freelawproject / pacer-issues

A place to discuss and track issues and improvements with PACER
8 stars 1 forks source link

Establish a vulnerability disclosure policy #66

Open mlissner opened 4 years ago

mlissner commented 4 years ago

Describe the solution you'd like Vulnerability disclosure policies are a common and straightforward way to provide guidance to researchers that identify problems with websites. Among other things, such policies describe who to contact about an issue and how the issue will be handled. The Department of Justice’s Cybersecurity Unit recently published a framework for creating such policies. This framework would be an excellent starting point for the AO in creating their own.

Additional context https://free.law/2017/08/09/more-details-on-the-pacer-vulnerability-we-shared-with-the-administrative-office-of-the-courts/