CYB-11 · Cyber security
The security.txt standard (RFC 9116) defines how organisations can communicate their vulnerability disclosure policy and security contact. Its presence signals security maturity and enables ethical hackers to report issues before they are exploited. Required at /.well-known/security.txt.
Trigger
No security.txt file at /.well-known/security.txt; or security.txt present but expired (Expires field in the past)
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Create a security.txt file at /.well-known/security.txt. Include: Contact: (email or URL), Expires: (12 months forward), Preferred-Languages: en, Encryption: (GPG key URL if available).
Evidence required
Automated assessment
Verified by the Provantis cyber scanner. Machine checks performed: