{"id":18561,"date":"2026-05-22T14:52:19","date_gmt":"2026-05-22T06:52:19","guid":{"rendered":"http:\/\/140.122.63.201\/2025itc\/?page_id=18561"},"modified":"2026-09-16T13:32:47","modified_gmt":"2026-09-16T05:32:47","slug":"18561-2","status":"publish","type":"page","link":"https:\/\/v2.itc.ntnu.edu.tw\/?page_id=18561&lang=en","title":{"rendered":"Website Vulnerability Scanning"},"content":{"rendered":"\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"has-small-font-size wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-right:0;margin-bottom:var(--wp--preset--spacing--20);margin-left:0\"><a accesskey=\"C\" style=\"text-decoration:none\" title=\"\u4e3b\u8981\u5167\u5bb9\u5340\" href=\"#start-C\" id=\"start-C\"> :::<\/a> <a href=\"http:\/\/140.122.63.201\/2025itc\/?page_id=17615&amp;lang=en\" data-type=\"page\" data-id=\"17615\">Home<\/a>&gt;<a href=\"http:\/\/140.122.63.201\/2025itc\/?page_id=18727&amp;lang=en\" data-type=\"page\" data-id=\"18727\">Services<\/a>&gt;Website Vulnerability Scanning<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-dfca8a51 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-top is-style-default has-base-2-background-color has-background is-layout-flow wp-container-core-column-is-layout-660d06fa wp-block-column-is-layout-flow\" style=\"padding-top:var(--wp--preset--spacing--20);padding-right:var(--wp--preset--spacing--10);padding-bottom:var(--wp--preset--spacing--10);padding-left:var(--wp--preset--spacing--10);flex-basis:16%\">\n<div class=\"wp-block-buttons is-vertical is-content-justification-stretch is-nowrap is-layout-flex wp-container-core-buttons-is-layout-666d7fb6 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#1\">Description<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#2\">Eligible Users<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#3\">Application and Usage<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#4\"><strong>U<\/strong>ser Guide<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#5\">Web Application Vulnerability Scanning Application and Execution Process<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#6\">Cybersecurity Vulnerability Scan Acceptance Standards<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#7\">Vulnerability Scan Acceptance Requirements<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#8\">Risk Acceptance Application Procedure<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#9\">Important Notes<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#10\">Contact Information<\/a><\/div>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"#11\">Related Websites<\/a><\/div>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column has-base-2-background-color has-background is-layout-flow wp-container-core-column-is-layout-16ea9b8e wp-block-column-is-layout-flow\" style=\"padding-top:var(--wp--preset--spacing--20);padding-right:var(--wp--preset--spacing--40);padding-bottom:var(--wp--preset--spacing--20);padding-left:var(--wp--preset--spacing--40)\">\n<h1 class=\"wp-block-heading\"><strong><strong>Website Vulnerability Scanning<\/strong><\/strong><\/h1>\n\n\n\n<p class=\"has-background wp-block-paragraph\" id=\"1\" style=\"border-radius:0.6rem;background-color:#e7f2de;margin-top:var(--wp--preset--spacing--20);margin-right:0;margin-bottom:var(--wp--preset--spacing--20);margin-left:0\"><strong>Service Description<\/strong><br>The Information Technology Center provides a <strong>Web Application Vulnerability Scanning Service<\/strong> using <strong>HCL AppScan Standard<\/strong>, procured through the Ministry of Digital Affairs Government e-Procurement Platform. This service helps ensure compliance with information security requirements, personal data protection regulations, and reduces the risk of data breaches.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"2\" style=\"margin-top:0;margin-bottom:0;padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\">Eligible Users<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-accent-2-color has-alpha-channel-opacity has-accent-2-background-color has-background is-style-wide\" style=\"margin-top:0;margin-bottom:0\"\/>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\">Official websites and service websites operated by all university departments and units.Each unit of the school<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"3\" style=\"padding-right:0;padding-left:0\">Application and Usage<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-accent-2-color has-alpha-channel-opacity has-accent-2-background-color has-background is-style-wide\"\/>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\" class=\"wp-block-list\">\n<li>Application fAuthorized staff members or website administrators may access the service through<\/li>\n\n\n\n<li>University Administrative Information Portal \u2192 Information Services \u2192 Vulnerability Scanning Service Registration System\n<ul class=\"wp-block-list\">\n<li>Departments may schedule regular annual vulnerability scans, which can serve as supporting documentation for website management, procurement acceptance procedures, and administrator handover processes.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"4\">User Guide<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-accent-2-color has-alpha-channel-opacity has-accent-2-background-color has-background is-style-wide\"\/>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\" class=\"wp-block-list\">\n<li>Please refer to the official <strong>Vulnerability Scanning Application Guide<\/strong> for detailed instructions. Once a scan schedule is registered, the website will automatically be added to the scanning queue and processed in chronological order<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"5\">Web Application Vulnerability Scanning Application and Execution Process<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-accent-2-color has-alpha-channel-opacity has-accent-2-background-color has-background is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">I. Pre-Application Assessment<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">(1) Security Classification Assessment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before applying for a web application vulnerability scan, departments are advised to evaluate the security classification of their website.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(2) Sensitive Data Review<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Review whether the website contains sensitive information, including personal data or other confidential information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(3) Sensitive Data Identification Criteria<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The classification of sensitive data shall be determined in accordance with the definitions published by the Ministry of Justice Personal Data Protection Information Website.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(4) Selection of Security Classification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Based on the above considerations, departments shall select the appropriate website security classification for vulnerability scanning (refer to the appendix for classification details).<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">II. Vulnerability Scanning and Result Processing<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">(5) Issuance of Compliance Certificate<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If the server meets the vulnerability scanning requirements for the selected security classification, the Information Technology Center will issue a Vulnerability Scanning Compliance Certificate as proof of compliance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(6) Application Review and Scan Execution<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Upon receiving an application, the Information Technology Center will conduct vulnerability scanning according to the security classification selected by the applicant department.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(7) Vulnerability Assessment Standards<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability scanning and protection requirements are based on the latest <strong>OWASP Top 10 Web Application Security Risks<\/strong>, as well as standards established by the Ministry of Education and Taiwan&#8217;s National Institute of Cyber Security.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(8) Scan Result Determination<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Upon completion of the scan, compliance with the selected security classification shall be determined based on the official Website Security Scan Report provided by the Information Technology Center (sample report available).<\/p>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\" class=\"wp-block-list\">\n<li><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"6\">Cybersecurity Vulnerability Scan Acceptance Standards<\/h2>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-accent-2-color has-alpha-channel-opacity has-accent-2-background-color has-background is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\"><strong>Applicable to Procurement Projects Initiated on or After January 12, 2026<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" ;color=\"#A80000\"><strong>Table 1. Vulnerability Risk Classification (Including Critical Severity)<\/strong><\/mark><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><th>Risk Level<\/th><th>Description<\/th><\/tr><tr><td><strong>Critical<\/strong><\/td><td>Vulnerabilities with extremely high risk that can be exploited immediately, often requiring little or no authentication. Such vulnerabilities may result in full system compromise, large-scale exposure of sensitive or personal data, or complete privilege takeover (e.g., Remote Code Execution, Unauthorized Access, Full Database Disclosure).<\/td><\/tr><tr><td><strong>High<\/strong><\/td><td>Vulnerabilities with significant cybersecurity risks and clearly identifiable attack paths. Exploitation may result in system compromise, data breaches, or service disruption, typically requiring specific conditions or actions.<\/td><\/tr><tr><td><strong>Medium<\/strong><\/td><td>Vulnerabilities posing indirect cybersecurity risks. Exploitation generally requires the combination of additional vulnerabilities, misconfigurations, or specific circumstances.<\/td><\/tr><tr><td><strong>Low<\/strong><\/td><td>Vulnerabilities with limited impact on system security. Although not easily exploitable in the short term, they may reduce the overall security posture.<\/td><\/tr><tr><td><strong>Informational<\/strong><\/td><td>Not considered actual vulnerabilities. These findings typically involve configuration recommendations or information disclosure notices intended to improve security and align with best practices.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\"><strong>Applicable to Procurement Projects Initiated Before January 12, 2026<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-accent-3-color\">Table 2. Legacy Vulnerability Risk Classification<\/mark><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Risk Category<\/td><td>Description<\/td><td>Impact Level<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Legal Compliance<\/td><td>Deploying systems with unremediated vulnerabilities may violate the Cyber Security Management Act and related security baseline requirements.<\/td><td>High<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Technical<\/td><td>Vulnerabilities may be exploited by attackers, resulting in system intrusion, data leakage, or malware infection.<\/td><td>High<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Operational<\/td><td>Cyberattacks may cause service interruptions, authentication failures, or data corruption, affecting university operations.<\/td><td>Medium-High<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Reputation<\/td><td>Public disclosure of cybersecurity incidents may reduce trust among students, parents, and stakeholders, damaging the university&#8217;s reputation.<\/td><td>High<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Outsourcing\/Vendor Management<\/td><td>Accepting systems that fail vulnerability scanning may reduce vendor accountability and security quality while increasing future maintenance costs.<\/td><td>Medium<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"7\">Vulnerability Scan Acceptance Requirements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--20);margin-bottom:var(--wp--preset--spacing--20)\">Vulnerability scanning requirements are established to ensure regulatory compliance and are not solely technical preferences.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Compliance helps prevent managers and project coordinators from assuming administrative liability arising from system vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also ensures that vendors fulfill contractual obligations to harden system security, maintain system quality, and support sustainable operation and maintenance.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"8\">Risk Acceptance Application Procedure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Departments requesting an exception or waiver must submit a <strong>Vulnerability Risk Acceptance Report<\/strong> and formally acknowledge the associated risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(1)The responsible department must submit a waiver request and complete the <strong>Vulnerability Risk Acceptance Report<\/strong>, including justification and operational necessity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(2)The report must be personally signed by the department head, confirming acceptance of the legal, operational, and cybersecurity risks associated with unresolved vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(3)The Information Technology Center may provide technical recommendations but will not assume responsibility for risks resulting from unremediated vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(4)The business unit must complete the report, obtain the official department head&#8217;s seal (proxy seals are not accepted), upload the electronic copy to the <strong>NTNU Vulnerability Scan Processing System<\/strong> for case closure, and submit the signed hard copy to the Information Technology Center.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>NTNU Vulnerability Scan Processing System:<\/strong><br>NTNU iPortal Home \u2192 Applications \u2192 Information Services \u2192 Vulnerability Scan Processing System<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">(5)Upon receipt, the Information Technology Center will review the submission. Cases involving excessive numbers of Medium- or High-Risk vulnerabilities may be referred to an independent third-party cybersecurity vendor for evaluation. After consultation with all parties, a compliance certificate may be issued.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"9\">Important Notes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A web vulnerability scan is similar to antivirus software:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Passing a vulnerability scan does not guarantee that a website will remain secure indefinitely. It only indicates that the website met the required security standards at the time of the scan.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Applicants are encouraged to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Conduct vulnerability scans on a regular basis.<\/li>\n\n\n\n<li>Perform additional scans after system modifications to ensure that updates do not introduce new vulnerabilities.<\/li>\n\n\n\n<li>Notify the Information Technology Center immediately if system abnormalities occur during scanning so that scanning activities can be suspended until normal operations are restored.<\/li>\n\n\n\n<li>Ensure that all newly established and existing university websites comply with the relevant provisions of the <strong>National Taiwan Normal University Campus Server Management Regulations<\/strong>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"10\">Contact Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Contact Person:<\/strong> Louis Wu<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Email:<\/strong> <a href=\"mailto:louiswu@ntnu.edu.tw\">louiswu@ntnu.edu.tw<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Telephone:<\/strong> Extension 5551<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For frequently asked questions, please contact the Information Technology Center&#8217;s online text support service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"11\">Related Websites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ministry of Justice Personal Data Protection Information <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WebsiteOWASP 2012 Cybersecurity Conference Documentary<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OWASP Official WebsiteOWASP Taiwan Chapter<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>::: Home&gt;Services&gt;Website Vulnerability Scanning  [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"wp-custom-template-1","meta":{"footnotes":""},"class_list":["post-18561","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=\/wp\/v2\/pages\/18561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18561"}],"version-history":[{"count":17,"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=\/wp\/v2\/pages\/18561\/revisions"}],"predecessor-version":[{"id":19484,"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=\/wp\/v2\/pages\/18561\/revisions\/19484"}],"wp:attachment":[{"href":"https:\/\/v2.itc.ntnu.edu.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}