Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Documenting your security contact information

"A clear statement of the policies and procedures of a CSIRT helps the constituent understand how best to report incidents and what support to expect afterwards.  Will the CSIRT assist in resolving the incident?   Will it provide help in avoiding incidents in the future? Clear expectations, particularly of the limitations of the services provided by a CSIRT, will make interaction with it more efficient and effective." - if you (infrastructure, collaboration, identity source) have a means to publish information, do so. 

  1. publish a 'security.txt' file in its well-known location: https://example.com/.well-known/security.txt
  2. write the brief description of the security team in RFC2350 format.

Well-known collaboration platform operators and security contacts

...