The Justice Department’s 2017 vulnerability disclosure framework was a planning guide, not a grant of immunity. It showed organizations how to define authorized security research clearly enough to reduce Computer Fraud and Abuse Act (CFAA) risk. DOJ’s current program, updated April 3, 2024, applies those principles to internet-accessible DOJ systems with strict limits on testing, data handling, notification and public disclosure.
What DOJ released in 2017
CyberScoop reported on July 31, 2017, that the Justice Department had issued an eight-page document, A Framework for a Vulnerability Disclosure Program for Online Systems, Version 1.0 (July 2017). DOJ presented it at DEF CON through Leonard Bailey, special counsel for national security in the department’s Computer Crime and Intellectual Property Section.
The document described itself as assistance for organizations creating a formal vulnerability disclosure program (VDP). DOJ said the framework was intended to make authorized vulnerability discovery and disclosure conduct explicit, “thereby substantially reducing” the likelihood that the described activity would violate the CFAA. At the time, it was characterized as the first federal-government framework of its kind.
The framework was not binding law. It expressly said it created no substantive or procedural rights, privileges or benefits enforceable in administrative, civil or criminal proceedings.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
What the 2017 framework told organizations to decide
Define the systems and data in scope
An organization should decide whether researchers may test every network component and data store or only named systems. Scope decisions should account for financial, medical, proprietary and personally identifiable information, as well as encryption and network segmentation.
The policy should state how researchers may access, copy, transfer, store and retain sensitive information. If a test could expose protected information, DOJ advised consulting legal counsel before publishing the authorization.
Confirm authority over third-party infrastructure
Cloud providers, hosting companies and other suppliers may operate the servers that contain an organization’s data. A customer may not have authority to let researchers test those provider-controlled systems without contractual permission. A VDP therefore needs a process for checking third-party authorization rather than assuming that ownership of the data equals authority to test the infrastructure.
Authorize methods, not just targets
A formal policy should distinguish permitted discovery techniques from prohibited conduct. It should explain how reports are accepted, whether and when information may be shared with affected parties or the public, and what level of testing is allowed. An informal request to “tell us about bugs” does not provide the same clarity as a written VDP.
Recommended Free Tools
Rank #3
Plan the handling of reports
The 2017 framework emphasized intake and authorization. HackerOne CEO Mårten Mickos said the guidance was useful but did not fully address remediation and bug fixing or how results should be reported to key stakeholders and decision-makers. Those operational steps still need to be assigned inside the organization.
Does a vulnerability disclosure policy protect researchers from the CFAA?
It can reduce uncertainty when a researcher follows the written authorization, but it is not a blanket safe harbor. The 2017 document is guidance rather than legislation, regulation or a court ruling. Protection depends on the policy’s wording, the systems covered, the methods allowed, the researcher’s compliance and other applicable laws or contracts.
Organizations should therefore specify authorized targets, techniques, data limits, reporting deadlines and disclosure rules before testing begins. Researchers should read those conditions literally and stop when a test reaches an unapproved system, sensitive data or a prohibited action.
How the current DOJ vulnerability disclosure program works
DOJ’s policy updated April 3, 2024, covers all DOJ-managed systems and services accessible from the internet, including DOJ.gov. The main operating rules are:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
| Area | Current DOJ requirement |
|---|---|
| Authorization | Compliant vulnerability discovery on covered DOJ systems is treated as authorized. |
| Notification | Notify DOJ’s Office of the Chief Information Officer within 72 hours of discovering a real or potential vulnerability. |
| Testing intensity | Use only the testing necessary to confirm the issue. |
| Sensitive data | If sensitive data is encountered, stop testing and report it immediately; do not copy or exfiltrate DOJ data. |
| Availability and integrity | Avoid privacy violations and disruption to production systems. |
| Public disclosure | Do not disclose a reported vulnerability publicly until DOJ has remediated it and has given explicit written authorization. |
Activities the DOJ policy prohibits
- Exfiltrating or copying DOJ data
- Opening or deleting files
- Establishing persistence
- Privilege escalation or lateral movement
- Denial-of-service testing
- Deploying malware
- Physical testing
- Social engineering
The policy is narrower than a general invitation to “hack anything.” A researcher must stay within the listed internet-accessible DOJ systems and stop as soon as minimal confirmation is complete.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What information a vulnerability report must include
DOJ accepts reports through its vulnerability disclosure portal or email. It says it will acknowledge each report within three business days. A useful submission includes:
- The vulnerability and its likely impact
- The affected product, version and configuration
- Step-by-step reproduction instructions
- A proof of concept
- Suggested mitigation or remediation
Reproduction detail lets DOJ validate the finding without repeating unnecessary probing. A clear impact statement helps triage teams prioritize remediation.
How to design a vulnerability disclosure program
- Inventory and select scope. List domains, applications, APIs and other online services that researchers may test. Mark excluded assets explicitly.
- Map authority. Confirm that the organization owns or has contractual permission to authorize testing of each system, including cloud and managed-service infrastructure.
- Set testing boundaries. Define allowed techniques, rate limits, test accounts, proof-of-concept limits and actions that are never permitted.
- Protect sensitive information. State what researchers should do if they encounter personal, medical, financial or proprietary data, including whether they may view, retain or transmit it.
- Publish secure intake channels. Specify the portal or email address, required report fields, encryption expectations and an emergency contact for active exposure.
- Assign internal owners. Give security, legal, privacy, engineering and communications teams clear responsibilities for validation, remediation and stakeholder updates.
- Define coordinated disclosure. Explain when DOJ or another organization may share a report with affected parties or authorize public disclosure.
- Review the policy. Update scope, contacts and authorization language when systems, vendors, contracts or law change.
Where NIST fits
NIST’s SP 800-216, published May 24, 2023, provides a broader federal recommendation for accepting, assessing, managing and communicating vulnerability reports. It is designed to cover software, hardware and digital services under federal control. That scope is broader than the 2017 DOJ document’s focus on online systems, while DOJ’s 2024 policy supplies concrete rules for testing its own internet-facing environment.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
What organizations and researchers should take away
- A written VDP reduces legal ambiguity by making authorization specific; it does not erase CFAA or other legal risk.
- Scope, sensitive-data handling and third-party authority must be settled before testing.
- Minimal confirmation, rapid notification and a ban on disruption or data removal are central to DOJ’s current rules.
- Reports should be reproducible, technically precise and useful to the remediation team.
- Policies should be tailored to the organization’s systems and contracts rather than copied without review.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

