Select Page

WiCyS

Vulnerability Disclosure & Handling

Vulnerability Disclosure Statement

Women in CyberSecurity (WiCyS) is committed to maintaining the safety and security of our systems, partners, and our members’ information. We value the role the independent security research community plays in internet security. We encourage responsible reporting of potential security vulnerabilities in any system or asset within the WiCyS ecosystem. Refer to the Vulnerability Rating Taxonomy (VRT) for processes and systems specifically out of scope. If there is a question about a system being in scope, an asset is not listed, do not test it without prior written authorization from WiCyS. If you accidentally encounter a potential vulnerability on an out-of-scope asset, stop testing and report it to WiCyS IT Team.

This policy outlines our submission process, including our guidelines for responsible disclosure, coordination, and the scope of what is authorized for testing.

Guidelines & Rules of Engagement

To promote a safe and productive environment for both WiCyS and our security research community, we require that all researchers submit any vulnerability information in full accordance with the following guidelines:

  • WiCyS will not respond to submissions made under threat of public disclosure, exposure of data, or withholding vulnerability information.
  • No data manipulation, copying, exporting, or sharing outside of WiCyS for the purpose of providing evidence when submitting the discovery
  • Do not engage in any activity that:
    • Can potentially cause harm to the WiCyS organization, staff, members, or external partners.
    • Potentially disrupt or degrade WiCyS products, systems, or assets.
    • Threats, extortion, or other tactics designed to elicit a response under duress.
    • Any activity that violates federal or state laws or regulations.
  • Denial of Service (DoS) attacks are strictly prohibited.
  • Do not store, share, compromise, or destroy data with the WiCyS ecosystems.
  • If Personal Identifiable Information (PII) of WiCyS members, proprietary financial data, strategic partner information, or received funding data is encountered, you must immediately halt your activity and contact the WiCyS IT Team, in addition to submitting the secure disclosure form.
  • Provide WiCyS a reasonable amount of time to fix any reported issue.
  • Maintain confidentiality for all findings and will not disclose publicly or to any third parties.

Scope & Vulnerability Taxonomy

Testing is limited to the systems managed by WiCyS or third party service providers, primarily our public website https://www.wicys.org, our member portal environment, and our specific implementations of connected integrations.

To help researchers understand how we prioritize findings, please review our Vulnerability Rating Taxonomy (VRT).

Strictly Out of Scope:

  • Vulnerabilities inherent to the underlying core infrastructure
  • Volumetric Attacks (DoS/DDoS)
  • Social Engineering (Phishing, vishing) or physical attacks against WiCyS staff or members
  • Third-Party Managed Apps

Vulnerability Reporting Process

If you believe you have found a vulnerability in a WiCyS system or asset, please submit the vulnerability information to us via the secure disclosure submission form.

To enable WiCyS to investigate and remedy the potential vulnerability effectively, please report it as soon as possible after discovery and provide a detailed summary, including:

  1. Vulnerability Name & Taxonomy Category (VTR)
  2. Affected system and/or Asset
  3. Description of the finding and how it was discovered
  4. Clear, step-by-step instructions to reproduce the potential vulnerability to enable our team to validate. (Proof of Concept scripts or screenshots are encouraged)
  5. Potential risk to WiCyS or its members

WiCyS IT will acknowledge receipt of your report, typically within 3 to 5 business days, excluding WiCyS and federally observed holidays.

Safe Harbor

We consider security research and vulnerability disclosure activities conducted entirely consistent with this policy to constitute “authorized” conduct.

To the extent that your activities conflict with the WiCyS Terms of Use and Privacy Policy, we waive those restrictions solely for the limited purpose of permitting good-faith security research under this policy. WiCyS will not pursue civil action or file a complaint with law enforcement for accidental, good-faith violations of this policy.

Note: We do not and will not authorize out-of-scope testing on our third-party service providers. If legal action is initiated by a third party against you, we will take steps to make it known that your actions were conducted in compliance with this statement, but we cannot grant Safe Harbor for systems we do not own.

Recognition

Although there is no monetary reward for this disclosure program, WiCyS understands the hard work that goes into security research. To show our appreciation for researchers who help keep our community secure, we recognize individuals who responsibly disclose validated vulnerabilities. If you are the first to disclose a qualifying vulnerability and consent to being acknowledged, we will credit your discovery by publishing your name on the WiCyS Security Hall of Fame on our website.