I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments. This document requests IANA allocation of registries for OWAMP. As such, it has minimal security impact. One practical note is the request to assign an "Experimentation" OWAMP-Control Command Number. Experience shows that such numbers are either never used, or used as experiments... which then get widely deployed before standards action catches up to practical needs. It may be good to add some discussion as to *how* experiments are done, and how experiments can transition from the "Experimentation" number to a standard number. One suggestion would be to change the label from "Experimentation" to "Site-Local". That would still allow sites to experiment with OWAMP-Control commands, but would make it clearer that such experimentation is only for the local site, and MUST NOT be used in a wider context.