{{ $t('FEZ002') }} Academic Affairs Office|
====Refer to the Official Letter No. 1140034271 dated April 24, 114 of the Republic of China, Taoyuan Education and Information Bureau ==== Our government has compiled a list of software known to pose risks to national information security and established a "List of Prohibited Software for Our Government" as a basis for asset management and usage regulations. In addition to the software listed in the aforementioned prohibited software list, agencies are requested to regularly/irregularly inventory other application software (excluding operating systems and drivers) used within the agency. Except for business needs, any unauthorized or non-official software should be removed or replaced within one month to ensure the overall information security of the agency. Attached is one copy of the "List of Prohibited Software for Our Government." (See attachment for details) |
=====Refer to the Official Letter No. 1140029690 dated April 8, 114 of the Republic of China, Taoyuan Education and Information Bureau =====
| I. | This is in accordance with the Official Letter No. 1140084422 dated April 1, 114 of our government, which was forwarded from the Executive Yuan's Official Letter No. 1141000253 dated March 31, 114. |
| II. | To prevent the improper theft of official and sensitive data, which could lead to the leakage of confidential official information or pose risks to national information security, the Executive Yuan has previously issued the "Principles for Restrictions on the Use of Information Security Risk-Causing Products by Government Agencies." This clearly requires central and local government agencies (organizations), public schools, public enterprises, administrative corporations, and venues that are operated independently or by outsourcing to provide public activities or services, to restrict the use of information security risk-causing products. Furthermore, the Executive Yuan Secretary-General's Official Letter No. 1090201804A dated December 18, 109, reiterated that information and communication products for official use must not be of mainland Chinese brands and must not have non-official software installed. |
| III. | In response to the emerging cybersecurity risks extended by new types of digital services, it is reiterated that all government agencies should comply with the aforementioned regulations and cooperate with the following matters: |
| (1) | Information and communication products for official use must not be of mainland Chinese brands and must not have non-official software installed. |
| (2) | Agencies should maintain a list of mainland Chinese brand information and communication products that are already in use or have been procured, and they must not be connected to the official network. |
| (3) | Before the aforementioned products are replaced, appropriate supporting measures or corresponding actions should be taken, such as: |
| 1. | Download them to a standalone computer without personal data or information and use them in an offline or non-official network environment. |
| 2. | Strengthen information security management measures, such as setting strong passwords and prohibiting remote maintenance. |
| 3. | If the product experiences a cybersecurity attack that causes its display to be replaced, immediately replace the static image or shut down the device. |
| 4. | If the product is hardware, ensure it does not have continuous network connectivity (not just by disabling it through software). If updates are required via external devices, a dedicated person must be present to supervise the entire process, and the external device must be removed immediately after the transmission is complete. |
| 5. | After the product's usage period expires, do not purchase any more information security risk-causing products. |
| 6. | Establish appropriate supporting control measures and include the usage status in the annual audit review items. |
| (4) | Government agencies shall, in principle, completely prohibit the use of mainland Chinese brand information and communication products such as Deepseek AI. If, due to business needs and the absence of alternative solutions, it is necessary to procure or use the aforementioned products, the reasons must be clearly stated and approved by the agency's Chief Information Security Officer and the Chief Information Security Officer of the higher-level agency, level by level. The procurement shall then be reported to the competent authority for the "Cybersecurity Management Act," the Digital Development Administration, for approval, and managed as a special project with a listed record. The usage principles for teaching and research environments shall be handled in accordance with the regulations separately established by the Ministry of Education and the National Science and Technology Council. |
{{ $t('FEZ012') }}
{{ $t('FEZ003') }} Invalid date
{{ $t('FEZ004') }} 2026-06-17|
{{ $t('FEZ005') }} 1861|