::: Home>Services>Website Vulnerability Scanning

Website Vulnerability Scanning

Service Description
The Information Technology Center provides a Web Application Vulnerability Scanning Service using HCL AppScan Standard, procured through the Ministry of Digital Affairs Government e-Procurement Platform. This service helps ensure compliance with information security requirements, personal data protection regulations, and reduces the risk of data breaches.

Eligible Users


Official websites and service websites operated by all university departments and units.Each unit of the school

Application and Usage


  • Application fAuthorized staff members or website administrators may access the service through
  • University Administrative Information Portal → Information Services → Vulnerability Scanning Service Registration System
    • Departments may schedule regular annual vulnerability scans, which can serve as supporting documentation for website management, procurement acceptance procedures, and administrator handover processes.

User Guide


  • Please refer to the official Vulnerability Scanning Application Guide for detailed instructions. Once a scan schedule is registered, the website will automatically be added to the scanning queue and processed in chronological order

Web Application Vulnerability Scanning Application and Execution Process


I. Pre-Application Assessment

(1) Security Classification Assessment

Before applying for a web application vulnerability scan, departments are advised to evaluate the security classification of their website.

(2) Sensitive Data Review

Review whether the website contains sensitive information, including personal data or other confidential information.

(3) Sensitive Data Identification Criteria

The classification of sensitive data shall be determined in accordance with the definitions published by the Ministry of Justice Personal Data Protection Information Website.

(4) Selection of Security Classification

Based on the above considerations, departments shall select the appropriate website security classification for vulnerability scanning (refer to the appendix for classification details).


II. Vulnerability Scanning and Result Processing

(5) Issuance of Compliance Certificate

If the server meets the vulnerability scanning requirements for the selected security classification, the Information Technology Center will issue a Vulnerability Scanning Compliance Certificate as proof of compliance.

(6) Application Review and Scan Execution

Upon receiving an application, the Information Technology Center will conduct vulnerability scanning according to the security classification selected by the applicant department.

(7) Vulnerability Assessment Standards

The vulnerability scanning and protection requirements are based on the latest OWASP Top 10 Web Application Security Risks, as well as standards established by the Ministry of Education and Taiwan’s National Institute of Cyber Security.

(8) Scan Result Determination

Upon completion of the scan, compliance with the selected security classification shall be determined based on the official Website Security Scan Report provided by the Information Technology Center (sample report available).

Cybersecurity Vulnerability Scan Acceptance Standards


Applicable to Procurement Projects Initiated on or After January 12, 2026

Table 1. Vulnerability Risk Classification (Including Critical Severity)

Risk LevelDescription
CriticalVulnerabilities with extremely high risk that can be exploited immediately, often requiring little or no authentication. Such vulnerabilities may result in full system compromise, large-scale exposure of sensitive or personal data, or complete privilege takeover (e.g., Remote Code Execution, Unauthorized Access, Full Database Disclosure).
HighVulnerabilities with significant cybersecurity risks and clearly identifiable attack paths. Exploitation may result in system compromise, data breaches, or service disruption, typically requiring specific conditions or actions.
MediumVulnerabilities posing indirect cybersecurity risks. Exploitation generally requires the combination of additional vulnerabilities, misconfigurations, or specific circumstances.
LowVulnerabilities with limited impact on system security. Although not easily exploitable in the short term, they may reduce the overall security posture.
InformationalNot considered actual vulnerabilities. These findings typically involve configuration recommendations or information disclosure notices intended to improve security and align with best practices.

Applicable to Procurement Projects Initiated Before January 12, 2026

Table 2. Legacy Vulnerability Risk Classification

Risk CategoryDescriptionImpact Level
Legal ComplianceDeploying systems with unremediated vulnerabilities may violate the Cyber Security Management Act and related security baseline requirements.High
TechnicalVulnerabilities may be exploited by attackers, resulting in system intrusion, data leakage, or malware infection.High
OperationalCyberattacks may cause service interruptions, authentication failures, or data corruption, affecting university operations.Medium-High
ReputationPublic disclosure of cybersecurity incidents may reduce trust among students, parents, and stakeholders, damaging the university’s reputation.High
Outsourcing/Vendor ManagementAccepting systems that fail vulnerability scanning may reduce vendor accountability and security quality while increasing future maintenance costs.Medium

Vulnerability Scan Acceptance Requirements

Vulnerability scanning requirements are established to ensure regulatory compliance and are not solely technical preferences.

Compliance helps prevent managers and project coordinators from assuming administrative liability arising from system vulnerabilities.

It also ensures that vendors fulfill contractual obligations to harden system security, maintain system quality, and support sustainable operation and maintenance.


Risk Acceptance Application Procedure

Departments requesting an exception or waiver must submit a Vulnerability Risk Acceptance Report and formally acknowledge the associated risks.

(1)The responsible department must submit a waiver request and complete the Vulnerability Risk Acceptance Report, including justification and operational necessity.

(2)The report must be personally signed by the department head, confirming acceptance of the legal, operational, and cybersecurity risks associated with unresolved vulnerabilities.

(3)The Information Technology Center may provide technical recommendations but will not assume responsibility for risks resulting from unremediated vulnerabilities.

(4)The business unit must complete the report, obtain the official department head’s seal (proxy seals are not accepted), upload the electronic copy to the NTNU Vulnerability Scan Processing System for case closure, and submit the signed hard copy to the Information Technology Center.

NTNU Vulnerability Scan Processing System:
NTNU iPortal Home → Applications → Information Services → Vulnerability Scan Processing System

(5)Upon receipt, the Information Technology Center will review the submission. Cases involving excessive numbers of Medium- or High-Risk vulnerabilities may be referred to an independent third-party cybersecurity vendor for evaluation. After consultation with all parties, a compliance certificate may be issued.

Important Notes

A web vulnerability scan is similar to antivirus software:

Passing a vulnerability scan does not guarantee that a website will remain secure indefinitely. It only indicates that the website met the required security standards at the time of the scan.

Applicants are encouraged to:

  • Conduct vulnerability scans on a regular basis.
  • Perform additional scans after system modifications to ensure that updates do not introduce new vulnerabilities.
  • Notify the Information Technology Center immediately if system abnormalities occur during scanning so that scanning activities can be suspended until normal operations are restored.
  • Ensure that all newly established and existing university websites comply with the relevant provisions of the National Taiwan Normal University Campus Server Management Regulations.

Contact Information

Contact Person: Louis Wu

Email: louiswu@ntnu.edu.tw

Telephone: Extension 5551

For frequently asked questions, please contact the Information Technology Center’s online text support service.

Related Websites

Ministry of Justice Personal Data Protection Information

WebsiteOWASP 2012 Cybersecurity Conference Documentary

OWASP Official WebsiteOWASP Taiwan Chapter