Summary

  • APNIC Blog reported on 14 September that four research-and-education-network leaders had signed the Auckland Declaration of Intent on Cyber Resilience during APAN62 in August.
  • The public announcement promises trust-building, preparedness, information sharing, incident coordination and mutual support, but expressly leaves action subject to national law and institutional policy.
  • The checked public pages do not carry the declaration itself or identify a request channel, decision owner, response clock, data boundary or exercise record. A two-layer coordination card could expose the authority path without exposing sensitive playbooks.

The most consequential words in the public account of the Auckland Declaration are not “mutual support.” They are “where national laws and institutional policies allow.”

That qualification is not a defect. Research and education networks operate across jurisdictions, public institutions and autonomous organisations. A regional partner cannot make a university disclose incident data, order another network to isolate a route or override a national reporting duty merely because four leaders signed a common statement. The clause preserves the authority that each participant already holds.

It also creates the declaration's first operational question. When an incident arrives, who determines what the law and policy allow?

The APNIC Blog report, published on 14 September, says the declaration was signed during APAN62 in Auckland. It names Amber McEwen of REANNZ, Shinji Shimojo of APAN, Jungsu Song of TEIN*CC and Roshan G. Ragel, who signed on behalf of the APAN/Asi@Connect Leaders Forum. It says they will work on trust, preparedness, information sharing, incident coordination and mutual support. It also says they will explore a regional chapter of the Global Security Policy Alliance, or a similar structure, while maintaining local priorities and autonomy.

Those are meaningful commitments. They can justify building relationships before a crisis rather than looking for introductions while systems are failing. But the checked public pages do not link the declaration text. They do not show which legal entity each signature binds, whether other APAN or Asi@Connect members are covered, how a new participant joins, or when the arrangement is reviewed. Nor do they give an incident address, authenticated channel, operating hours, acknowledgement target, severity rule or decision owner.

These details may exist in the signed document or in private operating material. Their absence from the public record is not evidence that the participants are unprepared. It means an outside member cannot yet use the public record to understand the path from a regional promise to an authorized local act.

One network problem, several kinds of authority

APAN describes itself in two ways: an association representing members and a backbone joining research and education networks across the region. REANNZ is both a membership organisation and a Crown-owned company governed by a board appointed through New Zealand's ministerial structure. Universities, research bodies, national networks, regional forums and incident teams therefore enter the cooperation with different constituencies and mandates.

That diversity is the point of the network. It is also why “coordinate” cannot be one undivided state.

An affected institution can report what it sees. Its national network can validate path or service effects. A regional forum can locate peers, compare observations and convene a call. A partner can offer expertise or capacity. Only the relevant system owner can normally approve a configuration change, preserve local evidence or accept operational risk. A statutory notice may belong to yet another body. None of those acts becomes interchangeable because the organisations trust one another.

A useful record would therefore distinguish at least eight states: received, authenticated, scoped, shareable, accepted, delegated, acted on and closed. It also needs honest branches for declined, referred and awaiting permission.

Without those states, an email acknowledgement can look like accepted assistance. A participant on a coordination call can be mistaken for the person authorized to change a network. A forwarded indicator can lose the restriction that travelled with it. A partner can appear unresponsive when it was legally unable to receive the requested data. The declaration's value depends on making those differences easier to navigate, not erasing them.

A label can control sharing without authorizing action

FIRST's Traffic Light Protocol offers a compact vocabulary for onward disclosure. TLP:RED, TLP:AMBER, TLP:GREEN and TLP:CLEAR tell recipients how far information may travel. The labels are useful in a region where one incident may touch universities, network operators, vendors and public authorities.

But a TLP label answers only part of the question. It does not prove that the sender was entitled to disclose the data, that the recipient has a lawful basis to store it, that a manager approved an intervention, or that the receiving team has capacity to act. TLP:AMBER can accompany a technically important indicator and still leave the requested action unauthorized. TLP:CLEAR can permit broad distribution while saying nothing about whether the observation is correct.

The incident record should keep four decisions separate: may the sender disclose; may the recipient receive; may the recipient act; and did the responsible operator accept the action? One colour should not be made to carry all four.

An old CSIRT template shows how little needs to be public

RFC 2350 has described expectations for computer-security incident response teams since 1998. Its age is useful here. Long before today's collaboration platforms, it separated a team's constituency from its authority and asked teams to disclose how they can be contacted, their operating hours, the incident types and support levels they handle, their cooperation and disclosure policy, and their secure-communication methods.

RFC 2350 does not govern the Auckland Declaration. The signatories have not announced that they are adopting it. Its lesson is narrower: a public operating shell need not reveal an investigation playbook.

A constituency can learn where to report, what response to expect and which organisation controls the next decision. Private material can hold names, telephone trees, cryptographic keys, infrastructure diagrams and legal advice. Public transparency and operational secrecy are not opposites if the boundary between them is explicit.

Publish a two-layer coordination card

The public layer should identify the declaration's current signatories and the constituency each one represents. It should state whether the signature binds a legal entity, a forum or only the named office; give the authoritative route for requesting coordination; name the role that accepts, declines or refers a request; and publish review, accession and withdrawal dates.

It should also expose state, not incident content. A member should be able to see that a request was authenticated, that a permission decision is pending, that assistance was accepted or declined, that a local operator owns the act, and that the case closed. Aggregate counts and exercise records can show whether the arrangement is being used without identifying affected institutions.

The protected layer can hold the sensitive machinery: verified contacts, keys, time zones, incident thresholds, data fields, TLP handling, national restrictions, vendor dependencies, escalation trees and fallback channels. Each item needs an owner and a last-tested date. During an incident, the card should generate a receipt that preserves who requested what, which data boundary applied, who decided, what authority supported the decision and where responsibility moved next.

This is not a demand for a regional command centre. A coordinator can route and record without taking control from a member. Nor is it evidence that the declaration has failed. The announcement arrived only now, and a regional chapter remains an option to explore.

The test is simpler. If an APAN member reads the declaration after detecting a cross-border incident, can it identify the first valid request, the first accountable decision and the boundary beyond which the regional promise cannot act? The public record does not yet provide that route.

Sources