Hello all,

A question came up regarding where a specific recommendation landed in the draft report. I’ve kept a table mapping what went where; a copy is below, and a copy is also now online here (in case the formatting doesn’t work for your mail client):

https://docs.google.com/spreadsheets/d/1V-S3dZFWtRTGeXOpreLj2ovkCEwmTEUGthiBoLlIcP4/edit


Old recommendation numberDescriptionWorkstreamNew recommendation number

Implement all SSR1 RecommendationsSSR11
Recommendation 2ISMS, CertificationSSR13
Recommendation 3Metrics, Vulnerability DisclosureSSR1 - still a work in progress5
Recommendation 4Budget TransparencySSR16
Recommendation 5SSAC, RSSAC rolesSSR12
Recommendation 6SSR Strategy and FrameworkSSR14
Recommendation 7Budgeting and gTLDsSSR17
Recommendation 8Risk ManagementSSR18
Recommendation 10Security Position, C-SuiteWS29
Recommendation 11Security Risk ManagementWS210
Recommendation 13DNS Test BedWS316
Recommendation 14IANA PortalWS317
Recommendation 15Root Server OpsWS319
Recommendation 19Research and BriefingsWS424
Recommendation 20Abusive NamingWS315
Recommendation 24Root ZoneWS320
Recommendation 26Key RolloverWS318
Recommendation 27DR PlanWS211
Recommendation 28Name CollisionWS422
Recommendation 35CryptoWS421
Recommendation 36PrivacyWS423

Abuse and Compliance: ComplianceWS312

Abuse and Compliance: Abuse Definitions & ReportingWS313

Abuse and Compliance: Policies and Agreements with Contracted PartiesWS314