Machine-Readable VDP, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to implement a machine-readable vulnerability disclosure policy (VDP), e.g., in a 'security.txt' file, for accessibility by vulnerability researchers.

Assessment Step

1
Machine-Readable VDP (Machine-ReadableVDP)
Does the organization implement a machine-readable vulnerability disclosure policy (VDP), e.g., in a 'security.txt' file, for accessibility by vulnerability researchers?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Machine-Readable VDP
The organization must implement a machine-readable vulnerability disclosure policy (VDP), e.g., in a 'security.txt' file, for accessibility by vulnerability researchers.
Citation
SBDP
(doc)