Skip to content

Commit

Permalink
Merge pull request #527 from w3c/simoneonofri-security-scope
Browse files Browse the repository at this point in the history
[ig/security] Scope/OSS
  • Loading branch information
simoneonofri authored Jun 26, 2024
2 parents 0238ee9 + ffdf3ee commit 62ebc93
Showing 1 changed file with 3 additions and 7 deletions.
10 changes: 3 additions & 7 deletions 2024/ig-security.html
Original file line number Diff line number Diff line change
Expand Up @@ -159,22 +159,18 @@ <h2>Motivation and Background</h2>
<section id="scope" class="scope">
<h2>Scope</h2>
<p>The Security Interest Group (SING) develops and documents guidelines, patterns, processes, and best practices for addressing security considerations in Web standards.</p>
<p>SING provides "<a href="https://www.w3.org/Guide/process/charter.html#horizontal-review">horizontal review</a>" - offering groups developing web standards on-request guidance on security issues and mitigations specific to their technologies. SING aims to offer this review as early in the technology development lifecycle as requested, observing that early feedback is often more helpful. SING may also seek out technologies that benefit from earlier security reviews and conduct such reviews on its initiative.</p>
<p>SING provides "<a href="https://www.w3.org/Guide/process/charter.html#horizontal-review">horizontal review</a>", offering groups on-request guidance on security issues and mitigations specific to their technologies. SING aims to offer this review as early in the technology development lifecycle as requested, observing that early feedback is often more helpful. SING may also seek out technologies that benefit from earlier security reviews and conduct such reviews on its initiative.</p>
<p>SING incubates standards work on security issues by collecting requirements, prototyping, and/or initiating the work within the IG and recommending that the W3C move the work into other groups when appropriate.</p>
<p>SING may recommend mitigations for security issues in existing features of the Web platform, up to and including their deprecation.</p>
<p>SING may provide input to the W3C Process Community Group on process changes that will improve security in Web standards, e.g., by establishing particular requirements for identifying and mitigating security issues in W3C Recommendations.</p>
<p>SING may provide input to the W3C Process Community Group on process changes that will improve security in Web standards, e.g., by establishing particular requirements or threat models for identifying and mitigating security issues in W3C Recommendations.</p>
<p>SING may recommend to the W3C Advisory Committee and the W3C TAG regarding the security impact of proposed standards.</p>

<section id="section-out-of-scope">
<h3 id="out-of-scope">Out of Scope</h3>
<p>The following features are out of scope, and will not be addressed by this <i class="todo">Interest</i> group.</p>
<p>The following features are out of scope, and will not be addressed by this Interest group.</p>
<p>The technical development of standards is not in the scope of the Interest Group. Identified Recommendation Track opportunities will be handed over to appropriate W3C groups if such a group exists or within a dedicated Community Group or Business Group when incubation is needed.</p>
<ul class="out-of-scope">
</ul>
</section>

</section>

<section id="deliverables">
<h2>
Deliverables
Expand Down

0 comments on commit 62ebc93

Please sign in to comment.