diff --git a/README.md b/README.md index f17c948..fc07b57 100644 --- a/README.md +++ b/README.md @@ -1,12 +1,12 @@ This repository contains the [Editor's Draft](https://w3ctag.github.io/security-questionnaire/) of the [Self-Review Questionnaire: Security and Privacy](https://www.w3.org/TR/security-privacy-questionnaire/) document, which spec authors can use to identify and work through possible security and privacy concerns related to their spec. -The questionnaire is a joint product of the [TAG](https://tag.w3.org/) and [PING](https://www.w3.org/Privacy/IG/). +The questionnaire is a joint product of three groups: the [TAG](https://tag.w3.org/), [PING](https://www.w3.org/Privacy/IG/), and the [Security Interest Group](https://www.w3.org/groups/ig/security/). When folks request a [design review](https://github.com/w3ctag/design-reviews) from the TAG, [filling out](questionnaire.markdown) the security and privacy questionnaire helps the TAG to understand potential security and privacy issues and mitigations for the design, and can save us asking redundant questions. Before requesting security and privacy review -from the security reviewers and PING, respectively, documents must +from the Security Interest Group and PING, respectively, documents must contain both "Security Considerations" and "Privacy Considerations" sections for their documents, as described in Section 2.15. While your answers to the questions in this document will inform your diff --git a/index.bs b/index.bs index 982cbff..ee265fe 100644 --- a/index.bs +++ b/index.bs @@ -74,12 +74,12 @@ parallel with this document. The IETF's RFC about privacy considerations, [[RFC6973]], is a wonderful resource, particularly section 7. -

TAG, PING, security reviews and this questionnaire

+

TAG, PING, the Security Interest Group, and this questionnaire

Before requesting privacy and security reviews from the [Privacy Interest Group -(PING)](https://www.w3.org/Privacy/IG/) and security reviewers, +(PING)](https://www.w3.org/Privacy/IG/) and the [Security Interest Group](https://www.w3.org/groups/ig/security/), write "Security Considerations" and "Privacy Considerations" sections in your document, as described in [[#considerations]]. Answering the questions in this @@ -1362,7 +1362,7 @@ Thomas Steiner, Wendy Seltzer, and -the many current and former participants in PING and the TAG +the many current and former participants in PING, the Security Interest Group, and the TAG for their contributions to this document. Special thanks to diff --git a/status.include b/status.include index 809bcaa..7561809 100644 --- a/status.include +++ b/status.include @@ -1,6 +1,6 @@

This section describes the status of this document at the time of its publication. A list of current W3C publications and the latest revision of this technical report can be found in the W3C technical reports index at https://www.w3.org/TR/.

-

This document was published by the Technical Architecture Group and the Privacy Interest Group as a Group Note using the Note track.

+

This document was published by the Technical Architecture Group, the Privacy Interest Group, and the Security Interest Group as a Group Note using the Note track.

Group Notes are not endorsed by W3C nor its Members.