<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proper protocol before publishing an article in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15732#M1514</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/808801723"&gt;@kbruce&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I am writing my first article, which will be exposing a vulnerable website, its disclosure of PII and its potential to assist in phishing attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Keith,&amp;nbsp;&lt;/P&gt;&lt;P&gt;A big part of the answer depends on how and where you plan to publish. If you are thinking of self-publishing, like in a blog, I recommend reconsidering that choice, given the mess full disclosure of a site vulnerabilities brings on (we're talking lots of lawyers). Rather, consider publishing in an established professional journal, magazine, or conference, and follow their guidelines for publishing disclosures of vulnerabilities.&lt;/P&gt;&lt;P&gt;If you are not familiar with the ongoing infosec topic of &lt;STRONG&gt;&lt;EM&gt;responsible disclosure&lt;/EM&gt;&lt;/STRONG&gt;, please search the net for that term and read up on the various positions on notification and responsibility.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Congrats on your first article! That is an exciting step.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Oct 2018 17:10:38 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2018-10-22T17:10:38Z</dc:date>
    <item>
      <title>Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15724#M1512</link>
      <description>&lt;P&gt;Hi Folks,&lt;BR /&gt;&lt;BR /&gt;I am writing my first article, which will be exposing a vulnerable website, its disclosure of PII and its potential to assist in phishing attempts.&lt;BR /&gt;&lt;BR /&gt;Knowing this, what is the proper protocol that I should follow before publishing, to avoid future repercussions to protect myself and ISC2.org?&amp;nbsp; Should I provide the exposed company with ample warning?&amp;nbsp; If so, what would be considered ample time (30, 60 or 90 days notice)? Do we have access to a template repository, of sorts? Should I publish anonymously?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions are greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 13:57:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15724#M1512</guid>
      <dc:creator>kbruce</dc:creator>
      <dc:date>2018-10-22T13:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15730#M1513</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A href="https://www.owasp.org/index.php/Vulnerability_Disclosure_Cheat_Sheet" target="_blank"&gt;https://www.owasp.org/index.php/Vulnerability_Disclosure_Cheat_Sheet&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless (ISC)² is the vulnerable web site, I recommend keeping unrelated parties out of any "article".&amp;nbsp; The more people you drag in, the more conversations you end up having with lawyers.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 16:51:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15730#M1513</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-10-22T16:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15732#M1514</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/808801723"&gt;@kbruce&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I am writing my first article, which will be exposing a vulnerable website, its disclosure of PII and its potential to assist in phishing attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Keith,&amp;nbsp;&lt;/P&gt;&lt;P&gt;A big part of the answer depends on how and where you plan to publish. If you are thinking of self-publishing, like in a blog, I recommend reconsidering that choice, given the mess full disclosure of a site vulnerabilities brings on (we're talking lots of lawyers). Rather, consider publishing in an established professional journal, magazine, or conference, and follow their guidelines for publishing disclosures of vulnerabilities.&lt;/P&gt;&lt;P&gt;If you are not familiar with the ongoing infosec topic of &lt;STRONG&gt;&lt;EM&gt;responsible disclosure&lt;/EM&gt;&lt;/STRONG&gt;, please search the net for that term and read up on the various positions on notification and responsibility.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Congrats on your first article! That is an exciting step.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 17:10:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15732#M1514</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-10-22T17:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15733#M1515</link>
      <description>&lt;P&gt;Amanda&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1566072329"&gt;@amandavanceISC2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This thread seems more appropriate for the &lt;A href="https://community.isc2.org/t5/Career/bd-p/Career" target="_blank"&gt;&lt;EM&gt;Career&lt;/EM&gt;&lt;/A&gt; area than in Member Support. If Keith&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/808801723"&gt;@kbruce&lt;/a&gt; is OK with changing, can you move it over there?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 17:16:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15733#M1515</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-10-22T17:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15746#M1516</link>
      <description>&amp;gt; kbruce (Viewer) posted a new topic in Member Support on 10-22-2018 09:57 AM in the (ISC)Â² Community :&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Hi Folks, I am writing my first article, which will be exposing a&lt;BR /&gt;&amp;gt; vulnerable website, its disclosure of PII and its potential to assist in&lt;BR /&gt;&amp;gt; phishing attempts. Knowing this, what is the proper protocol that I should&lt;BR /&gt;&amp;gt; follow before publishing, to avoid future repercussions to protect myself&lt;BR /&gt;&amp;gt; and ISC2.org?&lt;BR /&gt;&lt;BR /&gt;Are you identifying yourself with ISC2 in the article?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp; Should I provide the exposed company with ample warning?&lt;BR /&gt;&lt;BR /&gt;Definitely. I would have already notified them before starting to write the article&lt;BR /&gt;...&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;gt; If so, what would be considered ample time (30, 60 or 90 days notice)?&lt;BR /&gt;&lt;BR /&gt;Depends upon a number of factors. How many people/users does this vulnerability&lt;BR /&gt;affect? How complex is the issue? How long is it reasonable to expect the&lt;BR /&gt;company to take to fix it? If the breach is potentially serious for a large number&lt;BR /&gt;of people, it might be proper to publish and warn people before the company has&lt;BR /&gt;had time to patch, but, in most less serious cases, the company should have time&lt;BR /&gt;to fix the issue before you alert the "dark side" that they have a chance to attack.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Should I publish&lt;BR /&gt;&amp;gt; anonymously?&lt;BR /&gt;&lt;BR /&gt;Depends upon how well you've done your work ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;I clicked without thinking. That's what using a Mac does to you,&lt;BR /&gt;gives you a feeling of invincibility. - Martin Wehlou, 20061222&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Mon, 22 Oct 2018 19:26:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15746#M1516</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-10-22T19:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15776#M1517</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've gone ahead and moved this, as it is a better fit for the Career board. Thanks for tagging us!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 19:05:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/15776#M1517</guid>
      <dc:creator>SamanthaO_isc2</dc:creator>
      <dc:date>2018-10-23T19:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Proper protocol before publishing an article</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/16419#M1644</link>
      <description>Thanks, very helpful.</description>
      <pubDate>Fri, 16 Nov 2018 18:50:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Proper-protocol-before-publishing-an-article/m-p/16419#M1644</guid>
      <dc:creator>kbruce</dc:creator>
      <dc:date>2018-11-16T18:50:27Z</dc:date>
    </item>
  </channel>
</rss>

