Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Security

We take security and the protection of private data extremely seriously. If you believe you have found a vulnerability or other issue which has compromised or could compromise the security of any of our systems or private data managed by our systems, please do not hesitate to contact us using the method outlined below.

## Table of contents

- [Security](#security)
- [Responsible Disclosure](#responsible-disclosure)
- [Scope](#scope)
- [Response Process/Expectations](response-process-and-expectations)
- [Report a cyber security incident](report-a-cyber-security-incident)

## Responsible Disclosure

To learn more about responsible disclosure of security incidents you can read our [Security vulnerability disclosure policy](https://digital.nhs.uk/cyber-and-data-security/security-vulnerability-disclosure). This policy covers things like the scope and response SLAs

## Report a cyber security incident

Request immediate support for a cyber security issue - call [0300 303 5222](tel:0300 303 5222) (monitored 24/7).

Report an urgent cyber security issue by [logging a ServiceNow ticket](https://nhsdigitallive.service-now.com/csm?id=sc_cat_item&sys_id=0122c5351b280110892d4046b04bcb16&referrer=recent_items) and attaching all relevant details.

If you have found a vulnerability in an NHS system, [report it via our Vulnerability Disclosure Programme](https://digital.nhs.uk/cyber-and-data-security/security-vulnerability-disclosure).

For general cyber operations queries email [cybersecurity@nhs.net](mailto:cybersecurity@nhs.net).