diff --git a/index.src.html b/index.src.html index 51e51b9..01ee9a5 100644 --- a/index.src.html +++ b/index.src.html @@ -101,34 +101,17 @@

Introduction

How To Use The Questionnaire

- Thinking about security and privacy risks and mitigations early in a project - is the best approach as it helps ensure the privacy of your feature at an - architectural level and ensures the result, descriptions, protocols and - algorithms incorporate privacy by default as opposed to through possible - implementation mitigations. - - The Privacy Interest Group (PING) recommends that a feature group review the - guidance and questionnaire when first considering their feature and meet with - PING at that time to discuss any questions they have about how the - guidance/questionnaire intersects with their feature at a conceptual level. - After the feature group has developed their feature with the - guidance/questionnaire informing their development process, the group should - bring an early draft of their feature specification with Privacy consideration - section to PING for review. From there the feature group should iterate on - their design. - - When requesting a Technical Architecture Group review, include the filled - questionnaire, along with the description of changes or observations made - during the design process. This allows external reviewers understand the + When designing a new web feature or technology, you should think about + security and privacy risks and mitigations early. + Please have a look at this questionnaire document + as you consider the design of a new web fearure or technology. + + When requesting a Technical Architecture Group review, please include + responses to this questionnaire, along with the privacy-related aspects of + the design. This allows external reviewers understand the rationale, as well as the challenges and evolution of the feature, with respect to security and privacy. - It is understandable that developers may not always have the necessary data - to see the broader picture and possible implications, for example in relation - to other existing web functionalities. The answers to the questionnaire are - meant as help and input for people who may nonetheless make security and - privacy remarks, or the assessment. -