[Ncsg-discuss] SCCI Criteria 4 - “domain name security threats”
Manju
000020eb0920d952-dmarc-request at LISTSERV.SYR.EDU
Thu Jun 18 11:16:21 EEST 2026
Hi all,
Thank you for the questions.
Before answering them, please allow me to provide more context on what
we're doing in the SCCI with the Continuous Improvement Program Pilot and
what the criteria and indicators are for.
The Continuous Improvement Program (CIP) is ICANN's evolution of its
traditional Organizational Reviews, which previously assessed how well
Supporting Organizations, Advisory Committees, and the Nominating Committee
fulfilled their purpose, structure, and accountability.
The CIP rests on five shared principles covering purpose, structural
effectiveness, operational efficiency, accountability, and collaboration.
Each CIP assessment cycle runs up to three years and moves through three
phases:
- Assessment and Prioritization (data collection and identifying
improvement areas),
- Improvements (implementing changes), and
- Reporting (publishing results for public comment).
As the body in GNSO that's responsible for continuous improvement, SCCI has
been following the CIP framework and principles to develop the criteria and
indicators for future assessment and improvements. You can find the full
set of criteria and indicators here:
https://docs.google.com/document/d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/edit?tab=t.0#heading=h.49smw22t8kla
*Note: Please refrain from commenting on the Google Doc as we're currently
only allowing the SCCI members to comment.*
In short, we are now developing criteria and indicators for future data
collection. And after collecting the data, we will assess it against the
indicators and criteria, evaluating whether there is room for improvement.
What you were asked to review was one of the indicators, and as it is a
data point where we will be collecting data to assess against, we in SCCI
decided to word it open-ended enough to allow the ease of data collection,
while preventing scope creep by adding wording such as 'in scope for GNSO'.
If you're interested in knowing more, I'd encourage you to listen to the
recordings of our ICANN86 session, where we discussed this particular item
in depth: https://icann86.sched.com/event/2NQMw/gnso-scci-work-session
Hope this helps.
Best,
Manju
On Thu, Jun 18, 2026 at 3:34 PM Tapani Tarvainen <
00001e7f5908374c-dmarc-request at listserv.syr.edu> wrote:
> Dear Manju,
>
> Thank you for the explanation. Looking at the proposed text again
> it makes sense. But the language is a bit ambiguous:
>
> > Indicator 1: The GNSO has demonstrated meaningful activity towards
> > mitigating DNS Abuse and security threats relating to
> > domain names that are in scope for the GNSO.
>
> Specifically, it's not clear if the qualification "that are in scope..."
> applies also to DNS Abuse and not only to security threats.
>
> I'm not sure this matters here, but perhaps it would be worth
> thinking a moment if it could be clarified without making the
> text too cumbersome.
>
> Tapani
>
>
> On Jun 17 15:02, Manju (000020eb0920d952-dmarc-request at LISTSERV.SYR.EDU)
> wrote:
> >
> > Hi all,
> >
> > Thank you very much for the discussion.
> > As mentioned by Julf, I'm the chair of SCCI and have to maintain
> neutrality
> > when it comes to the discussion of substance. However, I believe I'm
> > allowed to provide some context and clarification on this issue.
> >
> > The change from domain name security threat to DNS Abuse was actually an
> > effort of the SCCI to tighten the scope, not the contrary. The general
> > agreement within the SCCI was that "domain name security threat" can be
> > interpreted to have a broader remit that is beyond GNSO's mission and
> > scope, which prompted the change to 'DNS Abuse' as narrowly defined in
> the
> > contract.
> >
> > One of the examples that can be understood as 'combating domain name
> > security threat', as shared during our SCCI working session in Seville,
> is
> > the Internationalized Domain Names PDP, which regulates the variant
> > management of IDNs. By this example, it should be clear that domain name
> > security threat actually has a broader scope than DNS abuse, the latter
> of
> > which is narrowly defined and codified in contract.
> >
> > Hope this helps.
> >
> > Best,
> > Manju
> >
> > On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <
> > 00001deb507b73c5-dmarc-request at listserv.syr.edu> wrote:
> >
> > > Hi Julf
> > >
> > > I agree and we tried really hard in our public comments to mention the
> > > security threat and not frame it as DNS abuse, but the CPH and others
> were
> > > really keen on adding DNS abuse at the time. Maybe we can clarify that
> DNS
> > > abuse as narrowly defined in RAAs.
> > >
> > >
> > >
> > > Farzaneh
> > >
> > >
> > > On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng <
> > > 00001edb87ceea84-dmarc-request at listserv.syr.edu> wrote:
> > >
> > >>
> > >> Hi all,
> > >>
> > >> I'm broadly aligned with the direction of the discussion, but I think
> > >> it's worth pausing to consider why this proposed change is being
> raised
> > >> within the SCCI framework specifically — that context seems important
> to
> > >> how we shape our response.
> > >>
> > >> On the substantive question: is excluding "DNS Abuse" altogether
> actually
> > >> to our advantage? If the term can be held to a narrow, operationally
> > >> precise definition — one explicitly grounded in user rights and human
> > >> rights principles — we may end up with more meaningful control over
> how it
> > >> is applied than a rejection would give us.
> > >> Best,
> > >>
> > >> Chia-I
> > >>
> > >> *寄件者: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> 代表 NPC SVG <
> > >> 0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU>
> > >> *日期: *星期二, 2026年6月16日 清晨6:12
> > >> *收件者: *NCSG-DISCUSS at LISTSERV.SYR.EDU <NCSG-DISCUSS at LISTSERV.SYR.EDU>
> > >> *主旨: *Re: SCCI Criteria 4 - “domain name security threats”
> > >>
> > >> Like Abbas and Julf , I also believe the use of the term DNS abuse
> > >> broadens the indicator into an area unsuitable for the GNSO council
> for
> > >> reasons described below.
> > >>
> > >> RD
> > >>
> > >> On Mon, Jun 15, 2026, 3:08 PM <
> > >> 0000222a86a53d44-dmarc-request at listserv.syr.edu> wrote:
> > >>
> > >> Julf, I agree with the analysis by Abbas. Explicitly Including “DNS
> > >> abuse” broadens the indicator into an area unsuitable for the GNSO
> Council
> > >> for the reasons he describes.
> > >>
> > >>
> > >>
> > >> In terms of a statement, we can perhaps relate something like “the
> ICANN
> > >> community has reached general consensus around a narrow set of DNS
> security
> > >> threats (phishing, malware, botnets, pharming, and spam as a delivery
> > >> mechanism). However, there has not been universal stakeholder
> consensus on
> > >> the broader conceptual definition of DNS Abuse or on where the
> boundary
> > >> lies between DNS abuse and content abuse. Therefore, since the term
> DNS
> > >> abuse” can mean different things to different stakeholders, even
> within the
> > >> narrow threats mentioned, by including "DNS abuse" as an indicator for
> > >> evaluating the performance of the GNSO council risks creating
> unclear, and
> > >> potentially unrealistic, expectations for achieving the stated
> criteria, to
> > >> say nothing of the opportunity for debate regarding whether or not the
> > >> criteria has been met.”
> > >>
> > >>
> > >>
> > >> I hope this helps.
> > >>
> > >>
> > >>
> > >> Ken
> > >>
> > >>
> > >>
> > >> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> *On Behalf Of
> *Abbas
> > >> Sibai
> > >> *Sent:* Monday, June 15, 2026 9:33 AM
> > >> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU
> > >> *Subject:* Re: SCCI Criteria 4 - “domain name security threats”
> > >>
> > >>
> > >>
> > >> Hi Julf,
> > >>
> > >> Thanks for flagging this. As an individual member of the NCUC, I
> > >> completely share your concerns. Specifically inserting the term "DNS
> Abuse"
> > >> into the GNSO Continuous Improvement Program framework is a major red
> flag
> > >> that we definitely need to push back against during the upcoming call
> on
> > >> Wednesday, 1 July 2026.
> > >>
> > >> From our constituency’s perspective, my understanding is that there
> are
> > >> two distinct "cans of worms" this proposal opens up:
> > >>
> > >> - *Mission Creep and Content Regulation:* Broadening the text to
> > >> explicitly name "DNS Abuse" risks shifting the GNSO's focus from
> core
> > >> technical layer infrastructure toward content regulation. What I
> > >> understood is that the NCUC has a long-standing commitment to
> > >> fiercely protecting freedom of expression and digital rights. If
> the
> > >> indicators explicitly target "DNS Abuse" rather than strictly
> defined
> > >> security threats, it invites outside pressure on the GNSO to
> police website
> > >> content, a precedent that directly undermines our core mission and
> > >> human rights principles.
> > >> - *Disproportionality and Human Rights Impacts:* I also understood
> > >> that NCUC has consistently advocated that any policy intervention
> > >> addressing domain security must be narrow, proportionate, and
> strictly
> > >> scoped. Tying the evaluation of the GNSO's performance to broad and
> > >> subjective perceptions of "DNS Abuse" (especially via a survey
> indicator)
> > >> creates an incentive to pass sweeping, reactive policies. This
> places
> > >> innocent registrants at risk of collective or automated domain
> suspensions
> > >> without adequate due process or Human Rights Impact Assessments
> (HRIAs).
> > >>
> > >> The original text, focusing strictly on "mitigating domain name
> security
> > >> threats," keeps the evaluation grounded within the GNSO's technical
> and
> > >> contractual scope. The proposed revision unnecessarily complicates it
> and
> > >> opens the door to over-policing at the registry/registrar level.
> > >>
> > >> I fully support our leadership taking a strong stance against this
> text
> > >> on Wednesday. Please let me know if you need any assistance with
> drafting a
> > >> formal statement or if there are specific points you want supported
> during
> > >> the call.
> > >>
> > >>
> > >> Warm Regards,
> > >>
> > >> *Abbas Sibai*
> > >> *Policy & Advocacy Specialist*
> > >>
> > >> +9613824725
> > >>
> > >> *|*
> > >>
> > >> https://www.linkedin.com/in/abbas-sibai/
> > >>
> > >>
> > >>
> > >>
> > >>
> > >> On Mon, Jun 15, 2026 at 12:28 PM Johan Helsingius <
> > >> 00001963cc94b85a-dmarc-request at listserv.syr.edu> wrote:
> > >>
> > >> Hi all,
> > >>
> > >> I am the NCSG representative to the Standing Committee on Continuous
> > >> Improvement (SCCI) that is formulating the Continuous Improvement
> > >> Program framework. The SCCI is chaired by Manju, another NCSG:er, but
> > >> as chair she has to remain neutral.
> > >>
> > >> The work until now has been developing the Criteria and Indicators
> > >> that will be used to judge how well the GNSO processes are working.
> > >>
> > >> We have made good progress under the very capable leadership of Manju,
> > >> and most issues haven't been very controversial, but I want to flag
> > >> the current issue where we probably want to speak up against the
> current
> > >> proposal.
> > >>
> > >> The issue is Criteria 4, "The GNSO actively combats domain name
> > >> security threats", where there is a proposal to change the draft
> > >> text from:
> > >>
> > >> Indicator 1: The GNSO has demonstrated meaningful activity
> towards
> > >> mitigating domain name security threats.
> > >>
> > >> Indicator 2: 66% of surveyed respondents agree that the GNSO
> > >> combats domain name security threats.
> > >>
> > >> to:
> > >>
> > >> Indicator 1: The GNSO has demonstrated meaningful activity
> towards
> > >> mitigating DNS Abuse and security threats relating
> to
> > >> domain names that are in scope for the GNSO.
> > >>
> > >>
> > >> Indicator 2: 66% of surveyed respondents agree that the GNSO has
> > >> demonstrated meaningful activity towards mitigating
> > >> DNS Abuse and security threats relating to domain
> > >> names that are in scope for the GNSO.
> > >>
> > >> While we probably are OK with mitigating domain name security threats,
> > >> specifically mentioning DNS Abuse opens up some cans of worms.
> > >>
> > >> We will have a chance to present our views at the next SCCI call on
> > >> Wednesday, 1 July 2026, so I welcome your comments/opinions.
> > >>
> > >> Julf
> > >>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20260618/89a0dead/attachment-0001.htm>
More information about the Ncsg-discuss
mailing list