As to recommendation 15, I am surprised that the IPC suggested changes are simply copy pasted in at least two instances in the report :
- Logs of Requests, Acknowledgements and Responses should be maintained in accordance with standard business recordation practices so that they are available to be produced as needed including, but not limited to, for audit purposes by ICANN Compliance;
-A separate timeline of [less than X business days] will considered for the response to ‘Urgent’ Reasonable Disclosure Requests, those Requests for which evidence is supplied to show an immediate need for disclosure [time frame to be finalized and criteria set for Urgent requests during implementation].
As far as I remember CPs on that thread (Alan Woods and Marc) and us (NCSG) objected to adding audit. Did anything change? I also see a change to "urgent" requests done by IPC which is totally unacceptable and I cannot remember we ever came to a consensus about that. This also applies to additions to logs of requests.
Sarah on that thread had suggested some acceptable changes that I believe addresses the issues and is middle ground. I have attached those suggestions.