Information Security, Risk and Complience Quarterly Planning
We have three objectives in publishing our quarterly planning:
- We want to be transparent about the work we are doing
- We want your input on that work and our planning, and we want to document that input and let you know if and when we can add your suggestions to our planning
- We want an open dialogue with members and community on developments around Information Security, Risk and Compliance
We launched this initiative in Q2 2022, and we are open to improving what we publish here and how we do that. So let us know if there are ways we can better present our plans. In Q1 2023, we separated the work items of Information Security, Risk and Compliance from the Information Technology and added them to this area.
We will update this page as our activities progress and continue to share updates on RIPE Labs, on the RIPE NCC Membership Discussion and RIPE NCC Services Working Group (WG) mailing lists, and at RIPE Meetings and other events.
Q3 2025 Plans
Last updated: 24 June 2025
Item 1: Ensure Adherence to Regulatory and Security Industry Standards
In 2024, we completed the ISAE 3000 / SOC2 Type I RPKI audit and received the final assurance report. In Q2 2025 we completed our preparation efforts for the RPKI ISAE 3000 / SOC2 Type II audit and initiated the audit activities. The execution of the audit activities will continue in Q3 and Q4 2025.
We continue to work on establishing compliance with the ISO 27001 standard. In Q3 we will continue focusing on increasing our business continuity readiness and formalising our data governance. We will also continue to invest in optimising our controls for secure software development.
In Q2 2025 we launched the RIPE NCC Trust Portal at trust.ripe.net to provide greater transparency into our operations and to help members and stakeholders better understand how we manage our security, compliance, and governance. The portal provides a comprehensive overview of how we protect the confidentiality, integrity, and availability of the services we operate on behalf of our members and the RIPE community. For law enforcement and other competent authorities, the Trust Portal also provides guidance on how to request information from the RIPE NCC, and links to other useful supporting information.
Status: In progress
Item 2: Secure System Security and Resiliency
In Q2 2025, we continued our vulnerability remediation efforts, by refining our policies and procedures and expanding our reporting capabilities. We also initiated our to enhance the security posture of our container orchestration platform and container management. These initiatives will continue in Q3 2025.
Status: In progress
Item 3: Elevate Organisational Risk Resilience
In Q3 2025, we will continue to monitor the timely execution of the treatment plans and the refinement of the Enterprise Risk Management framework based on gathered internal input. In Q3 we are also kicking off the execution of the yearly risk assessments.
From a tooling perspective, we are proceeding with the tooling selection process for a Governance, Risk and Compliance tool.
Status: In progress
Item 4: Strengthen Detection and Response
In Q3 2025, we will continue enhancing the scope and coverage of our security monitoring capabilities. Furthermore, we will evaluate various approaches to implementing 24/7 security alert monitoring to ensure comprehensive and continuous protection.
Status: In progress
Item 5: Enhance Team Efficiency and Capabilities
In Q2 2025, we streamlined our workflows for security reviews. In Q3 2025, we will continue to standardise our documentation and processes and establish specialised training paths for the Information Security team.
Status: In progress
Community Input on Planning
We want the community to contribute to our plans and suggest additional work items. Please share your comments with us or post them on the RIPE NCC Membership Discussion and RIPE NCC Services WG mailing lists. We'll also be monitoring all the other channels where people talk about these services.
When we receive feedback that can significantly impact our planning or that needs a further response, we will add it to the table below.
Archived Quarterly Plans
You can find our plans from the previous quarters on this page. The Q3 2025 plans will be archived once we publish the Q4 2025 planning.