Board Risk Committee (RC) – Minutes
RC Attendees: Steve Crocker, Bill Graham, Ram Mohan, Mike Silber – Chair, Jonne Soininen, Suzanne Woolf, and Kuo-Wei Wu
Other Board Member Attendees: Erika Mann, Bruce Tonkin
ICANN Executives and Staff Attendees: Francisco Arias (Director, Technical Services), Akram Atallah (President – Global Domains Division), Edward Beck (VP, Information Technology), Susanna Bennett (Chief Operating Officer), Megan Bishop (Board Support Coordinator), Michelle Bright (Board Support Manager), Xavier Calvez (Chief Financial Officer), John Jeffrey (General Counsel and Secretary), Patrick Jones (Global Stakeholder Engagement Senior Director), Jacks Khawaja (Enterprise Risk Director), Elizabeth Le (Senior Counsel), and Amy Stathos (Deputy General Counsel)
Apologies: Gonzalo Navarro
The following is a summary of discussion, actions taken, and actions identified:
DNS Risk Assessment Status Update – Staff provided an update on the DNS Risk Assessment. The RC discussed scope and methodology of the assessment and whether quality input is being received. The RC also discussed the timing of deliverables and next steps. It is anticipated that a strawman proposal will be published between the Singapore and London public meetings and a workshop to be held during the London meeting.
Enterprise Risk Management Status Update – Staff provided an update on the ERM status and the progress that the ERM Team has made toward identifying key enterprise risks, risk interactions, and risk mitigation efforts. The framework has been revised to align risk mitigation to key success factors (KSFs), key performance indicators (KPIs), and metrics. This will allow for the progress of each risk mitigation strategy to be measured and tracked. It is anticipated that the collection of KSFs, KPIs, and metrics will be completed by the end of March 2014. Staff provided an update on the timeline of the comparative analysis of past and current risk assessments.
IT Best Practices Review Update – Staff provided an update on the status of the IT best practices review. Some key items that have been accomplished include: the strategic plan; the development and implementation of skills based staffing strategy; a key systems rollout of the Salesforce.com core enterprise solution which allows for the management and tracking of several ongoing concurrent development projects; auditing of systems; and business continuity planning. The RC discussed building a matrix to identify DNS risks associated with the New gTLD Program.
New gTLD Risk Assessment – The RC received a report from staff regarding the status of New gTLD Program risk assessment efforts. The new risk assessment will be conducted in 2014 by an outside firm. The data from the previous assessment that was performed will be folded into consideration for the new assessment. It is anticipated that a vendor will be engaged in March 2014, and the goal is for the work to be completed by London in June 2014. The RC discussed how new gTLD risks are being evaluated by the New gTLD Program Committee and asked staff to prepare an analysis of how new gTLD risks should be addressed by the RC.
Action – Staff to prepare an analysis on how new gTLD risks should be addressed by the RC.
Name collision – Steve Crocker and Ram Mohan abstained from this discussion, noting conflicts. Staff presented the RC with a status update on name collision.
Published on 22 March 2014