Information Security
Information Security
Methods for Identifying and Resolving Data Security Issues
Methods for Identifying Data Security Vulnerabilities within Information Systems
Conduct regular security reviews and configuration checks of information systems, applications, and network environments to identify potential security risks.
Methods for resolving identified data security risks and vulnerabilities
Implement the principle of least privilege and restrict the access rights of system administrators and users to prevent unauthorized access and data leakage.
Adopt appropriate encryption mechanisms for sensitive data to ensure data confidentiality and integrity during transmission and storage.
Establish an information security incident response and notification mechanism, and conduct regular drills to strengthen information security incident handling and recovery capabilities.
Information Security Education and Training and Attack Method Awareness
To enhance the awareness and ability of NKUST’s faculty and staff in preventing common network attack methods, in addition to technical monitoring measures, we also employ educational training and outreach activities to strengthen vigilance against new types of attacks, such as the following:
ISO/IEC 27001 -Based Information Security Management Measures
In accordance with ISO/IEC 27001 Information Security Management System (ISMS), NKUST has established relevant management and technical measures to reduce the risk of network attacks, including the following:
Conducting regular risk assessments and vulnerability scans, and implementing vulnerability patching and improvements based on the results.
Regularly conducting information system security inspections and vulnerability scans to identify and improve equipment security flaws.
Establishing a response mechanism for information security incidents, including backup and data recovery measures, to reduce the impact caused by information security incidents.
Regularly conducting information security training to strengthen faculty and staff members’ ability to recognize attack techniques such as social engineering and phishing emails.
Monitoring the main computer room in real time through the network monitoring system and information security equipment to detect and defend against possible intrusion attempts.
Implementing secure configuration management to ensure that unnecessary services are disabled in systems and equipment, and maintaining secure settings.
Establishing a log management and monitoring mechanism to track system activities and detect abnormal activity early.
Approaches and Processes for Personal Data Protection
Information Lifecycle
NKUST places great importance on the protection of student personal data. In accordance with the Personal Data Protection Act and international privacy management standards such as ISO 29100 and BS 10012, the university has established a comprehensive data lifecycle management mechanism. This mechanism covers data collection, processing and utilization, storage, and destruction procedures to ensure that student data is appropriately protected at every stage.
The university continues to strengthen information security and personal data protection management. In the current year, there were no incidents of information leakage, data theft, or loss. The number of information leakage cases, the proportion of personal data breaches, and the number of affected students all remained at zero. In addition, no verified complaints regarding privacy violations have been received from external stakeholders or the education authorities, demonstrating the University’s effective management in information security governance and privacy protection.
Information leakage
Data theft, or loss
Privacy violations
The number of affected students