At CSI, our mission is to empower our clients to achieve success through secure, innovative, and reliable technology solutions. We partner with organizations to capture, process, and share critical information, enabling smarter decisions and sustainable growth. Our commitment is to protect the confidentiality, integrity, and availability of every system and piece of data we manage, ensuring trust, resilience, and exceptional service that drives our customers’ success.
CSI recognizes that external vulnerabilities can be discovered by anyone at any time and has issued this program to provide clear guidelines to security researchers so that they feel comfortable reporting vulnerabilities they have discovered in good faith.
This vulnerability disclosure program facilitates CSI’s awareness of otherwise unknown vulnerabilities. This Program is intended to give security researchers clear guidelines for conducting vulnerability discovery and disclosure activities to help CSI meet its objectives, and to convey how to submit discovered vulnerabilities to CSI. This program describes:
- What systems and types of research are covered under this program,
- General guidelines for demonstrating good faith,
- How to submit vulnerability reports, and
- What to expect following a vulnerability report.
Systems
This program applies to all CSI-managed systems that are accessible from the Internet.
CSI internal-only services are not in scope and are not authorized for testing. Additionally, vulnerabilities found in non-federal systems from our vendors and contractors fall outside of this Program’s scope and should be reported directly to the vendor or contractor according to their disclosure Program (if any).
Non-public CSI data is not authorized to reside on public third-party services. Although the third-party services themselves are not in scope, please report these data issues to CSI. The following types of non-public data are particularly sensitive, and warrant immediate reporting:
- Sensitive Personally Identifiable Information or PII (e.g., social security numbers)
- Financial information (e.g., credit card or bank account numbers)
- Proprietary information or trade secrets of companies of any party
Types of Testing
The following test types are NOT authorized:
- Social engineering-based attacks (e.g., getting a user to click an attacker-controlled link).
- Denial of Service, Rate Limiting, or Spamming issues (e.g., layer 7 DOS attacks, Slowloris, etc.).
- Clickjacking on pages with no sensitive actions.
- Any reports with the endpoint /wp-json/wp/v2/users
- Any reports with the endpoint xmlrpc.php
- Attacks requiring physical access to a user’s device
- Previously known vulnerable libraries without a working proof of concept.
- Content spoofing or text injection
- Reports from automated tools or scans without accompanying demonstration of exploitability
- Software version disclosure without accompanying demonstration of exploitability.
- Use of a known-vulnerable library without evidence of exploitability.
- Insecure SSL or TLS issues (e.g., ciphers, certificates, etc.).
- Missing security headers (e.g., HTTP Strict-Transport-Security (HSTS), Content Security Policy (CSP), etc.) that do not lead directly to a vulnerability.
- Presence of the “autocomplete” attribute on web forms.
- Host header injections unless you can show how they can lead to stealing data
- Insecure cookie settings for non-sensitive cookies.
- Directory Listing
- Vulnerabilities affecting users of outdated browsers or platforms.
- Issues related to descriptive or verbose error messages.
- Any other non-technical vulnerability testing
Guidelines
CSI requests that security researchers make every effort to:
- Avoid impacting the availability of production systems.
- Notify CSI via the methods described in the program as soon as possible after the discovery of a potential security issue.
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction, modification, or exfiltration of CSI data.
- Only use exploits to the extent necessary to confirm the presence of a vulnerability. Do not use an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or leverage the exploit to “pivot” to other systems.
- Once it is established that a vulnerability exists or any sensitive data is encountered (including personally identifiable information, financial information, proprietary information, or trade secrets of any party), you must stop your test, CSI must be notified immediately, and details of the vulnerability or sensitive data shall not be disclosed to anyone else.
No compensation is available, other than CSI’s gratitude for your help improving our security posture. By submitting a vulnerability report, you waive all claims to compensation.
Authorization
If a security researcher makes a good faith effort to comply with this program during security research, CSI will consider that research to be authorized, and will work with them to understand and resolve the issue quickly. In addition, CSI will not recommend or pursue legal action related to the research. Should legal action be initiated by a third party against a security researcher for activities that were conducted in accordance with this program, CSI will make this authorization known.
Reporting a Vulnerability
This submission form is the official channel to report vulnerabilities for CSI systems, please refrain from submitting vulnerabilities via other avenues.
This reporting mechanism is not intended for use by CSI employees, contractors, and others with authorized IT access at CSI. CSI personnel should use CSI-internal IT support and reporting mechanisms rather than this program.
Information submitted under this program will be used for defensive purposes only – to mitigate or remediate vulnerabilities.