Cybersecurity by Design: The Contact Initiative Approach

The Contact Initiative treats cybersecurity as an infrastructure-level property, not an add-on, through a defined set of controls:

  • Verified, role-based identity for every user, separate from any reassignable number.
  • Zero-trust access to the resolution layer — no standing access for any relying party, vendor, or MI agent.
  • Non-enumerable, rate-limited query-response verification, preventing bulk scraping of the identity graph.
  • Mandatory DNSSEC, SPF, DKIM, and enforced DMARC on every issued domain.
  • Aliases that hide the administrative address, shrinking the target for spear-phishing.
  • Scoped, short-lived credentials for vendors and MI agents instead of raw record access.
  • Persistent, tamper-evident logging at both the institution and national-registry level.
  • Mandatory dual control for high-impact actions like bulk data export or identifier retirement overrides.
  • A public security-disclosure and bug-bounty commitment for the registry and its reference implementation.

That vendor-focused control matters most: reported research indicates a majority of disclosed K–12 breaches trace back to a compromised vendor, not the district itself. Tokenized, scoped, short-lived vendor credentials are aimed squarely at closing that pathway.