{{ $t('FEZ002') }} Academic Affairs Office|
| I. | Social engineering refers to the exploitation of human weaknesses (such as curiosity, greed, and desire for knowledge) and interpersonal interactions (such as phone calls, emails, etc.) to trick individuals into revealing personal or sensitive information. It is a common hacking technique that has caused significant threats and losses to government agencies, businesses, and individuals in recent years. Schools are advised to periodically remind staff not to open or forward emails, web links, text messages, and files from unknown sources, to regularly back up important data, and to ensure computers are equipped with antivirus software. |
| II. | To prevent personal data leakage and cybersecurity incidents, schools are requested to implement the following preventive measures to enhance protection: |
| (1) | Student personal data should be properly stored and used in accordance with the Personal Data Protection Act and other relevant regulations for collection, processing, and utilization, ensuring strict adherence to personal data protection. |
| (2) | The bureau provides a centralized firewall (Forti3000D) for schools to use. Please review your firewall rules and disable any unused ports. Ensure that individual systems only open ports necessary for external services. If external services need to be provided, it is recommended to restrict access through a whitelist to enhance access control. |
| (3) | If school procurements include network-connected features (e.g., IP cameras, network printers, Network Attached Storage (NAS), infrared thermal imagers, etc.), please disable these features if they are not in use. Do not assign physical IP addresses to these devices. Exposing devices with physical IP addresses to the public internet makes them vulnerable to exploitation by malicious actors. If external access is required, please restrict the source IP addresses. Additionally, do not use the default usernames and passwords for related devices, hosts, and systems, and regularly check for firmware updates. |
| (4) | The bureau has provided antivirus software (ESET) and Microsoft volume licensing. Please update them regularly to the latest versions and do not use free or cracked software. When not using computer equipment, it is advisable to log out and lock the screen, set up a screen saver, shut down the computer, or take other appropriate protective measures. |
| (5) | Ensure that all managed system accounts are legally authorized, and avoid having idle (unused) accounts or unauthorized user accounts (e.g., for personnel who have changed positions or resigned). Unused system accounts should be deleted/disabled. Do not share accounts, and properly safeguard account credentials, refraining from disclosing or providing them to others. |
| (6) | Passwords for administrator or high-privilege user accounts should be changed regularly (e.g., monthly, quarterly) and set with strong complexity. Password recommendations are as follows: |
| 1. | Passwords should be at least 8 characters long. |
| 2. | Password complexity should involve a mix of alphanumeric characters, special symbols, and both uppercase and lowercase letters. |
| 3. | Passwords should be set to avoid any obvious associations that could make them easily guessable (e.g., ID numbers, birth dates, and phone numbers). |
{{ $t('FEZ003') }} Invalid date
{{ $t('FEZ014') }} Invalid date|
{{ $t('FEZ004') }} 2023-05-18|
{{ $t('FEZ005') }} 1273|