-
Notifications
You must be signed in to change notification settings - Fork 20
Open
Labels
enhancementNew feature or requestNew feature or request
Description
security.txt is an emerging practice on deployed websites which lets security researchers know how to properly disclose security issues related to a website. More details at https://securitytxt.org
The MoJ is the current gold standard for this and has clear guidelines for sites on what to do - see https://ministryofjustice.github.io/security-guidance/contact/implement-security-txt
There is interest from other departments including DWP and MetOffice. It would be good to get some similar guidance for DEFRA projects.
More information...
- Example file: https://raw.githubusercontent.com/ministryofjustice/security-guidance/master/contact/vulnerability-disclosure-security.txt
- The MoJ department wide disclosure policy https://mojdigital.blog.gov.uk/vulnerability-disclosure-policy/
- @joelsamuel on the #security Slack channel wrote the disclosure policy for MoJ
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request