Menu

“Katanya ketutup maskerpun aja masih ketahuan manisnya? Yang keliatan cuma mata tapi cukup bikin kamu bikin fokus.”

 This page is a free video sharing site on the Internet. To see what no one else can see, Content recommended for you today.

Introduction

At the European Commission, the security of our Communication and Information Systems is a top priority, in line with Commission Decision EC 2017/46.


However, vulnerabilities can never be completely eliminated, despite best efforts. When vulnerabilities are identified and exploited, it puts at risk the confidentiality, integrity or availability of the European Commission's systems and the information processed therein.


This vulnerability disclosure policy describes what systems and types of tests are authorised and how to send vulnerability reports. We encourage you to contact us to report potential security issues in our systems by following this policy.


Authorisation

If you are acting in good faith to identify and report vulnerabilities on European Commission systems, while complying with this policy we will work with you to understand and resolve the issues quickly.

The European Commission will not pursue legal action related to your activities of identifying vulnerabilities on our systems as long as you follow the guidelines in this policy.


Scope

This policy applies to all internet facing systems from the European Commission, including


the entire European Commission’s web presence

*.ec.europa.eu/*

*.commission.europa.eu/*

public IPs advertised under ASN 42848, and attached services

any other software published by the European Commission

Any services not expressly listed above are excluded from the scope and are not authorised for testing.

Moreover, vulnerabilities found in systems from vendors are also excluded from scope and should be reported directly to the vendor according to their own disclosure policy (if applicable).


Guidelines

While carrying out your activities, it is imperative that you

do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability, deleting, or modifying other people’s data

only use harmless exploits to confirm that a vulnerability is present

do not reveal any data downloaded during the discovery to the public or any other parties

do not reveal the vulnerability or problem to the public or other parties until it has been resolved

stop your tests when you discover any sensitive information (Personally Identifiable Information – PII, medical, financial, proprietary information or trade secrets) and notify us immediately and do not disclose any obtained data to anyone else

Do not perform the following actions

place malware (virus, worm, Trojan horse, etc.) on any system

compromise any systems using exploits to gain full or partial control

copy, modify or delete data from the system

make changes to the system

repeatedly access the system or share access with the public other parties

use any access obtained to attempt to access other systems

change access rights of other users

use automated scanning tools

use a so-called “brute force” attack to access any systems

use denial-of-service or social engineering (phishing, vishing, spam, etc.)

use attacks on physical security

Reporting a vulnerability

What we would like to see from you

If you have identified a vulnerability, please


e-mail your findings as soon as possible to EC-VULNERABILITY-DISCLOSURE@ec.europa.eu, specifying whether or not you agree to your name or pseudonym being made publicly available as the discoverer of the problem

encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands

provide us with sufficient information to reproduce the problem so that we can resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation in terms of technical information or potential proof-of-concept code

provide your report in English preferably, or in any other official language of the European Union

What you can expect from us

In return, we promise the following when you report a vulnerability to us, that is to


Introduction

The European Commission is committed to the protection of your personal data and respects your privacy on all its websites on the europa.eu domain.


This privacy policy on the protection of individuals with regard to the processing of personal data by the European Commission is based on the Regulation (EU) 2018/1725.


This privacy policy covers all the European Commission’s websites within the ec.europa.eu domain as well as inter-institutional EU websites on the europa.eu domain that are managed by the Commission. You can browse through most of these websites without giving any personal data.  


In certain cases though, your personal data may be required for the provision of an e-service. When personal data is required for that purpose, you can find more detailed information on that in a specific privacy statement linked to the website. You will find which service you should contact in that specific privacy statement.


In this respect:


an operational controller ensures conformity with the specific privacy statement in place for each e-service

the Data Protection Officer ensures in an independent manner the internal application of the Regulation in the Commission, and advises operational controllers on their data protection obligations

the European Data Protection Supervisor acts as an independent supervisory authority

Information contained in a specific privacy statement

When visiting other Commission websites, further specific privacy statements will contain the following information about the use of your personal data:


the purposes of the processing and how your personal data is processed

on what legal grounds your personal data is processed

which personal data is collected and further processed

how long it is kept

how it is protected and safeguarded

who has access to your personal data

what are your rights and how you can exercise them

who to contact if you have questions or complaints

e-services

An e-service on the ec.europa.eu websites is a service or resource that improves communication between people and the European Commission.


3 types of e-services are offered on the Commission websites:


information services that provide easy and effective access to information

interactive communication services to facilitate policy consultations and feedback

transaction services that allow basic forms of transactions with the EU, such as procurement, financial operations, recruitment, event enrollment, and ordering documents

Europa Analytics

Europa Analytics is the corporate service that measures the effectiveness and efficiency of the European Commission's websites on Europa.


You are free to refuse the use of this service – either via the cookie banner that appears at the top of the first page you visit or at Europa Analytics.


Choosing not to use this service does not affect your navigation experience on Europa websites of the Commission.


More about Europa Analytics for European Commission websites


More about Europa Analytics for European Union websites


IP adress and device ID

When you access a European Commission website, the European Commission receives as an essential technical requirement the Internet Protocol address (IP address) or the device ID of the device used to access the website.


Without this information, you will not be able to establish a technical connection between your devices and the server infrastructure maintained by the European Commission and therefore will not be able to access the websites of the European Commission.


The European Commission only keeps this information for the time necessary to fulfil the request, namely for the duration of the browsing session. In addition, IP addresses and device IDs might be saved for one year in the log files of the Directorate-General for Informatics operational environment for security or other purposes (see DPR-EC-02886 DIGIT IT security operations and services for more information).


Cookies and third parties

Some websites of the Commission on Europa use 'first-party cookies'. These are cookies set and controlled by the Commission, not by any external organisation.


Read more about our cookies here.


The Commission's websites within the ec.europa.eu domain may provide links to third-party sites. In order to use third party content on our websites, you may need to accept their specific terms and conditions, including their cookie policies over which we have no control.


Safeguarding information

Collected personal data are stored by the Commission under the Commission Decision (EU, Euratom) 2017/46 of 10 January 2017 on the security of communication and information systems in the Commission.  


The Commission’s contractors are bound by a specific contractual clause for any processing operations of your data on behalf of the Commission, and must guarantee the data protection and confidentiality level required by Regulation (EU) 2018/1725.


Your rights as a data subject

You have the right to obtain access to the personal data held by the Commission about you and to request its rectification or erasure, or restriction of processing or, where applicable, the right to object to processing or the right to data portability. Where the processing is based on your consent or explicit consent, you also have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.


For any request concerning the processing of your personal data, we invite you to contact the operational controller responsible (as identified in the privacy statement related to the specific processing activity or e-service).


Where to find more detailed information

The Commission Data Protection Officer (DPO) publishes the register of all processing operations on personal data by the Commission, which have been documented and notified to him.


respond to your report within three business days with our evaluation of the report

handle your report with strict confidentiality

where possible, inform you when the vulnerability has been remedied

process the personal data that you provide (such as your e-mail address and name) in accordance with the applicable data protection legislation and will not pass on your personal details to third parties without your permission

publish your name as the discoverer of the problem, if you have agreed to this in your initial e-mail, when and if we disclose the problem publicly


Disclaimer

The European Commission maintains this website to enhance public access to information about its initiatives and European Union policies in general. Our goal is to keep this information timely and accurate. If errors are brought to our attention, we will try to correct them. However, the Commission accepts no responsibility or liability whatsoever with regard to the information on this site.


This information is


of a general nature only and is not intended to address the specific circumstances of any particular individual or entity

not necessarily comprehensive, complete, accurate or up to date

sometimes linked to external sites over which the Commission services have no control and for which the Commission assumes no responsibility

not professional or legal advice (if you need specific advice, you should always consult a suitably qualified professional).

Please note that it cannot be guaranteed that a document available online exactly reproduces an officially adopted text. Only the Official Journal of the European Union (the printed edition or, since 1 July 2013, the electronic edition on the EUR-Lex website) is authentic and produces legal effects.


It is our goal to minimise disruption caused by technical errors. However some data or information on our site may have been created or structured in files or formats that are not error-free, and we cannot guarantee that our service will not be interrupted or otherwise affected by such problems. The Commission accepts no responsibility with regard to such problems incurred as a result of using this site or any linked external sites.


This disclaimer is not intended to limit the liability of the Commission in contravention of any requirements laid down in applicable national law nor to exclude its liability for matters which may not be excluded under that law.


External link disclaimer

European Commission websites in the europa.eu domain may contain “external links” to websites in domains other than europa.eu, which may not be owned or funded by the European Commission, over which Commission services have no control and for which the Commission assumes no responsibility.


When visitors to European Commission websites choose to follow a link to any external website, they leave the official domain of the European Commission, and are subject to the cookie, privacy and legal policies of the external website.


Compliance with applicable data protection and accessibility requirements of external websites linked to from Commission websites in the europa.eu domain, falls outside the control of the European Commission and is the explicit responsibility of the external website.


Disclaimer of endorsement

The purpose of any linked reference from European Commission websites to any specific external resource, online service or a website, is to enhance the information available on European Commission websites and help visitors to those websites.


Such linked references do not constitute endorsement by the European Commission of the specific external resource, online service or a website, nor endorsement of the information, contained in the linked reference, nor endorsement of the organisations owning the external websites.


Privacy policy

The European Union is committed to user privacy. The privacy policy covers the European Union's websites within the europa.eu domain.


The Commission's reuse policy is implemented by the Commission Decision of 12 December 2011 on the reuse of Commission documents.


Unless otherwise indicated (e.g. in individual copyright notices), content owned by the EU on this website is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. This means that reuse is allowed, provided appropriate credit is given and changes are indicated.


You may be required to clear additional rights if a specific content depicts identifiable private individuals or includes third-party works. To use or reproduce content that is not owned by the EU, you may need to seek permission directly from the rightholders. Software or documents covered by industrial property rights, such as patents, trade marks, registered designs, logos and names, are excluded from the Commission's reuse policy and are not licensed to you.


This site is managed by : Tuber Magazine Free


No comments:

Leave a Reply

Recent Posts

Comments

Blog Archive