This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Reminder: Ethical Vulnerability Testing Does Not Include DoS and DDoS Attacks
The point stipulates that a security researcher during vulnerability hunting has the obligation to: "match testing methods and intensity with the performance of the resource being tested (i.e., do not overload the tested ICT resource unless explicitly permitted by the Resource owner’s program)." Additionally, rule 6.1.6 and the participation rules of the "ALL – CERT.LV Vulnerability Program" specify: do not attempt to affect service availability through denial-of-service attacks (DoS or DDoS). CERT.LV emphasizes that performing DoS and DDoS overload attacks is not considered ethical cybersecurity testing unless explicitly authorized by the specific Resource owner’s program. To prove the existence of vulnerabilities, the testing method should be as gentle and proportionate as possible, avoiding unnecessary disruptions to the resource’s operation and not affecting its availability to other users. We invite users to review the rules for using the CERT.LV Vulnerability Reporting Platform and the specific program conditions before starting testing.