Richtlinie zur Meldung von Schwachstellen und Sicherheitsvorfällen
Introduction
Since security is of critical importance to us and to our customers, we at NUM are committed to ensuring the safety and security of our products and services. NUM supports coordinated vulnerability disclosure and encourages responsible vulnerability testing, we take any reports of potential security vulnerabilities and incidents seriously.
To report a potential security issue, please follow the steps described in the “Reporting procedure” section.
When in doubt about if your potential conduct complies with this policy, please contact us first, before taking action, at security(at)num.com and we will address your questions.
Reporting procedure
- Submit the Security Report at security@num.com
- Use our PGP public key to encrypt any material supplied by e-mail.
- Write the Security Report in English.
- Provide sufficient contact information, such as:
a) your email
b) name of the person who found the security issue
- Specify in the object of the email if you are reporting a potential vulnerability (exploitation not suspected) or a security incident (exploitation is suspected or confirmed).
- Provide the following information:
- date when the vulnerability or incident has been detected
- details about how it has been discovered
- a technical description of the issue
- Provide as much information as you can on the product or service affected, such as:
- version number (hardware and software)
- configuration of the setup used
- If you wrote specific proof-of-concept or exploit code of the vulnerability, please provide a copy. Please ensure all submitted code is clearly marked as such and is encrypted with our PGP key.
- If you have identified specific threats related to the root cause of the vulnerability or the incident, assessed the risk, or have seen the vulnerability being exploited in other products, please provide that information.
Internal assessment and action
1) NUM will acknowledge receiving your Security Report within 3 business days
- If the Security Report contains all the required information, NUM will provide a unique tracking number and a contact person;
- If the Security Report is not complete (more information is needed), NUM will request the missing information, and no more action will be taken.
2) NUM will start an internal management process to manage the reported security issue:
- Receipt
- Triage
- Verification
- Remediation
3) NUM will use existing customer notification processes to manage the release of patches or security fixes, which may include without limitation and at NUM’s sole discretion, direct customer notification or public release of an advisory notification on our website.
4) If the vulnerability or the incident source is actually in a third party component or service which is part of our product/service, NUM will notify the Security Report to that third party. To that end, please inform us in your email whether it is permissible in such cases to provide your contact information to the third party.
Notice
If you share any information with NUM in the context of responsible disclosure, you are agreeing that the information you submit will be considered as non-proprietary and non-confidential.
NUM is allowed to use shared information, or part of it, without any restriction. You agree that submitting information does not create any rights for you or any obligation for NUM.
Personal data is processed by NUM based on the privacy policy https://www.num.com/data-protection
PGP Key
Fingerprint: 2D5A46F9F0FD27238001088F6C644F1FDC80E6C1
The PGP key is available for download here: PGP Key Download.
Security File
The Security File is available for download here: Security File Download.