A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# /Security.txt file for https://www.commbank.com.au/ Contact: mailto:vulnerability@cba.com.au Encryption: https://www.commbank.com.au/support/security/rd-pgp-key.asc Preferred-Languages: en Policy: https://www.commbank.com.au/support/security/vulnerability-disclosure-program.html Hiring: https://www.commbank.com.au/about-us/careers.html
This policy crawled by Onyphe on the 2021-10-27 is sorted as securitytxt.
FireBounty © 2015-2024