移至網頁之主要內容區位置
::: 桃園國民中學

Information Group Announcement

Executive Yuan's "Principles for Government Agencies on Restricting the Use of Products That Harm National Information and Communication Security" and List of Prohibited Software

{{ $t('FEZ002') }} Academic Affairs Office|

 

====Refer to the Official Letter No. 1140034271 of the Department of Education, Taoyuan City, dated April 24, 2025 ====

This Administration has compiled a list of software known to pose risks to national cybersecurity, and established the "List of Prohibited Software for This Administration" as a basis for asset management and usage regulations for agencies. In addition to the software listed in the aforementioned prohibited software list, agencies are requested to regularly/irregularly inventory other application software (excluding operating systems and drivers) used within the agency. Except for business needs, any unauthorized or non-official software should be removed or replaced within one month to ensure the overall information security of the agency.

Attached is one copy of the "List of Prohibited Software for This Administration." (Details as per attachment)

 

 

 

=====Refer to the Official Letter No. 1140029690 of the Department of Education, Taoyuan City, dated April 8, 2025 =====

I.This is in accordance with the Official Letter No. 1140084422 of the Administration, dated April 1, 2025, which forwarded the Official Letter No. 1141000253 of the Executive Yuan, dated March 31, 2025.
II.To prevent the improper theft of official and sensitive data, leading to the leakage of confidential official information or posing risks to national cybersecurity, the Executive Yuan has previously issued the "Principles for Restrictions on the Use of Products that Endanger National Cybersecurity by Government Agencies," which clearly requires central and local government agencies (organizations), public schools, public enterprises, administrative corporations, and venues that are operated independently or by outsourcing to provide public activities or services, to restrict the use of products that endanger national cybersecurity. Furthermore, the Official Letter No. 1090201804A of the Secretary-General of the Executive Yuan, dated December 18, 2020, reiterated that ICT products for official use shall not be of mainland Chinese brands and shall not have non-official software installed.
III.In response to emerging cybersecurity risks extending from new types of digital services, it is reiterated that all government agencies should comply with the aforementioned regulations and cooperate with the following matters:
(1)ICT products for official use shall not be of mainland Chinese brands and shall not have non-official software installed.
(2)Agencies shall manage mainland Chinese brand ICT products that are already in use or have been procured by listing them, and they shall not be connected to the official network.
(3)Prior to the replacement of the aforementioned products, appropriate supplementary measures or corresponding actions should be taken, such as:
1.Download to a standalone computer without personal or sensitive data and use it offline or on an independent network not connected to the official network.
2.Strengthen cybersecurity management measures, such as: setting strong passwords, prohibiting remote maintenance, etc.
3.If the product experiences a cybersecurity attack that causes its display to be replaced, immediately replace the static image or shut down the device.
4.If the product is hardware, ensure it does not have continuous network connectivity (not just by disabling software). If updates are required via external devices, a dedicated person must be present to supervise the entire process, and the external device must be removed immediately after the transmission is complete.
5.After the product's usage period expires, do not purchase any more products that endanger national cybersecurity.
6.Establish appropriate supplementary control measures and include the usage status in the annual audit review items.
(4)Government agencies shall, in principle, completely prohibit the use of ICT products from mainland Chinese brands such as Deepseek AI. If, due to business needs and the absence of other alternatives, it is necessary to procure or use the aforementioned products, the reasons must be clearly stated, and approval must be obtained sequentially from the agency's Chief Information Security Officer and the Chief Information Security Officer of the higher-level agency. The procurement shall then be reported to the digital development department, the competent authority under the "Cybersecurity Management Act," for approval, and shall be managed through a special project with a listed inventory. The usage principles for teaching and research environments shall be handled in accordance with the regulations separately established by the Ministry of Education and the National Science and Technology Council.


{{ $t('FEZ003') }} Invalid date

{{ $t('FEZ004') }} 2026-06-17|

{{ $t('FEZ005') }} 1865|