Coordinated Vulnerability Disclosure (CVD)
RDW strives for a high level of security. However, it is possible that an unexpected weakness may be found in the RDW system. If you discover a vulnerability, you can report it to RDW in accordance with the following agreements. You may hold RDW to this policy regarding Coordinated Vulnerability Disclosure.
Vulnerabilities in RDW ICT systems
Are you reporting a vulnerability in one of the systems of RDW, please do so before you share it with others. This will allow us to take measures first. This is referred to as 'Coordinated Vulnerability Disclosure' (CVD).
RDW would like to work with you to improve the security of ICT systems and therefore asks you to:
- inform us of the vulnerability immediately after discovering it, and send us your findings by e-mail: [email protected]
If possible, encrypt your findings with our PGP key to prevent information from falling into the wrong hands. - provide sufficient information to be able to reproduce the problem, so that we can rectify this as quickly as possible.
In most cases, the IP address or the URL of the system affected and a description of the vulnerability are sufficient, but more information may be required for more complex vulnerabilities. - leave your contact details so that our Security Operations Centre can contact you in order to jointly find a safe solution.
Leave at least an e-mail address or telephone number. - do not share the information regarding the security problem with other people until we have solved it.
- handle the information regarding the security problem responsibly by not performing any actions that go further than necessary to demonstrate the security problem.
- realize that disclosure of any information from RDW systems is punishable in certain cases and may lead to prosecution and/or a claim for damages.
This text has been prepared in accordance with the Coordinated Vulnerability Disclosure guidelines of the Dutch National Cyber Security Centre.