[Ncsg-discuss] SCCI Criteria 4 - “domain name security threats”
NPC SVG
0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU
Wed Jun 17 14:53:30 EEST 2026
Can I ask, what is the impact of changing the language from security threat
to "abuse"?
RD
On Wed, Jun 17, 2026, 2:03 AM Manju <
000020eb0920d952-dmarc-request at listserv.syr.edu> wrote:
> Hi all,
>
> Thank you very much for the discussion.
> As mentioned by Julf, I'm the chair of SCCI and have to maintain
> neutrality when it comes to the discussion of substance. However, I
> believe I'm allowed to provide some context and clarification on this
> issue.
>
> The change from domain name security threat to DNS Abuse was actually an
> effort of the SCCI to tighten the scope, not the contrary. The general
> agreement within the SCCI was that "domain name security threat" can be
> interpreted to have a broader remit that is beyond GNSO's mission and
> scope, which prompted the change to 'DNS Abuse' as narrowly defined in the
> contract.
>
> One of the examples that can be understood as 'combating domain name
> security threat', as shared during our SCCI working session in Seville, is
> the Internationalized Domain Names PDP, which regulates the variant
> management of IDNs. By this example, it should be clear that domain name
> security threat actually has a broader scope than DNS abuse, the latter of
> which is narrowly defined and codified in contract.
>
> Hope this helps.
>
> Best,
> Manju
>
> On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <
> 00001deb507b73c5-dmarc-request at listserv.syr.edu> wrote:
>
>> Hi Julf
>>
>> I agree and we tried really hard in our public comments to mention the
>> security threat and not frame it as DNS abuse, but the CPH and others were
>> really keen on adding DNS abuse at the time. Maybe we can clarify that DNS
>> abuse as narrowly defined in RAAs.
>>
>>
>>
>> Farzaneh
>>
>>
>> On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng <
>> 00001edb87ceea84-dmarc-request at listserv.syr.edu> wrote:
>>
>>>
>>> Hi all,
>>>
>>> I'm broadly aligned with the direction of the discussion, but I think
>>> it's worth pausing to consider why this proposed change is being raised
>>> within the SCCI framework specifically — that context seems important to
>>> how we shape our response.
>>>
>>> On the substantive question: is excluding "DNS Abuse" altogether
>>> actually to our advantage? If the term can be held to a narrow,
>>> operationally precise definition — one explicitly grounded in user rights
>>> and human rights principles — we may end up with more meaningful control
>>> over how it is applied than a rejection would give us.
>>> Best,
>>>
>>> Chia-I
>>>
>>> *寄件者: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> 代表 NPC SVG <
>>> 0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU>
>>> *日期: *星期二, 2026年6月16日 清晨6:12
>>> *收件者: *NCSG-DISCUSS at LISTSERV.SYR.EDU <NCSG-DISCUSS at LISTSERV.SYR.EDU>
>>> *主旨: *Re: SCCI Criteria 4 - “domain name security threats”
>>>
>>> Like Abbas and Julf , I also believe the use of the term DNS abuse
>>> broadens the indicator into an area unsuitable for the GNSO council for
>>> reasons described below.
>>>
>>> RD
>>>
>>> On Mon, Jun 15, 2026, 3:08 PM <
>>> 0000222a86a53d44-dmarc-request at listserv.syr.edu> wrote:
>>>
>>> Julf, I agree with the analysis by Abbas. Explicitly Including “DNS
>>> abuse” broadens the indicator into an area unsuitable for the GNSO Council
>>> for the reasons he describes.
>>>
>>>
>>>
>>> In terms of a statement, we can perhaps relate something like “the ICANN
>>> community has reached general consensus around a narrow set of DNS security
>>> threats (phishing, malware, botnets, pharming, and spam as a delivery
>>> mechanism). However, there has not been universal stakeholder consensus on
>>> the broader conceptual definition of DNS Abuse or on where the boundary
>>> lies between DNS abuse and content abuse. Therefore, since the term DNS
>>> abuse” can mean different things to different stakeholders, even within the
>>> narrow threats mentioned, by including "DNS abuse" as an indicator for
>>> evaluating the performance of the GNSO council risks creating unclear, and
>>> potentially unrealistic, expectations for achieving the stated criteria, to
>>> say nothing of the opportunity for debate regarding whether or not the
>>> criteria has been met.”
>>>
>>>
>>>
>>> I hope this helps.
>>>
>>>
>>>
>>> Ken
>>>
>>>
>>>
>>> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> *On Behalf Of *Abbas
>>> Sibai
>>> *Sent:* Monday, June 15, 2026 9:33 AM
>>> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU
>>> *Subject:* Re: SCCI Criteria 4 - “domain name security threats”
>>>
>>>
>>>
>>> Hi Julf,
>>>
>>> Thanks for flagging this. As an individual member of the NCUC, I
>>> completely share your concerns. Specifically inserting the term "DNS Abuse"
>>> into the GNSO Continuous Improvement Program framework is a major red flag
>>> that we definitely need to push back against during the upcoming call on
>>> Wednesday, 1 July 2026.
>>>
>>> From our constituency’s perspective, my understanding is that there are
>>> two distinct "cans of worms" this proposal opens up:
>>>
>>> - *Mission Creep and Content Regulation:* Broadening the text to
>>> explicitly name "DNS Abuse" risks shifting the GNSO's focus from core
>>> technical layer infrastructure toward content regulation. What I
>>> understood is that the NCUC has a long-standing commitment to
>>> fiercely protecting freedom of expression and digital rights. If the
>>> indicators explicitly target "DNS Abuse" rather than strictly defined
>>> security threats, it invites outside pressure on the GNSO to police website
>>> content, a precedent that directly undermines our core mission and
>>> human rights principles.
>>> - *Disproportionality and Human Rights Impacts:* I also understood
>>> that NCUC has consistently advocated that any policy intervention
>>> addressing domain security must be narrow, proportionate, and strictly
>>> scoped. Tying the evaluation of the GNSO's performance to broad and
>>> subjective perceptions of "DNS Abuse" (especially via a survey indicator)
>>> creates an incentive to pass sweeping, reactive policies. This places
>>> innocent registrants at risk of collective or automated domain suspensions
>>> without adequate due process or Human Rights Impact Assessments (HRIAs).
>>>
>>> The original text, focusing strictly on "mitigating domain name
>>> security threats," keeps the evaluation grounded within the GNSO's
>>> technical and contractual scope. The proposed revision unnecessarily
>>> complicates it and opens the door to over-policing at the
>>> registry/registrar level.
>>>
>>> I fully support our leadership taking a strong stance against this text
>>> on Wednesday. Please let me know if you need any assistance with drafting a
>>> formal statement or if there are specific points you want supported during
>>> the call.
>>>
>>>
>>> Warm Regards,
>>>
>>> *Abbas Sibai*
>>> *Policy & Advocacy Specialist*
>>>
>>> +9613824725
>>>
>>> *|*
>>>
>>> https://www.linkedin.com/in/abbas-sibai/
>>>
>>>
>>>
>>>
>>>
>>> On Mon, Jun 15, 2026 at 12:28 PM Johan Helsingius <
>>> 00001963cc94b85a-dmarc-request at listserv.syr.edu> wrote:
>>>
>>> Hi all,
>>>
>>> I am the NCSG representative to the Standing Committee on Continuous
>>> Improvement (SCCI) that is formulating the Continuous Improvement
>>> Program framework. The SCCI is chaired by Manju, another NCSG:er, but
>>> as chair she has to remain neutral.
>>>
>>> The work until now has been developing the Criteria and Indicators
>>> that will be used to judge how well the GNSO processes are working.
>>>
>>> We have made good progress under the very capable leadership of Manju,
>>> and most issues haven't been very controversial, but I want to flag
>>> the current issue where we probably want to speak up against the current
>>> proposal.
>>>
>>> The issue is Criteria 4, "The GNSO actively combats domain name
>>> security threats", where there is a proposal to change the draft
>>> text from:
>>>
>>> Indicator 1: The GNSO has demonstrated meaningful activity towards
>>> mitigating domain name security threats.
>>>
>>> Indicator 2: 66% of surveyed respondents agree that the GNSO
>>> combats domain name security threats.
>>>
>>> to:
>>>
>>> Indicator 1: The GNSO has demonstrated meaningful activity towards
>>> mitigating DNS Abuse and security threats relating to
>>> domain names that are in scope for the GNSO.
>>>
>>>
>>> Indicator 2: 66% of surveyed respondents agree that the GNSO has
>>> demonstrated meaningful activity towards mitigating
>>> DNS Abuse and security threats relating to domain
>>> names that are in scope for the GNSO.
>>>
>>> While we probably are OK with mitigating domain name security threats,
>>> specifically mentioning DNS Abuse opens up some cans of worms.
>>>
>>> We will have a chance to present our views at the next SCCI call on
>>> Wednesday, 1 July 2026, so I welcome your comments/opinions.
>>>
>>> Julf
>>>
>>>
On Wed, Jun 17, 2026, 2:03 AM Manju <
000020eb0920d952-dmarc-request at listserv.syr.edu> wrote:
> Hi all,
>
> Thank you very much for the discussion.
> As mentioned by Julf, I'm the chair of SCCI and have to maintain
> neutrality when it comes to the discussion of substance. However, I
> believe I'm allowed to provide some context and clarification on this
> issue.
>
> The change from domain name security threat to DNS Abuse was actually an
> effort of the SCCI to tighten the scope, not the contrary. The general
> agreement within the SCCI was that "domain name security threat" can be
> interpreted to have a broader remit that is beyond GNSO's mission and
> scope, which prompted the change to 'DNS Abuse' as narrowly defined in the
> contract.
>
> One of the examples that can be understood as 'combating domain name
> security threat', as shared during our SCCI working session in Seville, is
> the Internationalized Domain Names PDP, which regulates the variant
> management of IDNs. By this example, it should be clear that domain name
> security threat actually has a broader scope than DNS abuse, the latter of
> which is narrowly defined and codified in contract.
>
> Hope this helps.
>
> Best,
> Manju
>
> On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <
> 00001deb507b73c5-dmarc-request at listserv.syr.edu> wrote:
>
>> Hi Julf
>>
>> I agree and we tried really hard in our public comments to mention the
>> security threat and not frame it as DNS abuse, but the CPH and others were
>> really keen on adding DNS abuse at the time. Maybe we can clarify that DNS
>> abuse as narrowly defined in RAAs.
>>
>>
>>
>> Farzaneh
>>
>>
>> On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng <
>> 00001edb87ceea84-dmarc-request at listserv.syr.edu> wrote:
>>
>>>
>>> Hi all,
>>>
>>> I'm broadly aligned with the direction of the discussion, but I think
>>> it's worth pausing to consider why this proposed change is being raised
>>> within the SCCI framework specifically — that context seems important to
>>> how we shape our response.
>>>
>>> On the substantive question: is excluding "DNS Abuse" altogether
>>> actually to our advantage? If the term can be held to a narrow,
>>> operationally precise definition — one explicitly grounded in user rights
>>> and human rights principles — we may end up with more meaningful control
>>> over how it is applied than a rejection would give us.
>>> Best,
>>>
>>> Chia-I
>>>
>>> *寄件者: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> 代表 NPC SVG <
>>> 0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU>
>>> *日期: *星期二, 2026年6月16日 清晨6:12
>>> *收件者: *NCSG-DISCUSS at LISTSERV.SYR.EDU <NCSG-DISCUSS at LISTSERV.SYR.EDU>
>>> *主旨: *Re: SCCI Criteria 4 - “domain name security threats”
>>>
>>> Like Abbas and Julf , I also believe the use of the term DNS abuse
>>> broadens the indicator into an area unsuitable for the GNSO council for
>>> reasons described below.
>>>
>>> RD
>>>
>>> On Mon, Jun 15, 2026, 3:08 PM <
>>> 0000222a86a53d44-dmarc-request at listserv.syr.edu> wrote:
>>>
>>> Julf, I agree with the analysis by Abbas. Explicitly Including “DNS
>>> abuse” broadens the indicator into an area unsuitable for the GNSO Council
>>> for the reasons he describes.
>>>
>>>
>>>
>>> In terms of a statement, we can perhaps relate something like “the ICANN
>>> community has reached general consensus around a narrow set of DNS security
>>> threats (phishing, malware, botnets, pharming, and spam as a delivery
>>> mechanism). However, there has not been universal stakeholder consensus on
>>> the broader conceptual definition of DNS Abuse or on where the boundary
>>> lies between DNS abuse and content abuse. Therefore, since the term DNS
>>> abuse” can mean different things to different stakeholders, even within the
>>> narrow threats mentioned, by including "DNS abuse" as an indicator for
>>> evaluating the performance of the GNSO council risks creating unclear, and
>>> potentially unrealistic, expectations for achieving the stated criteria, to
>>> say nothing of the opportunity for debate regarding whether or not the
>>> criteria has been met.”
>>>
>>>
>>>
>>> I hope this helps.
>>>
>>>
>>>
>>> Ken
>>>
>>>
>>>
>>> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> *On Behalf Of *Abbas
>>> Sibai
>>> *Sent:* Monday, June 15, 2026 9:33 AM
>>> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU
>>> *Subject:* Re: SCCI Criteria 4 - “domain name security threats”
>>>
>>>
>>>
>>> Hi Julf,
>>>
>>> Thanks for flagging this. As an individual member of the NCUC, I
>>> completely share your concerns. Specifically inserting the term "DNS Abuse"
>>> into the GNSO Continuous Improvement Program framework is a major red flag
>>> that we definitely need to push back against during the upcoming call on
>>> Wednesday, 1 July 2026.
>>>
>>> From our constituency’s perspective, my understanding is that there are
>>> two distinct "cans of worms" this proposal opens up:
>>>
>>> - *Mission Creep and Content Regulation:* Broadening the text to
>>> explicitly name "DNS Abuse" risks shifting the GNSO's focus from core
>>> technical layer infrastructure toward content regulation. What I
>>> understood is that the NCUC has a long-standing commitment to
>>> fiercely protecting freedom of expression and digital rights. If the
>>> indicators explicitly target "DNS Abuse" rather than strictly defined
>>> security threats, it invites outside pressure on the GNSO to police website
>>> content, a precedent that directly undermines our core mission and
>>> human rights principles.
>>> - *Disproportionality and Human Rights Impacts:* I also understood
>>> that NCUC has consistently advocated that any policy intervention
>>> addressing domain security must be narrow, proportionate, and strictly
>>> scoped. Tying the evaluation of the GNSO's performance to broad and
>>> subjective perceptions of "DNS Abuse" (especially via a survey indicator)
>>> creates an incentive to pass sweeping, reactive policies. This places
>>> innocent registrants at risk of collective or automated domain suspensions
>>> without adequate due process or Human Rights Impact Assessments (HRIAs).
>>>
>>> The original text, focusing strictly on "mitigating domain name
>>> security threats," keeps the evaluation grounded within the GNSO's
>>> technical and contractual scope. The proposed revision unnecessarily
>>> complicates it and opens the door to over-policing at the
>>> registry/registrar level.
>>>
>>> I fully support our leadership taking a strong stance against this text
>>> on Wednesday. Please let me know if you need any assistance with drafting a
>>> formal statement or if there are specific points you want supported during
>>> the call.
>>>
>>>
>>> Warm Regards,
>>>
>>> *Abbas Sibai*
>>> *Policy & Advocacy Specialist*
>>>
>>> +9613824725
>>>
>>> *|*
>>>
>>> https://www.linkedin.com/in/abbas-sibai/
>>>
>>>
>>>
>>>
>>>
>>> On Mon, Jun 15, 2026 at 12:28 PM Johan Helsingius <
>>> 00001963cc94b85a-dmarc-request at listserv.syr.edu> wrote:
>>>
>>> Hi all,
>>>
>>> I am the NCSG representative to the Standing Committee on Continuous
>>> Improvement (SCCI) that is formulating the Continuous Improvement
>>> Program framework. The SCCI is chaired by Manju, another NCSG:er, but
>>> as chair she has to remain neutral.
>>>
>>> The work until now has been developing the Criteria and Indicators
>>> that will be used to judge how well the GNSO processes are working.
>>>
>>> We have made good progress under the very capable leadership of Manju,
>>> and most issues haven't been very controversial, but I want to flag
>>> the current issue where we probably want to speak up against the current
>>> proposal.
>>>
>>> The issue is Criteria 4, "The GNSO actively combats domain name
>>> security threats", where there is a proposal to change the draft
>>> text from:
>>>
>>> Indicator 1: The GNSO has demonstrated meaningful activity towards
>>> mitigating domain name security threats.
>>>
>>> Indicator 2: 66% of surveyed respondents agree that the GNSO
>>> combats domain name security threats.
>>>
>>> to:
>>>
>>> Indicator 1: The GNSO has demonstrated meaningful activity towards
>>> mitigating DNS Abuse and security threats relating to
>>> domain names that are in scope for the GNSO.
>>>
>>>
>>> Indicator 2: 66% of surveyed respondents agree that the GNSO has
>>> demonstrated meaningful activity towards mitigating
>>> DNS Abuse and security threats relating to domain
>>> names that are in scope for the GNSO.
>>>
>>> While we probably are OK with mitigating domain name security threats,
>>> specifically mentioning DNS Abuse opens up some cans of worms.
>>>
>>> We will have a chance to present our views at the next SCCI call on
>>> Wednesday, 1 July 2026, so I welcome your comments/opinions.
>>>
>>> Julf
>>>
>>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20260617/5940da4a/attachment-0001.htm>
More information about the Ncsg-discuss
mailing list