------------------------------------------------------- prop-171-v001: Operational Accountability for Abuse Contacts in Sub-Allocated Address Space ------------------------------------------------------- Proposer: Tsung-Yi Yu yio.cs13@nycu.edu.tw Alban Kwan alban.kwan@trustednotifier.network 1. Problem statement ------------------------------------------------------- APNIC-127 requires resource holders to register and maintain an IRT object for each resource record in the APNIC Whois Database, and requires that registered abuse contacts be validated as reachable at least once every six months. This validation requirement, introduced by prop-125, has improved the accuracy of contact registration data across the APNIC region. However, reachability is not the same as operational accountability. In sub-allocated address space, the party registered as the abuse contact is frequently not the party able to investigate or resolve the incident. The registered contact may belong to an upstream provider, a centralised administrative function, or another intermediary that receives the report but has no direct operational relationship with the network from which the abuse originates. As a result, abuse reports are sent to a valid and reachable contact, yet fail to reach the party responsible for acting on them. This leads to delayed responses, unnecessary forwarding, unclear accountability, and confusion for abuse reporters. This gap is not addressed by current APNIC policy. Prop-125 and APNIC-127 confirm that a contact is reachable; they say nothing about whether the contact is positioned to act. In multi-layer resource environments -- where address space passes through one or more intermediary tiers before reaching the network operator -- this distinction is material. Operational data indicates that a significant share of abuse reports received by APNIC relating to non-responsive or non-functional IRT contacts originate from sub-allocated address space, where the registered contact and the operationally responsible party are not the same. This proposal addresses that gap by establishing a clear principle: where address space is sub-allocated, the upstream holder bears responsibility for ensuring that abuse reports can reach the operationally responsible downstream party. 2. Objective of policy change ------------------------------------------------------- This proposal seeks to establish a principle of operational accountability for abuse contacts in sub-allocated address space. If adopted, APNIC policy would require that where address space is sub-allocated, assigned, or otherwise used by a downstream organisation, the upstream holder must ensure there is a reliable operational path from the registered abuse contact to the party responsible for handling abuse reports for that address space. This principle applies regardless of the sub-allocation tier or organisational model involved. It does not prescribe a single operational model for how abuse handling should be organised, nor does it require the public disclosure of all downstream contact information. The intent is to ensure that the registered contact is operationally meaningful, not merely reachable. This proposal does not alter the existing validation requirement under APNIC-127. It does not introduce a new audit or compliance mechanism. The operational guidance needed to implement this principle across different sub-allocation tiers will be developed by the APNIC Secretariat in consultation with the community. 3. Situation in other regions ------------------------------------------------------- No RIR has adopted policy that addresses operational accountability for abuse contacts in sub-allocated address space. The cross-regional picture on abuse contact requirements is as follows. RIPE NCC has required a mandatory, annually validated abuse-c for all resource records since 2018. The obligation is limited to contact reachability. RIPE NCC has stated explicitly that it has no say in what action is taken once a report is received, and does not address how contacts in sub-allocated space should relate to operational responsibility. LACNIC's abuse contact policy, in force since 2020, is the most developed of any RIR. It requires a valid, monitored abuse-mailbox validated at least twice yearly, and attaches revocation consequences to persistent non-compliance. Like RIPE NCC, however, it addresses contact reachability and monitoring obligations only. It does not establish any principle regarding operational accountability in sub-allocated environments. ARIN requires a registered Abuse Point of Contact, verified annually. It does not impose requirements on how abuse reports must be received or handled beyond contact reachability, and does not address sub-allocation accountability. AFRINIC's abuse contact policy, developed through multiple drafts since 2018, is modelled on the LACNIC and RIPE NCC approaches. Its own supporting documentation states explicitly that the policy does not define what abuse is, and the framework is similarly limited to contact registration and reachability. This proposal would make APNIC the first RIR to address the operational accountability gap in sub-allocated address space. No equivalent proposal is known to be under active consideration in any other RIR region. 4. Proposed policy solution ------------------------------------------------------- It is proposed that APNIC policy be amended to include the following principle, to be inserted into APNIC-127 at a location to be confirmed through community discussion, noting that Section 5.3.3 (Registering Contact Persons) is one likely location: Where address space is sub-allocated, assigned, or otherwise used by a downstream organisation, the upstream holder responsible for the relevant registry record must ensure that there is a reliable operational path from the registered abuse or IRT contact to the party able to investigate and resolve abuse reports for that address space. The upstream holder may meet this requirement through any of the following arrangements: (a) the registered abuse or IRT contact is directly operated by the downstream organisation responsible for the address space; (b) the registered contact is a centralised function maintained by the upstream holder, provided that function has a reliable process for identifying the relevant downstream party and forwarding abuse reports to that party; or (c) another arrangement that ensures legitimate abuse reports reach the operationally responsible party without undue delay. Sub-allocating address space to a downstream organisation does not relieve the upstream holder of responsibility for maintaining a reliable operational path from the registered contact to the party able to act on abuse reports. Where a downstream organisation takes responsibility for its own abuse handling, the upstream holder must ensure that this is accurately reflected in the relevant registry record. APNIC Secretariat will develop operational guidance on how this principle applies across different sub-allocation tiers and organisational models. This guidance will be developed in consultation with the community and will take into account the operational diversity of sub-allocation arrangements in the APNIC region. For clarity, this proposal does not require the public disclosure of all downstream customer contact information. It does not prescribe one specific operational model for abuse handling. It does not alter the existing IRT validation requirement or the validation timelines under APNIC-127. And it does not assign APNIC any new investigative or enforcement role beyond what is already established under existing policy. 5. Advantages / Disadvantages ------------------------------------------------------- Advantages: Advantages Closes a structural accountability gap that current policy does not address: a validated abuse contact is only operationally useful if it can route reports to the party able to act. Applies consistently across all sub-allocation tiers and organisational models, without singling out any specific category of resource holder. Preserves operational flexibility. Upstream holders may continue using centralised abuse handling arrangements, provided those arrangements are genuinely effective. Builds directly on prop-125 and APNIC-127 without reopening the core validation requirement, which has already been settled through community consensus. Disadvantages: Disadvantages Upstream holders who sub-allocate address space may need to review their current abuse handling arrangements and, in some cases, update registry records or internal forwarding processes. Secretariat will need to invest in developing and maintaining operational guidance across a range of sub-allocation models, which represents a moderate administrative commitment. 6. Impact on resource holders ------------------------------------------------------- If adopted, the direct impact on APNIC Secretariat would be moderate. The Secretariat would be responsible for developing operational guidance on how the principle applies across different sub-allocation tiers, in consultation with the community. This would not require new systems or changes to the Whois Database schema. It would require internal review of existing operational processes for handling abuse reports relating to sub-allocated address space, and engagement with the relevant upstream holders to support the transition. For resource holders, the impact depends on their current arrangements. Holders who already ensure that their sub-allocation registry records reflect operationally responsible contacts are unlikely to need significant changes. Holders who use centralised abuse contacts for sub-allocated address space will need to confirm that those contacts have a reliable process for routing reports to the downstream party able to act. This proposal introduces no new validation frequency, audit mechanism, or compliance framework beyond the operational guidance Secretariat will develop following adoption. 7. References ------------------------------------------------------- prop-125-v001: Validation of "abuse-mailbox" and other IRT emails, www.apnic.net/community/policy/proposals/prop-125/ APNIC-127: APNIC Internet Number Resource Policies (current), www.apnic.net/community/policy/resources Operational Policies for National Internet Registries in the APNIC region, www.apnic.net/community/policy/operational-policies-nirs/ APNIC, "Security at APNIC," www.apnic.net/community/security/ LACNIC, Section 12: Registration and validation of "abuse-c" and "abuse-mailbox," LACNIC Policy Manual, www.lacnic.net/4419/2/lacnic/12-registration-and-validation-of-abuse-c-and-abuse-mailbox RIPE NCC, ripe-705: Abuse Contact Management in the RIPE NCC Database, www.ripe.net/publications/docs/ripe-705 ARIN, Number Resource Policy Manual, Section 3.6, www.arin.net/participate/policy/nrpm/ AFRINIC, AFPUB-2018-GEN-001: Abuse Contact Policy Update, afrinic.net/policy/proposals/2018-gen-001-d8