This wiki has undergone a migration to Confluence found Here
Difference between revisions of "CMHAFF call, Thursday, Oct 12"
Jump to navigation
Jump to search
Line 2: | Line 2: | ||
AGENDA: | AGENDA: | ||
− | |||
*Review short descriptions (most are new) of each section at the Heading 3 level (e.g., 3.4.1 User Authentication, 3.4.2 User Authorizations...) | *Review short descriptions (most are new) of each section at the Heading 3 level (e.g., 3.4.1 User Authentication, 3.4.2 User Authorizations...) | ||
*Review '''cMHAFF Label,''' a visual summary of key facts about an app and its conformance to cMHAFF (David) | *Review '''cMHAFF Label,''' a visual summary of key facts about an app and its conformance to cMHAFF (David) | ||
Line 11: | Line 10: | ||
**DKT11 -- removal of "suggested actor" from tables? | **DKT11 -- removal of "suggested actor" from tables? | ||
**DKT14 -- Secure Coding practices reference | **DKT14 -- Secure Coding practices reference | ||
+ | *For subsequent meeting: review of changes made, based on Adamu's recommendations from U.K. PAS277 Guidelines. Comments have been added, but specific wording has not all been incorporated yet. |
Revision as of 16:39, 12 October 2017
ATTENDEES:
AGENDA:
- Review short descriptions (most are new) of each section at the Heading 3 level (e.g., 3.4.1 User Authentication, 3.4.2 User Authorizations...)
- Review cMHAFF Label, a visual summary of key facts about an app and its conformance to cMHAFF (David)
- Review of Label format and "consumer friendly language" descriptions (new Section 2.2 in cMHAFF document), including the notes that suggest how a section could be scored Green, Yellow, or Red, and who should decide (self-attestation vs inspection vs test vs ____?)
- Work through two sections as examplars: Product Information and User Authorization (Consent) for Data Collection and Use, to work through how the label score might be determined by assessment against conformance statements.
- Review and decision on specific comments:
- DKT9 -- Environmental Scan
- DKT11 -- removal of "suggested actor" from tables?
- DKT14 -- Secure Coding practices reference
- For subsequent meeting: review of changes made, based on Adamu's recommendations from U.K. PAS277 Guidelines. Comments have been added, but specific wording has not all been incorporated yet.