Re: Security, Privacy, and Accessibility self-review Questionnaires.

> On 4 Nov 2014, at 8:46 pm, chaals@yandex-team.ru wrote:
> 
> It's a really good idea to have some documents that guide reviews.
>  
> It's not nearly such a good idea to encourage "check-a-box" review of architectural issues. (I presume this is obvious to the people writing, but it isn't obvious from what is being written).

+1, and I think the intent here is of the former kind.

I'm reminded of the document writeup in the IETF -- it's there to remind the reviewer about what to cover, not a 'tick these off' sort of thing:
  http://www.ietf.org/iesg/template/doc-writeup-essay-style.html

Cheers,

--
Mark Nottingham   https://www.mnot.net/

Received on Thursday, 6 November 2014 02:22:09 UTC