Public Sector Solutions: Enforcing the Cyber Security Management Act with Simultaneous Auditing and Certification
July 19, 2021


Internal Network Security: Easily Overlooked Beneath Layers of Protection

 

 

The public sector places a heavy emphasis on external network threats, leveraging hardened firewalls, antivirus software, and other measures to prevent malicious attacks from penetrating institutional networks. However, when the aforementioned risks originate from within, or when there is a persistent lack of awareness, the internal network possesses several inherent characteristics—advantages that external threats naturally lack:

 

 

・Access Granting during Routine Operations: Internal attackers have already been granted the necessary access privileges during their daily workflows.

・Familiarity with Data and Controls: Internal attackers already know where critical data is stored and are intimately familiar with the protective mechanisms in place.

 

 

If an organization faces an insider threat scenario and lacks detection or prevention mechanisms, the resulting damage becomes exceptionally difficult to contain. To achieve comprehensive cross-network defense, enterprises must swiftly establish a "Zero Trust" cybersecurity management architecture. By leveraging high internal network visibility and administration, organizations can reinforce their joint defense policies and perfect their network environments.

 

 

Key Issues Faced by the Public Sector

 

 

Cybersecurity incidents within government agencies present national security-level threats. According to data from iThome, over 20% of enterprises encountered more than 50 cybersecurity incidents in 2019. Among these, 40% caused service disruptions, and 60% involved data theft—reasons why nearly 30% of government agencies and academic institutions view cybersecurity as their primary IT investment priority. Furthermore, a Q1 2020 survey indicated that ransomware incidents spiked by 48% compared to the same period in the previous year, underscoring that perfecting cybersecurity defenses admits no delay. Below are common cybersecurity issues faced by the public sector::

 

 

 

 

 

Unclear Asset Quantities and Untrackable Device Statuses

 

In today's network environments, managing terminal devices within the OA (Office Automation) area is no longer the only priority. IoT devices scattered across various locations—such as surveillance cameras and badge readers—have also become a focal point of information security management. A common approach to endpoint management involves installing an agent on every machine to monitor device specifications and operational health.

 

 

However, the vast majority of IoT systems, BYOD (Bring Your Own Device) equipment, and guest devices cannot easily support agent installations. This leaves administrators unable to effectively grasp the asset attributes or the software and hardware statuses of these devices within the environment. Not only does this create administrative hurdles, but it also leaves lingering vulnerabilities in the overall security of the network environment.

 

 

 

 

Neglecting Guest Management Creates Cybersecurity Vulnerabilities

 

Government agencies receive a high volume of visitors, including foreign guests, citizens conducting public business, and outsourced contractors. These individuals frequently require network access. If administrators must manually approve access and configure permissions for each device, the process becomes incredibly time-consuming and labor-intensive. Furthermore, it prevents effective security compliance checks on the connecting devices. Administrators must also manually revoke network access once the relevant business is completed. Any omission in these steps can easily introduce security holes into the network environment, leading to malware intrusions or data theft incidents.

 

 

The Complete Shift from IPv4 to IPv6: How Government Agencies Should Respond

 

The Taiwanese government has pushed for comprehensive IPv6 adoption across its agencies, and Taiwan’s civilian IPv6 deployment rate ranks 6th globally. This indicates that the number of users accessing networks via IPv6 will steadily increase over the next few years. In today's dual-stack environments where IPv4 and IPv6 coexist, figuring out how to efficiently manage both protocols simultaneously has become an urgent problem that government agencies must address immediately.

 

 

 

Choosing the Right Cybersecurity Defense Under Legal Frameworks

 

Under the mandates of the Cyber Security Management Act and its subsidiary regulations, relevant agencies are required to pass ISO 27001 certification or align with the NIST CSF within designated timeframes. They must also complete Government Configuration Baseline (GCB) deployment and implement review measures for cyber security system protection standards. Concurrently, the Personal Data Protection Act stipulates that public agencies must adopt appropriate measures to prevent personal data from being stolen, altered, or destroyed.

 

 

A critical example occurred in 2019 when the Ministry of Civil Service was compromised by Trojan horse malware, resulting in the leakage of 590,000 government employee personal records. The leaked data included sensitive information of national security personnel, which not only put those individuals at risk but also dealt a severe blow to national security.

 

 

Given limited cybersecurity budgets, establishing an Information Security Management System (ISMS) that complies with ISO 27001 or adopting the NIST CSF—while simultaneously adhering to other regulatory laws—presents a major challenge for all relevant organizations.

 

 

Reducing Ransomware Risks Through Internal Network Defense Deployment

 

With rapid technological advancement, vast amounts of confidential data are now stored digitally. This has led hackers to scan for vulnerable devices to infiltrate internal corporate networks, deploy ransomware to encrypt assets, and block user access, subsequently extorting victims for ransom to regain file access.

 

 

 

 

How to Initiate VANS System Integration to Comply with Cyber Security Management Act Regulations

 

The Vulnerability Alert and Notification System (VANS), developed by the National Cyber Security Technology Service Center (ICST) under the Executive Yuan's National Cyber Security Program, cross-references software asset reports provided by various government agencies against the National Vulnerability Database (NVD) maintained by the U.S. National Institute of Standards and Technology (NIST). This process identifies cybersecurity vulnerabilities across agencies, providing real-time notifications so that units can patch loopholes immediately, eliminate security risks, and reinforce software asset management throughout government sectors.

 

Furthermore, subsidiary regulations of the Cyber Security Management Act explicitly stipulate compliance requirements for government agencies at all levels: Grade A cyber security responsibility agencies were mandated to complete comprehensive VANS integration, while Grade B and C agencies were required to follow suit.

 

 


 

 

UPAS NOC Core Value: A Zero Trust Security Architecture

 

What is "Zero Trust"?

 

Zero Trust is a framework where all resources are treated as external resources, and continuous verification is required to establish trust before any requested access permissions are granted. Simply put, it means treating the internal network as if it were an external network—shifting from the traditional mindset of "trust but verify" to "verify and never trust."

 

 

Consequently, whenever a user or asset requests access to organizational resources, UPAS recommends applying the Zero Trust principle first: you must thoroughly verify its trustworthiness before granting any access rights. To help organizations perfect their Zero Trust security, we look to Gartner's research report, which highlights:

 

 

"To reduce security risks, modern enterprises must establish a 'Zero Trust Network Architecture.' To achieve this goal, a comprehensive NAC solution is absolutely indispensable." — Market Guide for Network Access Control, Gartner

 

 

By implementing a Network Access Control (NAC) mechanism, UPAS NOC targets device visibility and control. It genuinely perfects asset inventories by discovering every connected device within the network environment and efficiently managing user access and authentication permissions. Furthermore, it inspects the installation and update statuses of endpoint software (such as antivirus and asset management software) and OS versions to facilitate vulnerability patching. Finally, it analyzes device information and exports comprehensive reports to deliver continuous tracking and visibility.

 

 

 

UPAS NOC Solutions

Effortless Deployment to Perfect Asset Inventory and IP Management Workflows

 

 

As public sector services and systems become increasingly digital, outsourced service supply chains have grown exceptionally complex. In the face of a volatile and ever-evolving threat landscape, one fundamental truth remains: foundational internal network security is indispensable, as attackers' ultimate objectives still lie within the internal network. Below is our optimized security solution designed to address the key challenges outlined above:

 

 

Comprehensive Asset Inventory and Complete Mastery of Device Status

 

 

Studies indicate that over 90% of IoT devices cannot support agent installations, rendering traditional device identification techniques ineffective. Leveraging proprietary patented ARP technology, UPAS NOC achieves Agentless automatic identification of nearly 30 types of connected device attributes across various environments:

 

 

・OA (Office Automation) Areas: Desktop computers, mobile devices, printers, and IoT systems.

・Server Room Infrastructure: Virtual machines, servers, and other virtualized or network device components.

・Common Network Hardware: Routers, switches, firewalls, wireless access points (APs), and controllers.

 

 

Beyond asset inventories, gathering comprehensive device metrics presents another major hurdle—such as OS versions, whether antivirus software is updated, the currency of virus definition signatures, and active software utilization. If even a single parameter falls out of compliance, the entire network environment can be left highly vulnerable.

 

 

UPAS NOC seamlessly integrates with WSUS servers, a wide array of antivirus software solutions, and asset management software databases. Combined with Tableau integration, it generates intuitive, visual charts that make your device intelligence clear and instantly actionable at a glance.

 

 

 

 

 

Automated Guest Management to Eliminate Security Vulnerabilities

 

 

In practical internal network management, scenarios frequently arise where external individuals require temporary internet access or need internal network connectivity within a specific timeframe. Compared to rigid and rigorous perimeter defenses, guest devices that enter the internal network without being monitored or having their access privileges segregated can easily become high-risk security loopholes. UPAS NOC provides the following solutions for guest management:

 

 

・Automated Guest Authentication and Logging: We offer internal network access authentication for guests through both on-site and pre-registered application methods. The system automatically verifies guest identities, grants appropriate access privileges, and maintains comprehensive compliance logs, significantly reducing administrative overhead.

 

・Strict Guest Network Segmentation: For guests who require internal network access, UPAS NOC can segment a dedicated guest network (VLAN) to restrict the specific data they can access. If a cybersecurity incident occurs within the guest segment, the damage is effectively contained within that block, minimizing potential losses.

 

・Dynamic Access and Automated Privilege Expiration: The system enforces strict access policies and expiration timers for guest internet and intranet usage. Once the allotted time expires, the device is automatically removed from the whitelist. This continuous control over permissions and durations prevents security holes caused by neglected or unrevoked guest access rights.

 

 

 

 

Resolving IP Management Challenges via Comprehensive IPv6 Management

 

Common difficulties under a dual-stack architecture include the mixing of IPv4 and IPv6 addresses, as well as the need to re-engineer subnet management and IP allocation when transitioning from IPv4 to IPv6. These scenarios introduce immense administrative complexity, heavily increasing the burden on IT personnel. UPAS NOC provides the following IPv6 management capabilities:

 

 

・IPv6 Whitelist Regulation: This feature automatically admits compliant devices utilizing IPv6 addresses into the system whitelist, granting them internal network access. It also dynamically generates detailed manifests mapping out the exact usage status of each IP address.

 

・Automated Allocation of IPv6 Addresses with IPv4 Suffixes: By preserving the structural outcomes of legacy network segments, this feature eliminates the need for additional re-configurations during protocol transitions, significantly reducing the administrative workload for IT staff.

 

・Automated IPv4-to-IPv6 Mapping Charts: In network environments running dual-stack protocols, UPAS NOC automatically generates cross-protocol IP address mapping charts, making the dual IP footprints used by every endpoint instantly clear at a glance.

 

 

 

Assisting Government Agencies in ISMS Construction to Meet Regulatory Compliance

 

 

・Regulatory System Compliance: Under the mandates of the Cyber Security Management Act, agencies must establish an ISMS (Information Security Management System) capable of passing ISO 27001 certification and fulfilling cyber security system protection baseline measures. UPAS NOC complies with numerous ISO 27001 control criteria and system protection baselines, dramatically lowering the costs required to pass validation.

 

・Simplified GCB & GPO Auditing: Deploying Government Configuration Baselines (GCB) is often a major headache for administrators due to intricate settings and massive device volumes, which frequently lead to deployment failures. UPAS NOC provides comprehensive GPO monitoring features that help administrators gain visibility into the exact GPO and GCB application statuses across the domain, instantly identifying non-compliant endpoint devices.

 

・Real-Time Alerts and Complete Audit Trails: UPAS NOC delivers immediate alerting for non-compliant behaviors along with full system log tracking—two features critical to personal data protection. When a device performs an unauthorized operation (such as cross-VLAN hopping or IP spoofing), real-time alerts immediately isolate the device from the network to contain the hazard. Simultaneously, the complete historical log trail serves as the most legally compelling forensic evidence following a security incident.

 

・Flexible NIST CSF Alignment: As a highly prominent modern cybersecurity framework, the NIST CSF emphasizes gradual, step-by-step security system improvement rather than the complex, all-or-nothing implementation often associated with ISO 27001. Industry surveys indicate that over 10% of government agencies are eager to adopt the CSF framework, making it an excellent choice for budget-constrained public sector units. UPAS NOC aligns with multiple CSF controls, allowing organizations to flexibly procure specific modules based on their exact needs, thereby optimizing deployment costs.

 

 

 

 

Constructing an Internal Network Defense Grid to Minimize Ransomware Risks

 

 

Most defensive mindsets in the public sector stem strictly from an antivirus perspective, relying on security solutions to intercept ransomware. However, if organizations neglect to inspect the installation and update statuses of their protective software, loopholes will inevitably undermine their defensive efficacy. Through the following defensive measures—such as comprehensive asset inventory and compliance inspection—UPAS NOC successfully achieves synchronized cross-network defense, securing a asset protection completeness rate of over 98%.

 

 

・Asset Inventory: Utilizing multi-dimensional technologies to identify and bring all connected equipment within the environment under management, gaining complete command over IP connection statuses across the internal network.

 

・Power Status Reports (Startup/Shutdown Logging): Evaluating potential vulnerabilities based on device power cycles. For example: identifying devices left running for extended periods (where unapplied OS patches create system vulnerabilities) or devices left powered off for long periods (where antivirus software and virus definitions have fallen behind the latest versions).

 

・Device Compliance Inspection: Auditing connecting devices against multiple security checkpoints, including OS versions, installation and update rates of antivirus software/definition signatures, and active asset management software.

 

・Data Traffic Monitoring: Regulating and auditing the network behavior of endpoint devices by providing comprehensive network traffic intelligence and generating related bandwidth utilization reports.

 

・AD Account Management: Maintaining precise records of Active Directory (AD) login and logout timestamps to manage idle endpoints or devices utilizing Remote Desktop Protocol (Protocol) connections, effectively reducing the surface area for hacker exploits.

 

・Configuration Behavior Auditing: Delivering real-time alerts for anomalous configuration activities, such as the unauthorized installation of illicit software, unauthorized modifications to GPO policies, or enabling full-permission shared folders.

 

 

 

Analyzing Defensive Measures Through a Hacker's Lens (Read More):

Defending Against Ransomware (Part 2): How Does UPAS Stop Ransomware from Causing Harm?

 

 

Highly Adaptive Advanced VANS Deployment Solutions

 

 

Through comprehensive asset inventory, UPAS NOC achieves a completeness rate of over 98% in software asset discovery. To accommodate varying client infrastructures, we offer two tailored VANS system deployment solutions:

 

 


 

 

Scenario A: Third-Party Systems Already Purchased to Assist with VANS

 

 

No Additional UPAS Agent Installation Required

 

 

If you have already purchased an asset management system from a third-party vendor and completed their agent deployment to convert software assets into CPE format for VANS uploading, UPAS NOC provides an advanced solution to completely eliminate lingering security blind spots.

 

 

The industry average for agent deployment and update success rates typically hovers around only 80%. This gap results in incomplete software asset inventories, leaving critical vulnerabilities undetected and exposing organizations to high cybersecurity risks. The root cause of this challenge lies in the fact that most third-party vendors rely directly on Active Directory (AD) servers to push agents; deployment failures or device incompatibility leave these specific endpoints uninventoried.

 

 

Leveraging proprietary patented ARP packet inspection technology, UPAS NOC drastically enhances device visibility across the environment, effortlessly discovering all connected endpoints. Building on this high-visibility foundation, the UPAS NOC SIM (Security Integration Module) interfaces directly with your asset management databases. By cross-referencing the complete monitoring list, it seamlessly flags unmanaged or outdated devices. Non-compliant endpoints are then funneled through a high-security network isolation mechanism, compelling users to patch vulnerabilities immediately.

 

 

Our advanced solution ensures that your existing asset management system brings 100% of endpoints under management without requiring an additional UPAS agent, guaranteeing that every software asset is accounted for and uploaded to VANS for exhaustive vulnerability screening.

 

 

Scenario B: No Third-Party VANS-Capable Systems Purchased Yet

 

 

UPAS Agent Installation Required

 

 

Built upon a foundation of comprehensive endpoint discovery, the UPAS NOC PM (Patch Management) Module goes a step further by cataloging all software assets. It automatically generates software inventories in the standardized CPE format for seamless, one-click uploading to VANS—making it effortless for public sector entities to satisfy the mandates of the Cyber Security Management Act while ensuring no endpoint vulnerability is overlooked.

 

 

This module requires installing the UPAS Agent on endpoints. Beyond facilitating VANS integration for government agencies, it executes a broad suite of compliance checks, including tracking Windows OS build versions, antivirus statuses, mandatory software, prohibited applications, and software license counts. Non-compliant devices are then restricted by UPAS NOC access control features until all required remediation and updates are performed.

 

 

 

 

Deploying an Easily Maintainable and Manageable Defense Grid

 

 

A network security architecture capable of achieving optimal results must undergo thorough deployment, administration, and maintenance processes. Because the users involved span multiple dimensions, "enforcing security" should never be a one-sided, unidirectional mandate. If maintaining the ideal efficacy of security policies requires various users to continuously perform overly complex, stressful tasks, it will inevitably become a hidden vulnerability within the defense grid itself.

 

 

 

 

UPAS NOC never stops optimizing the security experience. Our core advantage lies in deploying a highly pervasive defense grid without the need for agent installations, thereby enhancing visibility and effortlessly applying management policies. By utilizing non-802.1X technology, we deliver exceptional adaptability and simplicity, eliminating the management pressure and technical risks typically caused by network redeployments or software/hardware upgrades.

 

 

Click to Download: UPAS NOC Public Sector Industry Solution Guide

Please contact us to receive tailored industry solutions and expert consultation.

 

BACK TO LIST