Skip to content
arrow_back
search
ISM-1717 policy ASD Information Security Manual (ISM)

Implement Security.txt for Vulnerability Disclosure

Ensure a 'security.txt' file is available on each website to aid in reporting vulnerabilities.

record_voice_over

Plain language

A 'security.txt' file is like a signpost on your website that tells security researchers where they can report any problems they find. This is important for finding and fixing security issues quickly to prevent hackers from causing harm to your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A 'security.txt' file is hosted for each of an organisation's internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation's products and services.
policy ASD Information Security Manual (ISM) ISM-1717
priority_high

Why it matters

If a security.txt file is not hosted on internet-facing domains, researchers may not know how to report issues, delaying fixes and increasing breach risk.

settings

Operational notes

Keep security.txt current (contacts, PGP, policy) on every public domain, and triage/track reports so responses and remediation are timely.

Mapping detail

Mapping

Direction

Controls