diff --git a/index.bs b/index.bs
index 636cbc1..f3435e9 100644
--- a/index.bs
+++ b/index.bs
@@ -1458,11 +1458,15 @@ as appropriate.
-
Security
+
Security and Privacy
-All interfaces defined by extension specifications
-should only be available within a [=secure context=].
+Extension specifications are expected to:
+- conform with the generic [[#mitigation-strategies|mitigation strategies]],
+- consider [[#mitigation-strategies-case-by-case|mitigation strategies applied
+ on a case by case basis]],
+- be evaluated against the Self-Review Questionnaire on Security and Privacy
+ [[SECURITY-PRIVACY-QUESTIONNAIRE]].