A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.
# In the event that you have discovered a technical vulnerability in an IT system of the federal government, # we encourage you to report it to the National Cyber Security Centre NCSC using the Coordinated Vulnerability Disclosure program. # We will triage your request to the appropriate entity. # If you are interested in participating in the NCSC bug bounty programs you can apply here: https://www.bugbounty.ch/ncsc Contact: https://bstger.ch/en/contatti/formulario-di-contatto.html Contact: mailto:informatica@bstger.ch Preferred-Languages: en, de, fr, it Canonical: https://www.ncsc.admin.ch/.well-known/security.txt Policy: https://www.ncsc.admin.ch/ncsc/en/home/infos-fuer/infos-it-spezialisten/themen/schwachstelle-melden/scope-and-rules.html
This policy crawled by Onyphe on the 2024-03-01 is sorted as securitytxt.
FireBounty © 2015-2024