The Australian Health Geography Data (AHGD) project is committed to maintaining the highest security standards for handling Australian health and geographic data. This policy outlines our security practices, vulnerability reporting process, and response procedures.
We actively support the following versions with security updates:
| Version | Supported | Support Status |
|---|---|---|
| 1.0.x | ✅ Actively Supported | Current stable release |
| 0.9.x | End-of-life: 2025-12-31 | |
| < 0.9 | ❌ Not Supported | Please upgrade immediately |
- Current Version (1.0.x): Full support including security patches, bug fixes, and feature updates
- Previous Version (0.9.x): Critical security fixes only until end-of-life
- Legacy Versions: No security support - immediate upgrade recommended
- Email: security@ahgd-project.org
- Response Time: Within 24 hours for critical vulnerabilities
- Encryption: PGP public key available upon request
- Development Team: dev@ahgd-project.org
- Project Maintainer: massimo.raso@ahgd-project.org
For critical security issues requiring immediate attention:
- Emergency Email: security-emergency@ahgd-project.org
- Expected Response: Within 2 hours during business hours (AEST)
DO NOT create public GitHub issues for security vulnerabilities. Instead:
-
Email us directly at security@ahgd-project.org
-
Include the following information:
- Detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any proof-of-concept code (if applicable)
- Your contact information for follow-up
-
Use encryption if the vulnerability is sensitive:
- Request our PGP public key
- Encrypt sensitive details
- Acknowledgement: Within 24 hours for critical issues, 48 hours for others
- Initial Assessment: Within 48-72 hours
- Progress Updates: Weekly updates on investigation status
- Resolution Timeline: Communicated within 5 business days
- Definition: Remote code execution, authentication bypass, data exposure
- Acknowledgement: Within 2 hours (business hours), 24 hours (after hours)
- Initial Fix: Within 24-48 hours
- Public Disclosure: 7-14 days after fix is available
- Definition: Denial of service, privilege escalation, significant data integrity issues
- Acknowledgement: Within 24 hours
- Initial Fix: Within 1 week
- Public Disclosure: 14-30 days after fix is available
- Acknowledgement: Within 48 hours
- Initial Fix: Within 2-4 weeks
- Public Disclosure: 30-90 days after fix is available
- Privacy Act 1988: Full compliance with Australian privacy legislation
- Australian Government Information Security Manual (ISM): Following relevant security guidelines
- Healthcare Sector Cyber Security Framework: Implementing recommended practices
- Data at Rest: AES-256 encryption for sensitive datasets
- Data in Transit: TLS 1.3 for all network communications
- Access Control: Role-based access with principle of least privilege
- Audit Logging: Comprehensive logging of all data access and modifications
- Regular Audits: Monthly security audits using pip-audit and GitHub Dependabot
- Automated Scanning: CI/CD pipeline includes security vulnerability detection
- Update Policy: Security patches applied within defined response timeframes
- 20 vulnerabilities addressed across 15 packages
- 100% elimination of critical and high-severity vulnerabilities
- 70% overall reduction in security vulnerabilities
- Comprehensive testing of all security fixes
- ✅ 0 Critical vulnerabilities (down from 1)
- ✅ 0 High-severity vulnerabilities (down from 4)
- ✅ 0 Moderate vulnerabilities (down from 5)
⚠️ 6 Low-severity vulnerabilities remaining (development tools only)
See our Security Fix Report for complete details.
- Keep Dependencies Updated: Regularly update to latest versions
- Use Virtual Environments: Isolate project dependencies
- Enable Security Scanning: Use pre-commit hooks for security checks
- Follow Secure Coding: Review our security guidelines in
docs/security/
- Data Classification: Understand sensitivity levels of different datasets
- Access Controls: Use only necessary permissions for your role
- Secure Storage: Store derived datasets in approved locations
- Incident Reporting: Report any suspected security issues immediately
- Regular Updates: Apply security patches promptly
- Network Security: Implement appropriate firewall and network controls
- Monitoring: Enable comprehensive security logging
- Backup Security: Ensure backups are encrypted and tested
- Acknowledge vulnerability report
- Assess initial severity and impact
- Isolate affected systems if necessary
- Assemble response team
- Investigate vulnerability thoroughly
- Develop mitigation strategies
- Test potential fixes
- Prepare communication plan
- Implement security fixes
- Conduct comprehensive testing
- Deploy fixes to staging environment
- Prepare public disclosure
- Deploy fixes to production
- Monitor for any issues
- Conduct post-incident review
- Update security procedures
- Application Layer: Input validation, secure coding practices
- Data Layer: Encryption, access controls, audit trails
- Infrastructure Layer: Network security, system hardening
- Operational Layer: Security monitoring, incident response
- Authentication & Authorisation: Multi-factor authentication for admin access
- Data Encryption: End-to-end encryption for sensitive health data
- Network Security: VPN access for remote administration
- Logging & Monitoring: Comprehensive security event logging
- Acknowledge all security reports promptly
- Investigate thoroughly and communicate progress
- Fix vulnerabilities in a reasonable timeframe
- Credit security researchers appropriately (with permission)
We maintain a Security Researchers Hall of Fame to recognise contributions to project security.
- Day 0: Vulnerability reported
- Day 1-2: Initial assessment and acknowledgement
- Day 3-7: Investigation and fix development
- Day 8-14: Testing and validation
- Day 15-30: Deployment and public disclosure
- Secure Coding Practices: Annual training on OWASP Top 10
- Threat Modelling: Regular threat assessment exercises
- Incident Response: Quarterly incident response drills
- Security Documentation: Comprehensive security guides
- Best Practices: Regular communication of security best practices
- Awareness Updates: Monthly security awareness communications
- Internal Audits: Quarterly security reviews
- External Audits: Annual third-party security assessments
- Penetration Testing: Annual penetration testing exercises
- Regulatory Compliance: Regular compliance assessments
- Policy Updates: Annual review and update of security policies
- Training Records: Maintenance of security training records
- Email: security@ahgd-project.org
- Response Time: 24-48 hours
- Email: security-emergency@ahgd-project.org
- Response Time: 2-24 hours
- General Support: support@ahgd-project.org
- Development Issues: Create GitHub issue for non-security matters
Last Updated: 2025-06-22
Policy Version: 1.0
Next Review Date: 2025-12-22
This security policy is reviewed and updated every 6 months or after significant security incidents.