A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# If you have received a spam/phishing email or SMS, purporting to be from the Australian Taxation Office, report it by sending an email to reportemailfraud@ato.gov.au. # If you would like to report a security issue, contact us via: Contact: mailto:vulnerabilitydisclosure@ato.gov.au Expires: 2023-06-30T00:00:00.000Z Canonical: https://abr.gov.au/.well-known/security.txt Policy: https://www.ato.gov.au/General/Online-services/Online-security/Report-a-system-security-vulnerability # The ATO is serious about cyber security and we thank you for helping to protect the ATO and the community it serves.
This policy crawled by Onyphe on the 2023-03-15 is sorted as securitytxt.
FireBounty © 2015-2025