Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

SSAC Advisory Regarding Access to Domain Name Registration Data (R-5)


Date IssuedDocumentReference IDCurrent Phase

  

SSAC Advisory Regarding Access to Domain Name Registration Data (R-5)SAC101v2Phase 5 | Close




Progress Bar Container
step5
Progress Bar - Hyperlink Step
titlePhase 1 Receive
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 2 Understand
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 3 Evaluate
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 4 Implement
urlAdvice Process
Progress Bar - Hyperlink Step
titlePhase 5 Close
urlAdvice Process
Progress Bar - Hyperlink Step
titleClosed
urlAdvice Process


Description:

The SSAC reiterates Recommendation 2 from SAC061: "The ICANN Board should ensure that a formal security risk assessment of the registration data policy be conducted as an input into the Policy Development Process. A separate security risk assessment should also be conducted regarding the implementation of the policy." These assessments should be incorporated in PDP plans at the GNSO.


STATUS UPDATES

DatePhaseTypeStatus Updates

 

Phase 5AP FeedbackSSAC acknowledged the June 2019 notification and agreed with the ARR Team's classification of moving this item to "Phase 5 | Close Request".

 

Phase 5Phase UpdateOn 23 June 2019 the ICANN Board considered SAC101v2 and noted advice items 2A and three through seven in SAC101 version 2 and referred them to the GNSO Council for consideration for inclusion in the EPDP Phase 2 work (https://www.icann.org/resources/board-material/resolutions-2019-06-23-en#1.c). In its rationale the Board states "Advice item five reiterates Recommendation 2 from SAC061 and suggests that 'The ICANN Board should ensure that a formal security risk assessment of the registration data policy be conducted as an input into the Policy Development Process. A separate security risk assessment should also be conducted regarding the implementation of the policy.' The advice further suggests that 'These assessments should be incorporated in PDP plans at the GNSO.' As the advice suggests that the assessments be incorporated into PDP plans and the GNSO is the manager of PDPs, the Board notes and refers this advice to the GNSO Council."

 

Phase 5Phase ChangeNow in Phase 5: Close

 

Phase 3Board UpdateResolved (2019.06.23.06), the Board notes advice items 2A and three through seven in SAC101 version 2 and refers them to the GNSO Council for consideration for inclusion in the EPDP Phase 2 work. See full resolution at https://www.icann.org/en/board-activities-and-meetings/materials/approved-resolutions-regular-meeting-of-the-icann-board-open-session-23-06-2019-en#1.c.

 

Phase 2AP FeedbackSSAC confirmed understanding and added the following comments: SSAC notes that security risk assessments were not conducted as part of the recent ePDP that evaluated the Temp Spec.

 

Phase 2Board UnderstandingThe ICANN organization understands SAC101v2 Recommendation 5 to mean that the SSAC is reiterating its advice from SAC061 Recommendation 2, which states: "The ICANN Board should ensure that a formal security risk assessment of the registration data policy be conducted as an input into the Policy Development Process. A separate security risk assessment should also be conducted regarding the implementation of the policy." The ICANN org also understands that the SSAC is recommending that these security risk assessments of registration data policy be incorporated into PDP plans by the GNSO.

 

Phase 2Phase UpdateThe ICANN org received SAC101v2 on 12 December 2018 and is currently reviewing.

 

Phase 2Phase ChangeNow in Phase 2: Understand

 

Phase 1Phase UpdateICANN acknowledged receipt of SSAC101v2.

 

Phase 1Phase UpdateSSAC published SAC101v2: SSAC Advisory Regarding Access to Domain Name Registration Data Link: https://www.icann.org/en/system/files/files/sac-101-v2-en.pdf Version 2 of SAC101 was published to reflect evolving circumstances related to ICANN’s Temporary Specification for gTLD Registration Data, and the ongoing Expedited Policy Development Process (EPDP) on the Temporary Specification for gTLD Registration Data. Version 1 of SAC101 has been retired and version 2 is authoritative.