Information Security
資訊安全 Information Security & Sustainability
資通訊安全暨個人資料隱私管理規劃ICT Security & Personal Data Privacy Management Planning
本校訂定資訊安全管理政策,於校內建立可依循的標準規範與作法,透過 PDCA 機制,不斷強化本校資訊安全防護,建立可信賴之資訊安全環境。教育體系驗證中心每年定期委派校外稽核員至本校進行管理制度驗證,以確保 ISMS 資安管理制度及 PIMS 個人資料保護管理制度的有效性。其組織架構如下圖所示: The university has formulated an information security management policy to establish traceable standards and practices on campus. Through the PDCA (Plan-Do-Check-Act) cycle mechanism, we continuously reinforce our security defenses to foster a trustworthy computing environment. The Ministry of Education's certification center regularly appoints external auditors annually to verify our management systems, ensuring the continuous effectiveness of both our Information Security Management System (ISMS) and Personal Data Privacy Management System (PIMS). The organizational framework is illustrated below:
(圖:亞洲大學資訊安全組織體系 / Figure: Asia University Information Security Organizational Structure)
資安風險及改善策略Information Security Risks & Improvement Strategies
本校針對資訊安全的威脅提出相對應的因應策略與改善方式,致力維護校園中資訊安全與保護教職員與學生的個資。為維護良好資訊安全暨個人資料保護,本校資訊發展處規劃了六項管理政策與管理原則: In response to emerging cybersecurity threats, the university outlines proactive mitigation strategies and enhancement methods, striving to protect network security and safeguard the personal data of all faculty, staff, and students. To maintain excellent standards of information security and data privacy, the Office of Information Development has structured six core management policies and principles:
資訊管理的六項原則Six Principles of Information Management
執行成效與相關紀錄Performance Outcomes & Relevant Records
管理機制上,亞洲大學設有「亞洲大學資訊安全暨個人資料保護委員會」,並定期開會討論、執行並檢討精進。法規設置方面,為落實本校資訊安全、個資保護之管理,訂有「資訊安全暨個人資料保護管理制度政策」。最新年度執行成效摘要如下: Regarding governance mechanisms, the university operates the "Information Security and Personal Data Protection Committee," which convenes periodically to discuss implementation, execution, and continuous optimization. In terms of regulatory frameworks, the "Information Security and Personal Data Protection Management System Policy" has been enacted to enforce rigorous compliance. The performance highlights for the latest year are summarized below:
- 🛡️ 弱點掃描:完成 114 年度弱點掃描及複掃作業。 🛡️ Vulnerability Scanning: Completed vulnerability scanning and rescanning operations for AY114.
- 🔥 防火牆管理:完成 114 年度防火牆政策檢視,共清查出 179 條 防火牆進出限制規則,並持續管理中。 🔥 Firewall Management: Concluded the firewall policy review for AY114, auditing 179 restriction rules for ingress/egress under active management.
- 📂 個資盤點:落實全校個人資料檔案盤點作業,共 386 個 個資檔案列冊管理。 📂 Personal Data Inventory: Enforced a university-wide personal data audit, ensuring that 386 personal data files are officially cataloged and securely managed.
- 📊 資產管理盤點:資訊安全管理盤點列管項目中,共盤點出 52 項服務流程,並依性質區分統計 10 類資訊資產,共計 215 項 資訊資產。 📊 Asset Inventory Management: Within the scope of compliance auditing, 52 operational service workflows were identified, and information assets were categorized into 10 distinct classes across 215 separate configuration items.
- 📑 內外部稽核:順利完成 114 年度資訊安全暨個人資料保護管理制度內部稽核作業,以及 114 年度個資保護管理制度外部稽核作業。 📑 Internal & External Audits: Successfully finalized the internal audit operations for the management system, alongside the independent external certification audit for data privacy.
近三年資安事件統計Information Security Incident Statistics Over the Past Three Years
| 年度Year | 1 級 (輕微)Level 1 (Minor) | 2 級 (中度)Level 2 (Moderate) | 3 級 (嚴重)Level 3 (Severe) | 總計Total |
|---|---|---|---|---|
| 112 年2023 (AY112) | 8 件/Cases | 0 件/Cases | 0 件/Cases | 8 件/Cases |
| 113 年2024 (AY113) | 19 件/Cases | 0 件/Cases | 0 件/Cases | 19 件/Cases |
| 114 年2025 (AY114) | 4 件/Cases | 0 件/Cases | 0 件/Cases | 4 件/Cases |
說明:事件等級判定參照本國資通安全事件通報及應變辦法定義 1-4 級。若經判定為非本校資安或個資事件則定義為 0 級事件,僅作為內部事件統計用而不列入上表。 Note: Incident severity levels are defined from Level 1 to Level 4 based on national guidelines for cyber security incident reporting and response. Events determined to be unrelated to university core security or personal data are classified as Level 0 and are kept solely for internal analysis without being included in the dashboard above.
