跳到主要內容區

國內發生多起網站遭駭客入侵,盜取重要資料事件,請大家務必注意及執行資安相關要求。

各位師長、同仁、同學好:

最近一周國內陸續發生上市櫃公司網站遭駭客入侵,盜取重要資料事件,請各位師長、同仁、同學依資安法及教育部相關資安規定,進行重要資料防護與監控。下列幾點提供參酌:

1.務必定時備份所轄業務重要資料,並雙重備份至其他裝置。(建議至少一周一次,不得高於一個月) (桌機、筆電、伺服器、平板、手機內的重要檔案-email、照片、資料庫、程式碼、word、excel、powerpoint、pdf等)
   ■外接裝置(外接硬碟、USB隨身碟、雲端空間-建議加密等)備份完成後,務必移除,切勿一直連接在主機上。
   ■不可備份至同台電腦的其它空間,若因硬體故障或遭勒索軟體加密,會造成備份失效的狀況。

2.使用校外網站(FB、IG、Line、Gmail、YouTube、Netflix、購物網站、影音網站等),其帳號密碼切勿設定與校內系統相同,避免遭有心人士利用。

3.有校外連線至校內主機進行工作需求者,請使用VPN連線。(VPN申請表網址: https://www.cc.ntust.edu.tw/var/file/50/1050/img/3072/SSL-VPN_application_20221207.docx )

4.校內IP除非必要,盡可能不開放校外直接連線。在經費允許下,可購置硬體防火牆,增加其防護強度。

5.重要資料進行通訊軟體(email、line、Message、telegram、雲端空間)傳送時,務必將檔案加密,再利用第二管道通知收件人解密密碼。

若有資安相關問題,請洽電子計算機中心:
游順發組長 6209 rogeryu@mail.ntust.edu.tw
張云蘋   6929 applechang@mail.ntust.edu.tw


Hello everyone:

In the past week, there have been incidents of hackers intruding the websites of listed companies in China and stealing important information. Teachers, colleagues, and students are requested to protect and monitor important information in accordance with the Information Security Law and the relevant information security regulations of the Ministry of Education. The following points are provided for consideration:

1.Be sure to regularly back up important business data and double backup to other devices. (Recommended at least once a week, no more than once a month) (Important files in desktop computers, laptops, servers, tablets, mobile phones - emails, photos, databases, codes, word, excel, powerpoint, pdf, etc.) 
   ■After the backup of external devices (external hard drive, USB flash drive, cloud space - encryption is recommended, etc.) is completed, be sure to remove it and do not keep it connected to the host. 
   ■It cannot be backed up to other spaces on the same computer. If it is encrypted due to hardware failure or ransomware, the backup will become invalid.

2.When using off-campus websites (FB, IG, Line, Gmail, YouTube, Netflix, shopping websites, video websites, etc.), do not set the account password to be the same as the school system to avoid being exploited by malicious parties. 

3.If you need to connect to the on-campus host from outside the school for work, please use a VPN connection. (VPN application form URL: https://www.cc.ntust.edu.tw/var/file/50/1050/img/3072/SSL-VPN_application_20221207.docx

4.Unless necessary, direct connections from off-campus IP addresses should not be opened as much as possible. If funds permit, a hardware firewall can be purchased to increase its protection strength. 

5.When transmitting important information through communication software (email, line, Message, telegram, cloud space), be sure to encrypt the file and then use a second channel to notify the recipient of the decryption password.
For more question about information security, please directly consult with Computer Center, at rogeryu@mail.ntust.edu.tw or applechang@mail.ntust.edu.tw
 

發佈單位: 電子計算機中心
寄送群組: muser-xx-xxxx, stud-xxxx-x
寄送對象: 全校教職員工生
瀏覽數: