Jump to the main content block

Information Security

 

Information Security

NKUST places great importance on information security and personal data protection, striving to establish a comprehensive information security management system. In accordance with relevant regulations, the University has formulated guidelines and codes for information security and personal data protection management. NKUST was certified under ISO 27001:2013 from 2018 to 2023 and obtained ISO 27001:2022 certification in 2025. To ensure effective management, NKUST has established the Information Security and Personal Data Protection Management Committee. The Committee conducts annual meetings to review policies, conduct audits of information security systems and assets, regularly assess risks, and adjust measures accordingly.
ISO 27001:2022
ISO 27001:2013
Information Security Governance
Personal Data Protection
International Verification
2025
Obtained ISO 27001:2022 certification
Management Mechanism
Annually
The Committee conducts annual meetings to review policies
Information Leakage Incidents
 
0
 
Confirmed Privacy Violation Complaints
0
 

Methods for Identifying and Resolving Data Security Issues

Methods for Identifying Data Security Vulnerabilities within Information Systems

1
Information systems and network devices are periodically scanned using professional vulnerability scanning tools to identify potential security vulnerabilities and weaknesses in the systems. This may include systems or applications that need updating, weak password settings, and unnecessarily open services or ports.
2
Every two years, conduct penetration testing of the core system to simulate the behavior of attackers and evaluate the system for potential vulnerabilities.
3
Conduct information security social engineering drills in coordination with the Ministry of Education or the competent authorities, employing methods such as simulating phishing emails to assess the ability of faculty and staff to defend against social engineering attacks.
4

Conduct regular security reviews and configuration checks of information systems, applications, and network environments to identify potential security risks.

5
Analyze event logs of systems and applications in the main computer room to detect abnormal activities or potential information security events.
6
Establish a continuous security monitoring mechanism in the main computer room, such as firewall log monitoring, intrusion detection systems (IDS), and intrusion prevention systems (IPS), to detect and prevent potential information security threats in real time.

Methods for resolving identified data security risks and vulnerabilities

1
Based on the results of vulnerability scanning, penetration testing, and related security assessments, establish a vulnerability patching and flaw management mechanism, and execute patches based on risk level to reduce the risk of system attacks.
2

Implement the principle of least privilege and restrict the access rights of system administrators and users to prevent unauthorized access and data leakage.

3

Adopt appropriate encryption mechanisms for sensitive data to ensure data confidentiality and integrity during transmission and storage.

4
Establish and implement the Information Security Policy and related management systems to ensure that all units within the organization comply with consistent information security management measures.
5
Regularly conduct information security education and training and awareness campaigns to increase the security awareness of faculty and staff and reduce security risks caused by human factors.
6

Establish an information security incident response and notification mechanism, and conduct regular drills to strengthen information security incident handling and recovery capabilities.

Information Security Education and Training and Attack Method Awareness

To enhance the awareness and ability of NKUST’s faculty and staff in preventing common network attack methods, in addition to technical monitoring measures, we also employ educational training and outreach activities to strengthen vigilance against new types of attacks, such as the following:

Phishing
Attackers using fraudulent emails, phishing websites, or other deceptive methods to induce users to provide sensitive information, such as account passwords or personal data.
Internet of Things (IoT) device security risks
Some IoT devices may have vulnerabilities due to default account credentials or inadequate security mechanisms. Without proper management, attackers may exploit them to gain unauthorized access or use them as a staging point for attacks.

ISO/IEC 27001 -Based Information Security Management Measures

In accordance with ISO/IEC 27001 Information Security Management System (ISMS), NKUST has established relevant management and technical measures to reduce the risk of network attacks, including the following:

Risk assessments

Conducting regular risk assessments and vulnerability scans, and implementing vulnerability patching and improvements based on the results.

 

Vulnerability scans

Regularly conducting information system security inspections and vulnerability scans to identify and improve equipment security flaws.

Response mechanism for information security incidents

Establishing a response mechanism for information security incidents, including backup and data recovery measures, to reduce the impact caused by information security incidents.

 

Information security training

Regularly conducting information security training to strengthen faculty and staff members’ ability to recognize attack techniques such as social engineering and phishing emails.

Monitoring the main computer room in real time

Monitoring the main computer room in real time through the network monitoring system and information security equipment to detect and defend against possible intrusion attempts.

 

Secure configuration

Implementing secure configuration management to ensure that unnecessary services are disabled in systems and equipment, and maintaining secure settings.

Log management

Establishing a log management and monitoring mechanism to track system activities and detect abnormal activity early.

 

Approaches and Processes for Personal Data Protection

01
Establishment of a Comprehensive Personal Data Protection Management System (PIMS)
The University’s Computer Center has developed the Personal Data Protection Management System (PIMS) in accordance with international standards such as ISO 27701 and BS 10012. Personal information protection is integrated into the daily operations of school administration, and the operational procedures are reviewed to ensure compliance with the latest requirements of Taiwan’s Personal Data Protection Act and its enforcement rules.
02
Implementing a Periodic Inventory and Risk Management Mechanism
A university-wide "personal data file inventory" is conducted that identifies personal data processes and assesses the risk level of the data flows identified in the inventory in order to reduce the likelihood of excessive data collection or unexpected leakage.

 

03
Personal Data Protection Internal Audits
Through the personal data internal audit, the physical environment for personal data processing at each unit is reviewed, including whether official document cabinets are locked and electronic access mechanisms are in place. Spot checks are conducted on file transmission encryption to ensure that management systems are up-to-date.
04
Strengthen Post-Incident Adjustment and Boost Awareness of Personal Data Protection: Data Breach Response Drills and Awareness Improvement
A "personal data breach response drill" is conducted to test the incident reporting process and handling procedures, ensuring that reporting is completed and protective measures are activated within 1 hour of an incident occurring.

Information Lifecycle

NKUST places great importance on the protection of student personal data. In accordance with the Personal Data Protection Act and international privacy management standards such as ISO 29100 and BS 10012, the university has established a comprehensive data lifecycle management mechanism. This mechanism covers data collection, processing and utilization, storage, and destruction procedures to ensure that student data is appropriately protected at every stage.

Data collection
The university collects students’ basic information, learning records, and related data in accordance with operational needs and legal purposes
Processing and utilization
The data is used solely within the lawful scope of education, administrative management, and academic research
Storage
Data security is maintained through encryption technology, access control, and information security measures
Destruction
Secure deletion or media disposal is carried out in accordance with relevant regulations to prevent unauthorized access or improper use of data, thereby protecting students’ privacy rights and fulfilling personal data protection responsibilities

The university continues to strengthen information security and personal data protection management. In the current year, there were no incidents of information leakage, data theft, or loss. The number of information leakage cases, the proportion of personal data breaches, and the number of affected students all remained at zero. In addition, no verified complaints regarding privacy violations have been received from external stakeholders or the education authorities, demonstrating the University’s effective management in information security governance and privacy protection.

0

Information leakage

0

Data theft, or loss

0

Privacy violations

0

The number of affected students

Login Success