<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE rfc SYSTEM "rfc2629.dtd" [
<!ENTITY RFC2026 SYSTEM "http://xml.resource.org/public/rfc/bibxml/reference.RFC.2026.xml">
<!ENTITY RFC2418 SYSTEM "http://xml.resource.org/public/rfc/bibxml/reference.RFC.2418.xml">
<!ENTITY RFC3184 SYSTEM "http://xml.resource.org/public/rfc/bibxml/reference.RFC.3184.xml">
<!ENTITY RFC3934 SYSTEM "http://xml.resource.org/public/rfc/bibxml/reference.RFC.3934.xml">
<!ENTITY RFC7154 SYSTEM "http://xml.resource.org/public/rfc/bibxml/reference.RFC.7154.xml">
]>
<?xml-stylesheet type="text/xsl" href="http://xml.resource.org/authoring/rfc2629.xslt" ?>
<?rfc strict="yes" ?>
<?rfc toc="yes"?>
<?rfc tocdepth="4"?>
<?rfc symrefs="yes"?>
<?rfc sortrefs="yes" ?>
<?rfc compact="yes" ?>
<?rfc subcompact="no" ?>
<?rfc comments="yes" ?>
<?rfc inline="yes" ?>
<rfc category="bcp" seriesNo="25" docName="draft-farrresnickel-harassment-02" ipr="trust200902" updates="2418">
    <front>
        <title abbrev="Anti-Harassment Procedures">IETF Anti-Harassment Procedures</title>
        <author fullname="Pete Resnick" initials="P."
                surname="Resnick">
            <organization>Qualcomm Technologies, Inc.</organization>

            <address>
                <postal>
                    <street>5775 Morehouse Drive</street>
                    <city>San Diego</city>
                    <region>CA</region>
                    <country>US</country>
                    <code>92121</code>
                </postal>
                <phone>+1 858 6511 4478</phone>
                <email>presnick@qti.qualcomm.com</email>
            </address>
        </author>
        <author fullname="Adrian Farrel" initials="A."
                surname="Farrel">
            <organization>Juniper Networks</organization>

            <address>
                <email>adrian@olddog.co.uk</email>
            </address>
        </author>

        <date />

        <area>General</area>
        <workgroup>Internet Engineering Task Force</workgroup>

        <keyword></keyword>

        <abstract>
            <t>IETF participants must not engage in harassment while at IETF meetings, virtual meetings, social events, or on mailing lists.  This document lays out procedures for managing and enforcing this policy.</t>
            <t>This version of this document is provided as a continued point for discussion and does not represent the firm opinions of the authors.  Furthermore, the ideas presented in this document have not been fully discussed and reviewed by the IESG.</t>
        </abstract>
    </front>

    <middle>
        <section anchor="intro" title="Introduction">
            <t>The IETF has general policies for managing disruptive behavior in the context of IETF activities.  In particular, <xref target="RFC7154" /> provides a set of guidelines for personal interaction in the IETF, and <xref target="RFC2418" /> and <xref target="RFC3934" /> give guidelines for how to deal with disruptive behavior that occurs in the context of IETF working group face-to-face meetings and on mailing lists.</t>
            <t>However, there is other problematic, often more interpersonal, behavior that can occur in the context of IETF activities (meetings, mailing list discussions, or social events) that does not directly disrupt working group progress, but nonetheless is unacceptable behavior between IETF participants.  This sort of behavior, described in the <eref target="http://www.ietf.org/iesg/statement/ietf-anti-harassment-policy.html">IESG Statement on an "IETF Anti-Harassment Policy"</eref>, is not easily dealt with by our previously existing working group guidelines and procedures. Therefore, this document sets forth procedures to deal with such harassing behavior.  These procedures are intended to be used when other IETF policies and procedures do not apply or have been ineffective.</t>
            <t>Nothing in this document should be taken to interfere with the due process of law for the legal system under the jurisdiction of which any harassment takes place.  Similarly, it does not release any person from any contractual or corporate policies to which they may be subject.</t>
        </section>

        <section anchor="definitions" title="Definitions">
            <t>The following terms are used in this document:
                <list>
                    <t>Reporter: An IETF participant who reports potential harassment to an Ombudsperson.</t>
                    <t>Respondent: An IETF participant who is claimed to have engaged in harassing behavior.</t>
                    <t>Ombudsteam: A group of people who have been selected to take reports of potential harassement, evaluate them, and impose  appropriate actions and/or remedies to address the circumstance.</t>
                    <t>Ombudsperson: A member of the Ombudsteam.</t>
                    <t>Lead Ombudsperson: The Ombudsperson assigned to be the primary contact person for a particular report of potential harassment.</t>
                    <t>Subject: An individual, group, or class of IETF participant to whom the potentially harassing behavior was directed or who might be subject to the behavior.</t>
                </list>
            </t>
            <t>The IESG statement on harassment <eref target="http://www.ietf.org/iesg/statement/ietf-anti-harassment-policy.html" /> defines harassment as "unwelcome hostile or intimidating behavior, in particular speech and behavior that is sexually aggressive or intimidates based on attributes like race, gender, religion, age, color, national origin, ancestry, disability, sexual orientation, or gender identity."  This document adopts that definition and does not attempt to further precisely define behavior that falls under the set of procedures identified here except to note that it may be targeted at an individual, directed at a specific group of people, or more generally impacting a broader class of people.  In general, disruptive behavior that occurs in the context of an IETF general or working group mailing list, or happens in a face-to-face or virtual meeting of a working group or the IETF plenary, can be dealt with by our normal procedures, whereas harassing behavior that is interpersonal is more easily handled by the procedures described here. However, there are plausible reasons to address behaviors that take place during working-group meetings using these procedures. This document gives some guidance to those involved in these situations in order to decide how to handle particular incidents, but the final decision will involve judgment and the guidance of the Ombudsteam.</t>
        </section>

        <section anchor="ombudsteam" title="The Ombudsteam">
            <t>This section describes the role of the Ombudsteam in terms of the appointment of Ombudspersons, their qualifications and training, the length of the term of service, any recompense for their service, and how they may be removed from service.  The general operational procedures for the Ombudsteam are described in <xref target="handling" />, <xref target="remedies" />, and <xref target="appeals" />.</t>

            <section anchor="size" title="Size of the Ombudsteam">
                <t>The Ombudsteam shall comprise no fewer than three people.  From time to time, the size may fall below that number owing to changes in membership, but the team will be rapidly brought up to size through new appointments.  The team may be grown to a larger size as described in <xref target="appointment" /></t>
            </section>

            <section anchor="appointment" title="Appointing the Ombudsteam">
                <t>The Ombudsteam is appointed by the IETF Chair.  The appointment is solely the responsibility of the IETF Chair although the Chair may choose to consult with the IESG, the IAB, and with the ISOC Board of Trustees.  Furthermore, the IETF Chair may take opinion from the community.</t>
                <t>The IETF Chair is encouraged to appoint at least some of the Ombudsteam from within the IETF community.</t>
                <t>The IETF Chair may choose to solicit nominations or advertise the post.  This is entirely at the discretion of the IETF Chair.</t>
                <t>The IETF Chair is also free to decide to appoint more than three Ombudspersons to the Ombudsteam.  This may depend on the skillsets available, the work load, and the opinions of the seated Ombudsteam.  Furthermore, the IETF Chair may consider elements of diversity in making this decision.</t>
            </section>

            <section anchor="advisors" title="Professional Advisors">
                <t>It is recognized that the Ombudsteam may need to call on professional services from external advisors for certain matters including legal and Human Resources (HR) advice.  The IETF is committed to funding such advice on an "as needed" basis.</t>
            </section>

            <section anchor="qualifications" title="Qualifications and Training">
                <t>It is not expected that there will be candidates with all of the necessary ombudsperson skills and training who also have a clear understanding and familiarity with the IETF processes and culture.  The Chair might choose someone with a great deal of professional experience evaluating and mediating harassment disputes, but little exposure to the IETF, or could select someone with more exposure to the IETF community, but without as much experience dealing with issues of harassment.  Since all of these attributes may be regarded by the IETF Chair as essential for an appointment, the IETF is committed to provide funding for necessary training for appointed Ombudspersons.  In determining the appropriate training, the IETF chair and Ombudsteam shall take professional advice.</t>
            </section>

            <section anchor="term" title="Term of Service">
                <t>An Ombudsperson shall be appointed for a two year term.  That is, the Ombudsperson is making a commitment to serve for two years.  It is understood, however, that circumstances may lead an Ombudsperson to resign for personal or other reasons.  See also <xref target="removal" />.</t>
                <t>It is entirely at the discretion of the IETF Chair whether a serving Ombudsperson is reappointed at the end of their term.</t>
            </section>

            <section anchor="recompense" title="Recompense">
                <t>An Ombudsperson shall receive no recompense for their services.  This includes, but is not limited to:
                    <list>
                        <t>IETF meeting fees</t>
                        <t>Remuneration for time spent</t>
                        <t>Out-of-pocket expenses (such as telephone charges)</t>
                        <t>Travel or accommodation expenses</t>
                    </list>
                </t>
                <t>The IETF will, however, meet the costs of training when agreed to by the IETF Chair as described in <xref target="qualifications" />.</t>
            </section>

            <section anchor="removal" title="Removal">
                <t>The IETF Chair may remove a serving Ombudsperson before the end of their term without explanation to the community.  Such an action shall be appealable as described in <xref target="appeals" />.</t>
                <t>An Ombudsperson shall not be removed from service, even if their term has expired, if the IETF Chair is recused as described in <xref target="conflict" />.</t>
            </section>

            <section anchor="chair-appeals" title="Disputes with the IETF Chair regarding the Ombudsperson">
                <t>If an individual should disagree with an action taken by the IETF Chair regarding the appointment, removal, or management of the Ombudsperson, that person should first discuss the issue with the IETF Chair directly.  If the IETF Chair is unable to resolve the issue, the dissatisfied party may appeal to the IESG as a whole.  The IESG shall then review the situation and attempt to resolve it in a manner of its own choosing.  The procedures of Section 6.5.4 of <xref target="RFC2026" /> apply to this sort of appeal.</t>
            </section>
        </section>

        <section anchor="handling" title="Handling Reports of Harassment">
            <t>Any IETF participant who believes that they or other IETF participants have been harassed or may have been harassed may bring the concern to the attention of any serving Ombudsperson.  This can be done by email to <eref target="mailto:ombudsteam@ietf.org">"ombudsteam@ietf.org"</eref>, or can be done directly to a chosen Ombudsperson.  Direct contact information for the Ombudsteam, including the email addresses to which "ombudsteam@ietf.org" is forwarded, can be found at <eref target="https://www.ietf.org/ombudsteam">https://www.ietf.org/ombudsteam</eref>.</t>
            <t>When a Reporter brings an incident of potential harassment to the attention of the Ombudsteam, a single Ombudsperson shall be designated as the primary contact person (the Lead Ombudsperson) for the report.  When the Reporter contacts a single Ombudsperson, that Ombudsperson shall be the Lead Ombudsperson for the report unless mutually agreed between the Reporter and that Ombudsperson.</t>
            <t>The Lead Ombudsperson may share any information regarding the report with the rest of the Ombudsteam except when an Ombudsperson is recused (see <xref target="conflict" />).  If a Reporter believes that a member of the Ombudsteam should recuse, they should make this known to the Lead Ombudsperson as soon as possible.</t>
			<t>The Lead Ombudsperson will discuss the events with the Reporter and may give advice including recommendations on how the Reporter can handle the issue on their own as well as strategies on how to prevent the issue from arising again.  The Lead Ombudsperson may also indicate that the issue would be best handled using regular IETF procedures (such as those for dealing with disruptive behavior) outside the context of harassment, and in this case the Lead Ombudsperson will provide assistance in using the relevant IETF procedures.  Otherwise, with agreement to proceed from the Subject (or the Reporter if there is no individual Subject), the Ombudsteam may initiate detailed investigation of the matter, and may subsequently impose a remedy as described in <xref target="remedies" />.</t>
			
            <section anchor="operating" title="Ombudsteam Operating Practices">
                <t>The Ombudsteam is responsible for devising and documenting their operating practices.  These practices must be discussed with the IESG and published in a publicly visible place (such as on the IETF web site).  Discussion with the IETF community is encouraged and, while IETF consensus is not necessary, significant objection to the processes that are not addressed should result in an RFC 2026 Section 6.5.3 appeal and/or a recall petition against the IETF Chair (and the rest of the IESG if appropriate) if they do not address the concern.</t>
                <t>The practices must include at least the following high-level components:
                    <list>
                        <t>Each member of the Ombudsteam is expected to be present at the majority of IETF meetings and to be available for face-to-face discussions.  The Ombudsteam is expected to arrange itself so that there is coverage of every IETF meeting by at least one Ombudsperson.</t>
                        <t>All information brought to the Ombudsteam shall be kept in strict confidence.  Any electronic information (such as email messages) that needs to be archived shall be encrypted before it is stored using tools similar to those used by NomCom.</t>                        
                        <t>When conducting a detailed investigation of the circumstances regarding the complaint of harassment, the Ombudsteam may contact the Respondent and request a meeting in person or by a voice call.  The Respondent is not obliged to cooperate, but the Ombudsteam may consider failure to cooperate when determining a remedy (<xref target="remedies" />).</t>
                        <t>The Ombudsteam shall endeavor to complete its investigation in a timely manner.</t>
                        <t>Any individuals who make a good faith report of harassment or who cooperate with an investigation shall not be subject to retaliation for reporting, complaining, or cooperating, even if the investigation, once completed, shows no harassment occurred.  Anti-retaliation is noted here to alleviate concerns individuals may have with reference to reporting an incident they feel should be reviewed.</t>
                        <t>In all cases the Ombudsteam will strive to maintain confidentiality for all parties including the very fact of contact with the Ombudsteam.</t>
                    </list>
                </t>
                <t> When investigating reports and determining remedies, it is up to the Ombudsteam whether they choose to act as a body or delegate duties to the Lead Ombudsperson.</t>
            </section>

        </section>

        <section anchor="remedies" title="Remedies">
            <t>After examining the circumstances regarding the complaint of harassment the Ombudsteam should prepare a brief summary of the incident and their conclusions and discuss this with all parties.  The objective of this step is to make clear what the Ombudsteam has concluded, and to make an attempt at getting all parties to reach agreement.</t>
            <t>If the Ombudsteam determines that harassment has taken place, the Ombudsteam is expected to determine the next action.
                <list>
                    <t>In some cases a mechanism or established IETF process may already exist for handling the specific event.  In these cases the Ombudsteam may decide that the misbehavior is best handled with the regular IETF procedures for dealing with disruptive behavior and may assist the Reporter to bring the issue to the attention of the working group chair or IESG member who can deal with the incident.</t>
                    <t>In other cases there is a spectrum of remedies that may be appropriate to the circumstances.  At one end of the spectrum, the Ombudsteam might choose to discuss the situation with the Respondent and come up with a plan such that there is no repeat of the harassment.  With the agreement of both parties, the Ombudsteam can also help to mediate a conversation between the Respondent and the Subject (or the Reporter if there is no individual Subject) in order to address the issue.</t>
                    <t>At the other end of the spectrum the Ombudsteam could decide that the Respondent is no longer permitted to participate in a particular IETF activity (for example, ejecting them from a meeting or requiring that the Respondent can no longer attend future meetings.</t>
                    <t>In determining the appropriate remedy, the Ombudsteam may communicate with the Reporter, Subject, or Respondent in order to assess the impact that the imposition of a remedy might have on any of those parties. However, the Ombudsteam has ultimate responsibility for the choice of remedy.</t>
                    <t>In all cases, the Lead Ombudsperson informs the Respondent of the decision and imposes the remedy as appropriate.  In cases where the remedy is removal from IETF activities, the Lead Ombudsperson will confidentially notify the Secretariat of the remedy such that the Secretariat can take whatever logistical actions are required to effect the remedy.  Only the remedy itself shall be disclosed to the Secretariat, not any information regarding the nature of the harassment.</t>
                </list>
            </t>

            <section anchor="punishment" title="Remedy is Not Punishment">
                <t>It is understood that the purpose of a remedy is not punishment.  That is, the remedy is imposed in order to rectify the situation (to "put things right"), to try to make sure that the incident does not escalate, and to ensure that a similar situation is unlikely to occur with the same Respondent in the future.</t>
                <t>A remedy is not to be imposed for the purposes of retribution or as a deterrent to others.  It is also not intended to teach the community how to behave - there is RFC 7154 for that.  The Ombudsteam are expected to apply considerations of proportionality and reasonableness in selecting a remedy, and are asked to consider the impact of the remedy on the Respondent as well as on the Subject.</t>
            </section>

        </section>

        <section anchor="appeals" title="Disputes with the Ombudsteam">
            <t>If either the Subject (or the Reporter if there is no individual Subject) or the Respondent is dissatisfied with the decision of the Ombudsteam, the dissatisfied party should first contact the Lead Ombudsperson and discuss the situation. If the issue cannot be resolved through discussion with the Lead Ombudsperson, the issue may be raised with the IETF Chair.</t>
            <t>If necessary, the IETF Chair may recuse themself from any part of this process (see <xref target="conflict" />) and request the IESG to select another of its members to serve in this role.</t>
            <t>The IETF Chair (or the delegated IESG member if the Chair is recused) will attempt to resolve the issue in discussion with the dissatisfied party and the Lead Ombudsperson.  If this further discussion does not bring a satisfactory resolution, the Ombudsteam's decision may be formally appealed.  The appeal is strictly on the issue of whether the Ombudsteam exercised due diligence in both their decision as to whether harassment had taken place, as well as in their determination of any appropriate remedy that was imposed.  In particular, the purpose of the appeal is not to re-investigate the circumstances of the incident or to negotiate the severity of the remedy.</t>
            <t>All elements of the appeal, including the fact of the appeal, will be held in confidence, but will be recorded and held securely for future reference.</t>
            <t>The appeal will be evaluated by the IETF Chair  (or the delegated IESG member) and two other members of the IESG selected by the IETF Chair  (or the delegated IESG member) and confirmed by the appellant.  This Appeals Group shall convene as quickly as possible to evaluate and determine the appeal.  Where the impacts are immediate and related to participation in an ongoing meeting, this shall happen in no more than 24 hours after receiving the appeal. The Appeals Group may ask the appellant and the Lead Ombudsperson for statements or other information to consider.  If the Appeals Group concludes that due diligence was exercised by the Ombudsteam, this shall be reported to the appellant and the matter is concluded.  If the Appeals Group finds that due diligence was not exercised, the Appeals Group shall report this to the Ombudsteam, and consult with the Ombudsteam on how to complete the due diligence.</t>
            <t>Because of the need to keep the information regarding these matters as confidential as possible, the Appeals Group's decision is final with respect to the question of whether the Ombudsteam has used due diligence in their decision.  The only further recourse available is to claim that the procedures themselves (i.e., the procedures described in this document) are inadequate or insufficient to the protection of the rights of all parties.  Such a claim may be made in an appeal to the Internet Society Board of Trustees, as described in Section 6.5.3 of <xref target="RFC2026" />.  Again, even in this circumstance, the particulars of the incident at hand will be held in confidence.</t>
        </section>

        <section anchor="conflict" title="Conflicts of Interest">
            <t>In the event of any conflict of interest, the conflicted person (member of the Obmudsteam, member of the Appeals Group, IETF Chair, etc.) is expected to recuse themselves.</t>
            <t>A conflict of interest may arise is someone involved in the process of handling a harassment report is in the role of Reporter, Respondent, or Subject.  Furthermore, a conflict of interest arises if the person involved in the process of handling a harassment report is closely associated personally or through affiliation with any of the Reporter, Respondent, or Subject.</t>
            <t>For the avoidance of doubt, recusal in this context means completely stepping out of any advisory or decision-making part of any process associated with handling a harassment report, remedy arising from a harassment report, or appeal into the handling of a harassment report. That means that a recused person has no more right to participate in or witness the process than any other person from the community in the same situation. For example, therefore, an Ombudsperson subject to a complaint of harassment shall not be privy to the deliberations of another Ombudsperson handling the report. Nor would an IESG member who was party to an appeal be able to witness the discussions of the Appeals Group.</t>
            <t>In the event that there is an appeal and the IETF Chair is somehow involved, the Chair will immediately recuse and the IESG will select a single person to take the Chair's role in the appeal process.</t>
        </section>

        <section title="Security Considerations">
            <t>"Human beings the world over need freedom and security that they may be able to realize their full potential." -- Aung San Suu Kyi</t>
        </section>

    </middle>

    <back>

        <references title="Normative References">
            &RFC2026;
            &RFC2418;
            &RFC3934;
            &RFC7154;
        </references>

        <section title="Acknowledgements">
            <t>The text in this document benefited from the lively discussion on the ietf@ietf.org mailing list.  Thanks to everyone who participated.</t>
            <t>Specific changes to this document resulted from comments by Abdussalam Baryun, Alessandro Vesely, S Moonesamy, Timothy B. Terriberry, John Levine, Andrea Glorioso, Dave Crocker, John Leslie, Linda Klieforth, Brian Carpenter, Mary Barnes, Spencer Dawkins, and Michael StJohns.  The authors would like to express their gratitude.</t>
        </section>

        <section title="Open Issues">
            <t>This Appendix to be removed before publication as an RFC.</t>
            <t>This Appendix is used to track issues that have been raised for discussion, but which the authors have not yet addressed.</t>
            <t>
                <list>
                    <t>Timescales.  A suggestion was made that specific time limits should be defined for the periods event-to-report, report-to-contact-Respondent, report-to-remedy.  The authors do not consider this practical as events and circumstances will vary considerably.</t>
                    <t>Deletion of Emails.  There was good debate about the potential for deletion of offensive emails from the archive.  The authors believe this is not an issue to be addressed in this document although it might be a remedy directed by the Ombudsteam.  The authors also believe that the IESG should make a statement covering this point exactly as was done for the deletion of Internet-Drafts under exceptional circumstances.</t>
                    <t>Details of Specific or Example Remedies.  A suggestion was made to include more specific and example of remedies.  The authors consider that it is not helpful for this document to attempt to list all possible remedies: these are a matter for the Ombudsteam to determine.</t>
                    <t>Who Imposes Remedies?  Can the Ombudsteam impose/effect remedies, or can they only make recommendations to the IESG?</t>
                    <t>A Closed Incident is Closed.  There has been some private discussion with the authors about how to indicate that once a remedy has been determined and applied, the incident is closed.  That was intended to cover the issue of a continued trickle of remedies applied for a single incident, and also to prevent an Ombudsperson carrying knowledge of the incident into future interactions if they find themselves in an IETF management position.  The authors found not words to cover what they felt to be a self-evident fact.</t>
                    <t>Term Limits.  A view was expressed that there should be a maximum term limit for an Ombudsperson to ensure that they do not become institutionalised or jaded.  The authors need more opinions on this topic.</t>
                    <t>Removal from IETF Management Position.  We were questioned about whether the Ombudsteam can impose a remedy that removes an individual from an IETF position.  We do not believe that this remedy is available, but we need further comments, and need to decide whether this should be explicitly stated in this document.</t>
                    <t>Recognition of this Process.  It may be necessary for the "Note Well" type of participation documentation to mention this document and state that participants agree to be bound by it.</t>
                </list>
            </t>
        </section>
    </back>

</rfc>
