W3C

– DRAFT –
WoT Security

18 March 2024

Attendees

Present
Jan_Romann, Kaz_Ashimura, Michael_McCool, Tomoaki_Mizushima
Regrets
-
Chair
McCool
Scribe
kaz

Meeting minutes

Minutes

Mar-11

McCool: would check Mahda's availability

approved

Security Categories

<McCool_> https://github.com/w3c/wot-usecases/blob/mmccool-patch-2/USE-CASES/security-categories.csv

<McCool_> PR 255 - Update security-categories.csv

McCool: added some edits
… (goes through the updates within PR 255)
… related issue on wot-usecases repo
… want to bring up is security/privacy consideration within the Use Case template
… to see if each use case correspond to each categorization, e.g., Public Service or not

Jan: what's the different between "Private Information" and "Confidential Information"?

McCool: PII and business confidential

Kaz: That could be an initial definition, but "Private Information" is not equal to "PII"...
… PII is basically information to identify the user
… while "private information" could be broader and include "my shopping history"

McCool: should say "private/PII" instead then

Kaz: "business confidential" also could have several levels, e.g., personal level and company level

McCool: we could think about several sub-categories to handle those levels
… would work with David, etc., for further discussion
… also would add another column to capture if the submitter confirms the categorization

[adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 221 (Fri Jul 21 14:01:30 2023 UTC).