In May 2022, the Department of Justice revised its guidance for charging violations of the US’ main anti-hacking law, the Computer Fraud and Abuse Act (CFAA). Under the new guidance, federal prosecutors were directed that “good-faith security research” should not be charged as a violation of the CFAA. This is a huge step forward in reducing legal risk for security researchers, but it raises the question of what good-faith security research is and how prosecutors can spot it. The claim of research must not be used as a get-out-of-jail-free card for all manner of criminal behavior as this would ultimately undermine the credibility of actual research, risk unwarranted violations of privacy and potential harm to property, and expose researchers to more risk. This panel will bring together legal experts and security research leaders to discuss whether the time has come to articulate a Code of Practice for good-faith security research. We will investigate what one might include, and what challenges might exist in the creation, adoption, and utilization of a code. We will also discuss the broader legal landscape for researchers, both in the US and internationally, as well as where lines exist between security research, hacktivism, and hack back.