Clarify Security_Impact-None.

Change-Id: Ie9294ddfc5eb4902ff8903bfec130da00b381268
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2510353
Reviewed-by: Max Moroz <[email protected]>
Reviewed-by: danakj <[email protected]>
Commit-Queue: Adrian Taylor <[email protected]>
Cr-Commit-Position: refs/heads/master@{#824184}
diff --git a/docs/security/severity-guidelines.md b/docs/security/severity-guidelines.md
index 3082043..06d0166 100644
--- a/docs/security/severity-guidelines.md
+++ b/docs/security/severity-guidelines.md
@@ -154,6 +154,15 @@
 ([128163](https://crbug.com/128163)).
 
 
+## Can't impact Chrome users by default {#TOC-No-impact}
+
+If the bug can't impact Chrome users by default, this is denoted instead by
+the **Security-Impact_None** label. See
+[the security labels document](security-labels.md#TOC-Security_Impact-None)
+for more information. The bug should still have a severity set according
+to these guidelines.
+
+
 ## Not a security bug {#TOC-Not-a-security-bug}
 
 The [security FAQ](faq.md) covers many of the cases that we do not consider to