Responsible Disclosure Policy
1. Document Information
This document contains a description of genua CSIRT according to IETF RFC 2350. It provides basic information about the genua CSIRT, its communication channels and its services, roles and responsibilities.
1.1. Date of Last Update
2026-08-04
1.2. Distribution List for Notifications
There is no distribution list for notifications as of 2026-08-04.
1.3. Locations where this Document May Be Found
The current version of genua CSIRT's RFC 2350 is published at https://csirt.genua.de
1.4. Authenticating this Document
This document has been digitally signed with the genua CSIRT's GPG key. See section 2.8 for more details.
1.5. Document Identification
Title: "RFC 2350 Description of genua CSIRT"
Current Version: 1.0
Initial Date: 2026-07-23
Document classification: non confidential
Expiration: This document is valid until superseded by a later version
2. Contact Information
2.1. Name of the Team
genua Computer Security Incident Response Team
Short name: genua CSIRT
2.2. Address
genua GmbH
z.Hd. genua CSIRT
Domagkstrasse 7
85551 Kirchheim bei München
GERMANY
2.3. Time Zone
Europe/Berlin (UTC+1 / UTC+2 during DST)
2.4. Telephone Number
genua CSIRT Hotline: +49 (89) 991950-900
2.5. Facsimile Number
n.a.
2.6. Other Telecommunication
n.a.
2.7. Electronic Mail Address
For secure, PGP-encrypted communication, please use the key associated with security@genua.de as detailed in Section 2.8.
2.8. Public Keys and Other Encryption Information
genua CSIRT uses GPG to encrypt and digitally sign emails exchanged with its constituency. This ensures data confidentiality, integrity and non-repudiation.
The currently valid GPG key can be found at:
https://www.genua.de/.well-known/security%40genua.de.pub
2.9. Operating Hours
Standard Hours: 09:00–23:00 (UTC+1, and UTC+2 during DST), Monday to Friday (closed on Saturdays, Sundays, and public holidays in Bavaria, Germany).
After Hours: An on-call team is available for critical emergencies.
In addition, we can be contacted 24/7 via the IT service desk.
2.10. Team Members
Head of genua CSIRT: Martin Schulze
The list of the team members can be found on the corresponding internal CSIRT/PSIRT pages.
2.11. Other Information
General information about genua CSIRT as well as links to various security
resources can be found in the internal genua network.
3. Charter
3.1. Mission Statement
"We combine offensive and defensive skills - before, during, and after cybersecurity threats emerge to enhance the resilience of genua."
- Highest standards of ethical integrity
- High degree of service orientation and operational readiness
- Effective responsiveness in case of incidents and emergencies and maximum commitment to resolve the issues
- Building on and complementing the existing capabilities of the constituents
- Facilitating the exchange of good practices between constituents and with peers
- Fostering a culture of openness within a protected environment, operating on a need-to-know basis
3.2. Constituency
he constituency of genua CSIRT is equivalent to the union of the scopes of the internal Corporate Directives Information Security and Data Protection and Cybersecurity.
3.3. Sponsorship and/or Affiliation
genua CSIRT is sponsored and mandated by the office of genua CISO. genua shares information with BSI, ENISA and bdr.
3.4. Authority
The establishment of the genua CSIRT was mandated by the CEO.
genua CSIRT is authorized to order mandatory measures to resolve security incidents and vulnerabilities, and may appeal to its superior units and/or C/ISP to exert their authority, direct and indirect as necessary.
genua CSIRT operates on the following Internet IP addresses:
ip4:80.154.94.0/24 ip4:213.155.76.176/28 ip6:2a12:6900:1000::/36
4. Policies
4.1. Types of Incidents and Level of Support
genua CSIRT is authorized to address all types of cybersecurity incidents which occur, or threaten to occur in our constituency and which require cross-organizational coordination. The level of support given by genua CSIRT will vary depending on the type and severity of the cybersecurity incident or issue, the type of constituent,
the size of the user community affected, and our resources at the time. Incidents will be prioritized according to their apparent severity and extent. genua CSIRT handles the following incident categories:
- Abusive Content
- Malicious Code
- Information Gathering
- Intrusion Attempts
- Intrusions
- Availability Impairment
- Information Content Security
- Fraud
- Vulnerabilities in genua infrastructure and services
- Vulnerabilities in genua products
genua CSIRT is committed to keeping its constituency informed of potential vulnerabilities, and, where possible, will inform this community of such vulnerabilities before they are actively exploited. Product-specific advisories are internally available via an interactive web portal for user subscription.
4.2. Co-operation, Interaction and Disclosure of Information
genua CSIRT highly regards the importance of operational cooperation and information sharing among Computer Security Incident Response Teams, and also with other internal and external parties which may contribute towards or make use of their services. genua CSIRT operates within the confines imposed by national and international legislation and relevant regulations and policies within the genua group. genua CSIRT promotes the controlled information exchange via Traffic Light Protocol (TLP).
4.3. Communication and Authentication
genua CSIRT protects sensitive information in accordance with relevant legislation, regulations and policies within the genua group. Communication security (encryption and authentication) is currently achieved by S/MIME or PGP based email encryption.
5. Services
5.1. Incident Response
genua CSIRT provides assistance to its constituency in handling the technical and organizational aspects of security incidents. In particular, it provides assistance or advice with respect to the following aspects of incident management:
5.1.1 Incident Triage
- Investigating whether an incident did indeed occur.
- Determining the extent of the incident.
5.1.2 Incident Coordination
- Identifying other involved parties, including the constituent and, where applicable, external organizations.
- Facilitating contact with other parties involved, where necessary.
- Facilitating the exchange of information between involved parties.
5.1.3 Incident Resolution
- Advising constituents on appropriate actions in response to an incident.
- Following up on the progress of the constituent in resolving the incident.
- Assisting constituents in the collection and preservation of evidence, where applicable.
genua CSIRT may also act as a coordinator between the affected constituent and any other involved party (e.g. other CSIRTs, law enforcement) but does not directly perform incident handling on behalf of the constituent, unless explicitly agreed otherwise.
5.2. Proactive Activities
genua CSIRT provides the following proactive services to its constituency, to the extent resources permit:
- Distribution of security advisories and alerts relevant to the constituency.
- Monitoring of relevant threat intelligence sources.
- Security awareness activities.
- Vulnerability assessments and penetration testing of constituency-owned assets, upon request or as scheduled.
genua CSIRT reserves the right to prioritize resources based on the severity and impact of an incident, and may not be able to provide the same level of assistance for all reported incidents.
6. Cybersecurity Incident Reporting Forms
For internal incidents, the ways to report are clearly defined.
For external parties, please refer to https://www.genua.de/kontakt/schwachstellenmeldung. A second RFC compliant way to report bugs is documented at https://www.genua.de/.well-known/security.txt.
7. Disclaimers
While every precaution will be taken in the preparation of information, notifications and alerts, genua CSIRT assumes no responsibility for errors or omissions, or for damages resulting from the use of the information contained herein.