Coordinated Vulnerability Disclosure (CVD)

The LUMC works hard to maintain and improve secure ICT systems. However, vulnerabilities (weak spots) may still exist. If you discover a vulnerability in one of our ICT systems, please report it to us so we can take timely measures. This Coordinated Vulnerability Disclosure (CVD) explains how we handle your report.

Do not actively scan the network

This CVD policy is not an invitation to extensively and actively scan the LUMC corporate network for vulnerabilities. Such a scan is likely to be detected by us; we continuously monitor our network. Our CERT (Computer Emergency Response Team, a specialized team of ICT professionals) may then investigate and incur unnecessary costs.