_content/doc/security: request reporters to include preferred attribution

Also fix typo and reword surrounding area for hopefully better clarity.

Change-Id: I787d5ce95856db879afbfd629bfee5ae6a6a6964
Reviewed-on: https://go-review.googlesource.com/c/website/+/822367
Reviewed-by: Nicholas Husin <husin@google.com>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Damien Neil <dneil@google.com>
Auto-Submit: Nicholas Husin <nsh@golang.org>
diff --git a/_content/doc/security/policy.md b/_content/doc/security/policy.md
index 5cf8efe..d1c6c50 100644
--- a/_content/doc/security/policy.md
+++ b/_content/doc/security/policy.md
@@ -19,19 +19,18 @@
 {one-line summary}", and avoid sending attachments in your email unless strictly
 necessary in order to avoid your message being marked as spam.
 
-Please keep reports succint, including a description of the issue you've found,
+If desired, please include your preferred attribution as part of the report.
+This attribution will be added to the CVE, if one is published.
+
+Please keep reports succinct, including a description of the issue you've found,
 the way in which you believe it can be exploited, and a small reproduction test
 case or program which demonstrates the issue.
 
 We have a [list of decisions](/doc/security/decisions) about commonly-reported
 categories of issues.
 
-Your email will be acknowledged within 7 days, and you'll be kept up to date
-with the progress until resolution. Your issue will be fixed or made public
-within 90 days.
-
-If you have not received a reply to your email within 7 days, please follow up
-with the Go Security team again at
+Your email will be acknowledged within 7 days. If you have not received a reply
+by then, please follow up with the Go Security team again at
 [security@golang.org](mailto:security@golang.org). Please make sure the word
 **vulnerability** is in your email.
 
@@ -41,6 +40,9 @@
 report a technical security or an abuse risk related bug in a Google product
 (SQLi, XSS, etc.)"_, and list _"Go"_ as the affected product.
 
+Your issue will be fixed or made public within 90 days after our initial
+acknowledgement.
+
 ## Tracks
 
 Depending on the nature of your issue, it will be categorized by the Go