Dear Colleagues,


A new proposal "prop-171: Operational Accountability for Abuse Contacts in
Sub-Allocated Address Space"
has been sent to the Policy SIG for review.

It will be presented at the Open Policy Meeting (OPM) at APNIC 62 on
Thursday, 10 September 2026.

https://conference.apnic.net/62/program/program/index.html#/day/7/

We invite you to review and comment on the proposal on the mailing list
before the OPM.

The comment period on the mailing list before the OPM is an important part
of the Policy Development Process (PDP).


We encourage you to express your views on the proposal:

·         Do you support or oppose this proposal?

·         Does this proposal solve a problem you are experiencing? If so,
tell the community about your situation.

·         Do you see any disadvantages in this proposal?

·         Is there anything in the proposal that is not clear?

·         What changes could be made to this proposal to make it more
effective?


Information about this proposal is appended below as well as
https://www.apnic.net/community/policy/proposals/prop-171/

Regards
Bikram, Shaila, and Ching-Heng

APNIC Policy SIG Chairs



-------------
--------------------------------------------------------------------------

prop-171-v001: Operational Accountability for Abuse Contacts in
Sub-Allocated Address Space
-------------------------------------------------------

Proposer: Tsung-Yi [email protected]

Alban Kwan
[email protected]


1. Problem statement
-------------------------------------------------------
APNIC-127 requires resource holders to register and maintain an IRT
object for each resource record in the APNIC Whois Database, and
requires that registered abuse contacts be validated as reachable at
least once every six months. This validation requirement, introduced
by prop-125, has improved the accuracy of contact registration data
across the APNIC region.
However, reachability is not the same as operational accountability.
In sub-allocated address space, the party registered as the abuse
contact is frequently not the party able to investigate or resolve the
incident. The registered contact may belong to an upstream provider, a
centralised administrative function, or another intermediary that
receives the report but has no direct operational relationship with
the network from which the abuse originates. As a result, abuse
reports are sent to a valid and reachable contact, yet fail to reach
the party responsible for acting on them. This leads to delayed
responses, unnecessary forwarding, unclear accountability, and
confusion for abuse reporters.
This gap is not addressed by current APNIC policy. Prop-125 and
APNIC-127 confirm that a contact is reachable; they say nothing about
whether the contact is positioned to act. In multi-layer resource
environments -- where address space passes through one or more
intermediary tiers before reaching the network operator -- this
distinction is material. Operational data indicates that a significant
share of abuse reports received by APNIC relating to non-responsive or
non-functional IRT contacts originate from sub-allocated address
space, where the registered contact and the operationally responsible
party are not the same.
This proposal addresses that gap by establishing a clear principle:
where address space is sub-allocated, the upstream holder bears
responsibility for ensuring that abuse reports can reach the
operationally responsible downstream party.



2. Objective of policy change
-------------------------------------------------------
This proposal seeks to establish a principle of operational
accountability for abuse contacts in sub-allocated address space.
If adopted, APNIC policy would require that where address space is
sub-allocated, assigned, or otherwise used by a downstream
organisation, the upstream holder must ensure there is a reliable
operational path from the registered abuse contact to the party
responsible for handling abuse reports for that address space.
This principle applies regardless of the sub-allocation tier or
organisational model involved. It does not prescribe a single
operational model for how abuse handling should be organised, nor does
it require the public disclosure of all downstream contact
information. The intent is to ensure that the registered contact is
operationally meaningful, not merely reachable.
This proposal does not alter the existing validation requirement under
APNIC-127. It does not introduce a new audit or compliance mechanism.
The operational guidance needed to implement this principle across
different sub-allocation tiers will be developed by the APNIC
Secretariat in consultation with the community.



3. Situation in other regions
-------------------------------------------------------
No RIR has adopted policy that addresses operational accountability
for abuse contacts in sub-allocated address space. The cross-regional
picture on abuse contact requirements is as follows.
RIPE NCC has required a mandatory, annually validated abuse-c for all
resource records since 2018. The obligation is limited to contact
reachability. RIPE NCC has stated explicitly that it has no say in
what action is taken once a report is received, and does not address
how contacts in sub-allocated space should relate to operational
responsibility.
LACNIC's abuse contact policy, in force since 2020, is the most
developed of any RIR. It requires a valid, monitored abuse-mailbox
validated at least twice yearly, and attaches revocation consequences
to persistent non-compliance. Like RIPE NCC, however, it addresses
contact reachability and monitoring obligations only. It does not
establish any principle regarding operational accountability in
sub-allocated environments.
ARIN requires a registered Abuse Point of Contact, verified annually.
It does not impose requirements on how abuse reports must be received
or handled beyond contact reachability, and does not address
sub-allocation accountability.
AFRINIC's abuse contact policy, developed through multiple drafts
since 2018, is modelled on the LACNIC and RIPE NCC approaches. Its own
supporting documentation states explicitly that the policy does not
define what abuse is, and the framework is similarly limited to
contact registration and reachability.
This proposal would make APNIC the first RIR to address the
operational accountability gap in sub-allocated address space. No
equivalent proposal is known to be under active consideration in any
other RIR region.


4. Proposed policy solution
-------------------------------------------------------
It is proposed that APNIC policy be amended to include the following
principle, to be inserted into APNIC-127 at a location to be confirmed
through community discussion, noting that Section 5.3.3 (Registering
Contact Persons) is one likely location:
Where address space is sub-allocated, assigned, or otherwise used by a
downstream organisation, the upstream holder responsible for the
relevant registry record must ensure that there is a reliable
operational path from the registered abuse or IRT contact to the party
able to investigate and resolve abuse reports for that address space.
The upstream holder may meet this requirement through any of the
following arrangements:
(a) the registered abuse or IRT contact is directly operated by
the downstream organisation responsible for the address space;

(b) the registered contact is a centralised function maintained
by the upstream holder, provided that function has a reliable
process for identifying the relevant downstream party and
forwarding abuse reports to that party; or

(c) another arrangement that ensures legitimate abuse reports
reach the operationally responsible party without undue delay.

Sub-allocating address space to a downstream organisation does not
relieve the upstream holder of responsibility for maintaining a
reliable operational path from the registered contact to the party
able to act on abuse reports. Where a downstream organisation takes
responsibility for its own abuse handling, the upstream holder must
ensure that this is accurately reflected in the relevant registry
record.
APNIC Secretariat will develop operational guidance on how this
principle applies across different sub-allocation tiers and
organisational models. This guidance will be developed in consultation
with the community and will take into account the operational
diversity of sub-allocation arrangements in the APNIC region.
For clarity, this proposal does not require the public disclosure of
all downstream customer contact information. It does not prescribe one
specific operational model for abuse handling. It does not alter the
existing IRT validation requirement or the validation timelines under
APNIC-127. And it does not assign APNIC any new investigative or
enforcement role beyond what is already established under existing
policy.



5. Advantages / Disadvantages
-------------------------------------------------------
Advantages:
Advantages
Closes a structural accountability gap that current policy does not
address: a validated abuse contact is only operationally useful if it
can route reports to the party able to act.


Applies consistently across all sub-allocation tiers and
organisational models, without singling out any specific category of
resource holder.


Preserves operational flexibility. Upstream holders may continue using
centralised abuse handling arrangements, provided those arrangements
are genuinely effective.


Builds directly on prop-125 and APNIC-127 without reopening the core
validation requirement, which has already been settled through
community consensus.

Disadvantages:

Disadvantages
Upstream holders who sub-allocate address space may need to review
their current abuse handling arrangements and, in some cases, update
registry records or internal forwarding processes.


Secretariat will need to invest in developing and maintaining
operational guidance across a range of sub-allocation models, which
represents a moderate administrative commitment.


6. Impact on resource holders
-------------------------------------------------------
If adopted, the direct impact on APNIC Secretariat would be moderate.
The Secretariat would be responsible for developing operational
guidance on how the principle applies across different sub-allocation
tiers, in consultation with the community. This would not require new
systems or changes to the Whois Database schema. It would require
internal review of existing operational processes for handling abuse
reports relating to sub-allocated address space, and engagement with
the relevant upstream holders to support the transition.
For resource holders, the impact depends on their current
arrangements. Holders who already ensure that their sub-allocation
registry records reflect operationally responsible contacts are
unlikely to need significant changes. Holders who use centralised
abuse contacts for sub-allocated address space will need to confirm
that those contacts have a reliable process for routing reports to the
downstream party able to act.
This proposal introduces no new validation frequency, audit mechanism,
or compliance framework beyond the operational guidance Secretariat
will develop following adoption.


7. References
-------------------------------------------------------
prop-125-v001: Validation of "abuse-mailbox" and other IRT emails,
www.apnic.net/community/policy/proposals/prop-125/


APNIC-127: APNIC Internet Number Resource Policies (current),
www.apnic.net/community/policy/resources


Operational Policies for National Internet Registries in the APNIC
region, www.apnic.net/community/policy/operational-policies-nirs/


APNIC, "Security at APNIC," www.apnic.net/community/security/


LACNIC, Section 12: Registration and validation of "abuse-c" and
"abuse-mailbox," LACNIC Policy Manual,
www.lacnic.net/4419/2/lacnic/12-registration-and-validation-of-abuse-c-and-abuse-mailbox


RIPE NCC, ripe-705: Abuse Contact Management in the RIPE NCC Database,
www.ripe.net/publications/docs/ripe-705


ARIN, Number Resource Policy Manual, Section 3.6,
www.arin.net/participate/policy/nrpm/


AFRINIC, AFPUB-2018-GEN-001: Abuse Contact Policy Update,
afrinic.net/policy/proposals/2018-gen-001-d8
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]

Reply via email to