Skip to content

Latest commit

 

History

History
91 lines (55 loc) · 4.93 KB

CONTRIBUTING.md

File metadata and controls

91 lines (55 loc) · 4.93 KB

Participation Policy for the Security Interest Group

Status: Draft

Editor: @simoneonofri

Policy

This document details the participation stated in the Security Interest Group charter.

Expertise

The Security Interest Group is a particular group within W3C, in fact it seeks specific expertise:

  • Security Experts (e.g., Security Researchers, Penetration Testers, Security Architects, and Code Reviewrs)
  • Threat Modeling experts
  • Cryptographers and Cryptoanalysts

Participation

If a person have these skills and want to put them for shaping a secure web and for the good of users, they can participate in two ways:

Invited Expert

The Security Interest Group, from its charter, specifically welcomes individuals. Invited Experts are not given Member access, for this group.

The group welcomes and encourages all participants with proven specific expertise, even if they do not represent a W3C Member. In that case, they should join as Invited Experts. Invited Experts in this group are not granted access to Member-only information.

Invited Experts are described as follows:

W3C Invited Experts are individuals who are invited by a chair of a Working or Interest Group to participate in that group. The chair and the W3C staff must agree that the individual brings particular expertise to the group prior to inviting the individual.

Invitations

The Chairs and Staff Contact expect to invite individuals to participate in the Interest Group as Invited Experts in a manner consistent with the W3C Invited Expert policy and IG Charter.

The Chairs and Staff Contact will also take into consideration whether individuals:

  • Have contributed to the Security IG (e.g., via the mailing list or GitHub) as non-participants.
  • Have expertise that the Chairs and Staff Contact deem important to the success of the group, even if they have not previously contributed to the IG.

Once the Chairs have extended an invitation to someone to join as an Invited Expert, that person should review the instructions for joining the group.

Individuals are welcome to contact the Chairs and Staff Contact to initiate a discussion about participation as an Invited Expert.

Expectations

We expect Security Interest Group participants to contribute, which can take the form of:

  • Participating in security reviews
  • Scribing calls
  • Participating in discussions
  • ...among other things.

Inactive or non-contributing Invited Experts may not be renewed.

FAQ

I don't work for a W3C Member. Can I join the group?

Potentially, yes (per the charter).

I work for a W3C Member. Can I join as an Invited Expert?

No. Individuals who work for a W3C Member organization participate as representatives of their organization and not via the Invited Expert program.

Are there patent licensing obligations associated with participation in an Interest Group?

Potentially.

  • There are no patent licensing obligations associated with participation in an Interest Group. However see the disclosure obligations for Interest Group participants.
  • When a participant of this Interest Group contributes to a technical submission reviewing or marking comments on deliverables by other groups, they must agree to the terms of the W3C Patent Policy and License Grants from Non-Participants.

Can I subscribe to the mailing list even if I am not a participant?

Yes. Anyone may subscribe to the group’s mailing list and post to it. (People who join the group are automatically subscribed.)

References

See also:

Similar documents: