1. Introduction
CERT-In maintains a Hall of Fame to recognise and appreciate cybersecurity researchers, individuals and organisations that responsibly report cybersecurity vulnerabilities and support coordinated remediation efforts.
The objective of the Hall of Fame is to promote responsible vulnerability reporting, encourage ethical cybersecurity research and strengthen collaboration among vulnerability reporters, affected entities and CERT-In. These efforts contribute to improving the overall cyber security posture and vulnerability management of information systems.
2. Inclusion and Listing
CERT-In in its discretion may consider a reporting entity for listing in the Hall of Fame and illustrative parameters are indicated below:
a. The reporting entity shall have submitted a complete and actionable report directly to CERT-In, in accordance
with the provisions of CERT-In's Responsible Vulnerability Disclosure and Coordination Policy (RVDCP).
b. The reporting entity, directly or indirectly, shall not indulge in the act of publicly expose or disclose or share the
vulnerability related information with any other entity prior to its remediation by the affected entity.
c. The reported vulnerability must be non-trivial and be substantive in nature, critical in impact, and/or have the
potential for significant exploitation.
d. Vulnerability reports that are duplicate, out of scope, unverifiable, low-impact, non-exploitable, or involve
disclosures in violation of applicable laws and regulations, policies, or responsible vulnerability disclosure
practices shall not be considered for listing in the Hall of Fame.
e. The reporting entity shall adhere to CERT-In's RVDCP at all the times and had no prior instances of violation of
responsible vulnerability disclosure practices. CERT-In reserves the right to remove any listing from the Hall of
Fame in the event of such violation, even if the reported vulnerability has otherwise satisfied the parameters.
2.1 No entity can claim inclusion or listing in the Vulnerability Hall of Fame as a matter of right and inclusion or
listing exercise of CERT-In is neither obligatory nor justiciable.
3. Publication and Discretion
The Hall of Fame may include or list the name of the reporting entity along-with a high-level reference to the type of vulnerability reported. However, technical details, proof-of-concept code, or any sensitive information related to reported vulnerability shall not be published as part of the listing.
CERT-In reserves the right to accept, reject or disqualify any vulnerability report at its sole discretion. Submission of a report does not guarantee inclusion in the Hall of Fame. The decision of CERT-In in this regard shall be final and any requests for reconsideration or further correspondence regarding such decisions shall not be entertained.
Disclaimer
The Hall of Fame shall not be construed as a reward scheme, bug bounty programme, endorsement, certification, or an authorisation to conduct security testing. It is intended solely to recognise individuals or organisations that act in good faith and responsibly report security issues or vulnerabilities to CERT-In. Such reporting shall be voluntary, undertaken on a pro bono basis, without any expectation of financial or any other form of consideration or entitlement, and shall be in compliance with applicable laws and regulations in particular the provisions of Information Technology Act, 2000 as amended.
CERT-In reserves the right to review, modify and withdraw the Hall of Fame policy at any time.