generated: '2026-09-14' method: searched source: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/ provider: National Council on Disability providerId: national-council-on-disability program: published: true name: NCD Vulnerability Disclosure Policy url: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/ pdf: https://www.ncd.gov/assets/uploads/docs/national-council-on-disability-vulnerability-disclosure-policy-21-0601.pdf version: '1.0' issued: '2021-06-01' change_history: - version: '1.0' date: '2021-06-01' description: First issuance driver: >- CISA Binding Operational Directive 20-01, which directs US federal executive-branch agencies to publish a vulnerability disclosure policy. safe_harbor: offered: true statement: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized and we will work with you to understand and resolve the issue quickly, and NCD will not recommend or pursue legal action related to your research." third_party_support: >- NCD states it will make the authorization known if a third party initiates legal action over research conducted under this policy. scope: in_scope: - NCD.GOV - NCD systems or services out_of_scope: - Any connected service not expressly listed - Vulnerabilities in vendor systems (report to the vendor directly) prohibited_methods: - Network denial of service (DoS/DDoS) or any test that impairs access or damages a system or data - Physical testing (office access, open doors, tailgating) - Social engineering (phishing, vishing) or other non-technical vulnerability testing reporting: channel: email address: security@agency.gov anonymous_accepted: true pgp_supported: false sensitive_submission_url: https://ncd.gov/about acknowledgement_sla: 3 business days escalation: >- Reports affecting all users of a product or service (not solely NCD) may be shared with CISA and handled under its coordinated vulnerability disclosure process. NCD states it will not share reporter name or contact information without express permission. disclosure: researcher_embargo_days: 90 vendor_notification_schedule: - Initial attempt when the vulnerability is identified - Second attempt no less than one week after the initial attempt - Third attempt no less than two weeks after the initial attempt cert_escalation_days: 45 cert_bodies: - CERT/CC - ICS-CERT - national CERT bug_bounty: offered: false note: No monetary bounty, platform (HackerOne/Bugcrowd/Intigriti) or hall of fame is offered. security_txt: published: false probed: - url: https://www.ncd.gov/.well-known/security.txt status: 404 - url: https://ncd.gov/.well-known/security.txt status: 404 findings: - severity: defect finding: >- The reporting address published in the policy is "security@agency.gov" — the literal placeholder from the CISA BOD 20-01 / vulnerability-disclosure-policy-template, never replaced with an ncd.gov mailbox. A researcher following the policy as written would mail a domain NCD does not control. Verified in both the HTML page and the linked PDF text as the only email address the document contains. evidence: https://www.ncd.gov/accountability/vulnerability-disclosure-policy/ - severity: gap finding: >- No /.well-known/security.txt (RFC 9116) on either host, so the policy is discoverable only by browsing the Accountability section — automated scanners and agents will not find it. The policy also sits at /accountability/vulnerability-disclosure-policy/ rather than the /vulnerability-disclosure-policy path BOD 20-01 names (that path 404s). evidence: https://www.ncd.gov/vulnerability-disclosure-policy/ - severity: gap finding: >- The sensitive-submission fallback points at https://ncd.gov/about, which serves a client-side meta-refresh redirect page rather than a submission form. evidence: https://ncd.gov/about maintainers: - FN: Kin Lane email: kin@apievangelist.com