<metadata>
  <entry>
    <string>PUBLICCOMMENTCLOSE</string>
    <date>2020-03-20 00:00:00.0 UTC</date>
  </entry>
  <entry>
    <string>STATEMENTNAME</string>
    <string>&lt;p&gt;&lt;a href=&quot;https://www.icann.org/public-comments/ssr2-rt-draft-report-2020-01-24-en&quot;&gt;Second&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team Draft Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STATEMENTSTATUS</string>
    <string>&lt;p&gt;&lt;ac:structured-macro ac:name=&quot;status&quot; ac:schema-version=&quot;1&quot; ac:macro-id=&quot;ad5163de-eed9-4d5e-a952-cfe6f7d75d3f&quot;&gt;&lt;ac:parameter ac:name=&quot;colour&quot;&gt;Red&lt;/ac:parameter&gt;&lt;ac:parameter ac:name=&quot;title&quot;&gt;VOTE&lt;/ac:parameter&gt;&lt;/ac:structured-macro&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STATEMENTASSIGNEE</string>
    <string>&lt;p&gt;&lt;ac:link&gt;&lt;ri:user ri:userkey=&quot;8aa0802249f42f260149f4308adb0311&quot; /&gt;&lt;/ac:link&gt;&lt;/p&gt;&lt;p&gt;&lt;ac:link&gt;&lt;ri:user ri:userkey=&quot;8aa0802249f42f260149f4308aaf028e&quot; /&gt;&lt;/ac:link&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STAFFCONTACT</string>
    <string>&lt;p&gt;Negar Farzinnia&lt;br /&gt;&lt;a href=&quot;mailto:negar.farzinnia@icann.org&quot; style=&quot;text-decoration: none;&quot;&gt;negar.farzinnia@icann.org&lt;/a&gt;&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>STATEMENTNUMBER</string>
    <string></string>
  </entry>
  <entry>
    <string>PUBLICCOMMENTINFO</string>
    <string>&lt;h2 style=&quot;text-align: start;&quot;&gt;Brief Overview&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Purpose:&lt;/em&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;This Public Comment proceeding is on behalf of the second&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team. The&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review is mandated by&lt;span&gt; &lt;/span&gt;&lt;abbr class=&quot;&quot; style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s Bylaws (&lt;a href=&quot;https://www.icann.org/resources/pages/governance/bylaws-en/#article4.6&quot; style=&quot;text-decoration: none;&quot;&gt;Article 4, Section 4.6(c)&lt;/a&gt;) to review&lt;span&gt; &lt;/span&gt;&lt;em&gt;&amp;quot;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s execution of its commitment to enhance the operational stability, reliability, resiliency, security, and global interoperability of the systems and processes, both internal and external, that directly affect and/or are affected by the Internet&amp;apos;s system of unique identifiers that&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;coordinates.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Current Status:&lt;/em&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The SSR2 Review Team seeks to solicit input on its&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/ssr2-review-24jan20-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;draft report&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Next Steps:&lt;/em&gt;&lt;/strong&gt;&lt;span&gt; &lt;/span&gt;The SSR2 Review Team will carefully consider comments received and amend the report as it deems appropriate and in the public interest before submitting its final report to the Board. The final report will be published for Public Comment in advance of the Board&amp;apos;s consideration.&lt;/p&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section I: Description and Explanation&lt;/h2&gt;&lt;p&gt;This Public Comment proceeding is on behalf of the second&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team who seeks to solicit input on its&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/ssr2-review-24jan20-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;draft report&lt;/a&gt;. The report contains findings and recommendations in four key areas:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Implementation and impact of recommendations from the&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/resources/pages/ssr1-progress-milestones-2019-08-07-en&quot; style=&quot;text-decoration: none;&quot;&gt;first SSR review&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Key stability issues within&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;.&lt;/li&gt;&lt;li&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;, stability, and resilience of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name&quot;&gt;Domain Name&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;System (&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;).&lt;/li&gt;&lt;li&gt;Future challenges.&lt;/li&gt;&lt;/ul&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section II: Background&lt;/h2&gt;&lt;p&gt;The&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review is mandated by&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s Bylaws (&lt;a href=&quot;https://www.icann.org/resources/pages/governance/bylaws-en/#article4.6&quot; style=&quot;text-decoration: none;&quot;&gt;Article 4, Section 4.6(c)&lt;/a&gt;) to review&lt;span&gt; &lt;/span&gt;&lt;em&gt;&amp;quot;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s execution of its commitment to enhance the operational stability, reliability, resiliency, security, and global interoperability of the systems and processes, both internal and external, that directly affect and/or are affected by the Internet&amp;apos;s system of unique identifiers that&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;coordinates.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Per the&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/resources/pages/governance/bylaws-en/#article4.6&quot; style=&quot;text-decoration: none;&quot;&gt;Bylaws&lt;/a&gt;, the issues that the review team for the SSR Review (&amp;quot;SSR Review Team&amp;quot;) may assess are the following:&lt;/p&gt;&lt;p&gt;(A) security, operational stability and resiliency matters, both physical and network, relating to the coordination of the Internet&amp;apos;s system of unique identifiers;&lt;/p&gt;&lt;p&gt;(B) conformance with appropriate security contingency planning framework for the Internet&amp;apos;s system of unique identifiers; and&lt;/p&gt;&lt;p&gt;(C) maintaining clear and globally interoperable security processes for those portions of the Internet&amp;apos;s system of unique identifiers that&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;coordinates.&lt;/p&gt;&lt;p&gt;(iii) The SSR Review Team shall also assess the extent to which&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;has successfully implemented its security efforts, the effectiveness of the security efforts to deal with actual and potential challenges and threats to the security and stability of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;, and the extent to which the security efforts are sufficiently robust to meet future challenges and threats to the security, stability and resiliency of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;, consistent with&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Internet Corporation for Assigned Names and Numbers&quot;&gt;ICANN&lt;/abbr&gt;&amp;apos;s Mission.&lt;/p&gt;&lt;p&gt;(iv) The SSR Review Team shall also assess the extent to which prior SSR Review recommendations have been implemented and the extent to which implementation of such recommendations has resulted in the intended effect.&lt;/p&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section III: Relevant Resources&lt;/h2&gt;&lt;p style=&quot;text-align: start;&quot;&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Second&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;(SSR2) Review Team&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/ssr2-review-24jan20-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;Draft Report&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section IV: Additional Information&lt;/h2&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;SSR2 Review Team wiki space:&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://community.icann.org/x/AE6AAw&quot; style=&quot;text-decoration: none;&quot;&gt;https://community.icann.org/x/AE6AAw&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review page on &lt;a href=&quot;http://icann.org&quot;&gt;icann.org&lt;/a&gt;:&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/resources/reviews/specific-reviews/ssr&quot; style=&quot;text-decoration: none;&quot;&gt;https://www.icann.org/resources/reviews/specific-reviews/ssr&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Final Report of the first&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security – Security, Stability and Resiliency (SSR)&quot;&gt;Security&lt;/abbr&gt;,&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security, Stability and Resiliency&quot;&gt;Stability&lt;/abbr&gt;, and&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Security Stability &amp;amp; Resiliency (SSR)&quot;&gt;Resiliency&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;of the&lt;span&gt; &lt;/span&gt;&lt;abbr style=&quot;text-decoration: none;&quot; title=&quot;Domain Name System&quot;&gt;DNS&lt;/abbr&gt;&lt;span&gt; &lt;/span&gt;Review Team (SSR1):&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://www.icann.org/en/system/files/files/final-report-20jun12-en.pdf&quot; style=&quot;text-decoration: none;&quot;&gt;https://www.icann.org/en/system/files/files/final-report-20jun12-en.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;SSR1 Review implementation wiki page:&lt;span&gt; &lt;/span&gt;&lt;a href=&quot;https://community.icann.org/x/tYdCAw&quot; style=&quot;text-decoration: none;&quot;&gt;https://community.icann.org/x/tYdCAw&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 style=&quot;text-align: start;&quot;&gt;Section V: Reports&lt;/h2&gt;</string>
  </entry>
  <entry>
    <string>FINALVERSION</string>
    <string></string>
  </entry>
  <entry>
    <string>FINALDRAFT</string>
    <string></string>
  </entry>
  <entry>
    <string>FIRSTDRAFT</string>
    <string>&lt;p&gt;Draft submitted by Alan Greenberg and Jonathan Zuck, 25 February 2020, 16:20 UTC&lt;/p&gt;&lt;p&gt;Minor correction (confirming reference to CCT Review) and correcting a typo, 26 February 2020.&lt;/p&gt;&lt;p&gt;New text added in response to comments, shown in BLUE, added by Alan Greenberg, 19 March 2020, 20:48 UTC.&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;The ALAC appreciates the opportunity to comment on the Second Security, Stability, and Resiliency (SSR2) Review Team Draft Report.&lt;/p&gt;&lt;p&gt;Ensuring the security, stability and resiliency of the DNS is arguably ICANN&amp;apos;s single most important role.&lt;/p&gt;&lt;p&gt;SSR1 issued 28 recommendations. The ICANN Org reports indicated the Board judged all to be relevant and implementable and that all were fully implemented. The SSR2 analysis was that of the 28 recommendations, 2 were not implemented at all, 26 were partially implemented and none fully implemented. Of these 27 of the 28 were found to still be relevant. That is an astounding analysis 8 years after the acceptance of the SSR1 recommendations.&lt;/p&gt;&lt;p&gt;The ALAC has a particular interest in the recommendations related to domain name abuse, and notes that several of the recommendations overlap with and complement those issued by the RDS-WHOIS2-RT and the CCT RT.&lt;/p&gt;&lt;p&gt;The ALAC also notes that in the opinion of the SSR2 RT, many of the recommendations are deemed to be of high priority. Given the current interest in ICANN of prioritizing activities with the implicit effect of not addressing those lower on the list, this could lead to not addressing issues critical to the SSR of the DNS. DNS Security, stability and resiliency is not something that we can afford to ignore. The lead item in ICANN&amp;apos;s Strategic Plan is &lt;strong&gt;&lt;em&gt;&amp;quot;Strengthen the security of the Domain Name System and the DNS Root Server System.&amp;quot;&lt;/em&gt;&lt;/strong&gt;. This must be taken into account when allocating resources and we trust that this will be taken into account when the Board works with the RT Implementation Shepherds on deciding how to prioritize the recommendation implementation.&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #0000ff;&quot;&gt;The ALAC has a particular focus on and interest in DNS Abuse. To address this may require contractual changes to facilitate Contractual Compliance action. Such changes require either negotiations with the contracted parties or a PDP. A PDP will take considerable time and the ALAC does not advocate such a path, but rather it is time for ICANN Org and specifically Contractual Compliance to meet with those contracted parties who have shown an interest in DNS Abuse mitigation, and come to an agreement on needed contractual changes, factoring in not only penalties but any incentives that can be reasonably provided to encourage compliance.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #0000ff;&quot;&gt;Given the potential for rejection or deferral of the large number of high priority items, the ALAC encourages the review team to strengthen the justification on the high priority items.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Summary:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;We are living in a world where many parties seem to have a interest in destabilizing critical infrastructure and the Internet in particular. The fact that our systems have been sufficiently robust in the past is not an indication that this is sustainable moving forward. ICANN needs to take seriously the need to professionally and rigorously ensure the SSR of its DNS operations. In particular, known vulnerabilities need to be corrected with the utmost haste.&lt;/p&gt;</string>
  </entry>
  <entry>
    <string>CALLOPEN</string>
    <date>2020-02-26 00:00:00.0 UTC</date>
  </entry>
  <entry>
    <string>CALLCLOSE</string>
    <date>2020-03-19 00:00:00.0 UTC</date>
  </entry>
  <entry>
    <string>VOTEOPEN</string>
    <date>2020-03-20 00:00:00.0 UTC</date>
  </entry>
  <entry>
    <string>VOTECLOSE</string>
    <date>2020-03-25 00:00:00.0 UTC</date>
  </entry>
  <entry>
    <string>SUBMISSION</string>
    <date>2020-03-20 00:00:00.0 UTC</date>
  </entry>
</metadata>
