What is a Responsible Disclosure report?
23 February 2021A Responsible Disclosure report is a report you can submit to an organization where, as a visitor, user, researcher, or ethical hacker, you have discovered a weakness in ICT security. By submitting this report, you help prevent abuse and increase the security of ICT systems. A Responsible Disclosure report, also known as a Coordinated Vulnerability Disclosure (CVD) report, can be submitted by anyone.
The importance of a Responsible Disclosure report
A security researcher, ethical hacker, or other user may notice that he can gain access to information, systems, or applications of an organization, where he should not actually have access. It may also be that someone “accidentally” encounters something not intended for him.
Not everyone always reports this. The best way to encourage a Coordinated Vulnerability Disclosure report is to establish a Responsible Disclosure policy. This can indicate how the report will be handled and what promises are made.
Provide a Responsible Disclosure page
A list of the rules and promises of the responsible disclosure policy can be placed on a webpage.
A rule can be, for example, that the researcher reports the vulnerability to the organization and does not exploit or share it with the outside world. A promise can be that as an organization you will not take legal action and may even offer a reward (formally these hackers commit criminal offenses such as computer trespassing or unlawfully copying data).
Ensure that the report can actually be made by, for example, providing an email address or offering a contact form.