Hey Sara,

maybe this is the angle we can find agreement with LEAs on:

Instead of dictating a strict 24h deadline, we make it a more fluid, best effort approach. "Where a disclosure request has been categorized as High Priority, Provider shall use its best efforts towards actioning the request within 24 hours on business days or as close as possible to this."

I could agree to that.

Volker


Am 05.02.2018 um 18:05 schrieb Sara Bockey:

A few items.

 

Again, I’m concerned that we are creating policy, not implementing it.  Granted, the framework outlined in the Final Report is not as robust as what is detailed for IPC, but then again LEA did not participate in the PDP process. The IRT is not the place to be creating policy for LEAs.

 

That said, the problem with a strict 24-hour period is that it doesn’t acknowledge certain situations/matters may require additional time, falling outside a 24-hour period despite a Provider’s best efforts.  Language such as “Where a disclosure request has been categorized as High Priority, this must be actioned within 24 hours” are overly strict and sets the Provider up for failure/being out of compliance due to circumstances beyond its control.

Finally, I fear the LEA framework as currently written creates unrealistic expectations/SLAs. There seems to be a presumption of disclosure – if LEAs check all the right boxes, the information will be disclosed.  However, this decision should reside with the provider, who does not have to bypass due process just to please LEAs.

 

 

sara bockey

sr. policy manager | GoDaddy

sbockey@godaddy.com  480-366-3616

skype: sbockey

 

This email message and any attachments hereto is intended for use only by the addressee(s) named herein and may contain confidential information. If you have received this email in error, please immediately notify the sender and permanently delete the original and any copy of this message and its attachments.

 

 

From: Gdd-gnso-ppsai-impl <gdd-gnso-ppsai-impl-bounces@icann.org> on behalf of Amy Bivins <amy.bivins@icann.org>
Reply-To: "gdd-gnso-ppsai-impl@icann.org" <gdd-gnso-ppsai-impl@icann.org>
Date: Monday, February 5, 2018 at 7:51 AM
To: "gdd-gnso-ppsai-impl@icann.org" <gdd-gnso-ppsai-impl@icann.org>
Subject: [Gdd-gnso-ppsai-impl] Request for IRT Feedback: LEA Framework Specification, Receipt Process's Application to High Priority Requests

 

Dear Colleagues,

 

As mentioned on the list a couple of weeks ago, the current draft PPAA is still a bit ambiguous regarding how the review process outlined in Section 3.2.1 applies to high priority requests. We need ensure that the draft is clear about this requirement when we go out for public comment (and if there is opposition to the proposed requirement by any members of the IRT, this will be flagged in the call for comments).

 

Upon reviewing the IRT’s input to date, I am proposing an edit that I believe reflects the IRT discussion on this point. Please review and provide your comments on this proposed language no later than this Friday, 9 February.

 

To summarize, the current draft contains a two-step process for Providers upon receipt of a request from LEA. (1) Within two business days, the Provider must review the request and confirm to the LEA requester that it has been received and contains the relevant information required to meet the minimum standard for acceptance (See 3.2.1 of Specification 4). (2) The Provider must then action the request in accordance with the priority level (within 24 hours for “high priority” requests (4.1.2); or within the timeline requested by LEA, if possible, for other requests (See 4.1.3).

 

The current language may be a bit ambiguous as to whether the two business day “review period” applies before the 24-hour period for responding to high priority requests (as explained in more detail in the attached message). The view of registrar IRT members appears to be that requiring action within 24 hours of receipt of an LEA request, even if it is a high priority request, is unacceptable. PSWG members of the IRT disagree. Other IRT members appear to have mixed views on this (some referenced the RAA requirement that “Well-founded reports of Illegal Activity submitted to these [dedicated LEA] contacts must be reviewed within 24 hours by an individual who is empowered by Registrar to take necessary and appropriate actions in response to the report.” Registrar members of the IRT said that the RAA-required review is less intensive than the PPAA review due to the specific requirements in the PPAA draft).

 

Based on the views expressed within the IRT, it appears that one potential solution to this ambiguity would be to update Section 4.1.2 to state that (proposed edit in red), Where a disclosure request has been categorized as High Priority, this must be actioned within 24 hours of completion of the receipt process outlined in Section 3.2.” The LEA Requestor will detail the threat type and justification for a request with a Priority Level of High Priority.”

 

The practical impact of this proposed change would be that the provider must action a high priority request within 24 hours of determining that the request meets the minimum standard for acceptance. If the provider completes the receipt process sooner than 2 business days after receipt of the request, this would start the 24-hour clock for actioning the request. Thus, this could shorten the response window a bit, partially addressing the PSWG concerns of a “two business days plus 24 hours” requirement, while also addressing registrar concerns by not starting the clock until the provider has time to review the request, if the full time of the receipt process is required to conduct that review.

 

Please provide your feedback on this proposed change no later than this Friday,  9 Feb. And if you have further comments on this, please share those as well.

 

Best,

Amy

 

 

Amy E. Bivins

Registrar Services and Engagement Senior Manager

Registrar Services and Industry Relations

Internet Corporation for Assigned Names and Numbers (ICANN)

Direct: +1 (202) 249-7551

Fax:  +1 (202) 789-0104

Email: amy.bivins@icann.org

www.icann.org

 



_______________________________________________
Gdd-gnso-ppsai-impl mailing list
Gdd-gnso-ppsai-impl@icann.org
https://mm.icann.org/mailman/listinfo/gdd-gnso-ppsai-impl

-- 
Bei weiteren Fragen stehen wir Ihnen gerne zur Verfügung.

Mit freundlichen Grüßen,

Volker A. Greimann
- Rechtsabteilung -

Key-Systems GmbH
Im Oberen Werk 1
66386 St. Ingbert
Tel.: +49 (0) 6894 - 9396 901
Fax.: +49 (0) 6894 - 9396 851
Email: vgreimann@key-systems.net

Web: www.key-systems.net / www.RRPproxy.net
www.domaindiscount24.com / www.BrandShelter.com

Folgen Sie uns bei Twitter oder werden Sie unser Fan bei Facebook:
www.facebook.com/KeySystems
www.twitter.com/key_systems

Geschäftsführer: Alexander Siffrin
Handelsregister Nr.: HR B 18835 - Saarbruecken 
Umsatzsteuer ID.: DE211006534

Member of the KEYDRIVE GROUP
www.keydrive.lu 

Der Inhalt dieser Nachricht ist vertraulich und nur für den angegebenen Empfänger bestimmt. Jede Form der Kenntnisgabe, Veröffentlichung oder Weitergabe an Dritte durch den Empfänger ist unzulässig. Sollte diese Nachricht nicht für Sie bestimmt sein, so bitten wir Sie, sich mit uns per E-Mail oder telefonisch in Verbindung zu setzen.

--------------------------------------------

Should you have any further questions, please do not hesitate to contact us.

Best regards,

Volker A. Greimann
- legal department -

Key-Systems GmbH
Im Oberen Werk 1
66386 St. Ingbert
Tel.: +49 (0) 6894 - 9396 901
Fax.: +49 (0) 6894 - 9396 851
Email: vgreimann@key-systems.net

Web: www.key-systems.net / www.RRPproxy.net
www.domaindiscount24.com / www.BrandShelter.com

Follow us on Twitter or join our fan community on Facebook and stay updated:
www.facebook.com/KeySystems
www.twitter.com/key_systems

CEO: Alexander Siffrin
Registration No.: HR B 18835 - Saarbruecken 
V.A.T. ID.: DE211006534

Member of the KEYDRIVE GROUP
www.keydrive.lu 

This e-mail and its attachments is intended only for the person to whom it is addressed. Furthermore it is not permitted to publish any content of this email. You must not use, disclose, copy, print or rely on this e-mail. If an addressing or transmission error has misdirected this e-mail, kindly notify the author by replying to this e-mail or contacting us by telephone.