design for safe technology.
Safety by Design puts user safety and rights at the centre of the design and development of online products and services. Eva PenzeyMoog shines a light on how digital products are being used to enable domestic violence, and what we can do to protect our most vulnerable users
safety by design: Product development processes
Safety By Design - By eSafety Comission
Factors to consider
Embedding safety considerations in product design and development helps to prevent and reduce online harms.
Consider integrating formal safety reviews – including consultation and testing – into the design process from the beginning, and through the lifecycle of the product, platform or feature.
These reviews should include employees from teams across the organisation who are responsible for online safety, including the executive team.
Initial design
Some factors to consider when developing a safety review process:
scenario testing for known types of risk and harm and known techniques used for harm and abuse
new forms or techniques of abuse
assessment of false positives or negatives (in moderation processes or reported abuse)
internal safety vulnerability scans and penetration testing
external safety vulnerability scans and penetration testing
user behaviours, needs and impacts for at-risk groups
health and wellbeing impacts on employees, workers, community moderators, and users.
Formal safety reviews
Formal safety reviews should be conducted throughout the lifecycle of online platforms and services. The factors to consider in safety reviews often change, so these processes should be frequently refined, particularly as new updates are released.
The types of online harms and the techniques and tactics that abusers use will play an important role in scenario testing and are covered extensively in the Online Harms module.
Good practice for safety reviews
Timing
Each stage of product development presents an opportunity to conduct a thorough safety review.
Suggested timing for safety reviews include:
pre-development
during development
pre-launch
post-launch review of all features and functions
post-launch review of new features and functions
post-development reassessments
during platform updates or refreshes.
Scenario testing
Safety reviews should include scenario testing:
of specific edge cases, such as unusual user behaviour or incidents that require special handling
across all channels, features and tools
within different regions and jurisdictions.
Analysis
Safety reviews should include analysis of:
patterns of behaviour and network effects, focusing on abusive actors
online signals such as metadata and traffic signals
behavioural signals including patterns of interaction – this includes search activity, group membership and activity, violation indicators (such as reports and connection activity or friend requests), content creation and sharing, profiles and accounts
behavioural and online signals for at-risk groups.
Environmental scanning
The context your platform or service operates in constantly changes, so safety review processes require:
rapid assessment of new forms or techniques of abuse occurring on the platform
external research and analysis of new forms or techniques of abuse
cross-industry practices and information sharing
understanding the needs of victims/survivors and at-risk and marginalised groups.
Assessment
Safety review processes should assess the effectiveness, accuracy and impact of:
automated and human moderation systems
user safety controls and tools
prevention messaging
prevention interventions
reporting systems and processes
disruption techniques
detection tools
automated responses
feedback systems and processes
reduction of harms or risks, with a focus on at-risk or marginalised groups
user confusion or misunderstanding relating to how a product or feature functions.
Testing
As part of the review process, safety vulnerability scans and/or penetration testing should be introduced, both internally and externally.
External expertise
Safety review processes should be assessed by external experts or independent auditors where possible, along with other safety policies and procedures. Seek out innovations and research that will improve safety review processes.
Standards and frameworks
Your safety review should be informed by national and international regulatory frameworks, standards and industry standards.
Key considerations for reporting mechanisms
1. Platforms should streamline reporting advice and tools to make it easier for users to report – particularly vulnerable or at-risk groups.
2. Ensure reporting is built into the platform type – for example, in-app, in-chat, in-video or website reporting – and is consistent across all devices and modes of access.
3. Ensure that reporting tools are easy to locate and simple to navigate.
4. Communicate with users through in-platform tools and reminders to prompt users that they can report – and include direct pathways to report.
5. Provide users with opportunities to communicate with free text rather than limiting reporting to pre-determined response options alone.
6. Test reporting mechanisms across a diverse range of users, including children, young people and at-risk groups.
7. Consider using videos, images or screenshots of these processes to help users of different literacy levels to understand.
8. Allow the ability to report without the requirement to create or sign into an account.
9. Allow reporting of accounts, content, activities and features.
10. Assess the need for mandatory personal information fields in content reporting forms.
11. Provide users with updates and information about their reports – feedback loops should be continually monitored and evaluated to ensure they are fit for purpose.
12. State an expected timeframe for users to receive a response to their report or complaint.
13. Provide contact information for law enforcement, hotlines, regulatory bodies or other relevant authorities to all those making reports.
14. Ensure that information about third-party referral services is available at the time of reporting, such as mental health service providers. Wherever possible, these support services should also be as localised as possible.
Source:https://sbd.esafety.gov.au/startup