Coordinated Vulnerability Disclosure Readiness of Romanian Public Institutions: A Two-Vantage-Point RFC 9116 Census with Retrospective Web-Archive Analysis
收藏资源简介:
A census of RFC 9116 (security.txt) adoption among Romanian public institutions, measured on 30 July 2026 from two vantage points, one inside Romania and one in a German data centre, using the same code and an external control group in every run. Two populations were measured. Population A: all 588 unique domains in the official gov.ro subdomain registry, 2024 edition. Population B: 62 distinct public institutions of interest, in nine categories, from cybersecurity bodies and ministries to city halls and hospitals. Result: one institution publishes a security.txt, and its Expires field lapsed on 1 December 2025. Zero conformant and valid files in either population. The dataset includes the full method note, the complete measurement tooling, 536 evidence captures with response headers and SHA-256 manifests from both vantage points, a retrospective analysis of the Internet Archive index covering four years, and the reconstructed chronology of the only file found. Method contributions: a six-state classification that separates expired from absent files; an external control group measured in every run, so that a zero result carries proof the instrument could see; and a documented false positive showing that Internet Archive index metadata alone does not establish that a file existed. All measurements used HTTP GET requests on standardised public paths. No port scanning, no credential testing, no bypassing of access controls.



