Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Definitions of Security and Privacy in Architecture Document #134

Closed
mmccool opened this issue Jul 1, 2019 · 5 comments
Closed

Comments

@mmccool
Copy link
Contributor

mmccool commented Jul 1, 2019

As noted in w3ctag/design-reviews#355, the definitions of Security and Privacy in the Architecture document are too short and really should be based on another standard. Rather than defining them here and/or pointing at another standard, we can just depend on "well-understood" definitions of these terms and delete them from the Arch document.
Update: will generate standards-based definitions for these terms instead of just deleting them.

@mmccool
Copy link
Contributor Author

mmccool commented Jul 2, 2019

Issue w3c/wot-architecture#368, if merged, will resolve this issue.
There is also a definition of "Personally Identifiable Information". This is less "common" than Security and Privacy so I have not removed it. However, ideally the definition of this term would identify an external official source.

@mlagally
Copy link

mlagally commented Jul 3, 2019

An external reference for PII is https://www.iso.org/obp/ui/#iso:std:iso-iec:29100:ed-1:v1:en

@mmccool
Copy link
Contributor Author

mmccool commented Jul 8, 2019

The Architecture TF discussed this and decided that rather than deleting these definitions it would be better to add external references. Some references were found, but it is notable that ISO-IEC defines "Information Security" but not just "Security" as we have been using. See the discussion under w3c/wot-architecture#368.

I propose we define "Security" within the WoT documents to be equivalent to the ISO definition of "Information Security". An alternative would be to define "Security" as a combination of "Information Security" and "Physical Security" since anti-tampering measures may also be important in IoT. However, I personally think we should focus on Information Security and declare Physical Security measures out of scope (or use "Physical Security" explicitly when talking about such things).

@mmccool
Copy link
Contributor Author

mmccool commented Aug 5, 2019

Still in progress. I will create a PR for new standards-based definitions soon.

@mmccool mmccool changed the title Delete Definitions of Security and Privacy from Architecture Document Update Definitions of Security and Privacy in Architecture Document Aug 5, 2019
@mmccool
Copy link
Contributor Author

mmccool commented Nov 5, 2019

This has been done.

@mmccool mmccool closed this as completed Nov 5, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants