We ask that you do the following when reporting a CVD
- Reporting
Please report the vulnerability to us as soon as possible after discovering it. The reporting procedure is set out below. Findings can only be brought to the organisation’s attention in this way.
Please email your findings to cvd@apeldoorn.nl (to be used only for CVD reports). You can also submit the findings securely and in encrypted form via the website https://crypt.apeldoorn.nl/.
- Information
We would also ask you to provide sufficient information to enable us to reproduce the problem, so that we can resolve it quickly. The IP address or URL of the system in question and a description of the security issue will suffice. Any additional relevant information and tips are always welcome, as they may help us resolve the issue more quickly. Please do avoid promoting specific (security) tools, however.
Information about the security issue should not be shared with others until the issue has been resolved. Once the matter has been dealt with, it is possible to publish details of the vulnerability, subject to consultation.
- Contact
We would ask you to provide your contact details so that we can work together to resolve this issue. Please provide at least one email address or telephone number. This will enable our Security Operations Centre to get in touch with you.
The following actions are not permitted
- Installing malware.
- The brute-forcing regarding access to systems.
- Using social engineering, unless this proves strictly necessary to demonstrate that an employee has failed in their duty to handle sensitive information with due care.
This must be done entirely by lawful means; in other words, not through blackmail or other dishonest practices. Any findings obtained through social engineering must be intended to identify a security issue in the municipality’s procedures and working practices, not to cause harm to a municipal employee.
- Publishing or disclosing the security issue before it has been resolved.
- Carrying out unnecessary actions that go beyond what is strictly necessary to identify and report the security issue. Downloading, modifying or deleting data or system configurations is never permitted.
An alternative to this is to create a directory listing or take a screenshot.
- The use of techniques, such as a DoS attack, which limit the availability and/or usability of our systems or services.
What else you can expect
Legal aspect
- If you meet all the above conditions, we will not take any legal action in response to this report. However, if it transpires that you have breached the above conditions, we may still decide to take legal action against you.
Contact regarding the report
- We will send you an (automatic) confirmation of receipt within 1 working day.
- We will respond to your report within three working days with our (initial) assessment, including an expected resolution date.
- We will keep you informed of any progress regarding the report. We will resolve the security issue you have identified as quickly as possible and aim to resolve the problem within 30 days. In doing so, we are often dependent on our suppliers.
How we will handle your case and the report
- We will treat your report in confidence and will not share your personal data without your consent, unless we are required to do so by law or by a court order.
- We always share any reports we receive with the Information Security Service for Local Authorities (IBD). In this way, we ensure that local authorities can share their experiences in this area with one another.
- The manner in which the vulnerability is to be disclosed can be determined by mutual agreement. This will only take place once the problem has been resolved.
Remuneration
- We can offer you a reward as a token of our appreciation for your help. Depending on the severity of the security issue and the quality of the report, this reward can range from a simple ‘thank you’ to a sum of up to €300. However, the issue must be a previously unknown and serious security issue.