# Recurring domain-governance review

Use this agenda inside an existing technology, cyber, risk, supplier, continuity or service-governance forum. The purpose is to review change, uncertainty, exceptions and decisions - not to reproduce every source register.

## Review details

- Forum:
- Review date:
- Accountable review owner:
- Chair or decision owner:
- Participants:
- Evidence cut-off date:
- Previous review date:
- Next review date:
- Related committee, risk or service record:

## Pre-read and evidence sources

Confirm the current location or extract date for:

- domain register;
- registrar and DNS authority record;
- authorised-sender register;
- renewal horizon;
- recent material DNS and email changes;
- privileged-access and recovery review;
- domain-layer incidents and near misses;
- incident exercise record;
- material supplier changes;
- relevant public domain, DNS and email observations;
- open domain-governance actions and accepted exceptions.

## 1. Changes since the previous review

Discuss only changes that affect authority, continuity, ownership, public identity or trusted communication.

- New domains or material subdomains:
- Domains retired, redirected or proposed for retirement:
- Ownership or renewal responsibility changes:
- Registrar, reseller, DNS or hosting changes:
- Privileged administrator, service account or recovery changes:
- New, changed or removed email senders:
- Material SPF, DKIM, DMARC or public-signal changes:
- New digital services, campaigns, acquisitions or supplier arrangements:

## 2. Upcoming decisions and deadlines

- Domains renewing before the next review:
- Planned domain retirements or transfers:
- Provider migrations or contract decisions:
- Major DNS, email, identity or platform changes:
- Product, campaign, brand or service launches:
- Expiring temporary senders, access exceptions or risk acceptances:
- Scheduled incident exercise or recovery test:

## 3. Unknowns and exceptions

Review items that remain unclear, partial, unowned or dependent on exception.

| Unknown or exception | Domain or boundary | Owner | Current rationale | Expiry or decision date | Required outcome |
| --- | --- | --- | --- | --- | --- |
|  |  |  |  |  |  |

Prompts:

- Domains with unknown purpose, owner, provider, renewal responsibility or email use.
- Shared, personal or supplier-only privileged access.
- Missing MFA, recovery path or known-good DNS evidence.
- Unowned or obsolete email authority.
- Permissive or unexplained public mail posture.
- Untested incident and provider recovery arrangements.
- Accepted risk or temporary controls without a reconsideration date.

## 4. Incidents, near misses and exercises

- Domain-layer incidents since the last review:
- Near misses or unexplained public changes:
- Exercise completed and scenario:
- Provider or recovery limitations discovered:
- Changes required to registers, runbooks or supplier arrangements:
- Material lessons requiring wider escalation:

## 5. Public evidence and external context

Use public observation as supporting evidence, not as a score or substitute for internal records.

- Material registration or nameserver changes observed:
- Material DNS or DNSSEC changes observed:
- Material SPF, DKIM, DMARC or mail-provider changes observed:
- DMARC aggregate-report themes requiring action:
- Relevant repeated or sector context from .au Domain Observatory (.auDO):
- Relevant point-in-time checks from ThreatScope Check:
- Differences between expected internal authority and observed public state:

## 6. Overdue actions

| Action | Owner | Original due date | Current status | Decision required |
| --- | --- | --- | --- | --- |
|  |  |  |  |  |

For each overdue item decide whether to:

- complete;
- revise the scope or due date;
- escalate;
- accept with rationale and reconsideration date; or
- close because the requirement no longer applies.

## 7. Decisions and new actions

| Decision or action | Outcome type | Accountable owner | Action owner | Due date | Destination record | Completion evidence |
| --- | --- | --- | --- | --- | --- | --- |
|  |  |  |  |  |  |  |

Suggested outcome types:

- investigate;
- remediate;
- retain;
- retire;
- test;
- accept;
- escalate;
- close.

## 8. Record updates and escalation

- Domain register updates required:
- Registrar and DNS authority-record updates required:
- Authorised-sender register updates required:
- Incident runbook or exercise updates required:
- Supplier, contract or assurance records to update:
- Risk, change, project or architecture records to update:
- Executive, committee or board escalation required:
- Accountable person confirming updates are complete:

## 9. Close

- Decisions confirmed by:
- Action log updated:
- Next review date:
- Next evidence cut-off:
- Focus topic for next review, if any:
- Minutes or decision record location:

## Boundary

This agenda supports recurring domain governance through an existing forum. It is not a maturity assessment, scorecard, compliance report or substitute for the authoritative registers and organisational records reviewed through it.