Vulnerability Disclosure Policy
The Ohio Secretary of State emphasizes election security and access to safe, efficient services. Threats to digital infrastructure, including election infrastructure, have increased. The office values the cybersecurity testing community in keeping its systems secure.
If you choose to collaborate with the Ohio Secretary of State’s office by testing for vulnerabilities, please be aware of the office’s policy regarding what systems and testing types are covered, and how to report vulnerabilities.
If you’re familiar with the office’s vulnerability disclosure policy, you may submit a vulnerability report.
Guidelines
The office requires that you:
Avoid privacy violations. If you encounter any personally identifiable information (e.g., Social Security numbers, driver license numbers, etc.) or financial information (e.g., credit card or bank account numbers), stop your test and notify the office.
Only test as necessary to confirm a vulnerability in systems defined under the policy’s scope. If you've established that a vulnerability exists or encountered sensitive data outlined, stop your test and notify the office.
Avoid damaging the system’s user experience, disrupting production systems, destroying data, or manipulating data.
Do not compromise or withdraw data, pivot to other systems, or establish command line access or persistence.
Use the identified communication channels to report vulnerability information to the office.
Keep information about discovered vulnerabilities confidential for at least 120 calendar days after you have notified the office. Review the coordinated disclosure section for details.
The following tests are not allowed:
Denial of service (DoS or DDoS).
Defacement.
Physical testing (e.g., office access, open doors, tailgating).
Social engineering (e.g., phishing, vishing).
Potentially disruptive test types (e.g., DNS spoofing or DNS tunneling).
Functionality bugs, clickjacking, email spoofing, etc. do not fit under the policy’s scope due to their low impact. Testers may report such issues but these problems may not be handled as an issue related to this policy.
Scope
The policy applies to these systems:
BoE.ohio.gov
MilitaryVotes.ohio.gov
OhioBusinessCentral.gov
OhioSecretaryOfState.gov
OhioSoS.gov
SafeAtHomeOhio.gov
SoS.state.oh.us
Vote.ohio.gov
VoteOhio.gov
All subdomains of the above systems
The State of Ohio, Ohio.gov, and State.oh.us are outside the scope of this policy. Vulnerabilities found in vendor systems are outside of this policy's scope and should be reported to the vendor. Systems not covered under this policy include (but are not limited to):
Voting machines
Electronic pollbooks
Remote ballot markers
County voter registration systems
If you aren't sure whether a website, system, or endpoint fits under the scope of this policy, contact [email protected] before testing.
Coordinating Disclosure
The office’s security and IT teams attempt to resolve vulnerabilities in 120 days or less and may disclose the details of those vulnerabilities when they have been resolved.
You may not share your report during this 120-day window. If you believe other agencies may benefit from seeing your report before the vulnerability has been resolved, please communicate this to the Ohio Secretary of State’s office.
Once an identified vulnerability is resolved, or 120 days have passed, the office may coordinate a public advisory with you. Please contact the office prior to releasing any information related to the vulnerability and ensure you are not releasing sensitive information.
Vulnerabilities in the office’s system may be relevant to other state and local governments that use similar technology. The office may share your vulnerability reports with federal, state, local government agencies, and the information-sharing organizations that work with them.
Reporting a Vulnerability
You can submit a vulnerability report using this form.
Reports should include:
A description of the location and potential impact of the vulnerability.
A detailed description of the steps required to reproduce the vulnerability. Proof of concept scripts, screenshots, and screen recordings are recommended. Please label and protect any exploit code.
Any technical information and related materials required to reproduce the issue.
The office will acknowledge your report within seven business days and will work with you to understand the report and validate the vulnerability. The office will attempt to provide you with updates.
The office will notify you when a vulnerability has been resolved and offer the opportunity to test and verify. The coordinated disclosure section describes the office’s commitment to publishing vulnerabilities after reporting. The office does not offer financial compensation for vulnerability testing.