{"id":22661,"date":"2016-10-04T16:15:21","date_gmt":"2016-10-04T16:15:21","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/"},"modified":"2026-08-08T04:57:48","modified_gmt":"2026-08-08T04:57:48","slug":"6-must-haves-for-fed-bug-bounty-programs","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/","title":{"rendered":"6 must-haves for fed bug bounty programs"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">When you are the U.S. federal government, how do you uncover security weaknesses and vulnerabilities without jeopardizing the country&#8217;s most critical systems and data? The answer is to follow in the footsteps of leading technology brands who crowdsource vulnerability discovery and disclosure while ensuring uptime and security.<br\/><br\/> Defense Digital Service (DDS), the Department of Defense&#8217;s arm of the White House&#8217;s U.S. Digital Service, did just that in early 2016 with the DoD&#8217;s first ever bug-bounty, called &#8220;Hack the Pentagon.&#8221; By taking advantage of the innovations and new thinking that characterize the private sector, the DoD found a cost-effective way to support its internal cybersecurity experts and better protect its systems and networks.<br\/><br\/><\/p>\n\n\n\n\n\n<p class=\"wp-block-paragraph\"><b>What is a Bug Bounty Program?<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While bug bounties are common in the private sector, the federal government had never implemented this approach. That said, the concept is relatively simple: An organization incentivizes outside researchers \u2013 or white-hat hackers \u2013 to test the security of its networks and applications and report what they find so that the organization can address the vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, DDS hired a third party, HackerOne, to organize and manage the hackers who would try to identify vulnerabilities. Specific web sites with high-visibility, owned and hosted by the DoD\u2019s Defense Media Activity (DMA) \u2013 a government agency providing DoD enterprisewide cloud services consisting of a web-based content management system for over 700 public-facing military and DoD websites \u2013 were chosen for the program as targets for the approved hackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Hack The Pentagon: Lessons Learned<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Hack the Pentagon program ran from April 18 through May 12, during which time 252 vetted hackers submitted at least one vulnerability report each, for a total of <a href=\"http:\/\/www.defense.gov\/Portals\/1\/Documents\/Fact_Sheet_Hack_the_Pentagon.pdf\" title=\"Link: http:\/\/www.defense.gov\/Portals\/1\/Documents\/Fact_Sheet_Hack_the_Pentagon.pdf\">1,189 reports<\/a>. As the hacker reports were submitted, DDS and DMA worked to qualify and remediate each vulnerability in real time with support from HackerOne.<\/p>\n\n\n\n\n\n<p class=\"wp-block-paragraph\">For agencies hoping to emulate DoD\u2019s success with the next big &#8220;hackathon,&#8221; they must ensure that the proper practices are in place before, during and after the bug-bounty program in order to fully maximize all the benefits. Here are some key insights to keep in mind:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Thwart internet-based attacks<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">: All sites related to the agency that is being tested are high visibility targets and a bug bounty program would shine even more media attention on them, increasing the likelihood of attacks. Securing sites to the utmost degree should be a key requirement of any bug-bounty program.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Ensure availability<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">: To get the most value out of a bug bounty program, the agency needs to certify that the sites that it\u2019s offering up for vulnerability testing remain online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Broaden the invite list<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">: The more white-hat hackers that are invited to participate, the more bugs that could be found. In this case, too many cooks in the kitchen is a good thing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Expand the attack surface<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">: To provide both experienced researchers and novice hackers with a meaningful challenge, the program needs to include sites that are significant enough targets along with some outside the perimeter of the agency being tested. Widening the scope and adding websites enables even less skilled hackers to find vulnerabilities on outdated and poorly configured web domains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Handle external communications<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">: In addition to launching and managing the overall program effectively, the agency and its supporting partners need to manage all external communications with the press regarding every aspect of the program.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Utilize actionable intelligence<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">: Agencies should harness programs that leverage advanced algorithms to compute a risk score based on prior behavior observed across the entire network. This means that on day one of the hackathon, agencies have actionable intelligence on thousands of unique client IP addresses trying to target the website in question.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The total contract value for Hack the Pentagon reports that qualified for the bounty, including the paid out bounties, was <a href=\"http:\/\/www.defense.gov\/Portals\/1\/Documents\/Fact_Sheet_Hack_the_Pentagon.pdf\" title=\"Link: http:\/\/www.defense.gov\/Portals\/1\/Documents\/Fact_Sheet_Hack_the_Pentagon.pdf\">approximately $150,000<\/a>. In Secretary of Defense Ash Carter\u2019s estimation, the DoD would have spent <a href=\"http:\/\/www.defense.gov\/Portals\/1\/Documents\/Fact_Sheet_Hack_the_Pentagon.pdf\" title=\"Link: http:\/\/www.defense.gov\/Portals\/1\/Documents\/Fact_Sheet_Hack_the_Pentagon.pdf\">more than $1 million<\/a>uncovering the same vulnerabilities if it had undergone its typical process of hiring an outside firm to conduct a security audit and vulnerability assessment. Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Tom Ruff is the vice president of public sector for Akamai Technologies where he helps federal and state government agencies, as well as higher education institutions, accelerate and improve the secured delivery of content and applications over the Internet and in the cloud. Tom has more than 30 years of IT industry experience, having held numerous executive management positions at Fortune 500 companies.<\/i><\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.<\/p>\n","protected":false},"author":7,"featured_media":27481,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":0,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[26],"tags":[],"coauthors":[1805],"class_list":["post-22661","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinions"],"acf":{"subheadline":"","legacy_arc_id":"J3OQXPNGU5AHVBKI4IXCJS2HPM","arc_canonical_url":"\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>6 must-haves for fed bug bounty programs - Federal Times<\/title>\n<meta name=\"description\" content=\"Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"6 must-haves for fed bug bounty programs\" \/>\n<meta property=\"og:description\" content=\"Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2016-10-04T16:15:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T04:57:48+00:00\" \/>\n<meta name=\"author\" content=\"Staff\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Staff\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"6 must-haves for fed bug bounty programs\",\n\t            \"datePublished\": \"2016-10-04T16:15:21+00:00\",\n\t            \"dateModified\": \"2026-08-08T04:57:48+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/\"\n\t            },\n\t            \"wordCount\": 760,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ruff.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Opinion\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/\",\n\t            \"name\": \"6 must-haves for fed bug bounty programs - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ruff.jpg.jpg\",\n\t            \"datePublished\": \"2016-10-04T16:15:21+00:00\",\n\t            \"dateModified\": \"2026-08-08T04:57:48+00:00\",\n\t            \"description\": \"Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ruff.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ruff.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/2016\\\/10\\\/04\\\/6-must-haves-for-fed-bug-bounty-programs\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Opinion\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/opinions\\\/\",\n\t                    \"ad_zone\": \"opinions\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"6 must-haves for fed bug bounty programs\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"6 must-haves for fed bug bounty programs - Federal Times","description":"Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/","og_locale":"en_US","og_type":"article","og_title":"6 must-haves for fed bug bounty programs","og_description":"Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/","og_site_name":"Federal Times","article_published_time":"2016-10-04T16:15:21+00:00","article_modified_time":"2026-08-08T04:57:48+00:00","author":"Staff","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Staff","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"6 must-haves for fed bug bounty programs","datePublished":"2016-10-04T16:15:21+00:00","dateModified":"2026-08-08T04:57:48+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/"},"wordCount":760,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ruff.jpg.jpg","articleSection":["Opinion"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/","name":"6 must-haves for fed bug bounty programs - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ruff.jpg.jpg","datePublished":"2016-10-04T16:15:21+00:00","dateModified":"2026-08-08T04:57:48+00:00","description":"Thanks to the success of Hack the Pentagon, we can expect to see additional bug bounty programs continue to ramp up across the federal government.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ruff.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ruff.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/2016\/10\/04\/6-must-haves-for-fed-bug-bounty-programs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Opinion","item":"https:\/\/one.sightlinemg.com\/federaltimes\/opinions\/","ad_zone":"opinions"},{"@type":"ListItem","position":3,"name":"6 must-haves for fed bug bounty programs"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/ruff.jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/22661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=22661"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/22661\/revisions"}],"predecessor-version":[{"id":22675,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/22661\/revisions\/22675"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=22661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=22661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=22661"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=22661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}