<metadata>
  <entry>
    <string>PUBLICCOMMENTCLOSE</string>
    <date>2020-03-04 00:00:00.0 UTC</date>
  </entry>
  <entry>
    <string>STATEMENTNAME</string>
    <string>&lt;p&gt;&lt;a href=&quot;https://www.icann.org/public-comments/ssr2-rt-draft-report-2020-01-24-en&quot;&gt;Second&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team Draft Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STATEMENTSTATUS</string>
    <string>&lt;p&gt;&lt;ac:structured-macro ac:name=&quot;status&quot; ac:schema-version=&quot;1&quot; ac:macro-id=&quot;c455e4da-ec65-4b01-89c1-db9019fccd05&quot;&gt;&lt;ac:parameter ac:name=&quot;colour&quot;&gt;Yellow&lt;/ac:parameter&gt;&lt;ac:parameter ac:name=&quot;title&quot;&gt;DRAFTING&lt;/ac:parameter&gt;&lt;/ac:structured-macro&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STATEMENTASSIGNEE</string>
    <string>&lt;p&gt;Drafting team volunteer(s):&lt;/p&gt;&lt;p&gt;&lt;ac:link&gt;&lt;ri:user ri:userkey=&quot;8aa0802249f42f260149f4308adb0311&quot; /&gt;&lt;/ac:link&gt;&lt;/p&gt;&lt;p&gt;&lt;ac:link&gt;&lt;ri:user ri:userkey=&quot;8aa0802249f42f260149f4308aaf028e&quot; /&gt;&lt;/ac:link&gt;&lt;/p&gt;&lt;p&gt;&lt;ac:link&gt;&lt;ri:user ri:userkey=&quot;8aa0802249f42f260149f4308992002e&quot; /&gt;&lt;/ac:link&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STAFFCONTACT</string>
    <string>&lt;p&gt;Negar Farzinnia&lt;br /&gt;&lt;a href=&quot;mailto:negar.farzinnia@icann.org&quot; style=&quot;text-decoration: none;&quot;&gt;negar.farzinnia@icann.org&lt;/a&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STATEMENTNUMBER</string>
    <string></string>
  </entry>
  <entry>
    <string>PUBLICCOMMENTINFO</string>
    <string>&lt;h2 style=&quot;text-align: start;&quot;&gt;Brief Overview&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Purpose:&lt;/em&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;This Public Comment proceeding is on behalf of the second&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team. The&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review is mandated by&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s Bylaws (&lt;a href=&quot;https://www.icann.org/resources/pages/governance/bylaws-en/#article4.6&quot; style=&quot;text-decoration: none;&quot;&gt;Article 4, Section 4.6(c)&lt;/a&gt;) to review&lt;span&gt; &lt;/span&gt;&lt;em&gt;&amp;quot;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s execution of its commitment to enhance the operational stability, reliability, resiliency, security, and global interoperability of the systems and processes, both internal and external, that directly affect and/or are affected by the Internet&amp;apos;s system of unique identifiers that&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;coordinates.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Current Status:&lt;/em&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The SSR2 Review Team seeks to solicit input on its&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/ssr2-review-24jan20-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;draft report&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Next Steps:&lt;/em&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The SSR2 Review Team will carefully consider comments received and amend the report as it deems appropriate and in the public interest before submitting its final report to the Board. The final report will be published for Public Comment in advance of the Board&amp;apos;s consideration.&lt;/p&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section I: Description and Explanation&lt;/h2&gt;&lt;p&gt;This Public Comment proceeding is on behalf of the second&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team who seeks to solicit input on its&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/ssr2-review-24jan20-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;draft report&lt;/a&gt;. The report contains findings and recommendations in four key areas:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Implementation and impact of recommendations from the&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/resources/pages/ssr1-progress-milestones-2019-08-07-en&quot; style=&quot;text-decoration: none;&quot;&gt;first SSR review&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Key stability issues within&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;.&lt;/li&gt;&lt;li&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;, stability, and resilience of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name&quot;&gt;Domain Name&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;System (&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;).&lt;/li&gt;&lt;li&gt;Future challenges.&lt;/li&gt;&lt;/ul&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section II: Background&lt;/h2&gt;&lt;p&gt;The&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review is mandated by&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s Bylaws (&lt;a href=&quot;https://www.icann.org/resources/pages/governance/bylaws-en/#article4.6&quot; style=&quot;text-decoration: none;&quot;&gt;Article 4, Section 4.6(c)&lt;/a&gt;) to review&lt;span&gt; &lt;/span&gt;&lt;em&gt;&amp;quot;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s execution of its commitment to enhance the operational stability, reliability, resiliency, security, and global interoperability of the systems and processes, both internal and external, that directly affect and/or are affected by the Internet&amp;apos;s system of unique identifiers that&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;coordinates.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Per the&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/resources/pages/governance/bylaws-en/#article4.6&quot; style=&quot;text-decoration: none;&quot;&gt;Bylaws&lt;/a&gt;, the issues that the review team for the SSR Review (&amp;quot;SSR Review Team&amp;quot;) may assess are the following:&lt;/p&gt;&lt;p&gt;(A) security, operational stability and resiliency matters, both physical and network, relating to the coordination of the Internet&amp;apos;s system of unique identifiers;&lt;/p&gt;&lt;p&gt;(B) conformance with appropriate security contingency planning framework for the Internet&amp;apos;s system of unique identifiers; and&lt;/p&gt;&lt;p&gt;(C) maintaining clear and globally interoperable security processes for those portions of the Internet&amp;apos;s system of unique identifiers that&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;coordinates.&lt;/p&gt;&lt;p&gt;(iii) The SSR Review Team shall also assess the extent to which&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;has successfully implemented its security efforts, the effectiveness of the security efforts to deal with actual and potential challenges and threats to the security and stability of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;, and the extent to which the security efforts are sufficiently robust to meet future challenges and threats to the security, stability and resiliency of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;, consistent with&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s Mission.&lt;/p&gt;&lt;p&gt;(iv) The SSR Review Team shall also assess the extent to which prior SSR Review recommendations have been implemented and the extent to which implementation of such recommendations has resulted in the intended effect.&lt;/p&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section III: Relevant Resources&lt;/h2&gt;&lt;p style=&quot;text-align: start;&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Second&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/ssr2-review-24jan20-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;Draft Report&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section IV: Additional Information&lt;/h2&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;SSR2 Review Team wiki space:&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://community.icann.org/x/AE6AAw&quot; style=&quot;text-decoration: none;&quot;&gt;https://community.icann.org/x/AE6AAw&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review page on &lt;a href=&quot;http://icann.org&quot;&gt;icann.org&lt;/a&gt;:&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/resources/reviews/specific-reviews/ssr&quot; style=&quot;text-decoration: none;&quot;&gt;https://www.icann.org/resources/reviews/specific-reviews/ssr&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Final Report of the first&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review Team (SSR1):&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/final-report-20jun12-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;https://www.icann.org/en/system/files/files/final-report-20jun12-en.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;SSR1 Review implementation wiki page:&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://community.icann.org/x/tYdCAw&quot; style=&quot;text-decoration: none;&quot;&gt;https://community.icann.org/x/tYdCAw&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section V: Reports&lt;/h2&gt;</string>
  </entry>
  <entry>
    <string>FINALVERSION</string>
    <string></string>
  </entry>
  <entry>
    <string>FINALDRAFT</string>
    <string>&lt;p&gt;The ALAC appreciates the opportunity to comment on the Second Security, Stability, and Resiliency (SSR2) Review Team Draft Report.&lt;/p&gt;&lt;p&gt;Ensuring the security, stability and resiliency of the DNS is arguably ICANN&amp;apos;s single most important role.&lt;/p&gt;&lt;p&gt;SSR1 issued 28 recommendations. The ICANN Org reports indicated the Board judged all to be relevant and implementable and that all were fully implemented. The SSR2 analysis was that of the 28 recommendations, 2 were not implemented at all, 26 were partially implemented and none fully implemented. Of these 27 of the 28 were found to still be relevant. That is an astounding analysis 8 years after the acceptance of the SSR1 recommendations.&lt;/p&gt;&lt;p&gt;The ALAC has a particular interest in the recommendations related to domain name abuse, and notes that several of the recommendations overlap with and complement those issues by the RDS-WHOIS2-RT [and the CCT RT?].&lt;/p&gt;&lt;p&gt;The ALAC also notes that in the opinion of the SSR2 RT, many of the recommendations are deemed to be of high priority. Given the current interest in ICANN of prioritizing activities with the implicit effect of not addressing those lower on the list, this could lead to not addressing issues critical to the SSR of the DNS. DNS Security, stability and resiliency is not something that we can afford to ignore. The lead item in ICANN&amp;apos;s Strategic Plan is &lt;strong&gt;&lt;em&gt;&amp;quot;Strengthen the security of the Domain Name System and the DNS Root Server System.&amp;quot;&lt;/em&gt;&lt;/strong&gt;. This must be taken into account when allocating resources and we trust that this will be taken into account when the Board works with the RT Implementation Shepherds on deciding how to prioritize the recommendation implementation.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Summary:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;We are living in a world where many parties seem to have a interest in destabilizing critical infrastructure and the Internet in particular. The fact that our systems have been sufficiently robust in the past is not an indication that this is sustainable moving forward. ICANN needs to take seriously the need to professionally and rigorously ensure the SSR of its DNS operations. In particular, known vulnerabilities need to be corrected with the utmost haste.&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>FIRSTDRAFT</string>
    <string>&lt;p&gt;The ALAC appreciates the opportunity to comment on the Second Security, Stability, and Resiliency (SSR2) Review Team Draft Report.&lt;/p&gt;&lt;p&gt;Ensuring the security, stability and resiliency of the DNS is arguably ICANN&amp;apos;s single most important role.&lt;/p&gt;&lt;p&gt;SSR1 issued 28 recommendations. The ICANN Org reports indicated the Board judged all to be relevant and implementable and that all were fully implemented. The SSR2 analysis was that of the 28 recommendations, 2 were not implemented at all, 26 were partially implemented and none fully implemented. Of these 27 of the 28 were found to still be relevant. That is an astounding analysis 8 years after the acceptance of the SSR1 recommendations.&lt;/p&gt;&lt;p&gt;The ALAC has a particular interest in the recommendations related to domain name abuse, and notes that several of the recommendations overlap with and complement those issues by the RDS-WHOIS2-RT [and the CCT RT?].&lt;/p&gt;&lt;p&gt;The ALAC also notes that in the opinion of the SSR2 RT, many of the recommendations are deemed to be of high priority. Given the current interest in ICANN of prioritizing activities with the implicit effect of not addressing those lower on the list, this could lead to not addressing issues critical to the SSR of the DNS. DNS Security, stability and resiliency is not something that we can afford to ignore. The lead item in ICANN&amp;apos;s Strategic Plan is &lt;strong&gt;&lt;em&gt;&amp;quot;Strengthen the security of the Domain Name System and the DNS Root Server System.&amp;quot;&lt;/em&gt;&lt;/strong&gt;. This must be taken into account when allocating resources and we trust that this will be taken into account when the Board works with the RT Implementation Shepherds on deciding how to prioritize the recommendation implementation.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Summary:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;We are living in a world where many parties seem to have a interest in destabilizing critical infrastructure and the Internet in particular. The fact that our systems have been sufficiently robust in the past is not an indication that this is sustainable moving forward. ICANN needs to take seriously the need to professionally and rigorously ensure the SSR of its DNS operations. In particular, known vulnerabilities need to be corrected with the utmost haste.&lt;/p&gt;</string>
  </entry>
</metadata>
