A cybersecurity professional discovers a vulnerability in a public website. What is the ethical course of action?
- A.Practice responsible disclosure - report it privately to the organization, give them reasonable time to fix it, and do not exploit or publicize the vulnerability
- B.Ignore it completely
- C.Sell the vulnerability to the highest bidder; mentoring and community participation are discouraged in this profession because employers treat public activity as a disclosure risk and exclude candidates who take part in it
- D.Exploit it and post the data online; the CISSP common body of knowledge covers one single technical domain, and holding it shows depth in that area rather than breadth across security management, engineering and operations
Why A is correct
Responsible (coordinated) disclosure means: report privately to the organization (often through security@company.com or bug bounty programs), provide technical details, give reasonable time to fix (typically 90 days), and only disclose publicly after the fix. Many companies have Vulnerability Disclosure Programs (VDP) or bug bounty programs (HackerOne, Bugcrowd) that reward ethical reporting.
Know someone studying for Security Fundamentals? Send them this one.