Skip to content

Commit 3bc5728

Browse files
authored
Docs: [AEA-4303] - update security.md (#152)
## Summary - Routine Change ### Details - update SECURITY.md
1 parent db04fff commit 3bc5728

File tree

1 file changed

+20
-23
lines changed

1 file changed

+20
-23
lines changed

SECURITY.md

Lines changed: 20 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -1,38 +1,35 @@
11
# Security
22

3-
NHS Digital takes security and the protection of private data extremely
4-
seriously. If you believe you have found a vulnerability or other issue which
5-
has compromised or could compromise the security of any of our systems and/or
6-
private data managed by our systems, please do not hesitate to contact us using
7-
the methods outlined below.
3+
NHS England takes security and the protection of private data extremely seriously. If you believe you have found a vulnerability or other issue which has compromised or could compromise the security of any of our systems and/or private data managed by our systems, please do not hesitate to contact us using the methods outlined below.
4+
5+
## Table of Contents
6+
7+
- [Security](#security)
8+
- [Table of Contents](#table-of-contents)
9+
- [Reporting a vulnerability](#reporting-a-vulnerability)
10+
- [Email](#email)
11+
- [NCSC](#ncsc)
12+
- [General Security Enquiries](#general-security-enquiries)
813

914
## Reporting a vulnerability
10-
**PLEASE NOTE: Email and HackerOne are our preferred methods of receiving
11-
reports.**
15+
16+
Please note, email is our preferred method of receiving reports.
1217

1318
### Email
14-
If you wish to notify us of a vulnerability via email, please include detailed
15-
information on the nature of the vulnerability and any steps required to
16-
reproduce it.
19+
20+
If you wish to notify us of a vulnerability via email, please include detailed information on the nature of the vulnerability and any steps required to reproduce it.
1721

1822
You can reach us at:
19-
* cybersecurity@nhs.net
20-
* api.management@nhs.net
2123

22-
### HackerOne
23-
If you are registered with HackerOne and have been admitted to the NHS
24-
Programme, you can report directly to us at: https://hackerone.com/nhs
24+
- [epssupport@nhs.net](epssupport@nhs.net)
25+
- [cybersecurity@nhs.net](cybersecurity@nhs.net)
2526

2627
### NCSC
27-
You can send your report to the National Cyber Security Centre, who will assess
28-
your report and pass it on to NHS Digital if necessary.
2928

30-
You can report vulnerabilities here:
31-
https://www.ncsc.gov.uk/information/vulnerability-reporting
29+
You can send your report to the National Cyber Security Centre, who will assess your report and pass it on to NHS England if necessary.
3230

33-
### OpenBugBounty
34-
We also accept bug reports via OpenBugBounty: https://www.openbugbounty.org/
31+
You can report vulnerabilities here: [https://www.ncsc.gov.uk/information/vulnerability-reporting](https://www.ncsc.gov.uk/information/vulnerability-reporting)
3532

3633
## General Security Enquiries
37-
If you have general enquiries regarding our cyber security, please reach out
38-
to us at cybersecurity@nhs.net
34+
35+
If you have general enquiries regarding our cybersecurity, please reach out to us at [cybersecurity@nhs.net](cybersecurity@nhs.net)

0 commit comments

Comments
 (0)