Skip to content

Commit 818be7b

Browse files
mesh-2922: security.md
1 parent 401daa6 commit 818be7b

1 file changed

Lines changed: 23 additions & 36 deletions

File tree

SECURITY.md

Lines changed: 23 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -1,38 +1,25 @@
11
# Security
22

3-
NHS Digital takes security and the protection of private data extremely
4-
seriously. If you believe you have found a vulnerability or other issue which
5-
has compromised or could compromise the security of any of our systems and/or
6-
private data managed by our systems, please do not hesitate to contact us using
7-
the methods outlined below.
8-
9-
## Reporting a vulnerability
10-
**PLEASE NOTE: Email and HackerOne are our preferred methods of receiving
11-
reports.**
12-
13-
### Email
14-
If you wish to notify us of a vulnerability via email, please include detailed
15-
information on the nature of the vulnerability and any steps required to
16-
reproduce it.
17-
18-
You can reach us at:
19-
* cybersecurity@nhs.net
20-
* api.management@nhs.net
21-
22-
### HackerOne
23-
If you are registered with HackerOne and have been admitted to the NHS
24-
Programme, you can report directly to us at: https://hackerone.com/nhs
25-
26-
### NCSC
27-
You can send your report to the National Cyber Security Centre, who will assess
28-
your report and pass it on to NHS Digital if necessary.
29-
30-
You can report vulnerabilities here:
31-
https://www.ncsc.gov.uk/information/vulnerability-reporting
32-
33-
### OpenBugBounty
34-
We also accept bug reports via OpenBugBounty: https://www.openbugbounty.org/
35-
36-
## General Security Enquiries
37-
If you have general enquiries regarding our cyber security, please reach out
38-
to us at cybersecurity@nhs.net
3+
We take security and the protection of private data extremely seriously. If you believe you have found a vulnerability or other issue which has compromised or could compromise the security of any of our systems or private data managed by our systems, please do not hesitate to contact us using the method outlined below.
4+
5+
## Table of contents
6+
7+
- [Security](#security)
8+
- [Responsible Disclosure](#responsible-disclosure)
9+
- [Scope](#scope)
10+
- [Response Process/Expectations](response-process-and-expectations)
11+
- [Report a cyber security incident](report-a-cyber-security-incident)
12+
13+
## Responsible Disclosure
14+
15+
To learn more about responsible disclosure of security incidents you can read our [Security vulnerability disclosure policy](https://digital.nhs.uk/cyber-and-data-security/security-vulnerability-disclosure). This policy covers things like the scope and response SLAs
16+
17+
## Report a cyber security incident
18+
19+
Request immediate support for a cyber security issue - call [0300 303 5222](tel:0300 303 5222) (monitored 24/7).
20+
21+
Report an urgent cyber security issue by [logging a ServiceNow ticket](https://nhsdigitallive.service-now.com/csm?id=sc_cat_item&sys_id=0122c5351b280110892d4046b04bcb16&referrer=recent_items) and attaching all relevant details.
22+
23+
If you have found a vulnerability in an NHS system, [report it via our Vulnerability Disclosure Programme](https://digital.nhs.uk/cyber-and-data-security/security-vulnerability-disclosure).
24+
25+
For general cyber operations queries email [cybersecurity@nhs.net](mailto:cybersecurity@nhs.net).

0 commit comments

Comments
 (0)