UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot

Call 4 now open for applications

19 June 2025

BREAKING NEWSFlorian Wirtz spotted at airport as incoming Liverpool star boards private jet ahead of £116MILLION record-breaking move to Anfield – with move likely to be confirmed TOMORROW

19 June 2025

Charlie Kirk says college for girls is only to find husband | News – UK Times

19 June 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Advocating security.txt across UK government – Technology in government
News

Advocating security.txt across UK government – Technology in government

By uk-times.com19 June 2025No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Technology has revolutionised every aspect of our society and our economy, including the way that we deliver our public services, helping to make people’s lives easier and safer. Security vulnerabilities are discovered all the time online and people want to be able to report them directly to the organisation responsible. That’s why we are advocating for the use of security.txt as a standardised way of doing just that. One of the most important elements of vulnerability disclosure, and a challenge for the finder, is understanding who to contact.

Security.txt describes a text file that advertises the organisation’s vulnerability disclosure process so that someone can quickly find all of the information needed to report a vulnerability. It is a voluntary standard for internet users set by the Internet Engineering Task Force (RFC 9116).

Security.txt will serve the government in its aim to become more resilient in its online security by making it easier for anyone to report vulnerabilities they have found. Quick, easy and secure reporting directly to the affected department speeds up the triage and remediation time and reduces the risk of compromise, such as reporting of a vulnerable web server so it can be remediated before being exploited. The security.txt was endorsed by the Data Standards Authority in March 2023.

Benefits to government departments & finders

The ability to receive, respond and ultimately fix a reported vulnerability is essential to providing secure products and services. Being open to receiving vulnerability reports helps departments engage constructively with those who find them – ‘finders’. Engaging with finders can be a source of valuable information that would otherwise be missed or require additional time and effort to discover.

Vulnerability disclosure policy

Departments should define what they expect from someone reporting a vulnerability, as well as what they will do in response, by providing a clear policy. This enables the department and the finder to confidently work within an agreed framework.

In its basic form, a vulnerability disclosure policy should contain the following information:

  • how you want to be contacted
  • secure communication options (for example, a secure web form)
  • what information to include in the report
  • what the finder should expect to happen
  • guidance on what is in and out of scope for the finder to do in finding vulnerabilities

How to implement security.txt

Security.txt is a plaintext file that should be published in the “/.well-known” directory of the domain root.

The file contains three key fields: 

CONTACT: How finders should report vulnerabilities. For example, email or secure web form.

POLICY: A link to the department’s vulnerability disclosure policy.

EXPIRES: Indicates the date and time after which the data contained in the “security.txt” file is considered stale and should not be used. The value of this field is formatted according to the Internet profile of [ISO.8601] as defined in [RFC3339]. It is recommended that the value of this field be less than a year into the future to avoid staleness.

The ENCRYPTION field is optional and should link to the PGP public key you wish to be used for encrypted communication.

The National Cyber Security Centre (NCSC) has published the NCSC Vulnerability Disclosure Toolkit that provides information on how to implement security.txt as well as an example vulnerability disclosure policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Charlie Kirk says college for girls is only to find husband | News – UK Times

19 June 2025

M4 westbound between J21 and J22 | Westbound | Accident

19 June 2025

M1 J31 northbound exit | Northbound | Congestion

19 June 2025

‘Canadian-only’ deals launched by US as cross-border vacation visits fall amid Trump’s 51st state rhetoric – UK Times

19 June 2025

A34 northbound between A272 and A303 | Northbound | Vehicle Fire

19 June 2025

Woman, 66, arrested over death of film director linked to missing diamond-encrusted Rolex – UK Times

19 June 2025
Top News

Call 4 now open for applications

19 June 2025

BREAKING NEWSFlorian Wirtz spotted at airport as incoming Liverpool star boards private jet ahead of £116MILLION record-breaking move to Anfield – with move likely to be confirmed TOMORROW

19 June 2025

Charlie Kirk says college for girls is only to find husband | News – UK Times

19 June 2025

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

© 2025 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version