This document summarizes Richard Lamb's presentation on DNSSEC at IANA. It discusses:
1) The design goals of maintainability, reliability, security and target domains for DNSSEC at IANA.
2) The hardware, software, and operational practices used to securely generate and manage keys, including using dual signers and an HSM to protect sensitive keys.
3) Questions around compromised key recovery given disinterested users and update vectors, and detecting compromised keys.