<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML xmlns="http://www.w3.org/TR/REC-html40" xmlns:v =
"urn:schemas-microsoft-com:vml" xmlns:o =
"urn:schemas-microsoft-com:office:office" xmlns:w =
"urn:schemas-microsoft-com:office:word" xmlns:x =
"urn:schemas-microsoft-com:office:excel" xmlns:p =
"urn:schemas-microsoft-com:office:powerpoint" xmlns:a =
"urn:schemas-microsoft-com:office:access" xmlns:dt =
"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s =
"uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs =
"urn:schemas-microsoft-com:rowset" xmlns:z = "#RowsetSchema" xmlns:b =
"urn:schemas-microsoft-com:office:publisher" xmlns:ss =
"urn:schemas-microsoft-com:office:spreadsheet" xmlns:c =
"urn:schemas-microsoft-com:office:component:spreadsheet" xmlns:odc =
"urn:schemas-microsoft-com:office:odc" xmlns:oa =
"urn:schemas-microsoft-com:office:activation" xmlns:html =
"http://www.w3.org/TR/REC-html40" xmlns:q =
"http://schemas.xmlsoap.org/soap/envelope/" xmlns:rtc =
"http://microsoft.com/officenet/conferencing" XMLNS:D = "DAV:" XMLNS:Repl =
"http://schemas.microsoft.com/repl/" xmlns:mt =
"http://schemas.microsoft.com/sharepoint/soap/meetings/" xmlns:x2 =
"http://schemas.microsoft.com/office/excel/2003/xml" xmlns:ppda =
"http://www.passport.com/NameSpace.xsd" xmlns:ois =
"http://schemas.microsoft.com/sharepoint/soap/ois/" xmlns:dir =
"http://schemas.microsoft.com/sharepoint/soap/directory/" xmlns:ds =
"http://www.w3.org/2000/09/xmldsig#" xmlns:dsp =
"http://schemas.microsoft.com/sharepoint/dsp" xmlns:udc =
"http://schemas.microsoft.com/data/udc" xmlns:xsd =
"http://www.w3.org/2001/XMLSchema" xmlns:sub =
"http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/" xmlns:ec =
"http://www.w3.org/2001/04/xmlenc#" xmlns:sp =
"http://schemas.microsoft.com/sharepoint/" xmlns:sps =
"http://schemas.microsoft.com/sharepoint/soap/" xmlns:xsi =
"http://www.w3.org/2001/XMLSchema-instance" xmlns:udcs =
"http://schemas.microsoft.com/data/udc/soap" xmlns:udcxf =
"http://schemas.microsoft.com/data/udc/xmlfile" xmlns:udcp2p =
"http://schemas.microsoft.com/data/udc/parttopart" xmlns:wf =
"http://schemas.microsoft.com/sharepoint/soap/workflow/" xmlns:dsss =
"http://schemas.microsoft.com/office/2006/digsig-setup" xmlns:dssi =
"http://schemas.microsoft.com/office/2006/digsig" xmlns:mdssi =
"http://schemas.openxmlformats.org/package/2006/digital-signature" xmlns:mver =
"http://schemas.openxmlformats.org/markup-compatibility/2006" xmlns:m =
"http://schemas.microsoft.com/office/2004/12/omml" xmlns:mrels =
"http://schemas.openxmlformats.org/package/2006/relationships" xmlns:spwp =
"http://microsoft.com/sharepoint/webpartpages" xmlns:ex12t =
"http://schemas.microsoft.com/exchange/services/2006/types" xmlns:ex12m =
"http://schemas.microsoft.com/exchange/services/2006/messages" xmlns:pptsl =
"http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/" xmlns:spsl =
"http://microsoft.com/webservices/SharePointPortalServer/PublishedLinksService"
XMLNS:Z = "urn:schemas-microsoft-com:" xmlns:st = ""><HEAD>
<META content="MSHTML 6.00.2900.3676" name=GENERATOR>
<STYLE>@font-face {
font-family: Calibri;
}
@font-face {
font-family: Consolas;
}
@page Section1 {size: 612.0pt 792.0pt; margin: 70.85pt 70.85pt 70.85pt 70.85pt; }
P.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman","serif"
}
LI.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman","serif"
}
DIV.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman","serif"
}
H2 {
FONT-WEIGHT: bold; FONT-SIZE: 18pt; MARGIN-LEFT: 0cm; MARGIN-RIGHT: 0cm; FONT-FAMILY: "Times New Roman","serif"; mso-style-priority: 9; mso-style-link: "Heading 2 Char"; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto
}
A:link {
COLOR: blue; TEXT-DECORATION: underline; mso-style-priority: 99
}
SPAN.MsoHyperlink {
COLOR: blue; TEXT-DECORATION: underline; mso-style-priority: 99
}
A:visited {
COLOR: purple; TEXT-DECORATION: underline; mso-style-priority: 99
}
SPAN.MsoHyperlinkFollowed {
COLOR: purple; TEXT-DECORATION: underline; mso-style-priority: 99
}
P.MsoPlainText {
FONT-SIZE: 10.5pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: Consolas; mso-style-priority: 99; mso-style-link: "Plain Text Char"
}
LI.MsoPlainText {
FONT-SIZE: 10.5pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: Consolas; mso-style-priority: 99; mso-style-link: "Plain Text Char"
}
DIV.MsoPlainText {
FONT-SIZE: 10.5pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: Consolas; mso-style-priority: 99; mso-style-link: "Plain Text Char"
}
P {
FONT-SIZE: 12pt; MARGIN-LEFT: 0cm; MARGIN-RIGHT: 0cm; FONT-FAMILY: "Times New Roman","serif"; mso-style-priority: 99; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto
}
SPAN.Heading2Char {
FONT-WEIGHT: bold; FONT-FAMILY: "Calibri","sans-serif"; mso-style-priority: 9; mso-style-link: "Heading 2"; mso-style-name: "Heading 2 Char"
}
SPAN.PlainTextChar {
FONT-FAMILY: Consolas; mso-style-priority: 99; mso-style-link: "Plain Text"; mso-style-name: "Plain Text Char"
}
SPAN.EmailStyle21 {
COLOR: #1f497d; FONT-FAMILY: "Calibri","sans-serif"; mso-style-type: personal
}
SPAN.EmailStyle22 {
COLOR: #1f497d; FONT-FAMILY: "Calibri","sans-serif"; mso-style-type: personal-reply
}
.MsoChpDefault {
FONT-SIZE: 10pt; mso-style-type: export-only
}
DIV.Section1 {
page: Section1
}
OL {
MARGIN-BOTTOM: 0cm
}
UL {
MARGIN-BOTTOM: 0cm
}
</STYLE>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></HEAD>
<BODY lang=FR vLink=purple link=blue>
<DIV dir=ltr align=left><FONT face=Arial color=#0000ff size=2><SPAN
class=345374908-31052010>FYI</SPAN></FONT></DIV>
<DIV> </DIV><!-- Converted from text/rtf format --><BR>
<P><SPAN lang=de><FONT face="Courier New" size=2>Regards</FONT></SPAN> <BR><SPAN
lang=de><FONT face="Courier New" size=2>Wolf-Ulrich</FONT></SPAN> </P>
<DIV> </DIV><BR>
<BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px">
<DIV class=OutlookMessageHeader lang=de dir=ltr align=left>
<HR tabIndex=-1>
<FONT face=Tahoma size=2><B>Von:</B> owner-liaison6c@gnso.icann.org
[mailto:owner-liaison6c@gnso.icann.org] <B>Im Auftrag von </B>Glen de Saint
Géry<BR><B>Gesendet:</B> Dienstag, 25. Mai 2010 12:13<BR><B>An:</B>
liaison6c@gnso.icann.org<BR><B>Betreff:</B> [liaison6c] Public Comment: April
2010 DNS-CERT Operational Requirements & Collaboration
Analysis<BR></FONT><BR></DIV>
<DIV></DIV>
<DIV class=Section1>
<P class=MsoNormal><o:p> </o:p></P>
<P
style="MARGIN-BOTTOM: 7.5pt; MARGIN-LEFT: 0cm; MARGIN-RIGHT: 0cm; mso-margin-top-alt: 0cm"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'"><A
href="http://www.icann.org/en/announcements/announcement-24may10-en.htm">http://www.icann.org/en/announcements/announcement-24may10-en.htm</A></SPAN><SPAN
style="COLOR: #1f497d"><o:p></o:p></SPAN></P>
<H2 style="MARGIN-BOTTOM: 0pt"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Public Comment: April 2010 DNS-CERT
Operational Requirements & Collaboration Analysis</SPAN><o:p></o:p></H2>
<P
style="MARGIN-BOTTOM: 0pt; MARGIN-LEFT: 0cm; MARGIN-RIGHT: 0cm; mso-margin-top-alt: 11.25pt"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">24 May 2010</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-FAMILY: 'Arial','sans-serif'">ICANN is today opening a
public comment period on the <A
href="http://www.icann.org/en/topics/ssr/dns-cert-collaboration-analysis-24may10-en.pdf">April
2010 DNS-CERT Operational Requirements and Collaboration Analysis Workshop
Report</A> (with Minority Statement). In advance of the ICANN Brussels
meeting, ICANN is seeking comments on the potential requirements identified in
the workshop report, DNS Security response gaps.</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-FAMILY: 'Arial','sans-serif'">In addition, ICANN is
publishing the <A
href="http://www.icann.org/en/public-comment/summary-analysis-strategic-ssr-initiatives-and-dns-cert-business-case-24may10-en.pdf">Summary
& Analysis of Comments on the Security Strategic Initiatives and Global
DNS-CERT Business Case papers</A>, and the <A
href="http://www.icann.org/en/topics/ssr/dns-cert-consultation-record-24may10-en.pdf">DNS-CERT
Consultation record</A>. The consultation record is included for transparency
on the formation of the DNS-CERT concept and consultations that have occurred
in parallel with the public comment period on the Security Strategic
Initiatives papers.</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-FAMILY: 'Arial','sans-serif'">The DNS-CERT Operational
Requirements and Collaboration Analysis Workshop report was prepared by Jose
Nazario, Arbor Networks, Roy Arends, Nominet, and Chris Morrow, Google, and is
the output from a tabletop workshop conducted 6-7 April 2010 in Washington DC.
Participants identified several requirements for responding to Internet and
DNS security events, many of which are under-met or ignored by existing DNS
security capabilities. They are:</SPAN><o:p></o:p></P>
<UL style="MARGIN-TOP: 0cm" type=disc>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">A trusted communications channel,
or multiple channels, for use during event response that is usable by the
appropriate parties.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Standing incident coordination and
response functions, which enable consistent and professional incident
handling efforts.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Incident status tracking through
to completion, with communication to the necessary
parties.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Trusted guidance on issues with
knowledge and experience with the various and varied areas of Internet and
DNS security. Respect of these voices by the areas of the Internet and DNS
communities with which they speak is important.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">A trust broker / introduction
service across traditional communities boundaries, recognizing that the
community identifying threats to Internet and DNS operations is often
far-flung and sometimes outside the knowledge of the Internet and DNS
operator and vendor communities.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Analysis capabilities, including
data such as DNS traffic, software vulnerabilities and attack traffic, to
validate incidents and identify next steps as quickly as
possible.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Institutional memory in the form
of reports, recommendations, and best practices, which can inform the
various Internet and DNS security communities, support future successful
incident responses, and help evolve incident response
capabilities.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">Outreach and education functions
to share best practices for securing Internet and DNS operations, secure
registration functions, implementing DNSSEC, and other key DNS and security
factors.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">The ability to act quickly, and to
be prepared to act with necessary resources in response to threats to the
DNS of a global nature in a timely and sustained manner.</SPAN><o:p></o:p>
<LI class=MsoNormal style="mso-list: l1 level1 lfo3"><SPAN
style="FONT-FAMILY: 'Arial','sans-serif'">A sensitivity to the complexity of
the international nature of the DNS, understanding the capabilities and
limitations of the global DNS community.</SPAN><o:p></o:p> </LI></UL>
<P><SPAN style="FONT-FAMILY: 'Arial','sans-serif'">Workshop participants noted
many of these functions are addressed by various groups, either standing or
ad-hoc. Some participants expressed concern that only a few of the existing
organizations are DNS-specific. The report includes a <A
href="http://www.icann.org/en/topics/ssr/dns-cert-collaboration-analysis-minority-statement-18may10-en.pdf">Minority
Statement</A> from Kathy Kleiman, Public Interest Registry, and Greg Aaron,
Afilias.</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-FAMILY: 'Arial','sans-serif'">Comments on the Operational
Requirements and Collaboration Analysis Report submitted to <A
href="mailto:dns-collab-analysis@icann.org">dns-collab-analysis@icann.org</A>
will be considered until 2 Jul 2010 23:59 UTC. Comments may be viewed at <A
href="http://forum.icann.org/lists/dns-collab-analysis/">http://forum.icann.org/lists/dns-collab-analysis/.</A></SPAN><o:p></o:p></P>
<P><SPAN style="FONT-FAMILY: 'Arial','sans-serif'">A consultation session will
be held at the ICANN meeting in Brussels on the Security Strategic Initiatives
(DNS-CERT and system-wide DNS Risk Assessment and exercises), with a date and
time soon to be included in the Brussels meeting
schedule.</SPAN><o:p></o:p></P>
<P class=MsoPlainText><SPAN
style="FONT-SIZE: 12pt; FONT-FAMILY: 'Arial','sans-serif'">Glen de Saint
Géry<o:p></o:p></SPAN></P>
<P class=MsoPlainText><SPAN
style="FONT-SIZE: 12pt; FONT-FAMILY: 'Arial','sans-serif'">GNSO
Secretariat<o:p></o:p></SPAN></P>
<P class=MsoPlainText><SPAN lang=EN-US
style="FONT-SIZE: 12pt; FONT-FAMILY: 'Arial','sans-serif'"><A
href="mailto:gnso.secretariat@gnso.icann.org"><SPAN
lang=FR>gnso.secretariat@gnso.icann.org</SPAN></A></SPAN><SPAN
style="FONT-SIZE: 12pt; FONT-FAMILY: 'Arial','sans-serif'"><o:p></o:p></SPAN></P>
<P class=MsoPlainText><SPAN lang=EN-US
style="FONT-SIZE: 12pt; FONT-FAMILY: 'Arial','sans-serif'"><A
href="http://gnso.icann.org">http://gnso.icann.org</A><o:p></o:p></SPAN></P>
<P style="TEXT-ALIGN: center"
align=center><o:p> </o:p></P></DIV></BLOCKQUOTE></BODY></HTML>