Responsible Disclosure
At the Municipality of Moerdijk, we take the security of our systems very seriously. Despite our efforts to ensure the security of our systems, there may still be a vulnerability.
If you have found a vulnerability in one of our systems, please let us know so that we can take action as soon as possible. We would like to work with you to better protect our systems.
Please note!Not all reports will be processed. See the "See also" section on the right for a list of vulnerabilities that fall within and outside the scope of our policy:
We ask you:
- Please submit your findings via certified email. Be sure to include your contact information (email address and/or phone number) and specify that this concerns a vulnerability at the Municipality of Moerdijk.
- Do not exploit the vulnerability by, for example, downloading more data than is necessary to demonstrate the vulnerability or by viewing, deleting, or modifying third-party data.
- Delete all confidential data obtained through the breach immediately after the breach is reported.
- Do not use attacks targeting physical security, social engineering, spam, brute-force attacks, or third-party applications. The municipality also asks that you refrain from using techniques that reduce the availability and/or usability of the system or the service.
- Do not post, send, upload, link to, transmit, or store any malicious software.
- Do not test anything that would result in the sending of unsolicited or unauthorized junk email, spam, or other forms of unsolicited messages.
- Do not run automatic scans without consulting us first.
- Do not conduct tests in a way that would compromise the effectiveness of the solutions we use.
- Do not disclose a vulnerability within 30 days after we have resolved it, and do not do so without our prior written consent. Also, do not include any sensitive information in the disclosed vulnerability.
- Please provide enough information to reproduce the issue so that we can resolve it as quickly as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability, including the error message, are sufficient, but more information may be needed for more complex vulnerabilities.
What we promise:
- We will respond to your report within 5 business days with our assessment of the report and an estimated date for a resolution.
- If you have complied with the reporting requirements outlined above, the municipality will not take any legal action against you regarding the report.
- Your report will be treated confidentially, and your personal information will not be shared with third parties without your consent, unless the municipality is required to do so by law or by a court order. You may submit a report using a pseudonym.
- The security issue you reported will be resolved as soon as possible. However, the municipality is often dependent on external parties in this regard. The municipality will keep you informed of the progress.
- Whether and how the issue will be publicized after it has been resolved will be determined by mutual agreement and in consultation with the Municipal Information Security Service. If you wish, the municipality will list your name as the discoverer of the vulnerability in the “Hall of Fame” on its website.
- The municipality may offer you a reward as a token of appreciation for your help. Whether you receive a reward—and the amount of the reward—depends on the severity, the vulnerability involved, and the quality of the report. The municipality therefore evaluates each report on a case-by-case basis.
Legal Aspects
By submitting an entry to the Municipality of Moerdijk, you acknowledge that you have read and agree to the above terms and conditions. You also warrant that you are the creator of the entry and hereby grant us permission to use, reproduce, copy, modify, and otherwise dispose of your entry in any manner we deem necessary.
You agree that you will not use this disclosure for:
- for marketing or financing purposes
- as a reference in any personal or professional presentation
- in documentation or other materials;
In addition, you may not use the logo or name of the Municipality of Moerdijk in any way whatsoever in any form of communication related to this vulnerability report under Responsible Disclosure.
This policy is partly inspired by and partly based on the example found on the Responsible Disclosure website.