Skip to content

Commit c8cb39a

Browse files
author
Laurence Joseph Pakenham-Smith
authored
Merge pull request #44 from NHSDigital/apm-2541-add-security.md
APM-2541 Add SECURITY.md
2 parents 866c3f9 + 70324e3 commit c8cb39a

File tree

1 file changed

+38
-0
lines changed

1 file changed

+38
-0
lines changed

SECURITY.md

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
# Security
2+
3+
NHS Digital takes security and the protection of private data extremely
4+
seriously. If you believe you have found a vulnerability or other issue which
5+
has compromised or could compromise the security of any of our systems and/or
6+
private data managed by our systems, please do not hesitate to contact us using
7+
the methods outlined below.
8+
9+
## Reporting a vulnerability
10+
**PLEASE NOTE: Email and HackerOne are our preferred methods of receiving
11+
reports.**
12+
13+
### Email
14+
If you wish to notify us of a vulnerability via email, please include detailed
15+
information on the nature of the vulnerability and any steps required to
16+
reproduce it.
17+
18+
You can reach us at:
19+
* cybersecurity@nhs.net
20+
* api.management@nhs.net
21+
22+
### HackerOne
23+
If you are registered with HackerOne and have been admitted to the NHS
24+
Programme, you can report directly to us at: https://hackerone.com/nhs
25+
26+
### NCSC
27+
You can send your report to the National Cyber Security Centre, who will assess
28+
your report and pass it on to NHS Digital if necessary.
29+
30+
You can report vulnerabilities here:
31+
https://www.ncsc.gov.uk/information/vulnerability-reporting
32+
33+
### OpenBugBounty
34+
We also accept bug reports via OpenBugBounty: https://www.openbugbounty.org/
35+
36+
## General Security Enquiries
37+
If you have general enquiries regarding our cyber security, please reach out
38+
to us at cybersecurity@nhs.net

0 commit comments

Comments
 (0)