    X.sreg-ICSSecurity Requirements and Evaluation Guidelines for Intelligent Customer ServicesTD115/4
32.    X.sg-GenAIdSecurity Guidelines for Generative Artificial Intelligence Data Life CycleTD116/4
8/17
(3)
33.    X.sr-aicp*Security Requirements for Artificial Intelligence Cloud PlatformTD168/4
34.    X.sr-AIec*Security Requirements for AI-Enhanced Collaboration in Cloud InfrastructureTD177/4
35.    X.sgds-bdi*Security guidelines for data sharing across big data infrastructuresTD185/4
10/17
(8)
36.    XSTR.gidi**Technical Report: Globally Interoperable Digital Identity (including Humans/Enterprise/Non-Humans i.e. Agentic AI)TD145/1
37.    X.sc-sd*Security capability for implementing selective disclosure system in the decentralized identity systemTD129/1
38.    X.sg-dfivc*Security guidelines for data format interoperability of verifiable credential in decentralized identity systemTD127/1
39.    X.dpidm-aAI*Terminology and design guidelines for Agentic AI identity management TD134/1
40.    X.remote-qes*Security and interoperability framework for remote and cloud qualified electronic signaturesTD121/1
41.    X.f2am*FAPI 2.0 Attacker Model TD140/1
42.    X.f2sp*FAPI 2.0 Security Profile TD143/1
43.    X.sup-dsa**Supplement to X.1286: Implementation guidelines for DLT-based secure authentication (DSA) in digital financial servicesTD120/1
11/17
(6)
44.    XSTR.qrbp**Technical Report: Quantum Readiness, Best Practices and Guidelines"TD152/1
45.    X.migrate |
(ISO/IEC 9594-x)
Information Technology - Open systems Interconnection - The Directory - Generic methods for migration of cryptographic algorithms TD153/1
46.    X.510rev3rd edition of Rec. ITU-T X.510 | ISO/IEC 9594-11: The Directory - Protocol specifications for secure operationsTD154/1
47.    X.pmi
(ISO/IEC 9594-x)
Information Technology - Open systems Interconnection - The Directory - Framework for privilege management infrastructureTD155/1
48.    X.509rev10th edition of Rec. ITU-T X.509 | ISO/|IEC 9594-8: The Directory: Public-key and attribute certificate frameworksTD156/1
49.    X.508revNew work item proposal for 2nd edition of Rec. ITU-T X.508 | ISO/IEC 9594-12TD157/1
13/17
(2)
50.    X.abt-sec*Security guidelines for accounting-based ticketing in intelligent transport systemsTD133/2
51.    X.1375rev*Guidelines for an intrusion detection system for in-vehicle networksTD134/2
14/17
(1)
52.    XSTR.SR4DLTsec**Technical Report: Standardization roadmap for DLT securityTD150/4
15/17
(3)
53.    X.sec_QKDNi_ccmSecurity requirements and measures for QKDN interworking - Concatenated modelTD136/1
54.    XSTR.QKDN-nq-ZTA**Technical Report: Technical implications of applying zero trust architecture into QKDN TD138/1
55.    X.sec-QKDN-un-reqSecurity requirements and measures for the integration of QKDN and user network TD150/1

Note:  * marked items are for approval by TAP;  ** marked items are for approval by agreement; Items without any mark are for approval by AAP.


Annex C
Work items discontinued

QuestionAcronymTitle
Q1/17CRAMM RoadmapSG17 Cyber Security Reference Architectures, Models and Methodologies Strategy and Roadmap

 


 

Annex D
SG17 meeting Statistics

408/54 Participants/Countries (TD96/P)

  • new record (previous: 374/57, (last study period 302/47**, 292/55, 292/52, 276/39)) 
    Note ** 1-week meeting  
  • Provisional list of participants

     ​195 sessions (i.e.,1.5-hour slot) in this 7-days SG17 meeting (vs 191 sessions in last 8-days SG17 meeting in April 2025)

     
 Participants#of Countries# of Member States# of Sector Members# of SG17 Associates# of Academia# Invited Experts
Final4085442472737

 

Meeting input and organization

Table of SG17 statistics of this meeting

 

CLS/iLS/oTD
221
16667GENPLENWP1WP2WP3WP4
2339291755976

 

Contributions

221 – new record (past meetings: 189, 187, 153, 119, 104, 101). DDP: 99%

o   APT 184 (83%) (= China 84.5 + Korea 75.5 + India 12 + Japan 8.5 + Singapore 1 + Malaysia 2.5)

o   EUR 17.5 (8%) (= UK 9 + Denmark 5 + Switzerland 2 + France 1.5)

o   Americas 6.5 (3%) (= Canada 2.5 + US 4)

o   AFR 7 (3%) (= Congo 3 + Mali 1 + Rwanda 1 + South Africa 1 + Nigeria 1)

o   ARAB 4 (= Oman 1 + UAE 1 + Palestine 2)

o   RCC 2 (= Russia 2)

o   LAM (0)

LS/i/o (matrix in TD106/P)

·       166/70​​ (past meetings: 104/54, 187/28, 89/41 60/25 61/22, 55/21, 72/21)

TDs (632)

TD
GENPLENWP1WP2WP3WP4
239
9291755976

​