Update on 40th Policy Advisory Committee Meeting

40th Policy Advisory Committee
40th Policy Advisory Committee
11 July 2024
11 July 2024
Agenda
Agenda
1.
Introduction & Membership Matters
2.
Matters Arising
Policy Proposal: Amendments to PAC Terms of Reference
3.
Criminal & Technical Abuse
NetCraft Service Update
D
i
s
c
u
s
s
i
o
n
 
-
 
I
n
t
e
r
n
e
t
 
W
a
t
c
h
 
F
o
u
n
d
a
t
i
o
n
 
P
r
o
c
e
s
s
e
s
4.
NIS2 Updates
5.
Internet Governance
WSIS+20, GDC, & Technical Community Updates
Debrief from EuroDIG 2024
Ireland IGF announcement
6.
AOB
Membership Matters
Membership Matters
P
l
e
a
s
e
 
k
e
e
p
 
m
i
c
r
o
p
h
o
n
e
s
 
m
u
t
e
d
 
t
h
r
o
u
g
h
o
u
t
 
t
h
e
 
c
a
l
l
P
l
e
a
s
e
 
"
r
a
i
s
e
 
a
 
h
a
n
d
"
 
t
o
 
a
s
k
 
a
 
q
u
e
s
t
i
o
n
 
o
r
 
a
d
d
 
c
o
m
m
e
n
t
s
 
i
n
 
t
h
e
 
c
h
a
t
 
b
o
x
B
e
f
o
r
e
 
s
p
e
a
k
i
n
g
,
 
p
l
e
a
s
e
 
s
t
a
t
e
 
y
o
u
r
 
n
a
m
e
 
f
o
r
 
t
h
e
 
r
e
c
o
r
d
M
e
e
t
i
n
g
 
w
i
l
l
 
b
e
 
r
e
c
o
r
d
e
d
 
t
o
 
a
s
s
i
s
t
 
w
i
t
h
 
m
i
n
u
t
e
 
d
r
a
f
t
i
n
g
R
e
c
o
r
d
i
n
g
 
w
i
l
l
 
b
e
 
d
e
l
e
t
e
d
 
o
n
c
e
 
t
h
e
 
M
i
n
u
t
e
s
 
a
r
e
 
a
p
p
r
o
v
e
d
 
b
y
 
t
h
e
 
P
A
C
Minutes of PAC #39
Minutes of PAC #39
Meeting minutes are circulated to the membership after each meeting.
Comments & feedback are accepted over a two-week period.
If edits are requested, and consensus exists, these are reflected in the Minutes.
Minutes and slides are published on weare.ie after the comment period has ended.
Matters
Matters
Arising
Arising
P
r
o
p
o
s
a
l
:
 
A
m
e
n
d
m
e
n
t
s
 
t
o
 
P
A
C
 
T
e
r
m
s
 
o
f
R
e
f
e
r
e
n
c
e
 
&
 
P
o
l
i
c
y
 
D
e
v
e
l
o
p
m
e
n
t
 
P
r
o
c
e
s
s
Proposals – Amending PAC Terms of Reference
Proposals – Amending PAC Terms of Reference
At PAC 39, a proposal was introduced to update and amend the Eligible Organisations
appendix in the PAC Terms of Reference.
T
h
e
 
E
l
i
g
i
b
l
e
 
O
r
g
a
n
i
s
a
t
i
o
n
s
 
L
i
s
t
 
h
a
d
 
s
e
v
e
r
a
l
 
o
u
t
-
o
f
-
d
a
t
e
 
r
e
f
e
r
e
n
c
e
s
 
a
n
d
 
d
i
d
 
n
o
t
 
i
n
c
l
u
d
e
a
n
y
 
o
f
 
t
h
e
 
D
i
g
i
t
a
l
 
R
e
g
u
l
a
t
o
r
s
.
A
n
o
t
h
e
r
 
s
u
g
g
e
s
t
i
o
n
 
w
a
s
 
m
a
d
e
 
t
o
 
s
t
r
e
a
m
l
i
n
e
 
s
i
m
i
l
a
r
 
p
o
l
i
c
y
 
a
m
e
n
d
m
e
n
t
s
 
i
n
 
t
h
e
 
f
u
t
u
r
e
.
Amendment 1: PAC Eligible Organisations
Amendment 1: PAC Eligible Organisations
Amendment 2 – Policy Development Process
Amendment 2 – Policy Development Process
C
u
r
r
e
n
t
 
P
D
P
 
M
o
d
e
l
 
I
s
s
u
e
s
Not reflective of practice
Every proposal in chart requires working
group
No process for minor (de minimis) issues
like correcting typos or updating links (all
changes currently to go to PAC)
Amendment 2 – Policy Development Process
Amendment 2 – Policy Development Process
P
r
o
p
o
s
a
l
:
 
P
A
C
 
t
o
 
a
s
y
n
c
h
r
o
n
o
u
s
l
y
 
p
r
o
v
i
d
e
 
i
n
p
u
t
,
 
s
u
p
p
o
r
t
,
 
o
r
 
o
b
j
e
c
t
i
o
n
 
b
y
 
P
A
C
 
4
1
.
Criminal &
Criminal &
Technical Abuse
Technical Abuse
Updates from NetCraft Service
Participation in IWF
NetCraft
NetCraft
Number of Attacks (YTD)
NetCraft
NetCraft
Attacks by Group (YTD)
Discussion – Internet Watch Foundation
Discussion – Internet Watch Foundation
A
t
 
P
A
C
 
3
9
,
 
t
h
e
 
I
W
F
 
p
r
e
s
e
n
t
e
d
 
o
n
 
t
h
e
i
r
 
D
o
m
a
i
n
 
A
l
e
r
t
 
a
n
d
 
T
L
D
 
H
o
p
p
i
n
g
 
L
i
s
t
 
S
e
r
v
i
c
e
s
.
D
o
m
a
i
n
 
A
l
e
r
t
 
p
r
o
v
i
d
e
s
 
r
e
a
l
-
t
i
m
e
 
a
l
e
r
t
s
 
o
f
 
c
o
n
f
i
r
m
e
d
 
C
S
A
M
 
o
n
 
a
 
T
L
D
s
 
d
o
m
a
i
n
.
T
L
D
 
H
o
p
p
i
n
g
 
L
i
s
t
 
p
r
o
v
i
d
e
s
 
l
i
s
t
 
o
f
 
d
o
m
a
i
n
 
s
t
r
i
n
g
s
 
k
n
o
w
n
 
t
o
 
b
e
 
u
s
e
d
 
t
o
 
d
i
s
t
r
i
b
u
t
e
C
S
A
M
.
The PAC was generally supportive of .ie participating in these programs but emphasized
that .ie should have processes in place to handle IWF reports.
D
i
s
c
u
s
s
i
o
n
:
 
W
h
a
t
 
c
o
u
l
d
 
a
 
I
W
F
 
m
i
t
i
g
a
t
i
o
n
 
p
r
o
c
e
s
s
 
f
o
r
 
.
i
e
 
l
o
o
k
 
l
i
k
e
?
Discussion – Internet Watch Foundation
Discussion – Internet Watch Foundation
P
u
b
l
i
c
 
I
n
t
e
r
e
s
t
 
R
e
g
i
s
t
r
y
 
(
.
o
r
g
 
&
 
.
n
g
o
)
s
 
p
r
o
c
e
s
s
 
f
o
r
 
D
o
m
a
i
n
 
A
l
e
r
t
s
.
 
N
O
T
E
A “defanged” URL is one that has been modified so it does not resolve (hxxps://example.ie)
Potential to replicate or adapt similar process for .ie.
Discussion – Internet Watch Foundation
Discussion – Internet Watch Foundation
 
P
o
s
s
i
b
l
e
 
p
r
o
c
e
s
s
 
f
o
r
 
T
L
D
 
H
o
p
p
i
n
g
 
L
i
s
t
.
 
N
O
T
E
A
 
r
e
s
e
r
v
e
d
 
d
o
m
a
i
n
 
i
s
 
r
e
s
t
r
i
c
t
e
d
 
f
r
o
m
 
b
e
i
n
g
 
r
e
g
i
s
t
e
r
e
d
 
n
o
r
m
a
l
l
y
.
 
T
h
i
s
 
i
s
 
d
i
f
f
e
r
e
n
t
 
f
r
o
m
 
a
 
b
l
o
c
k
e
d
d
o
m
a
i
n
,
 
w
h
i
c
h
 
c
a
n
 
n
e
v
e
r
 
b
e
 
r
e
g
i
s
t
e
r
e
d
.
Due to the higher risk with these domains, the list of domains should not be published.
A
 
p
r
o
c
e
s
s
 
f
o
r
 
R
A
N
T
s
 
t
o
 
a
p
p
l
y
 
f
o
r
 
r
e
s
e
r
v
e
d
 
d
o
m
a
i
n
s
 
w
a
s
 
a
p
p
r
o
v
e
d
 
b
y
 
t
h
e
 
P
A
C
 
a
t
 
P
A
C
 
2
4
 
(
1
1
J
u
n
e
 
2
0
2
0
)
.
Discussion – Internet Watch Foundation
Discussion – Internet Watch Foundation
Discussion – Internet Watch Foundation
Discussion – Internet Watch Foundation
NIS2
NIS2
Roadmap & Tracker
Key Updates
Updates from Working Group
Tour de Table
NIS2 Roadmap
NIS2 Roadmap
Task Complexity
High:
Med:
Low:
  
PAC / Working Group Engagement (On-Going)
 Registrar webinar trainings on NIST
CSF 2.0 & policy requirements
Registrar
Capacity
Survey
What We Heard
Report
Audit Policy
Impacts
Policy Impact
Report
White Papers
for public
consultations
Advocate to relevant policymakers
Monitor legislative changes at each stage
Fast Track
Changes
Adjust policy options as legislation evolves to ensure
alignment
RAR webinars for awareness
  ICANN & CENTR calls, conferences and workshops as needed
Open Letters and Blog Posts on NIS 2 Implications
Tracker
Tracker
Actions taken since last PAC Meeting 
(25th April 2024)
4
Actions
taken
3
Actions
taken
3
Action
taken
Key Updates
Key Updates
N
C
S
C
 
C
o
n
f
e
r
e
n
c
e
 
(
2
5
 
J
u
n
e
 
2
0
2
4
)
N
e
w
 
H
e
a
d
s
 
o
f
 
B
i
l
l
 
f
o
r
 
J
u
l
y
 
2
0
2
4
.
NCSC to create online portal for self-reporting entity status (essential/important).
NIST CSF 2.0 to be the recommended framework for NIS2 compliance.
“Working Group on “Registrant Verification” expected to publish guidance over summer.
P
a
r
t
i
c
i
p
a
t
i
o
n
 
i
n
 
E
N
I
S
A
 
S
t
u
d
y
.
“Baseline” Verification = ICANN’s “Operational Verification”
“IDV” recognised as burdensome and resource-heavy
C
E
N
T
R
 
J
a
m
b
o
r
e
e
 
(
M
a
y
 
2
0
2
4
)
Included sessions on NIS2 from RAR perspective, talk from ENISA rep, & RAR compliance.
NIS2 Working Group
NIS2 Working Group
M
e
t
 
o
n
 
0
9
 
J
u
l
y
 
2
0
2
4
 
t
o
 
d
i
s
c
u
s
s
 
k
e
y
 
u
p
d
a
t
e
s
 
a
n
d
 
t
h
e
 
p
r
o
p
o
s
e
d
 
G
D
P
R
 
C
o
d
e
 
o
f
 
C
o
n
d
u
c
t
Reviewed the draft Implementing Acts
Concerns over definition of “service”
Definition of “serious incident” very generous
Recommendation to increase communications with RARs on the NIST 2.0
Emphasis on NIST 2.0 from the NCSC as the Best Practice
NIS2 Working Group – GDPR Code of Conduct
NIS2 Working Group – GDPR Code of Conduct
The WG agreed with the general approach of the voluntary GDPR Code of Conduct:
The NIS2 WG (on behalf of the PAC) would be 
“Code Owner” 
responsible for drafting.
The draft Code would undergo public consultation with Registrars.
.ie would act as the 
“Monitoring Body” 
for the Code of Conduct.
Tour de Table
Tour de Table
Internet
Internet
Governance
Governance
Key Updates & EuroDIG 2024 Debrief
Ireland IGF Announcement
Key Updates – Internet Governance
Key Updates – Internet Governance
Updates on WSIS+20 and Global Digital Compact processes
Technical Community Coalition for Multistakeholderism (TCCM)
Debrief from EuroDIG 2024 and Baltic Domain Days 2024
EuroDIG: Discussions on EU Policy, Digitalising Public Services, AI
BDD: Discussions on Domain Names, IP Rights, ccTLD Abuse Rates
Ireland Internet Governance Forum
Ireland Internet Governance Forum
The UN Internet Governance Forum (IGF) is a multi-stakeholder platform for
policy discussions related to internet governance.
National and Regional Initiatives (NRI) are events organized by local internet
communities in a “bottom-up” manner.
To date, Ireland has never hosted a national IGF event.
Multistakeholder Core Organising Team established.
A
i
m
 
f
o
r
 
l
a
u
n
c
h
 
e
v
e
n
t
 
i
n
 
Q
4
 
2
0
2
4
;
 
m
a
i
n
 
e
v
e
n
t
 
i
n
 
Q
2
 
2
0
2
5
AOB
AOB
Next Meetings - 2024
Next Meetings - 2024
P
A
C
 
4
1
:
 
1
0
 
O
c
t
o
b
e
r
 
2
0
2
4
P
A
C
 
4
2
:
 
1
2
 
D
e
c
e
m
b
e
r
 
2
0
2
4
Slide Note
Embed
Share

The 40th Policy Advisory Committee meeting held on July 11, 2024, discussed various important matters including proposed amendments to PAC Terms of Reference, updates on NIS2, Internet Governance, and more. The meeting emphasized membership protocols and the importance of recording for minute drafting. Several proposals were put forward, including updating the list of Eligible Organizations in the PAC Terms of Reference.

  • Policy Advisory Committee
  • PAC Meeting
  • Amendments
  • Internet Governance
  • Membership Matters

Uploaded on Sep 28, 2024 | 0 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. Download presentation by click this link. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

E N D

Presentation Transcript


  1. 40th Policy Advisory Committee 11 July 2024 Proprietary

  2. Agenda 1. Introduction & Membership Matters 2. Matters Arising Policy Proposal: Amendments to PAC Terms of Reference 3. Criminal & Technical Abuse NetCraft Service Update Discussion - Internet Watch Foundation Processes 4. NIS2 Updates 5. Internet Governance WSIS+20, GDC, & Technical Community Updates Debrief from EuroDIG 2024 Ireland IGF announcement 1. AOB Proprietary

  3. Membership Matters Please keep microphones muted throughout the call Please "raise a hand" to ask a question or add comments in the chat box Before speaking, please state your name for the record Meeting will be recorded to assist with minute drafting Recording will be deleted once the Minutes are approved by the PAC Proprietary

  4. Minutes of PAC #39 Meeting minutes are circulated to the membership after each meeting. Comments & feedback are accepted over a two-week period. If edits are requested, and consensus exists, these are reflected in the Minutes. Minutes and slides are published on weare.ie after the comment period has ended. Proprietary

  5. Matters Arising Proposal: Amendments to PAC Terms of Reference & Policy Development Process Proprietary

  6. Proposals Amending PAC Terms of Reference At PAC 39, a proposal was introduced to update and amend the Eligible Organisations appendix in the PAC Terms of Reference. The Eligible Organisations List had several out-of-date references and did not include any of the Digital Regulators. Another suggestion was made to streamline similar policy amendments in the future. Proprietary

  7. Amendment 1: PAC Eligible Organisations Current List (Apr 2021) Proposed List (July 2024) 1. *Amend Name* Department of Communications, Climate Action & Environment (DCCAE) *Amend Name* Department of Business, Enterprise & Innovation (DBEI) *Remove*Internet Service Providers Association of Ireland (ISPAI) Accredited .ie Registrars Irish Computer Society (ICS) Law Society of Ireland Small Firms Association (SFA) Association of Patents and Trademarks Attorneys(APTMA) HEAnet 10. Enterprise Ireland 11. *Amend Name* Cybersafe Ireland 12. Irish Reporting & Information Security Service (IRISS) Observer Members Department of Environment, Climate & Communications (DECC) Department of Enterprise, Trade and Employment (DETE) Enterprise Ireland *New* ComReg *New* Data Protection Commission *New* Coimisi n na Me n *New* Competition & Consumer Protection Commission 2. 3. 4. 5. 6. 7. 8. 9. Non-Observer Members .ie Accredited Registrars Association of Patent & Trade Mark Attorneys (APTMA) CyberSafeKids HEAnet Irish Computer Society (ICS) Irish Reporting & Information Security Service (IRISS) Law Society of Ireland Small Firms Association (SFA) Proprietary

  8. Amendment 2 Policy Development Process Current PDP Model Issues Not reflective of practice Every proposal in chart requires working group No process for minor (de minimis) issues like correcting typos or updating links (all changes currently to go to PAC) Proprietary

  9. Amendment 2 Policy Development Process Proposal: PAC to asynchronously provide input, support, or objection by PAC 41. Proprietary

  10. Criminal & Technical Abuse Updates from NetCraft Service Participation in IWF Proprietary

  11. NetCraft Number of Attacks (YTD) Proprietary

  12. NetCraft Attacks by Group (YTD) Proprietary

  13. Discussion Internet Watch Foundation At PAC 39, the IWF presented on their Domain Alert and TLD Hopping List Services. Domain Alert provides real-time alerts of confirmed CSAM on a TLD s domain. TLD Hopping List provides list of domain strings known to be used to distribute CSAM. The PAC was generally supportive of .ie participating in these programs but emphasized that .ie should have processes in place to handle IWF reports. Discussion: What could a IWF mitigation process for .ie look like? Proprietary

  14. Discussion Internet Watch Foundation Public Interest Registry (.org & .ngo) s process for Domain Alerts. Domain Alert received from IWF to PIR with defanged URL. If no If no confirmation from RAR in 48 hours, PIR follows up again. confirmation in 96 hours (4 days), domain is suspended. PIR confirms if RAR has mitigated issue. PIR notifies RAR & Authorities. Notify parties & monitor for appeals. NOTE A defanged URL is one that has been modified so it does not resolve (hxxps://example.ie) Potential to replicate or adapt similar process for .ie. Proprietary

  15. Discussion Internet Watch Foundation Possible process for TLD Hopping List. If rejected, .ie decision can be appealed to the Board of Directors. Domain is included on TLD Hopping List .ie places Domain on reserved domain list. If application accepted, registration can occur. RANT may apply for domain NOTE A reserved domain is restricted from being registered normally. This is different from a blocked domain, which can never be registered. Due to the higher risk with these domains, the list of domains should not be published. A process for RANTs to apply for reserved domains was approved by the PAC at PAC 24 (11 June 2020). Proprietary

  16. Discussion Internet Watch Foundation Proprietary

  17. Discussion Internet Watch Foundation Proprietary

  18. Roadmap & Tracker Key Updates NIS2 Updates from Working Group Tour de Table Proprietary

  19. NIS2 Roadmap Task Complexity High: Med: Low: Q2 2023 Q3 2023 Q4 2023 Q1 2024 Q2 2024 Q3 2024 Q4 2024 Stage Preliminary Analysis Advocate & Monitor Implement Awaiting Heads of Bill Awaiting Heads of Bill Awaiting Heads of Bill Awaiting Heads of Bill Legislative Process Transposed by Oct 17th Legislative Milestones Audit Policy Impacts What We Heard Report Policy Impact Report Adjust policy options as legislation evolves to ensure alignment Fast Track Changes Registrar Capacity Survey Alignment Monitor legislative changes at each stage PAC / Working Group Engagement (On-Going) White Papers for public consultations Advocacy Advocate to relevant policymakers Registrar webinar trainings on NIST CSF 2.0 & policy requirements RAR webinars for awareness Awareness Open Letters and Blog Posts on NIS 2 Implications ICANN & CENTR calls, conferences and workshops as needed Proprietary

  20. Tracker Actions taken since last PAC Meeting (25th April 2024) Advocacy Frequently present the concerns and views of stakeholders to policymakers Alignment Awareness Actively inform Registrars of impending changes from NIS2 Ensure that .IE Policies and Processes are aligned with NIS2 requirements 4 3 3 Actions taken Actions taken Action taken +2 from last update (25 April) +2 from last update (25 April) +1 from last update (25 April) NIS2 WG Meeting held (9 July 2024) CENTR Jamboree Participation Participation in ENISA Study NCSC Cyber Security Conference Engagement with NCSC & DECC Requested input from DPC on Article 28 Participation in ENISA Study NIST RAR Webinar scheduled for July Launch of .ie Accreditation Framework Blog on EU regulations (12 June 2024) Proprietary

  21. Key Updates NCSC Conference (25 June 2024) New Heads of Bill for July 2024. NCSC to create online portal for self-reporting entity status (essential/important). NIST CSF 2.0 to be the recommended framework for NIS2 compliance. Working Group on Registrant Verification expected to publish guidance over summer. Participation in ENISA Study. Baseline Verification = ICANN s Operational Verification IDV recognised as burdensome and resource-heavy CENTR Jamboree (May 2024) Included sessions on NIS2 from RAR perspective, talk from ENISA rep, & RAR compliance. Proprietary

  22. NIS2 Working Group Met on 09 July 2024 to discuss key updates and the proposed GDPR Code of Conduct Reviewed the draft Implementing Acts Concerns over definition of service Definition of serious incident very generous Recommendation to increase communications with RARs on the NIST 2.0 Emphasis on NIST 2.0 from the NCSC as the Best Practice Proprietary

  23. NIS2 Working Group GDPR Code of Conduct The WG agreed with the general approach of the voluntary GDPR Code of Conduct: The NIS2 WG (on behalf of the PAC) would be Code Owner responsible for drafting. The draft Code would undergo public consultation with Registrars. .ie would act as the Monitoring Body for the Code of Conduct. Proprietary

  24. Tour de Table Proprietary

  25. Internet Governance Key Updates & EuroDIG 2024 Debrief Ireland IGF Announcement Proprietary

  26. Key Updates Internet Governance Updates on WSIS+20 and Global Digital Compact processes Technical Community Coalition for Multistakeholderism (TCCM) Debrief from EuroDIG 2024 and Baltic Domain Days 2024 EuroDIG: Discussions on EU Policy, Digitalising Public Services, AI BDD: Discussions on Domain Names, IP Rights, ccTLD Abuse Rates Proprietary

  27. Ireland Internet Governance Forum The UN Internet Governance Forum (IGF) is a multi-stakeholder platform for policy discussions related to internet governance. National and Regional Initiatives (NRI) are events organized by local internet communities in a bottom-up manner. To date, Ireland has never hosted a national IGF event. Multistakeholder Core Organising Team established. Aim for launch event in Q4 2024; main event in Q2 2025 Proprietary

  28. AOB Proprietary

  29. Next Meetings - 2024 PAC 41: 10 October 2024 PAC 42: 12 December 2024 Proprietary

  30. Proprietary

Related


More Related Content

giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#giItT1WQy@!-/#