移至網頁之主要內容區位置
::: 桃園國民中學

Academic Affairs Announcement

Executive Yuan's "Principles for Government Agencies on Restricting the Use of Products That Endanger National Cybersecurity" and List of Prohibited Software

{{ $t('FEZ002') }} Academic Affairs Office|

 

====Refer to the Official Letter No. 1140034271 of the Department of Education, Taoyuan City, dated April 24, 2025 ====

This Administration has compiled a list of software known to pose risks to national cybersecurity, and established the "List of Prohibited Software for This Administration" as a basis for asset management and usage regulations. In addition to the software listed in the aforementioned prohibited software list, agencies are requested to regularly/irregularly inventory other application software (excluding operating systems and drivers) used within the agency. Except for business needs, any unauthorized or non-official software shall be removed or replaced within one month to ensure the overall information security of the agency.

Attached is one copy of the List of Prohibited Software for This Administration. (Details as per attachment)

 

 

 

=====Refer to the Official Letter No. 1140029690 of the Department of Education, Taoyuan City, dated April 8, 2025 =====

I.This is in accordance with the Official Letter No. 1140084422 of the Taoyuan City Government, dated April 1, 2025, which forwarded the Official Letter No. 1141000253 of the Executive Yuan, dated March 31, 2025.
II.To prevent improper theft of official and sensitive data, leading to the leakage of confidential official information or posing risks to national cybersecurity, the Executive Yuan has previously issued the "Principles for Restrictions on the Use of Products that Endanger National Cybersecurity by Government Agencies," which clearly requires central and local government agencies (institutions), public schools, public enterprises, administrative corporations, and venues that are operated by themselves or outsourced to provide public activities or services, to restrict the use of products that endanger national cybersecurity. Furthermore, the Official Letter No. 1090201804A of the Secretary-General of the Executive Yuan, dated December 18, 2020, reiterated that information and communication products for official use shall not be of mainland Chinese brands and shall not install non-official software.
III.In response to the emerging cybersecurity risks extended by new forms of digital services, it is reiterated that all government agencies should comply with the aforementioned regulations and cooperate with the following matters:
(1)Information and communication products for official use shall not be of mainland Chinese brands and shall not install non-official software.
(2)Agencies shall manage mainland Chinese brand information and communication products that are already in use or have been procured by listing them, and they shall not be connected to the official network.
(3)Before the aforementioned products are replaced, appropriate supporting measures or corresponding actions shall be taken, such as:
1.Download them to a standalone computer without personal or sensitive data and use them in an offline or non-official network environment.
2.Strengthen cybersecurity management measures, such as setting strong passwords and prohibiting remote maintenance.
3.If the product experiences a cybersecurity attack that causes its display to be replaced, immediately replace the static image or shut down the device.
4.If the product is hardware, ensure it does not have continuous network connectivity (not just by disabling software). If updates are required via external devices, a dedicated person must be present to supervise the entire process, and the external device must be removed immediately after the transmission is complete.
5.After the product's service life expires, do not purchase any more products that endanger national cybersecurity.
6.Establish appropriate supporting control measures and include the usage status in the annual audit review items.
(4)Government agencies shall, in principle, completely prohibit the use of mainland Chinese brand information and communication products such as Deepseek AI. If, due to business needs and the absence of other alternatives, it is necessary to procure or use the aforementioned products, the reasons must be clearly stated, and approval must be obtained from the agency's Chief Information Security Officer and the Chief Information Security Officer of the higher-level agency, sequentially. The procurement shall be reported to the digital development department, the competent authority under the "Cybersecurity Management Act," for approval, and managed as a special project with a listed record. The usage principles for teaching and research environments shall be handled in accordance with the regulations separately established by the Ministry of Education and the National Science and Technology Council.


{{ $t('FEZ003') }} Invalid date

{{ $t('FEZ004') }} 2026-06-17|

{{ $t('FEZ005') }} 1869|