Home | Digital Manufacturing

 

security.txt: Standardised contact information for IT security disclosures

IT security vulnerabilities, caused by design and programming errors, threaten a wide variety of systems. The contact methods used so far, such as website forms, are often ineffective for quickly and securely reporting discovered security issues. In addition, legal uncertainties, e.g. due to the “hacker paragraph” (§ 202c StGB in German legislation), make it difficult to responsibly report such vulnerabilities (Responsible Disclosure).

The security.txt specification offers a solution. This is a standardized text file that provides contact and encryption information. This file is stored in the.well-known/ directory on web servers and is globally accessible via a fixed URL. Security researchers and companies can thus communicate with confidence.

The advantages for both sides are that security researchers can be honored, and recognition published. Companies can also attract qualified specialists. The use of security.txt will be mandatory in the future under a new EU regulation to ensure accessibility and avoid fines. Further information and support can be found at https://dguv.de/securitytxt_EN

Contact

Christian Werner
Institute for occupational safety and health of the German Social Accident Insurance
Sankt Augustin, Germany

Christian.Werner(at)dguv.de

Members of the Project Group
Digital integration in machines and process industry

July 7th, 2023, Rome

Proceedings of the seminar

Emerging risks in industry 4.0

Innovative approaches for safety and security
Nov. 25th, 2019, Rome

Proceedings of the seminar

Publications

  • Fact Sheet No. 4 published: Carry out updates safely: indispensable even in small businesses!
    DE PDF 2nd issue, 03/2023 / EN PDF 1st issue, 07/2022
  • Fact Sheet No. 3: Shut the Door against Cyber Attacks on Small Businesses
    DE PDF 2nd issue, 03/2023 / EN PDF 1st issue, 10/2020
  • Fact Sheet No. 2: Safe Passwords in Small Enterprises
    DE PDF 2nd issue, 03/2023 / EN PDF 1st issue, 07/2022
  • Fact Sheet No. 1: Cyber Security in Small Enterprises
    DE PDF 2nd issue, 03/2023 / EN PDF 1st issue, 09/2019
  • Safety in additive manufacturing. Powder bed fusion/sintering
    EN Summary
    IT PDF
  • Digital transformation of technical systems with explosion risk
    DE PDF / EN PDF (English summary)
  • Digital manufacturing – challenges for occupational safety and health (OSH) due to digital transformation
    EN PDF
  • Occupational safety and health in the new digital world - XXI World Congress on Safety & Health at Work 2017 - Proceedings
    EN PDF
  • Digitisation of Production: General Targets of Cyberattacks and Prevention Strategy
    EN PDF