Body
It has now become a standard practice to responsibly and privately disclose to an organization any issue that may cause a security problem. While Information Security tries to be proactive in preventing security problems, we do not assume they’ll never come up. As a result, we work with and rely on both internal and external organizations as well as individuals for vulnerability reports as part of our responsible disclosure program. Once a security vulnerability is reported, we provide responsive support based on our Security Incident Response procedures. Information Security provides several methods and tools by which potential security vulnerabilities can be reported, however, the preferred method is to submit vulnerability reports through the Report a Security Vulnerability form or by sending an email to informationsecurity@villanova.edu with details of the security vulnerability.
Frequently Asked Questions
What is a security vulnerability?
A security vulnerability is a type of bug or weakness that can affect the security of Villanova University systems. Specifically, it is a report of a bug that you have found in the Villanova University technology infrastructure, and that you have determined can be used to gain some level of access to sensitive data.
Where do I report security vulnerabilities?
The preferred method is to submit vulnerability reports through the Report a Security Vulnerability form or by sending an email to informationsecurity@villanova.edu with details of the security issue. You can also contact the Technology Support Services at 610-519-7777, or for individuals with a Villanova Account, log in to support.villanova.edu and click Get Started. Regardless of the method of reporting a vulnerability, Information Security will review the security issue reported and follow up accordingly.
What information should I include in my vulnerability report?
When reporting, please try to include the following:
- A detailed description of the issue which ideally provides enough information to reproduce the problem
- Contact email address we can get in touch with who can answer all related questions
- List of Villanova hardware involved
- List of Villanova software involved
- Logs and other supporting information
Where is your security.txt file?
Villanova University publishes a security.txt file to provide security researchers and others with information about how to report potential security vulnerabilities.
The file is available at: https://www.villanova.edu/.well-known/security.txt
Do you provide a bug bounty?
Villanova University presently does not offer a financial bug bounty. If a vulnerability you report is considered new in our vulnerability tracking system, and can be reproduced and is rated as critical, upon remediation of the vulnerability by Villanova University and/or the vendor, the participant will receive a letter of recognition from Information Security and their name will be added to the list of successful bug bounty hunters.
Visit the Vulnerability Management: Getting Started article to learn more about Vulnerability Management.