Is there a reason it wasn't published through the RSSAC process?
I would personally say that the contents of the document was very technically tied to the *implementation* of the RSS at the various root server operators, and how the current operator deployment architectures address the perceived threats. This is very different (and subtly the same, yes) as the remit of RSSAC which is at the policy level, how should it perform as a whole, what are the requirements of the larger system, what does the community need of the RSS, etc type of questioning.
--