Dear Colleagues,

I am Satoru Tsurumaki from Japan Open Policy Forum Steering Team.

I would like to share key feedback from our community regarding prop-171,
based on a meeting we organized on 24th Aug to discuss these proposals.
Please note that this is a summary of the discussion held by 17 Japanese
community members who attended the meeting, including those who actually
handle abuse reports.

The discussion was generally supportive of the proposal.

(Comment details)

- Participants generally agreed that it is reasonable for upstream resource
holders to ensure that abuse contacts remain operational and that abuse
reports are either handled appropriately or reliably forwarded to
downstream organizations. Clarifying this responsibility was viewed as a
natural extension of the existing resource delegation hierarchy.
- Several participants noted that the proposal appears to establish a
responsibility framework rather than introducing compliance monitoring,
audit authority, or enforcement mechanisms. This approach was considered
appropriate as an initial step.
- It was observed that, without audit or reporting mechanisms, the proposal
alone would not significantly change operational practice. However,
participants understood that the proposer may intend this proposal to
provide a foundation for future policy development.
- Some participants pointed out that introducing such responsibilities
could eventually have legal or regulatory implications. For example, the
policy could potentially be referenced in disputes regarding whether an
upstream resource holder exercised appropriate oversight. Therefore,
careful consideration should be given before expanding the proposal beyond
clarification of responsibilities.
- Some participants suggested that operational expectations and best
practices may be better documented in implementation guidelines rather than
directly in APNIC policy.

Regards,

Satoru Tsurumaki
Japan Open Policy Forum Steering Team

2026年8月10日(月) 12:02 Shaila Sharmin <[email protected]>:

> Dear Colleagues,
>
>
>
> A new proposal "prop-171: Operational Accountability for Abuse Contacts in
> Sub-Allocated Address Space"
> has been sent to the Policy SIG for review.
>
> It will be presented at the Open Policy Meeting (OPM) at APNIC 62 on
> Thursday, 10 September 2026.
>
> https://conference.apnic.net/62/program/program/index.html#/day/7/
>
> We invite you to review and comment on the proposal on the mailing list
> before the OPM.
>
> The comment period on the mailing list before the OPM is an important part
> of the Policy Development Process (PDP).
>
>
> We encourage you to express your views on the proposal:
>
> ·         Do you support or oppose this proposal?
>
> ·         Does this proposal solve a problem you are experiencing? If so,
> tell the community about your situation.
>
> ·         Do you see any disadvantages in this proposal?
>
> ·         Is there anything in the proposal that is not clear?
>
> ·         What changes could be made to this proposal to make it more
> effective?
>
>
> Information about this proposal is appended below as well as
> https://www.apnic.net/community/policy/proposals/prop-171/
>
> Regards
> Bikram, Shaila, and Ching-Heng
>
> APNIC Policy SIG Chairs
>
>
>
> -------------
> --------------------------------------------------------------------------
>
> prop-171-v001: Operational Accountability for Abuse Contacts in Sub-Allocated 
> Address Space
> -------------------------------------------------------
>
> Proposer: Tsung-Yi [email protected]
>
> Alban Kwan
> [email protected]
>
>
> 1. Problem statement
> -------------------------------------------------------
> APNIC-127 requires resource holders to register and maintain an IRT object 
> for each resource record in the APNIC Whois Database, and requires that 
> registered abuse contacts be validated as reachable at least once every six 
> months. This validation requirement, introduced by prop-125, has improved the 
> accuracy of contact registration data across the APNIC region.
> However, reachability is not the same as operational accountability. In 
> sub-allocated address space, the party registered as the abuse contact is 
> frequently not the party able to investigate or resolve the incident. The 
> registered contact may belong to an upstream provider, a centralised 
> administrative function, or another intermediary that receives the report but 
> has no direct operational relationship with the network from which the abuse 
> originates. As a result, abuse reports are sent to a valid and reachable 
> contact, yet fail to reach the party responsible for acting on them. This 
> leads to delayed responses, unnecessary forwarding, unclear accountability, 
> and confusion for abuse reporters.
> This gap is not addressed by current APNIC policy. Prop-125 and APNIC-127 
> confirm that a contact is reachable; they say nothing about whether the 
> contact is positioned to act. In multi-layer resource environments -- where 
> address space passes through one or more intermediary tiers before reaching 
> the network operator -- this distinction is material. Operational data 
> indicates that a significant share of abuse reports received by APNIC 
> relating to non-responsive or non-functional IRT contacts originate from 
> sub-allocated address space, where the registered contact and the 
> operationally responsible party are not the same.
> This proposal addresses that gap by establishing a clear principle: where 
> address space is sub-allocated, the upstream holder bears responsibility for 
> ensuring that abuse reports can reach the operationally responsible 
> downstream party.
>
>
>
> 2. Objective of policy change
> -------------------------------------------------------
> This proposal seeks to establish a principle of operational accountability 
> for abuse contacts in sub-allocated address space.
> If adopted, APNIC policy would require that where address space is 
> sub-allocated, assigned, or otherwise used by a downstream organisation, the 
> upstream holder must ensure there is a reliable operational path from the 
> registered abuse contact to the party responsible for handling abuse reports 
> for that address space.
> This principle applies regardless of the sub-allocation tier or 
> organisational model involved. It does not prescribe a single operational 
> model for how abuse handling should be organised, nor does it require the 
> public disclosure of all downstream contact information. The intent is to 
> ensure that the registered contact is operationally meaningful, not merely 
> reachable.
> This proposal does not alter the existing validation requirement under 
> APNIC-127. It does not introduce a new audit or compliance mechanism. The 
> operational guidance needed to implement this principle across different 
> sub-allocation tiers will be developed by the APNIC Secretariat in 
> consultation with the community.
>
>
>
> 3. Situation in other regions
> -------------------------------------------------------
> No RIR has adopted policy that addresses operational accountability for abuse 
> contacts in sub-allocated address space. The cross-regional picture on abuse 
> contact requirements is as follows.
> RIPE NCC has required a mandatory, annually validated abuse-c for all 
> resource records since 2018. The obligation is limited to contact 
> reachability. RIPE NCC has stated explicitly that it has no say in what 
> action is taken once a report is received, and does not address how contacts 
> in sub-allocated space should relate to operational responsibility.
> LACNIC's abuse contact policy, in force since 2020, is the most developed of 
> any RIR. It requires a valid, monitored abuse-mailbox validated at least 
> twice yearly, and attaches revocation consequences to persistent 
> non-compliance. Like RIPE NCC, however, it addresses contact reachability and 
> monitoring obligations only. It does not establish any principle regarding 
> operational accountability in sub-allocated environments.
> ARIN requires a registered Abuse Point of Contact, verified annually. It does 
> not impose requirements on how abuse reports must be received or handled 
> beyond contact reachability, and does not address sub-allocation 
> accountability.
> AFRINIC's abuse contact policy, developed through multiple drafts since 2018, 
> is modelled on the LACNIC and RIPE NCC approaches. Its own supporting 
> documentation states explicitly that the policy does not define what abuse 
> is, and the framework is similarly limited to contact registration and 
> reachability.
> This proposal would make APNIC the first RIR to address the operational 
> accountability gap in sub-allocated address space. No equivalent proposal is 
> known to be under active consideration in any other RIR region.
>
>
> 4. Proposed policy solution
> -------------------------------------------------------
> It is proposed that APNIC policy be amended to include the following 
> principle, to be inserted into APNIC-127 at a location to be confirmed 
> through community discussion, noting that Section 5.3.3 (Registering Contact 
> Persons) is one likely location:
> Where address space is sub-allocated, assigned, or otherwise used by a 
> downstream organisation, the upstream holder responsible for the relevant 
> registry record must ensure that there is a reliable operational path from 
> the registered abuse or IRT contact to the party able to investigate and 
> resolve abuse reports for that address space.
> The upstream holder may meet this requirement through any of the following 
> arrangements:
> (a) the registered abuse or IRT contact is directly operated by
> the downstream organisation responsible for the address space;
>
> (b) the registered contact is a centralised function maintained
> by the upstream holder, provided that function has a reliable
> process for identifying the relevant downstream party and
> forwarding abuse reports to that party; or
>
> (c) another arrangement that ensures legitimate abuse reports
> reach the operationally responsible party without undue delay.
>
> Sub-allocating address space to a downstream organisation does not relieve 
> the upstream holder of responsibility for maintaining a reliable operational 
> path from the registered contact to the party able to act on abuse reports. 
> Where a downstream organisation takes responsibility for its own abuse 
> handling, the upstream holder must ensure that this is accurately reflected 
> in the relevant registry record.
> APNIC Secretariat will develop operational guidance on how this principle 
> applies across different sub-allocation tiers and organisational models. This 
> guidance will be developed in consultation with the community and will take 
> into account the operational diversity of sub-allocation arrangements in the 
> APNIC region.
> For clarity, this proposal does not require the public disclosure of all 
> downstream customer contact information. It does not prescribe one specific 
> operational model for abuse handling. It does not alter the existing IRT 
> validation requirement or the validation timelines under APNIC-127. And it 
> does not assign APNIC any new investigative or enforcement role beyond what 
> is already established under existing policy.
>
>
>
> 5. Advantages / Disadvantages
> -------------------------------------------------------
> Advantages:
> Advantages
> Closes a structural accountability gap that current policy does not address: 
> a validated abuse contact is only operationally useful if it can route 
> reports to the party able to act.
>
>
> Applies consistently across all sub-allocation tiers and organisational 
> models, without singling out any specific category of resource holder.
>
>
> Preserves operational flexibility. Upstream holders may continue using 
> centralised abuse handling arrangements, provided those arrangements are 
> genuinely effective.
>
>
> Builds directly on prop-125 and APNIC-127 without reopening the core 
> validation requirement, which has already been settled through community 
> consensus.
>
> Disadvantages:
>
> Disadvantages
> Upstream holders who sub-allocate address space may need to review their 
> current abuse handling arrangements and, in some cases, update registry 
> records or internal forwarding processes.
>
>
> Secretariat will need to invest in developing and maintaining operational 
> guidance across a range of sub-allocation models, which represents a moderate 
> administrative commitment.
>
>
> 6. Impact on resource holders
> -------------------------------------------------------
> If adopted, the direct impact on APNIC Secretariat would be moderate. The 
> Secretariat would be responsible for developing operational guidance on how 
> the principle applies across different sub-allocation tiers, in consultation 
> with the community. This would not require new systems or changes to the 
> Whois Database schema. It would require internal review of existing 
> operational processes for handling abuse reports relating to sub-allocated 
> address space, and engagement with the relevant upstream holders to support 
> the transition.
> For resource holders, the impact depends on their current arrangements. 
> Holders who already ensure that their sub-allocation registry records reflect 
> operationally responsible contacts are unlikely to need significant changes. 
> Holders who use centralised abuse contacts for sub-allocated address space 
> will need to confirm that those contacts have a reliable process for routing 
> reports to the downstream party able to act.
> This proposal introduces no new validation frequency, audit mechanism, or 
> compliance framework beyond the operational guidance Secretariat will develop 
> following adoption.
>
>
> 7. References
> -------------------------------------------------------
> prop-125-v001: Validation of "abuse-mailbox" and other IRT emails, 
> www.apnic.net/community/policy/proposals/prop-125/
>
>
> APNIC-127: APNIC Internet Number Resource Policies (current), 
> www.apnic.net/community/policy/resources
>
>
> Operational Policies for National Internet Registries in the APNIC region, 
> www.apnic.net/community/policy/operational-policies-nirs/
>
>
> APNIC, "Security at APNIC," www.apnic.net/community/security/
>
>
> LACNIC, Section 12: Registration and validation of "abuse-c" and 
> "abuse-mailbox," LACNIC Policy Manual, 
> www.lacnic.net/4419/2/lacnic/12-registration-and-validation-of-abuse-c-and-abuse-mailbox
>
>
> RIPE NCC, ripe-705: Abuse Contact Management in the RIPE NCC Database, 
> www.ripe.net/publications/docs/ripe-705
>
>
> ARIN, Number Resource Policy Manual, Section 3.6, 
> www.arin.net/participate/policy/nrpm/
>
>
> AFRINIC, AFPUB-2018-GEN-001: Abuse Contact Policy Update, 
> afrinic.net/policy/proposals/2018-gen-001-d8
>
>
> _______________________________________________
> SIG-policy - https://mailman.apnic.net/[email protected]/
> To unsubscribe send an email to [email protected]



-- 
--
Satoru Tsurumaki
BBIX, Inc
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]

Reply via email to