View Document

Vulnerability Disclosure Policy

This is the current version of this document. You can provide feedback on this document to the document author - refer to the Status and Details on the document's navigation bar.

Section 1 - Purpose

(1) This Policy outlines the University’s Security Vulnerability disclosure program, which aims to provide a method for users to notify the University of any identified or suspected security vulnerabilities within the University’s IT Resources or products.

Scope

(2) This Policy applies to any user with lawful access to Macquarie University’s (the University’s) IT Resources or products provided by the University. This includes:

  1. staff employed by the University and its controlled entities;
  2. students of the University including former students; and
  3. affiliates including contractors, agents, honorary, clinical or adjunct appointees and consultants of the University.
Those listed above will be known as Users for the purpose of this Policy.

Background

(3) The University is committed to maintaining a secure technology environment and as such, believes in the responsible disclosure of potential security vulnerabilities. By establishing an official reporting channel, the University aims to remediate security vulnerabilities and therefore decrease the likelihood of malicious exploitation.

Top of Page

Section 2 - Policy

Reporting Protection

(4) To encourage responsible reporting, the University will not take legal action against a User who reports a Security Vulnerability, so long as the report is made in accordance with the requirements of this Policy.

Unauthorised Conduct

(5) Any User with access to the University’s IT Resources must comply with Australian law, and not compromise or exploit the University’s Information, personnel, infrastructure or operations. The following actions are not authorised, unless specifically approved by the University:

  1. engaging in unlawful or unethical behaviour;
  2. disclosing Security Vulnerability information publicly;
  3. engaging in physical testing;
  4. leveraging deceptive techniques (e.g., Social Engineering);
  5. executing resource exhaustion attacks (g., Distributed Denial of Service);
  6. leveraging automated vulnerability assessment tools;
  7. introducing malicious software that could negatively impact the University;
  8. reverse engineering the University’s products or IT Resources;
  9. modifying, destroying, or exfiltrating the University’s Information;
  10. hacking or penetration testing the University’s IT Resources; and
  11. accessing or attempting to access University accounts or Information.

Vulnerability Assessment & Mitigation

(6) Upon receiving a Security Vulnerability report, the University will:

  1. analyse and evaluate the Security Vulnerability to determine its validity and potential impact to the University; and
  2. take appropriate action to mitigate the Security Vulnerability.
Top of Page

Section 3 - Procedures

How to Report

(7) A potential Security Vulnerability can be reported to cyber@mq.edu.au and should contain the following information (where possible):

  1. a detailed explanation of the potential Security Vulnerability;
  2. the name of the product(s) and/or IT Resource(s) that may be affected;
  3. the number of potential end Users affected;
  4. detailed steps taken to identify and reproduce the potential Security Vulnerability;
  5. evidence (g., proof-of-concept code/scripts, screenshots, screen recordings); and
  6. the contact details of the reporter and whether they wish to be publicly acknowledged.

Outcome

(8) The University will:

  1. respond to the User acknowledging receipt of the report within 2 weeks;
  2. request additional information regarding the Security Vulnerability (if required); and
  3. keep the User informed of the progress if requested.

(9) The University will not:

  1. provide any financial compensation for the disclosure of a Security Vulnerability; or
  2. share a User’s details without permission.
Top of Page

Section 4 - Guidelines

(10) Nil.

Top of Page

Section 5 - Definitions

(11) The following definitions apply for the purpose of this Policy:  

  1. Information means any information in either physical or electronic format that is generated, created, stored, purchased or received during the conduct of University operations.
  2. Information Technology Resources, or IT Resources, includes, but is not limited to:
    1. All computers and all associated data networks and systems, internet access and network bandwidth, email, hardware, data storage, computer accounts, all OneID systems, media, software (both proprietary and those developed by the University) and telephony services.
    2. Information Technology services provided jointly, or as part of a joint venture between the University and a research centre, school, institute affiliated with the University, a subsidiary organisation owned by the University or any other partner organisation.
    3. Information Technology services provided by third-parties that have been engaged by the University.
  3. Security Vulnerability means a weakness in an IT Resource that can be exploited for malicious purposes.