TTS issued the vulnerability disclosure policy in an effort to assure security researchers that GSA will not initiate legal action under the Computer Fraud and Abuse Act for research efforts that are considered âauthorized,â according to a blog post published Nov. 22 on 18F website.
The policy covers five TTS-operated systems that include vote.gov, analytics.usa.gov, calc.gsa.gov, micropurchase.18f.gov and 18f.gsa.gov.
GSAâs TTS wants security researchers to avoid privacy violations and disruption to production systems as well as keep the use of exploits âto the extent necessary to confirm a vulnerability.”
Security researchers should maintain the confidentiality of identified vulnerabilities 90 days after submission of notification reports to TTS, according to the policy.
The Defense Department also introduced a vulnerability disclosure policy that aims to facilitate reporting of cyber vulnerabilities in DoD websites.