A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 # Canonical URI Canonical: https://www.cisco.com/.well-known/security.txt # Cisco PSIRT email address Contact: mailto:psirt@cisco.com # Cisco PSIRT OpenPGP key Encryption: https://cscrdr.cloudapps.cisco.com/cscrdr/security/center/files/Cisco_PSIRT_PGP_Public_Key.asc # Cisco's security vulnerability policy Policy: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html # Cisco's Common Security Advisory Framework (CSAF) publications CSAF: https://www.cisco.com/.well-known/csaf/provider-metadata.json Expires: 2027-01-01T00:00:00.000Z -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEECB448+sRAmWiFFFBJLPsYeQgWAIFAmdjOQAACgkQJLPsYeQg WAJU6A//ZSml7VZKbmElKnixpGkpixh6cX98ausJASDmdZTwVNa05IQXMAuTauV9 DwnrBFj2ZgD91CudcWPvZrG9FlPBVtvqVfpxHXRjUOChZh56KLWLPcY8JEKg7+RL wWGZwQF9ia6xfArCQ6RSWwLdy7dbCYBHbj5DgI157CZ1ApGW83Kt2PaTDWFu3ZcO ElN2mmlvQsDwPoYWNvNz2CEbkcPnzzj2K4uf5jMRi8CLKh/RildsaV3ntPy4UFWG aKe4uuUEPr0NsB2ONqPOW8rfSJcONfq2SYEvY17A/1RCkoz2bZ9q3nNemv6hM26L i/+0uPkClo+fvkEmXerArXL7c39Q04rRSpbhdwgPS+MTh5ka/poad04xXx3JNhJy h1t7zYkkHDUZQ5zjpkTwm3BJDEHoSkPFhJyIPhxHYAsueIH52SM7ZBJAd6+ceaSW k2SPVnXu42hPFLcEJWOIfpGWim+VejZvw46gmqael20vIP4OoD+vV9QHBMiV/vT2 nIqoeUI7vjiuL6NuR+MpBKCmBx5ADFhK14Ug5L7fNsQgFIysTdwl4D2ESq09t1L2 9SMVPoExnfDNAtAwqXHJ9ui8Z55mBkGpYxTGA0CpfXjSMU/6RnOj1IfYYVJ/ubH1 gqNNe5io8iQSzdRbJfi0PKbVpo7gLrzBfKYlh7DwLvzde+HW4cA= =LU2s -----END PGP SIGNATURE-----
This policy crawled by Onyphe on the 2023-03-15 is sorted as securitytxt.
FireBounty © 2015-2025