{"id":12552,"date":"2026-05-08T22:57:04","date_gmt":"2026-05-08T20:57:04","guid":{"rendered":"https:\/\/www.apeldoorn.nl\/overig\/coordinated-vulnerability-disclosure-cvd\/"},"modified":"2026-07-07T15:51:00","modified_gmt":"2026-07-07T13:51:00","slug":"coordinated-vulnerability-disclosure-cvd","status":"publish","type":"page","link":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/","title":{"rendered":"Coordinated Vulnerability Disclosure (CVD)"},"content":{"rendered":"<div data-acfblock=\"Tekst\" class=\"section a section--grey e-tekst\">\r\n\t<div class=\"container\">\r\n\t\t<div class=\"row justify-content-center elementOnTop\">\r\n\t\t\t<div class=\"col article-content__content-custom-1220 editor elementOnTop\">\r\n\t\t\t\t<h2>We ask that you do the following when reporting a CVD<\/h2>\r\n<ul>\n<li><strong>Reporting<\/strong><br \/>\nPlease report the vulnerability to us as soon as possible after discovering it. The reporting procedure is set out below. Findings can only be brought to the organisation\u2019s attention in this way.<\/p>\n<p>Please email your findings to\u00a0<a href=\"mailto:cvd@apeldoorn.nl\">cvd@apeldoorn.nl<\/a>\u00a0(to be used only for CVD reports). You can also submit the findings securely and in encrypted form via the website\u00a0<a href=\"https:\/\/crypt.apeldoorn.nl\/\">https:\/\/crypt.apeldoorn.nl\/.<br \/>\n<\/a><\/li>\n<li><strong>Information<br \/>\n<\/strong>We would also ask you to provide sufficient information to enable us to reproduce the problem, so that we can resolve it quickly. The IP address or URL of the system in question and a description of the security issue will suffice. Any additional relevant information and tips are always welcome, as they may help us resolve the issue more quickly. Please do avoid promoting specific (security) tools, however.<\/p>\n<p>Information about the security issue should not be shared with others until the issue has been resolved. Once the matter has been dealt with, it is possible to publish details of the vulnerability, subject to consultation.<\/li>\n<li><strong>Contact<br \/>\n<\/strong>We would ask you to provide your contact details so that we can work together to resolve this issue. Please provide at least one email address or telephone number. This will enable our Security Operations Centre to get in touch with you.<\/li>\n<\/ul>\n<h2>The following actions are not permitted<\/h2>\n<ul>\n<li>Installing\u00a0<strong>malware<\/strong>.<\/li>\n<li>The\u00a0<strong>brute-forcing<\/strong>\u00a0regarding access to systems.<\/li>\n<li>Using\u00a0<strong>social engineering<\/strong>, unless this proves strictly necessary to demonstrate that an employee has failed in their duty to handle sensitive information with due care.<\/li>\n<\/ul>\n<p><em>This must be done entirely by lawful means; in other words, not through blackmail or other dishonest practices. Any findings obtained through social engineering must be intended to identify a security issue in the municipality\u2019s procedures and working practices, not to cause harm to a municipal employee.<\/em><\/p>\n<ul>\n<li>Publishing or disclosing the security issue before it has been resolved.<\/li>\n<li>Carrying out unnecessary actions that go beyond what is strictly necessary to identify and report the security issue. Downloading, modifying or deleting data or system configurations is never permitted.<\/li>\n<\/ul>\n<p><em>An alternative to this is to create a directory listing or take a screenshot.<\/em><\/p>\n<ul>\n<li>The use of techniques, such as a DoS attack, which limit the availability and\/or usability of our systems or services.<\/li>\n<\/ul>\n<h2>What else you can expect<\/h2>\n<h3>Legal aspect<\/h3>\n<ul>\n<li>If you meet all the above conditions, we will not take any legal action in response to this report. However, if it transpires that you have breached the above conditions, we may still decide to take legal action against you.<\/li>\n<\/ul>\n<h3>Contact regarding the report<\/h3>\n<ul>\n<li>We will send you an (automatic) confirmation of receipt within 1 working day.<\/li>\n<li>We will respond to your report within three working days with our (initial) assessment, including an expected resolution date.<\/li>\n<li>We will keep you informed of any progress regarding the report. We will resolve the security issue you have identified as quickly as possible and aim to resolve the problem within 30 days. In doing so, we are often dependent on our suppliers.<\/li>\n<\/ul>\n<h3>How we will handle your case and the report<\/h3>\n<ul>\n<li>We will treat your report in confidence and will not share your personal data without your consent, unless we are required to do so by law or by a court order.<\/li>\n<li>We always share any reports we receive with the Information Security Service for Local Authorities (IBD). In this way, we ensure that local authorities can share their experiences in this area with one another.<\/li>\n<li>The manner in which the vulnerability is to be disclosed can be determined by mutual agreement. This will only take place once the problem has been resolved.<\/li>\n<\/ul>\n<h3>Remuneration<\/h3>\n<ul>\n<li>We can offer you a reward as a token of our appreciation for your help. Depending on the severity of the security issue and the quality of the report, this reward can range from a simple \u2018thank you\u2019 to a sum of up to \u20ac300. However, the issue must be a previously unknown and serious security issue.<\/li>\n<\/ul>\n\r\n\t\t\t<\/div>\r\n\t\t<\/div>\r\n\t<\/div>\r\n<\/div>\r\n\n\n<div data-acfblock=\"Uitklapper-1\" class=\"section section--grey\">\r\n\t<div class=\"container\">\r\n\t\t<div class=\"row justify-content-center\">\r\n\t\t\t<div class=\"col editor  elementOnTop\">\r\n\t\t\t\t<div class=\"accordion\" id=\"accordion1\">\r\n\t\t<div class=\"accordion-item\">\n\t\t  <h2 class=\"accordion-header\" id=\"heading-u1-i1\">\n\t\t\t<button class=\"accordion-button collapsed\" type=\"button\" data-bs-toggle=\"collapse\" data-bs-target=\"#collapse-u1-i1\" aria-expanded=\"false\" aria-controls=\"collapse-u1-i1\">\n\t\t\t  <span class=\"accordion-toggle\"><\/span>Exceptions to the remuneration scheme\t\t\t<\/button>\n\t\t  <\/h2>\n\t\t  <div id=\"collapse-u1-i1\" class=\"accordion-collapse collapse\" aria-labelledby=\"heading-u1-i1\">\n\t\t\t<div class=\"accordion-body\">\n\t\t\t  <p>In the case of a vulnerability involving a low or accepted risk, the Municipality of Apeldoorn may decide not to offer a reward for a report. Below are some examples of such vulnerabilities. This list is not exhaustive.<\/p>\n<ul>\n<li>HTTP 404 codes or other non-HTTP 200 codes.<\/li>\n<li>Adding plain text to 404 pages.<\/li>\n<li>Version banners on public services.<\/li>\n<li>Files and folders containing non-sensitive information that are accessible to the public.<\/li>\n<li>Clickjacking on pages without a login function.<\/li>\n<li>Certificates with weak or outdated ciphers.<\/li>\n<li>Cross-site request forgery (CSRF) on forms that can be accessed anonymously.<\/li>\n<li>Absence of \u2018secure\u2019 \/ \u2018HTTP Only\u2019 flags on non-sensitive cookies.<\/li>\n<li>Using the HTTP OPTIONS method.<\/li>\n<li>Host Header Injection.<\/li>\n<li>Absence of SPF, DKIM and DMARC records.<\/li>\n<li>One or more HTTP security headers are missing.<\/li>\n<li>Support for \u2018auto-complete\u2019 or \u2018save password\u2019 functions. Brute-force attacks on the \u2018forgot password\u2019 form and \u2018account lockout\u2019 are not prevented.<\/li>\n<li>The absence of a confirmation step, such as re-entering a password or requesting an additional email confirmation.<\/li>\n<li>The absence of HTTP Public Key Pinning (HPKP).<\/li>\n<li>Content spoofing and text injection on pages displaying an error message.<\/li>\n<li>Reporting old software versions without a proof-of-concept or a working exploit.<\/li>\n<li>Expired or inactive domain names.<\/li>\n<li>Same-Site Scripting or use via a localhost DNS rule.<\/li>\n<li>Lack of DNSSEC.<\/li>\n<li>Potentially outdated server or application versions (from third parties) without evidence that these versions are vulnerable and without evidence of exploitation.<\/li>\n<li>Potentially outdated server or application versions (from third parties) without evidence that these versions are vulnerable and without evidence of exploitation.<\/li>\n<li>Missing or incorrectly configured HTTP security headers, such as:\n<ul>\n<li>Strict Transport Security (HSTS).<\/li>\n<li>HTTP Public Key Pinning (HPKP).<\/li>\n<li>Content Security Policy (CSP).<\/li>\n<li>X-Content-Type-Options.<\/li>\n<li>X-Frame-Options.<\/li>\n<li>X-WebKit-CSP.<\/li>\n<li>X-XSS-Protection.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>This text has been drawn up in accordance with the guidelines issued by the National Cyber Security Centre (NCSC).<\/p>\n\t\t\t<\/div>\n\t\t  <\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\r\n\t\t\t<\/div>\r\n\t\t<\/div>\r\n\t<\/div>\r\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The Municipality of Apeldoorn considers the security of its systems very important. As part of our commitment to cybersecurity and the...<\/p>","protected":false},"author":3,"featured_media":0,"parent":7181,"menu_order":16,"comment_status":"closed","ping_status":"closed","template":"verdiepend","meta":{"_acf_changed":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","ep_exclude_from_search":false,"footnotes":""},"categories":[],"tags":[],"folder":[],"class_list":["post-12552","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.1 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Coordinated Vulnerability Disclosure | Gemeente Apeldoorn<\/title>\n<meta name=\"description\" content=\"Ontdekte u een kwetsbaarheid in onze website? Meld dit via het Coordinated Vulnerability Disclosure-beleid van gemeente Apeldoorn.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Coordinated Vulnerability Disclosure (CVD)\" \/>\n<meta property=\"og:description\" content=\"Ontdekte u een kwetsbaarheid in onze website? Meld dit via het Coordinated Vulnerability Disclosure-beleid van gemeente Apeldoorn.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/\" \/>\n<meta property=\"og:site_name\" content=\"Apeldoorn\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/gemeenteapeldoorn\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-07T13:51:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.apeldoorn.nl\/wp-content\/uploads\/2026\/02\/gemeente-apeldoorn.png\" \/>\n\t<meta property=\"og:image:width\" content=\"696\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/coordinated-vulnerability-disclosure-cvd\\\/\",\"url\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/coordinated-vulnerability-disclosure-cvd\\\/\",\"name\":\"Coordinated Vulnerability Disclosure | Gemeente Apeldoorn\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/#website\"},\"datePublished\":\"2026-05-08T20:57:04+00:00\",\"dateModified\":\"2026-07-07T13:51:00+00:00\",\"description\":\"Ontdekte u een kwetsbaarheid in onze website? Meld dit via het Coordinated Vulnerability Disclosure-beleid van gemeente Apeldoorn.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/coordinated-vulnerability-disclosure-cvd\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/coordinated-vulnerability-disclosure-cvd\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/coordinated-vulnerability-disclosure-cvd\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.apeldoorn.nl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Over deze website\",\"item\":\"https:\\\/\\\/www.apeldoorn.nl\\\/over-deze-website\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Privacyverklaring Gemeente Apeldoorn\",\"item\":\"https:\\\/\\\/www.apeldoorn.nl\\\/privacy\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Coordinated Vulnerability Disclosure (CVD)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/\",\"name\":\"Gemeente Apeldoorn\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/#organization\",\"name\":\"Apeldoorn\",\"url\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.apeldoorn.nl\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/ape-logo-kleur.png\",\"contentUrl\":\"https:\\\/\\\/www.apeldoorn.nl\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/ape-logo-kleur.png\",\"width\":1877,\"height\":500,\"caption\":\"Apeldoorn\"},\"image\":{\"@id\":\"https:\\\/\\\/www.apeldoorn.nl\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/gemeenteapeldoorn\",\"https:\\\/\\\/www.instagram.com\\\/gemeenteapeldoorn\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/gemeente-apeldoorn\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Coordinated Vulnerability Disclosure | Gemeente Apeldoorn","description":"Ontdekte u een kwetsbaarheid in onze website? Meld dit via het Coordinated Vulnerability Disclosure-beleid van gemeente Apeldoorn.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/","og_locale":"en_GB","og_type":"article","og_title":"Coordinated Vulnerability Disclosure (CVD)","og_description":"Ontdekte u een kwetsbaarheid in onze website? Meld dit via het Coordinated Vulnerability Disclosure-beleid van gemeente Apeldoorn.","og_url":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/","og_site_name":"Apeldoorn","article_publisher":"https:\/\/www.facebook.com\/gemeenteapeldoorn","article_modified_time":"2026-07-07T13:51:00+00:00","og_image":[{"width":696,"height":500,"url":"https:\/\/www.apeldoorn.nl\/wp-content\/uploads\/2026\/02\/gemeente-apeldoorn.png","type":"image\/png"}],"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/","url":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/","name":"Coordinated Vulnerability Disclosure | Gemeente Apeldoorn","isPartOf":{"@id":"https:\/\/www.apeldoorn.nl\/en\/#website"},"datePublished":"2026-05-08T20:57:04+00:00","dateModified":"2026-07-07T13:51:00+00:00","description":"Ontdekte u een kwetsbaarheid in onze website? Meld dit via het Coordinated Vulnerability Disclosure-beleid van gemeente Apeldoorn.","breadcrumb":{"@id":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.apeldoorn.nl\/en\/coordinated-vulnerability-disclosure-cvd\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.apeldoorn.nl\/"},{"@type":"ListItem","position":2,"name":"Over deze website","item":"https:\/\/www.apeldoorn.nl\/over-deze-website\/"},{"@type":"ListItem","position":3,"name":"Privacyverklaring Gemeente Apeldoorn","item":"https:\/\/www.apeldoorn.nl\/privacy\/"},{"@type":"ListItem","position":4,"name":"Coordinated Vulnerability Disclosure (CVD)"}]},{"@type":"WebSite","@id":"https:\/\/www.apeldoorn.nl\/en\/#website","url":"https:\/\/www.apeldoorn.nl\/en\/","name":"Municipality of Apeldoorn","description":"","publisher":{"@id":"https:\/\/www.apeldoorn.nl\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.apeldoorn.nl\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.apeldoorn.nl\/en\/#organization","name":"Apeldoorn","url":"https:\/\/www.apeldoorn.nl\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.apeldoorn.nl\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.apeldoorn.nl\/wp-content\/uploads\/2026\/02\/ape-logo-kleur.png","contentUrl":"https:\/\/www.apeldoorn.nl\/wp-content\/uploads\/2026\/02\/ape-logo-kleur.png","width":1877,"height":500,"caption":"Apeldoorn"},"image":{"@id":"https:\/\/www.apeldoorn.nl\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/gemeenteapeldoorn","https:\/\/www.instagram.com\/gemeenteapeldoorn\/","https:\/\/www.linkedin.com\/company\/gemeente-apeldoorn"]}]}},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.apeldoorn.nl\/en\/author\/houwinn\/","display_name":"Nicky Houwing"},"relative_dates":{"created":"Posted 2 months ago","modified":"Updated 2 weeks ago"},"absolute_dates":{"created":"Posted on 8 May 2026","modified":"Updated on 7 July 2026"},"absolute_dates_time":{"created":"Posted on 8 May 2026 22:57","modified":"Updated on 7 July 2026 15:51"},"featured_img_caption":"","featured_img":false,"series_order":"","publishpress_future_action":{"enabled":false,"date":"2026-10-22 08:44:40","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/pages\/12552","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/comments?post=12552"}],"version-history":[{"count":2,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/pages\/12552\/revisions"}],"predecessor-version":[{"id":12648,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/pages\/12552\/revisions\/12648"}],"up":[{"embeddable":true,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/pages\/7181"}],"wp:attachment":[{"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/media?parent=12552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/categories?post=12552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/tags?post=12552"},{"taxonomy":"folder","embeddable":true,"href":"https:\/\/www.apeldoorn.nl\/en\/wp-json\/wp\/v2\/folder?post=12552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}