{"id":"98d48fa1-0ee2-4aaa-843b-35eb26f08fb7","engagementId":"9f64ef40-973c-493c-8e7b-17b9e737a170","data":{"brief":{"id":"4043c22c-9f18-44a1-900b-85e0290c7a82","name":"Equal Employment Opportunity Commission: Vulnerability Disclosure Program","tagline":"Report EEOC Vulnerabilities! ","description":"\u003cp\u003eThis policy provides a standard Equal Employment Opportunity Commission (EEOC), Office of the Information Technology (OIT) in support of the Commission’s commitment to protecting unwarranted disclosure of information. This policy describes which EEOC information systems (IS) are within the scope and defines accepted cybersecurity (CS) research that is covered under this policy, including how to send EEOC vulnerability reports, and how long we ask security researchers to delay publicly disclosing vulnerabilities. EEOC expects that the VDP will provide an independent assessment of the domain’s security and defense measures by potentially identifying vulnerabilities not found by existing penetration-team and automated efforts, non-compliance with cybersecurity guidance as well as training deficiencies. This policy is presented to ensure acceptance and acknowledgment of the existence of potential vulnerabilities, their assessment for security research purposes as well as the process in which they are to be provided to the Commission.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003eThough we may develop and maintain other internet-accessible systems or services, EEOC requests that active research and testing only be conducted on the systems and services covered by the scope of this policy. If there is a particular system not in scope that is discovered and potentially merits testing, please contact EEOC to discuss it first.\u003c/p\u003e\n\n\u003ch2\u003eACTION.\u003c/h2\u003e\n\n\u003cp\u003eAll citizens, researchers and EEOC Leadership shall ensure that staff are familiar with the following policies and guidelines, and that these are followed unless exceptions are formally approved.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe request that you:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNotify the Commission upon initiating active security vulnerability research within our scope.\u003c/li\u003e\n\u003cli\u003eNotify the Commission as soon as possible after you discover a real or potential security issue.\u003c/li\u003e\n\u003cli\u003eProvide EEOC ninety days to resolve the issue before you disclose it publicly.\u003c/li\u003e\n\u003cli\u003eComply with Privacy laws, making every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.\u003c/li\u003e\n\u003cli\u003eOnly use exploits to the extent necessary to confirm the presence of a vulnerability. Do not use or attempt to use an exploit to compromise or exfiltrate data, establish unauthorized access and/or persistence, or use the exploit to “pivot” to other systems.\u003c/li\u003e\n\u003cli\u003eOnce you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information (PII), financial information, or proprietary information or trade secrets of any party within our domain(s)), you must cease your test, notify EEOC immediately, and not disclose this data to any other individuals or entities.\u003c/li\u003e\n\u003cli\u003eRefrain from submission of misinformation or a high volume of low-quality reports.- \nIf at any point you are uncertain whether to continue testing, please engage our team.\u003c/li\u003e\n\u003cli\u003eThis is EEOC’s initial effort to create a positive feedback loop between researchers and EEOC – please be patient as we refine and update the process.\u003c/li\u003e\n\u003cli\u003ePlease review, understand, and agree to the following terms and conditions before conducting any testing of EEOC applications and before submitting a report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eGood-faith security research.\u003c/strong\u003e We authorize good-faith research, that is consistent with accessing a computer program solely for purposes of good-faith testing, investigation and/or correction of a security flaw or vulnerability, where such activity is carried out in a controlled environment designed to avoid any harm to individuals or the public.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and EEOC will not recommend or pursue legal action related to your research.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eSecurity research testing. The following test types are not authorized:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eApplication, Network or IS denial of service (DoS or DDoS) tests.\u003c/li\u003e\n\u003cli\u003ePhysical testing (e.g. office access, open doors, tailgating).\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g. mishing, phishing, vishing), or any other non-technical vulnerability testing.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease provide EEOC with fundamental elements of the vulnerability research, to include:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYour name, contact information, any affiliations (i.e., academia, organization, personal interest).\u003c/li\u003e\n\u003cli\u003eResearch purpose, goal of research, research environment(s) (i.e., lab, home, public).\u003c/li\u003e\n\u003cli\u003eDescription of the vulnerability, where it was discovered, likelihood or the potential impact of exploitation.\u003c/li\u003e\n\u003cli\u003eSpecific asset(s), Internet protocol (IP) space, Operating system (OS), Application(s), software development coding or development activities affected.\u003c/li\u003e\n\u003cli\u003eOffer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts, images or screenshots are helpful).\u003c/li\u003e\n\u003cli\u003eBe presented in English, if possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eROLES AND RESPONSIBILITIES.\u003c/strong\u003e VDP activities will be governed by the Office of the Information Technology (OIT) by delegation. Following briefing on the vulnerability as well as potential control measures, the CIO will be briefed and formally decide the outcome of each VDP risk decision or delegate this action to the appropriate directorate or staff.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFORMS/REPORTS.\u003c/strong\u003e VDP reports will be generated monthly or as critical disclosure warrants reporting to OIT and as applicable, the Enterprise Risk Management (ERM) leadership. Upon review of the vulnerability and potential ensuing risk, a risk decision will be documented and executed accordingly. The Commission will engage external stakeholders accordingly to pursue the remediation of vulnerabilities. This includes contacting service providers, software vendors and federal partners while confirming the existence of the vulnerability.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eREQUEST FOR CHANGES.\u003c/strong\u003e The CIO, Deputy CIO, and Chief Information Security Officer (CISO) are the points of contact for questions and changes to this policy. Changes may be proposed in the same manner as described for proposal and adoption of policies; however, those which affect general OIT policy and operations should first be discussed with management staff.\u003c/p\u003e\n\n\u003cp\u003e** QUESTIONS and FURTHER INFORMATION.** Any questions about this policy should be directed to the EEOC Chief Information Security Officer, which can be directed to the VDP submission address at vdp.security@eeoc.gov. Any ethical questions should be directed to the Office of Legal Counsel (OLC) at OLC@eeoc.gov.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eENFORCEMENT: POLICY VIOLATIONS.\u003c/strong\u003e Failure to adhere to this policy may result in reporting to Cybersecurity and Infrastructure Security Agency (CISA), Law Enforcement (LE) entities and other legal actions as determined by Agency leadership.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThe Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Platform (VDP Platform) gives agencies the option to use a centrally managed system to intake vulnerability information from and collaborate with the public to improve the security of their internet-accessible systems. CISA has a contract with EnDyna and Bugcrowd, private companies, to manage the platform used by the public to report vulnerability information; CISA exercises general oversight of the program.  CISA does not collect, maintain, use, or disseminate any Personally Identifiable Information (PII) provided to Bugcrowd for the purposes of creating a profile on the website or reporting a vulnerability to agencies other than CISA.  Participating agencies provide their own program vulnerability disclosure policy, setting out the agency’s parameters for vulnerability disclosures, including provisions for collection and use of submitted information. Any submissions of vulnerabilities pertaining to CISA’s own information systems would be governed by the DHS VDP brief.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"0d621c78-99f6-4b84-9344-256971ebdacc","name":"In Scope","targets":[{"id":"ae8d2fa5-99bd-4c3b-9f80-6f587231cef5","uri":"","name":"eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"05ac97ca-2483-42d7-8115-3f7e9d4bc8ee","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ae8d2fa5-99bd-4c3b-9f80-6f587231cef5"}],"recentChangeFlags":null},{"id":"d1056c5e-4795-45b8-9d01-b78249740699","uri":"","name":"nxg.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"eb601ab0-6cd9-42ba-adf6-c8bd2cd0b8b7","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d1056c5e-4795-45b8-9d01-b78249740699"}],"recentChangeFlags":null},{"id":"087f34db-4ace-455a-bc86-998add652710","uri":"","name":"ims.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ccd22264-4893-47e5-8b0a-ef495424676b","sortOrder":0},"sortOrder":0,"tags":[{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"087f34db-4ace-455a-bc86-998add652710"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"087f34db-4ace-455a-bc86-998add652710"}],"recentChangeFlags":null},{"id":"ad46cf87-77bc-46fd-a115-8e9e3a844ecb","uri":"","name":"uat-www.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cb4dd6cf-fd89-46f4-83f4-6303df653fd6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ad46cf87-77bc-46fd-a115-8e9e3a844ecb"}],"recentChangeFlags":null},{"id":"e30e4195-cc38-4703-a039-92c26c9ea07b","uri":"","name":"sts.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9c0b42d8-9e72-4405-accc-8aa7a8e60257","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e30e4195-cc38-4703-a039-92c26c9ea07b"}],"recentChangeFlags":null},{"id":"d70670f9-2928-4058-b7f8-3d500f14cecf","uri":"","name":"surveys.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"39213707-199d-44cd-9be2-f5c92fde2b7f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d70670f9-2928-4058-b7f8-3d500f14cecf"}],"recentChangeFlags":null},{"id":"7df8a315-41d1-42c7-b23d-d6734e44adf4","uri":"","name":"youth.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a729961e-9802-4d3c-9b54-0c3d52ccaa44","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7df8a315-41d1-42c7-b23d-d6734e44adf4"}],"recentChangeFlags":null},{"id":"9e25b99c-f280-4e03-bc9a-a8d196656fa5","uri":"","name":"alertus.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"87412e51-5eab-4319-80a5-f63931b511ab","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9e25b99c-f280-4e03-bc9a-a8d196656fa5"}],"recentChangeFlags":null},{"id":"2fc64f9f-dd26-49fd-bc63-bed529987261","uri":"","name":"arcuat.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2d4badf0-74fb-459e-849f-20c06552c936","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2fc64f9f-dd26-49fd-bc63-bed529987261"}],"recentChangeFlags":null},{"id":"eec51ebc-de40-4872-99c7-9f8e8e7ef98d","uri":"","name":"arctrain.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"96c6fcc2-accc-406e-9b49-10c58e1ef756","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"eec51ebc-de40-4872-99c7-9f8e8e7ef98d"}],"recentChangeFlags":null},{"id":"3f0f387c-0b14-4c68-ba8d-7be19983bc5d","uri":"","name":"arcdev.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5515e43c-0d8b-4279-ba24-ffb9b4f7ac7d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3f0f387c-0b14-4c68-ba8d-7be19983bc5d"}],"recentChangeFlags":null},{"id":"10f19f8c-bff3-4d14-a787-fac72b2cbff0","uri":"","name":"https://arc.eeoc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"03e7d73a-df1d-4c59-a28c-5e59bb14f36e","sortOrder":0},"sortOrder":0,"tags":[{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"10f19f8c-bff3-4d14-a787-fac72b2cbff0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"10f19f8c-bff3-4d14-a787-fac72b2cbff0"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThe following EEOC internet-accessible applications and systems are within the scope of this policy.\u003c/p\u003e\n\n\u003cp\u003eAny service not expressly listed below, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in non-federal systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy, if any. If unsure whether a system or endpoint is in scope or not, contact EEOC by email with the subject Security Research Query at vdp.disclosure@eeoc.gov prior to beginning your research.\u003c/p\u003e\n\n\u003cp\u003eEEOC domains and subdomains that are within scope:\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"9f64ef40-973c-493c-8e7b-17b9e737a170","code":"eeoc-vdp","state":"in_progress","endsAt":null,"bountyId":"1b32cfaa-19db-4af2-bae8-249025a53793","startsAt":"2021-07-29T13:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/34c1/3702/e151efa6/f01aed457a7e94174d5a5b5c16cfcf4e_T4ayloAB_400x400.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-07-29T13:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/eeoc-vdp","changelogs":"/engagements/eeoc-vdp/changelog","submissions":null,"announcements":"/engagements/eeoc-vdp/announcements","hallOfFame":"/engagements/eeoc-vdp/hall_of_fames","crowdstream":"/engagements/eeoc-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/eeoc-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=eeoc-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/eeoc-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/eeoc-vdp/changelog","publishedAt":"2022-04-27T19:38:25.587Z","engagementChangelogUrl":"/engagements/eeoc-vdp/changelog/98d48fa1-0ee2-4aaa-843b-35eb26f08fb7","createUserFeedbacksUrl":"/engagements/eeoc-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/eeoc-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}