Information Security and Coordinated Vulnerability Disclosure
The Netherlands Cancer Institute attaches great importance to the safety of its (medical) equipment, software and services. Despite the care taken to ensure its security, it is possible that there is still a vulnerability. If you discover such a vulnerability, you can report it to us confidentially. This approach is called Coordinated Vulnerability Disclosure. In this way, the NKI can take protective measures.
Reporting a vulnerability
Report a vulnerability
If you have found a vulnerability, we would like to hear from you immediately. This enables us to take any measures as quickly as possible. The NKI would like to work with you to protect our customers and systems even better.
Our Coordinated Vulnerability Disclosure policy is not an invitation to actively scan our company network (our systems) extensively for vulnerabilities. We constantly monitor our network. As a result, there is a good chance that a scan will be noticed by our IT department and that an investigation will be started, which will incur unnecessary costs.
If you report vulnerabilities to us via our Coordinated Vulnerability Disclosure policy, we have no reason to attach legal consequences to your report. We ask you to adhere to the following rules:
- You should report your findings to the Z-CERT Foundation, preferably via this CVD form or otherwise by sending an e-mail to cvd@z-cert.nl. You can use the PGP key for this. The Z-CERT Foundation is the organisation that handles Coordinated Vulnerability Disclosure reports for the NKI. The foundation works together with you as a reporter and with the NKI to ensure that your report is dealt with.
- In your report, you provide sufficient information so that the problem can be reproduced. That way we can solve it as quickly as possible. Usually the IP address or URL of the affected system and a description of the vulnerability are sufficient, but with more complex vulnerabilities more information is sometimes desired/necessary.
- You do not abuse the vulnerability that has been identified. For example, by downloading more data than is necessary to demonstrate the leak or by viewing, deleting or modifying data from third parties.
- If you suspect that you can view medical data through a vulnerability, we ask you not to verify this yourself but to have us do this for you.
- You do not share your findings with others until the vulnerability has been resolved. In addition, we ask you to immediately delete all confidential data you have obtained after closing the leak.
- You will not attack(s) our physical security and will not use social engineering, distributed denial of service, spam, brute-force attacks and/or third-party applications.
How we handle your report:
- The NKI and Z-CERT will treat your report confidentially and will not share your personal data with third parties without your consent, unless this is required by law.
- You will receive a confirmation of receipt from Z-CERT and within 3 working days you will receive a response to your report with an assessment of the report and an expected date for a solution.
- As the reporter of the problem, Z-CERT will keep you informed of the progress of resolving the problem.
- Any reporter of a non-trivial security problem will be listed in the hall of fame if he/she appreciates it. In exceptional cases, depending on the nature of the report, we may also decide to provide the reporter with a reward.
We strive to resolve security issues as quickly as possible. Together, after the security problem has been resolved, we discuss the added value of a possible publication about it.
This text describes the responsible disclosure policy of the Netherlands Cancer Institute as a supplement to the responsible disclosure guideline (publication date 2-10-2018) published by the NCSC.
Hall of fame
In the NKI Hall of Fame , the NKI includes people who have reported a vulnerability or problem in the security of our systems. In doing so, they followed the Coordinated Responsible Disclosure policy. The NKI is grateful to the reporters, because thanks to their report, our security can be further improved.
Out of scope statement
The NKI does not reward trivial vulnerabilities or bugs that cannot be exploited. Below are examples of known or trivial vulnerabilities and accepted risks, which fall outside the scope of the above regulation:
- HTTP 404 codes/pages or other HTTP non-200 codes/pages and content spoofing/text injection on these pages
- Fingerprinting/version listing on public services
- Public files or directories containing non-sensitive information (e.g., robots.txt)
- Clickjacking and problems that can only be exploited through clickjacking
- No secure/HTTP-only flags on non-sensitive cookies
- OPTIONS HTTP method enabled
- Rate limiting vulnerabilities with no apparent impact
- Everything related to HTTP security headers, for example:
- Strict-Transport-Securit
- X-Frame-Options
- X-XSS-Protection
- X-Content-Type-Options
- Content-Security-Policy
- SSL configuration issues
- SSL Forward secrecy disabled
- weak/insecure cipher suites
- Issues with SPF, DKIM or DMARC
- Host header injection
- Reporting outdated versions of any software without a proof of concept of a working exploit
- Information exposure in metadata
General information security policy
The Netherlands Cancer Institute has an up-to-date information security policy. Interested parties can view this document at our visiting address. If you wish to make use of this option, please contact informatiebeveiliging@nki.nl to make an appointment.
nl