Official framework for ethical security researchers to discover and report vulnerabilities within the Cybersecurity Center of Excellence (CCoE) infrastructure.
CCoE is a cybersecurity organization. We hold ourselves to the same standards of responsible security practice that we teach. If you discover a security vulnerability in any CCoE-operated system, platform, or service, we want to know about it — and we are committed to responding promptly, transparently, and without retaliation.
ccoe.bd
*.ccoe.bd (All Subdomains)
Learning Management Systems (LMS)
Cyber Range Infrastructure
Institutional Portals
Third-party hosted services
Physical security of CCoE facilities
Denial of Service (DoS/DDoS) attacks
Social Engineering / Phishing
Resource exhaustion attacks
Report in good faith. If you discover a vulnerability, report it to us before disclosing it publicly or to any third party.
Do not access, modify, or delete data beyond what is necessary to confirm the vulnerability exists.
Do not disrupt CCoE services or compromise the data or safety of our participants.
Give us reasonable time to respond and remediate before any public disclosure.
Include enough detail in your report for us to reproduce and assess the vulnerability.
security@ccoe.bd
SUBJECT LINE
Vulnerability Report — [brief description]
PGP encryption is available for sensitive reports. Contact us at security@ccoe.bd to request our public key.
Description of the vulnerability, affected system/URL, steps to reproduce, potential impact assessment, and any proof-of-concept (non-destructive only).
We will acknowledge receipt of your report within 3 business days.
We will provide an initial assessment of severity and scope within 10 business days.
We aim to remediate critical vulnerabilities within 30 days, and all other validated vulnerabilities within 90 days.
We will keep you informed of progress throughout the remediation process.
With your consent, we will acknowledge valid reports in our program reports or on a public security acknowledgements page.
We will not pursue legal action against researchers acting in good faith under this policy.
CCoE follows a coordinated disclosure model. We request that researchers allow us a minimum of 90 days to remediate a validated vulnerability before any public disclosure. If you have concerns about our progress, please contact us before going public so we can coordinate an appropriate response.
Accessing accounts of other users.
Modifying or deleting data not yours.
Automated attacks affecting availability.
Demanding payment for disclosure.
The Cyber Security Center of Excellence (CCoE) is a national initiative designed to strengthen Bangladesh’s cybersecurity ecosystem by developing skilled professionals, enabling real-world security operations, and fostering collaboration between academia, industry, and community stakeholders.