您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [美国国家电信和信息管理局]:美国政府评论 - 发现报告

美国政府评论

报告封面

Mr. Peter Dengate-ThrushChairman of the Board of DirectorsInternet Corporation for Assigned Names and Numbers4676AdmiraltyWay,Suite330Marina del Rey, CA 90292-6601 Dear Chairman Dengate-Thrush: On February 12. 2010, the Internet Corporation for Assigned Names andNumbers (ICANN) posted for public comment a Strategic Initiatives paper that describestwo proposed activities related to Domain Name System (DNS) security, stability andresiliency as well as an accompanying Global DNS-CERT Business Case. Given theimportance of the Internet as a global medium to support economic growth andinnovation, continuing to preserve the security and stability of the DNs remains a toppriority for the National Telecommunications and Information Administration (NTIA)We therefore appreciate this opportunity to offer the views of the U.S. government onthese proposals. Preserving the stability and security of the Internet DNS is a shared responsibilityamong all actors in the DNS arena and NTIA thanks ICANN for initiating a publicdiscussion on such an important issue and developing strawman proposals to generatecommunity discussion about DNS security and stability. We believe that further data-gathering and community input is needed, including consideration of budgetaryrequirements, before these proposals can be considered for implementation. With respect to the specific Initiative 1"System-wide DNS Risk Analysis,Contingency Planning and Exercises", while NTIA appreciates ICANN's efforts toidentify the full range of risks to the operation of the DNS, the proposal does not providesuficient data to support the proposed initiative. As a first step, we urge ICANN to workwith all relevant stakeholders in developing a thorough gap analysis to permit thecommunity to more effectively evaluate this proposed effort and subsequently todeterminethebestpath forward. In general, NTIA believes the concept of a DNS CERT has merit and deservesserious and thoughtful consideration. As the Internet matures, the need will increase formore effective mechanisms to enable the operators of the Internet's distributedinfrastructure to work together to manage an incident affecting the DNs. However, wedo not believe sufficient information is available on which to form an informed opinionof the specific proposal as described in Initiative 2 *DNS-CERT" and the accompanying"Global DNS-CERT Business Case". In addition to the substantive concerns with theproposal, global experience with CERTs has shown that their effectiveness and successare dependent upon the support and active participation of all the relevant stakeholders. NTIA therefore views it as vital that ICANN consult fully with these criticalstakeholders. NTIA also seeks to understand in more detail how this proposed effortwould take into consideration and avoid duplication of existing activities such as theDNS Operations, Analysis, and Research Center (DNS-OARC) and national CERTs. Inaddition, the NTIA believes that ICANN needs to develop a more complete record withrespect to the threats to, and vulnerabilities of, the DNS that the proposed DNS-CERTcapability would help to mitigate. While ICANN management has made somepreliminary assertions concerning these issues, the response from some members of thecommunity, most recently at ICANN's 37th Annual Meeting in Nairobi, seem to suggestthat a more complete risk assessment and gap analysis is needed. Finally, NTIA does notsupport any operational role by ICANN in the management of this capability, as webelieve that such a role would be inconsistent with ICANN's core functions and mightcreate conflicts of interest that would undermine the effectiveness and credibility of aDNS-CERT Lastly,given the prominent reference of the Affirmation of Commitments in thedescription of the two initiatives,NTIA believes it importanttomake clearthat nothingtherein mandates these two particular initiatives or implies any particular role for ICANNin connection therewith. Any activity that ICANN undertakes in this area should beconsistentwith its roleas atechnical coordinator oftheDNS.NTIA believes that thesecurity and stability of the DNS will continte to depend on broad-based, activeengagement of all parties involved in the operations of the DNS. We therefore havereached out to key stakeholders to encourage a cross-industry led solution. We lookforward to continuing the dialogue on this important subject.