Code of Conduct for Abuse Prevention
Why a Code of Conduct for Abuse Prevention?
As a provider of digital infrastructure, you are increasingly facing stricter requirements for abuse prevention. Legislation such as the DSA and the Cybersecurity Act requires providers to take responsibility for what happens on their networks.
The Code of Conduct for Abuse Prevention helps you put this into practice. With clear agreements on detection, response, and prevention, you make your approach demonstrable: for your internal processes, for regulators, and in tender procedures.
What does the code of conduct contain?
The code of conduct has four sections, the same as the document itself:
- Policy
You implement the code of conduct and make this known on your website. You maintain an Acceptable Use Policy (AUP) and an Abuse Policy (AP), publish an abuse contact on your website and in whois, keep your customers’ contact details correct, and follow best practices such as the M3AAWG code of conduct. You verify new customers before delivering a service, including when they pay with cryptocurrency (Know Your Customer). And you adhere to the Notice-and-Take-Down Code of Conduct. - Obligations
You reduce the effects of abuse in your network, as an Autonomous System at least by implementing MANRS. You subscribe to abuse feeds or join Clean Networks, accept abuse reports from automated systems and from individuals, and take action as soon as you become aware of abuse. Where serious harm to individuals is at stake, you act immediately. In cases of prolonged, substantial, or repeated violations of your AUP, you suspend services or terminate the contract. You act on formal orders from competent authorities, immediately notify the authorities of life-threatening criminal offences, and continuously work on your own performance. - Notices
Notices regarding unlawful or criminal content, such as defamation, hate speech, or copyright infringement, follow the separate procedure in the Notice-and-Take-Down Code of Conduct. - Non-compliance
A reasonable suspicion that a provider is not complying with the code of conduct can be reported to one of the organizations representing it. Participants refrain, where possible, from business relationships with organizations that evidently act in violation of the code of conduct.
The full text is in the Code of Conduct for Abuse Prevention (pdf).
Sign the Code of Conduct
Clean Networks is an initiative of NBIP and is funded by the European Union. Participation is free.
What does signing mean?
You commit to the standards set out in the code of conduct and to the expectations that the DSA places on providers of digital infrastructure.
What happens after signing?
- You will receive a starter package with explanations, templates, and self-checks.
- You will be added to the list of signatories.
- You give NBIP permission to exchange your AS numbers with notifiers.
- You will receive notifications about vulnerabilities and abuse in your network.
- You will gain insight into your own performance through the TU Delft benchmark.