|
1 | 1 | # Security |
2 | 2 |
|
3 | | -NHS Digital takes security and the protection of private data extremely |
4 | | -seriously. If you believe you have found a vulnerability or other issue which |
5 | | -has compromised or could compromise the security of any of our systems and/or |
6 | | -private data managed by our systems, please do not hesitate to contact us using |
7 | | -the methods outlined below. |
| 3 | +NHS England takes security and the protection of private data extremely seriously. If you believe you have found a vulnerability or other issue which has compromised or could compromise the security of any of our systems and/or private data managed by our systems, please do not hesitate to contact us using the methods outlined below. |
| 4 | + |
| 5 | +## Table of Contents |
| 6 | + |
| 7 | +- [Security](#security) |
| 8 | + - [Table of Contents](#table-of-contents) |
| 9 | + - [Reporting a vulnerability](#reporting-a-vulnerability) |
| 10 | + - [Email](#email) |
| 11 | + - [NCSC](#ncsc) |
| 12 | + - [General Security Enquiries](#general-security-enquiries) |
8 | 13 |
|
9 | 14 | ## Reporting a vulnerability |
10 | | -**PLEASE NOTE: Email and HackerOne are our preferred methods of receiving |
11 | | -reports.** |
| 15 | + |
| 16 | +Please note, email is our preferred method of receiving reports. |
12 | 17 |
|
13 | 18 | ### Email |
14 | | -If you wish to notify us of a vulnerability via email, please include detailed |
15 | | -information on the nature of the vulnerability and any steps required to |
16 | | -reproduce it. |
| 19 | + |
| 20 | +If you wish to notify us of a vulnerability via email, please include detailed information on the nature of the vulnerability and any steps required to reproduce it. |
17 | 21 |
|
18 | 22 | You can reach us at: |
19 | | -* cybersecurity@nhs.net |
20 | | -* api.management@nhs.net |
21 | 23 |
|
22 | | -### HackerOne |
23 | | -If you are registered with HackerOne and have been admitted to the NHS |
24 | | -Programme, you can report directly to us at: https://hackerone.com/nhs |
| 24 | +- [epssupport@nhs.net](epssupport@nhs.net) |
| 25 | +- [cybersecurity@nhs.net](cybersecurity@nhs.net) |
25 | 26 |
|
26 | 27 | ### NCSC |
27 | | -You can send your report to the National Cyber Security Centre, who will assess |
28 | | -your report and pass it on to NHS Digital if necessary. |
29 | 28 |
|
30 | | -You can report vulnerabilities here: |
31 | | -https://www.ncsc.gov.uk/information/vulnerability-reporting |
| 29 | +You can send your report to the National Cyber Security Centre, who will assess your report and pass it on to NHS England if necessary. |
32 | 30 |
|
33 | | -### OpenBugBounty |
34 | | -We also accept bug reports via OpenBugBounty: https://www.openbugbounty.org/ |
| 31 | +You can report vulnerabilities here: [https://www.ncsc.gov.uk/information/vulnerability-reporting](https://www.ncsc.gov.uk/information/vulnerability-reporting) |
35 | 32 |
|
36 | 33 | ## General Security Enquiries |
37 | | -If you have general enquiries regarding our cyber security, please reach out |
38 | | -to us at cybersecurity@nhs.net |
| 34 | + |
| 35 | +If you have general enquiries regarding our cybersecurity, please reach out to us at [cybersecurity@nhs.net](cybersecurity@nhs.net) |
0 commit comments