Jump to the main content block

[Cybersecurity Policy] Regulations on the Prohibition of Use and Procurement of "Chinese ICT Products"

Title:
[Cybersecurity Policy] Regulations on the Prohibition of Use and Procurement of "Chinese ICT Products"
Announcement Date:
January 12, 2024
Content:

1. In accordance with the Ministry of Education letter No. 1112703805 dated September 21, 2022, regarding the 2022 National University CISOs Conference, information security has been included in the "Cybersecurity Section of the Higher Education Sprout Project", and the "Cybersecurity Operation Guidelines for National Universities" must be implemented. Private universities are advised to refer to these guidelines to enhance incident response mechanisms and protection measures.

2. According to the Executive Yuan letter No. 1121000202 dated June 20, 2023, the following principles for the use of ICT products by public agencies are reiterated:

(1) Based on the Executive Yuan Secretary-General letter No. 1090201804A dated December 18, 2020, it is prohibited to use or procure Chinese brand ICT products (including software, hardware, and services).

(2) If use is necessary due to business needs and there are no alternatives, agencies must clearly state the reasons and obtain approval from their CISO and the higher-level CISO, and submit to the competent authority (Ministry of Digital Affairs) for approval. Until such products are phased out, the following cybersecurity measures must be strengthened:

  1. Enhance cybersecurity management measures, such as setting strong passwords and prohibiting remote maintenance.
  2. If the product is attacked and its display is altered, the display must be replaced with a static screen or the device must be shut down immediately.
  3. If the product is hardware, ensure it does not have persistent connectivity features like WiFi (not simply disabled via software). For updates via external devices, supervision is required, and the external device must be removed immediately after transfer.
  4. After the product reaches its end of life, Chinese ICT products must not be purchased again.

(3) When handling procurement cases, agencies must observe the following:

  1. Refer to Point 16 of the standard bidding instructions from the Public Construction Commission, which disallows products originating from mainland China (including engineering, goods, and services). If the procurement involves ICT software, hardware, or services, agencies may require that project team members are not Chinese nationals and that Chinese ICT products are neither provided nor used.
  2. For agency-run or outsourced public venues, products that pose national cybersecurity threats must not be used, and such restrictions must be included in outsourcing contracts or usage regulations.

3. Agencies must verify during procurement according to the Principles for Identifying Chinese Brand ICT Products and Outsourced Public Venues to avoid procuring Chinese brand ICT products.

4. It is recommended to use joint supply contracts for related equipment to avoid procurement of Chinese ICT brands.

Common Chinese Brand List:

Black Shark, Coolpad, GIONEE, HUAWEI, Koobee, K-Touch, Lenovo (Motorola), Meitu, Meizu, Nubia (ZTE), OPPO, realme, SUGAR (WIKO), vivo, Xiaomi / Redmi, ZTE, ZOPO, TP-Link (Shenzhen), Mercusys (Shenzhen Mercury), TOTOLINK (Shenzhen), HIKVISION
 
 
Click Num: