Circular No. 01/2011/TT-NHNN stipulates the measures to ensure the safety and security of information technology (IT) systems in banking activities. It applies to the State Bank of Vietnam and credit organizations, foreign bank branches. Notably, it requires the establishment of IT safety regulations, IT asset management, information security, access control, backup, incident handling, and continuous operation of IT systems.
Đối tượng áp dụng
The State Bank of Vietnam; credit organizations; foreign bank branches (hereinafter referred to collectively as the entity).
Các điểm cốt lõi
- The entity must establish and implement IT safety and security regulations appropriate to its IT system.
- Classify IT assets according to their value and importance to apply suitable protective measures.
- Manage internal and third-party human resources regarding IT safety and security.
- Ensure physical safety and environment for the IT system.
- Develop operational procedures, backup, network management, virus and malware prevention.
- Manage information and application access based on users' functions and responsibilities.
- Ensure continuous operation of the IT system through disaster recovery plans and procedures.
- Conduct internal audits and report compliance with the provisions of this Circular.
🌐 Tác động xã hội từ văn bản này
- Reduce risks of information security breaches for the IT system, protecting customer and business interests.
- Require investment in IT safety management resources, increasing operating costs for credit organizations.
- Depend on the technical capability and personnel strength of the entity in ensuring IT safety.
❓ Câu hỏi thường gặp
How should the entity establish IT safety and security regulations?
Regulations must include IT asset management, human resources, physical and environmental protection, communication and operations, access, acceptance, development, maintenance of information systems, incident management, storage, and disaster recovery. The regulation needs to be approved by the entity's head and implemented.
How should the entity manage human resources?
Before hiring or assigning tasks, determine IT safety responsibilities; check background, moral character, and professional qualifications; require signing confidentiality agreements. During employment, disseminate regulations to staff; apply disciplinary measures for violations. Upon termination of employment, clarify responsibilities and revoke system access rights.
How should the entity protect IT assets?
Inventory and classify types of IT assets; prioritize them based on value and importance. Assign usage rights to specific individuals or departments and comply with management regulations.
How should the entity back up data?
Issue and implement backup procedures; list data and software to be backed up. Backed-up data must be securely stored and regularly checked. Test and restore the system from backup data at least every six months.
How should the entity handle IT incidents?
Establish incident reporting and control procedures. Clearly define staff reporting responsibilities; immediately report to authorized persons when a security breach occurs. Resolve incidents promptly and minimize recurrence potential.
Toàn văn
CIRCULAR
Regulations on ensuring the safety and security of information technology systems in banking operations
____________________________________
Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12 dated June 16, 2010;
Pursuant to the Law on Credit Institutions No. 47/2010/QH12 dated June 16, 2010;
Pursuant to the Law on Information Technology No. 67/2006/QH11 dated June 29, 2006;
Pursuant to Decree No. 96/2008/NĐ-CP dated August 26, 2008 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
The State Bank of Vietnam stipulates the regulations on ensuring the safety and security of information technology systems in banking operations as follows:
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation and Applicability
1. This Circular sets forth the requirements for ensuring the safety and security of information technology (IT) systems in banking operations.
2. This Circular applies to the State Bank of Vietnam; credit organizations; foreign bank branches (hereinafter referred to collectively as entities).
Article 2. Interpretation of Terms
In this Circular, the following terms are understood as follows:
1. Information Technology System: is a structured set of hardware, software, databases, and network systems serving one or more technical and business activities of banks.
2. IT Assets: include equipment, information belonging to the IT system of the entity. It includes:
a) Physical Assets: are IT devices, communication means, and other equipment serving the operation of the IT system.
b) Information Assets: are data and documents related to the IT system. Information assets are represented in paper form or electronic data.
c) Software Assets: include application programs, system software, databases, and development tools.
3. IT Risk: is the possibility of loss occurring when carrying out activities related to the IT system. IT risks relate to the management, use of hardware, software, communication, system interfaces, operation, and human factors.
4. Risk Management: involves coordinated activities aimed at identifying and controlling potential IT risks.
5. Third Party: refers to organizations or individuals with expertise hired or collaborating with the entity to provide goods or technical services for the IT system.
6. Network Security System: is a collection of firewalls; devices for controlling and detecting unauthorized access; software for managing, monitoring, logging network security status, and other equipment designed to ensure the safe operation of networks, all working synchronously according to a consistent network security policy to strictly control all activities on the network.
7. Firewall: is a set of components or a system of equipment and software placed between two networks, designed to control all connections from inside to outside the network or vice versa.
8. Virus: is a computer program capable of spreading, causing abnormal activity on digital devices or copying, modifying, or deleting stored information in digital devices.
9. Malicious Software (Malware): includes harmful software such as viruses, spyware, adware, or similar types.
10. Technical Vulnerability: is a position within the IT system that is susceptible to damage when attacked or illegally accessed.
Article 3. General Principles
1. Each entity must ensure the safety and security of its own IT system in accordance with the provisions of this Circular.
2. Timely identify, classify, assess, and effectively handle potential IT risks that may occur within the entity.
3. Develop and implement IT safety and security regulations based on a harmonious balance between benefits, costs, and risk tolerance levels of the entity.
4. Allocate sufficient quality resources commensurate with scale to ensure the safety and security of the IT system.
5. Clearly define the authority and responsibility of the entity's head, various levels, departments, and each individual within the entity regarding the work of ensuring the safety and security of the IT system.
Article 4. Rules on Information Technology System Safety and Security
1. Units must establish rules on information technology system safety and security that are appropriate to their information technology systems, organizational structure, management requirements, and operations. These rules on information technology system safety and security must be approved by the unit head, implemented, and disseminated to all staff members and related parties.
2. The rules on information technology system safety and security must include basic provisions on:
a) Management of IT assets;
b) Human resource management;
c) Physical and environmental regulations;
d) Communication and operation regulations;
đ) Access management;
e) Receiving, developing, and maintaining information systems;
g) Incident management;
h) Storage and disaster recovery.
3. Units must periodically review, amend, and perfect their rules on information technology system safety and security at least once a year to ensure their appropriateness, completeness, and effectiveness. In cases where deficiencies or inconsistencies leading to information technology system safety breaches are discovered or upon request from competent authorities, units must immediately amend and supplement their rules.
Chapter II
PROVISIONS ON INFORMATION TECHNOLOGY SYSTEM SAFETY AND SECURITY GUARANTEES
PART 1
ORGANIZATION FOR INFORMATION TECHNOLOGY SYSTEM SAFETY AND SECURITY GUARANTEES
Article 5. Internal Management of Information Technology System Safety and Security
1. Unit heads must directly direct work on ensuring information technology system safety and security and clearly define responsibilities for individuals and departments in this work.
2. Individuals within the unit involved in information security must sign confidentiality agreements.
Article 6. Management of Information Technology System Safety and Security for Third Parties
1. Assess the technical capabilities, personnel, and financial capacity of third parties before signing contracts for provision of goods and services.
2. Clearly define the responsibilities, rights, and obligations of both parties regarding information technology system safety and security when signing contracts. Contracts with third parties must include clauses on penalties for third parties violating safety and security regulations and the responsibility to compensate for damages caused by third parties' violations.
3. Pay special attention to issues of confidentiality, integrity, availability, reliability, maximum performance, disaster recovery capability, and storage means of information systems.
4. Fully identify risks associated with third parties that may arise and apply risk management measures.
5. Apply strict monitoring measures and limit third-party access when allowing them to access the unit's information technology systems.
PART 2
MANAGEMENT OF INFORMATION TECHNOLOGY ASSETS
Article 7. Determination of Responsibilities for Information Technology Assets
1. Conduct inventory of various types of information technology assets within the unit at least once a year. Inventory content must include asset type, value, level of importance, installation location, backup information, copyright information.
2. Classify and prioritize assets based on their value and level of importance to implement appropriate protective measures. Establish and enforce regulations on asset management and usage.
3. Assign asset usage rights to specific individuals or departments. Users of information technology assets must comply with asset management and usage regulations to ensure proper use of assets.
Article 8. Classification of Information Assets
1. Classify information assets based on criteria such as value, sensitivity, importance, frequency of use, and retention period.
2. Implement appropriate management measures for each classified type of information asset.
PART 3
HUMAN RESOURCE MANAGEMENT
Article 9. Management of Internal Human Resources
1. Before hiring or assigning tasks
a) Determine the responsibility for information technology (IT) security and confidentiality of the position to be hired or assigned.
b) Conduct thorough background checks and strictly evaluate the moral character and professional qualifications when hiring or assigning staff to critical IT system positions such as system administration, security and confidentiality system administration, system operation, and database administration.
c) The decision or employment contract (if applicable) must include terms regarding the hired person's responsibility to ensure IT security and confidentiality during and after working at the unit.
2. During the period of work
a) The unit is responsible for disseminating and updating regulations on IT security and confidentiality for staff.
b) Require and inspect compliance with IT security and confidentiality regulations of individuals and organizations within the unit at least once a year.
c) Apply disciplinary measures against unit staff who violate IT security and confidentiality regulations.
d) Important tasks such as configuring network security systems, changing operating system parameters, installing firewall devices, and intrusion prevention systems (IPS) must be performed by at least two people or supervised by another person.
đ) It is not allowed to grant administrative rights (individuals who can modify configurations, data, logs) on primary and backup IT systems to the same individual.
3. When terminating or changing work
When officers and staff terminate or change their work, the unit must:
a) Clearly define the responsibilities of staff and related parties concerning the IT system.
b) Prepare handover records with staff.
c) Revoke or change the IT system access rights of staff in accordance with their changed job duties.
Article 10. Management of Third-Party Human Resources
1. Before implementing work
a) Request third-party providers to provide a list of personnel participating.
b) Verify the legal status and professional qualifications of third-party personnel in accordance with job requirements.
c) Request third-party providers to sign commitments not to disclose important information of the unit.
2. During the implementation of work
a) Provide and require third-party providers to fully comply with the unit's regulations and rules on IT security and confidentiality.
b) Monitor compliance with IT security and confidentiality regulations of third-party personnel.
c) In case of signs or violations of IT security and confidentiality regulations by third-party personnel, the unit needs to:
- Temporarily suspend or terminate the activities of the third party depending on the severity of the violation.
- Officially notify third-party personnel of IT security and confidentiality violations.
- Investigate, report the level of violation, and inform the third party of any damage incurred.
- Revoke the IT system access rights granted to the third party.
3. Upon completion of work
a) Request third-party providers to return assets used by the unit during the work implementation.
b) Revoke the IT system access rights granted to the third party immediately upon completion of work.
c) Change passwords and keys handed over from the third party.
PART 4
PHYSICAL AND ENVIRONMENTAL SECURITY ASSURANCE
Article 11. Physical Safety and Environment
1. Areas for processing and storing information and information processing equipment must be protected by secure walls and controlled entry gates.
2. Areas with high safety and confidentiality requirements such as server rooms must apply appropriate access control measures to ensure that only authorized personnel can enter those areas.
3. Measures to protect against fire, explosion, flooding, earthquakes, and other natural and human-induced disasters must be implemented. Server rooms must meet industrial hygiene standards: no leaks, no water seepage; equipment installed on technical floors should not be directly exposed to sunlight; humidity and temperature levels must comply with the specified standards for devices and servers; adequate fire, explosion, flood prevention equipment, lightning protection systems must be provided.
4. Rules and guidelines for working in secure and confidential areas must be established.
5. Common use areas, distribution, and delivery zones must be monitored and isolated from secure and confidential areas.
Article 12. Safety and Security of ICT Assets
1. ICT assets must be located and installed at safe locations and protected to minimize risks from environmental threats and unauthorized intrusions.
2. ICT assets must be secured with power supply and support systems when the main power source is interrupted. Overload and voltage drop prevention measures, surge protection, grounding systems, backup generators, and uninterrupted power supply systems must be in place to ensure continuous operation of equipment.
3. Power cables and communication cables used for data transmission or supporting services must be protected from intrusion or damage.
4. All data storage devices must be checked to ensure that important data and licensed software stored on them are erased or overwritten without recovery capability before disposal or reuse for other purposes.
5. ICT assets may only be taken outside the organization with the approval of the competent authority.
6. Equipment used for business operations installed outside the organization's premises must have monitoring and security measures to prevent unauthorized access.
SECTION 5
MANAGEMENT AND OPERATIONS
Article 13. Operation Procedures
1. Issuance and implementation of operation procedures for ICT systems to users including: device startup/shutdown procedures; data backup/recovery procedures; equipment maintenance procedures; application operation procedures; incident handling procedures.
2. Control changes to ICT systems including: software versions, hardware configurations, documentation, operation procedures; contingency plans for recovery if changes fail or unexpected incidents occur; record changes; plan, test, and verify changes before formal implementation.
3. The official operational system must meet the following requirements:
- Separation from development and testing environments.
- Only allow internet connections for ICT systems that have fully applied security and safety solutions and are capable of protecting against external threats and attacks.
- Do not install application development tools on the official operational system.
4. For business information systems:
a) A single individual should not handle all stages from initiating to approving a business transaction.
b) All activities on the system must be logged and available for review and control when necessary.
Article 14. Management of services provided by third parties
1. Must supervise and inspect services provided by third parties to ensure the service provision level and system operation capability comply with the agreements signed.
2. Ensure the implementation and maintenance of safety and security measures for services provided by third parties according to the agreements.
3. Manage changes to third-party services including: upgrading to new versions; using new techniques, new development tools and environments. Conduct a full impact assessment and ensure safety before implementing the changes.
Article 15. Management of planning and acceptance of ICT systems
1. Monitor and optimize the performance of ICT systems; plan future performance and capacity of ICT systems to ensure necessary standards.
2. Establish requirements and standards such as performance, recovery time when incidents occur, ensuring continuity; train and transfer technical knowledge for users on changes, and conduct testing and evaluation of the new ICT system or upgraded system's ability to meet requirements before formal application.
Article 16. Backup and Recovery
1. Issue and implement backup and recovery procedures for essential software and data.
2. List the data and software that need to be backed up, classified by storage period, backup frequency, backup method, and recovery system test period from backup data.
3. Backup data must be securely stored and regularly tested to ensure readiness for use when needed. Test and recover the system from backup data at least once every six months.
Article 17. Management of Network Security and Privacy
1. Implement network management and control to prevent threats and maintain security for systems and applications using networks:
a) Have logical and physical diagrams of the network system;
b) Use firewalls, intrusion detection and prevention devices, and other equipment to ensure network security and privacy.
2. Set up and fully configure network security device features. Use tools to detect and promptly identify vulnerabilities, weaknesses, and unauthorized access to the network. Regularly check and detect illegal connections, devices, and software installations on the network.
3. Identify and clearly specify security features, levels of privacy protection, and management requirements in service agreements for third-party-provided network services.
Article 18. Information Exchange
1. Issue regulations on information and software exchange through communication networks within the organization and with other organizations. Determine responsibilities and legal obligations for participating components.
2. Agree on information exchange with external parties.
3. Take protective measures for carriers of information during transportation.
4. Develop and implement measures to protect information exchanged between ICT systems.
Article 19. E-commerce Services
1. Take measures to protect information in e-commerce transactions against fraudulent activities and unauthorized modifications:
a) Communication channels and protocols must be encrypted;
b) Use strong authentication methods such as multi-factor authentication or digital signatures for transaction participants.
2. Information in online transactions must be transmitted completely, accurately to the correct address, avoiding unauthorized modification, disclosure, or reproduction.
3. Public information on ICT systems must be protected to prevent unauthorized modification.
Article 20. Supervision and Logging of ICT System Activities
1. Record logs and specify the retention period for information on the activities of the ICT system, users, errors, and security incidents to assist in subsequent investigation and supervision.
2. Review and prepare periodic reports on logs and undertake necessary actions to handle errors and incidents.
3. Protect logging functions and log information from forgery and unauthorized access. System administrators and users shall not delete or modify logs recording their own activities.
4. Establish mechanisms to synchronize time between ICT systems.
Article 21. Prevention of Viruses and Malware
Develop and implement regulations on preventing viruses and malware that meet the following basic requirements:
1. Deploy a computer virus prevention system for the entire ICT system of the organization.
2. Daily scan and remove viruses and malware from the entire ICT system of the organization and external devices before use.
3. Do not open unfamiliar emails, attachments, or links within unfamiliar emails to avoid viruses and malware.
4. Do not visit websites with unclear origins or suspicious sources.
5. Timely update new virus and malware samples and new anti-virus software.
6. Immediately report to the system administrator for handling if viruses or malware are detected but cannot be removed.
7. Do not install software without permission from the system administrator.
SECTION 6
ACCESS CONTROL MEASURES
Article 22. Operational Requirements for Access Control
1. Develop and implement regulations on user access management to ensure operational needs and security requirements are met. User access management regulations include the following main contents:
a) Registration, issuance, extension, and revocation of user access rights;
b) Limitation and control of privileged access;
c) Password management;
d) Review, inspection, and re-evaluation of user access rights.
2. Password management regulations must meet the following requirements:
a) Passwords must be at least six characters long, consisting of numbers, letters, and special characters if the system allows. Valid password requirements must be automatically checked when setting passwords;
b) Default manufacturer passwords set on equipment, software, and databases must be changed immediately upon use;
c) Password management software must have the following functions: notify users to change expiring passwords; invalidate expired passwords; allow immediate password changes if exposed, at risk of exposure, or at user request; prevent reuse of old passwords for a specified period.
3. User responsibilities when granted access rights: use passwords according to regulations, keep passwords confidential, and log out of the system when not working or temporarily not using it.
Article 23. Network Access Management
1. Issue regulations on network usage and network services; procedures for granting, revoking network and service access permissions; methods and means of accessing networks and services. Specifically:
a) Permitted networks and services;
b) Conditions for network connection.
2. Use appropriate measures to authenticate external users connecting to the internal network to ensure safety and confidentiality.
3. Control access to ports used for configuring and managing network devices.
4. Segregate the network system into different zones based on user type, purpose, and information systems.
Article 24. Access Control to Operating Systems
1. Establish procedures for controlling access to operating systems; specify secure and confidential password management regulations.
2. Each user of the operating system must have a unique identifier and be authenticated, identified, and logged when accessing the operating system.
3. Use additional authentication methods such as biometrics or cards in addition to password authentication for important servers.
4. Limit and strictly control system utilities that can affect the system and other applications.
5. Automatically terminate sessions after a period of inactivity to prevent unauthorized access.
6. Set limits on connection times for high-risk applications.
Article 25. Access Control to Information and Applications
1. Manage and grant permissions for accessing information and applications according to the functions and responsibilities of users.
a) Allocate access rights to individual directories and program functions;
b) Allocate read, write, delete, and execute permissions for information, data, and programs.
2. Important information systems must be placed in a separate computer network environment. If information systems share common resources, they must be approved by the system administrator.
PART 7
ACCEPTANCE, DEVELOPMENT, MAINTENANCE OF INFORMATION SYSTEMS
Article 26. Safety and Security Requirements for Information Systems
When building new information systems or improving existing ones, safety and security requirements must be established concurrently with technical and operational requirements.
Article 27. Ensuring Safety and Security of Applications
Business application programs must meet the following requirements:
1. Verify the validity of data entered into applications to ensure that the data is accurately and validly inputted.
2. Verify the validity of automatically processed data within applications to detect discrepancies caused by processing errors or intentional information modifications.
3. Measures to ensure data authenticity and integrity in applications must be implemented.
4. Verify the validity of data output from applications to ensure that the information processing by the applications is accurate and valid.
Article 28. Management of Encryption
1. Establish and implement encryption measures and key management according to recognized national or international standards to protect unit information. Use encryption algorithms such as:
a) AES: Advanced Encryption Standard;
b) 3DES: Triple Data Encryption Standard;
c) RSA: Rivest-Shamir-Adleman;
d) Other algorithms.
2. Customer passwords, user passwords, and other sensitive data must be encrypted when transmitted over networks and when stored.
Article 29. Safety and Security of System Files
1. Regulations for managing, installing, and updating software on current systems to ensure the safety of system files.
2. Test data must be carefully selected, protected, managed, and controlled.
3. Access to source code must be strictly managed and controlled.
Article 30. Safety and Security in Support and Development Processes
1. There must be regulations for managing and controlling changes to information systems.
2. When changing operating systems, critical business applications must be tested and reviewed to ensure stable and safe operation in the new environment.
3. Modifications to software packages must be strictly managed and controlled.
4. Closely monitor and manage the purchase of external software.
Article 31. Management of Technical Weaknesses
1. Regulations for assessing, managing, and controlling technical weaknesses of currently used IT systems must be established. Regularly assess and report on technical weaknesses of currently used IT systems.
2. Develop and implement solutions to address technical weaknesses and mitigate related risks.
PART 8
MANAGEMENT OF IT INCIDENTS
Article 32. Incident Reporting
1. Establish procedures for reporting, templates for reports, and clearly identify the recipients of reports on information technology incidents.
2. Specify the responsibility of staff members, employees, and third parties to report information technology incidents.
3. Information security incidents must be immediately reported to those with authority and relevant parties to take corrective measures as soon as possible.
Article 33. Control and Resolution of Incidents
1. Issue procedures, responsibilities for resolving and preventing incidents, ensuring that incidents are handled within the shortest time possible and minimizing the likelihood of recurrence.
2. The incident handling process must be recorded and stored at the unit.
3. Collect, record, preserve evidence and proof for inspection, handling, resolution, and prevention of incidents. In cases where information technology incidents involve violations of the law, the unit has the responsibility to collect and provide evidence to competent authorities in accordance with the provisions of the law.
SECTION 9
ENSURING CONTINUOUS OPERATION OF INFORMATION TECHNOLOGY SYSTEMS
Article 34. Ensuring Continuous Operation
1. Based on the scale and importance of each information technology system to the unit's operations, select critical information technology systems that significantly impact the unit's operations.
2. Develop and implement plans and procedures to ensure continuous operation of critical information technology systems.
3. At least once every six months, conduct inspections, tests, evaluations, and updates of procedures to ensure continuous operation of critical information technology systems.
4. Plans and procedures for ensuring continuous operation must be reviewed, evaluated, and updated when there are changes to the system.
Article 35. Disaster Recovery Work
1. Establish a disaster recovery system for the unit's critical information technology systems. The disaster recovery system must be at least 30 kilometers away from the main system measured in a straight line between the two systems.
2. The disaster recovery system must replace the main system within four hours from the time the main system experiences an unrecoverable incident.
3. At least once every three months, switch operations from the main system to the disaster recovery system to ensure consistency and readiness of the disaster recovery system.
4. At least once every three months, conduct inspections and evaluations of the disaster recovery system's operations.
SECTION 10
INTERNAL AUDITS AND REPORTING
Article 36. Internal Audits
1. Units must organize internal audits of compliance with the provisions of this Circular at least once a year.
2. Audit results and recommendations must be compiled into a report.
Article 37. Reporting
Units have the responsibility to submit reports to the State Bank of Vietnam (Information Technology Department) as follows:
1. Information Security and Confidentiality Regulations of the Unit:
a) For units that have issued information security and confidentiality regulations before the effective date of this Circular: Units must submit their information security and confidentiality regulations within fifteen days from the effective date of this Circular.
b) For units that have not issued information security and confidentiality regulations since the effective date of this Circular: Units must issue and submit their information security and confidentiality regulations within six months from the effective date of this Circular.
2. Annual Report:
a) Any amendments or additions to the information security and confidentiality regulations if applicable; Internal audit report of the unit as stipulated in Article 36 of this Circular.
b) Deadline for submission: Before March 15th each year.
c) Format and template of the report: As guided by the State Bank of Vietnam (Information Technology Department).
3. Emergency Reports:
When incidents involving loss of security occur in information technology systems, units must submit emergency reports in writing, specifically as follows:
a) Deadline for submission: Within ten days from the date the incident was discovered.
b) Content of emergency reports:
- Date and location of the incident;
- Cause of the incident;
- Risk assessment and impact on the information technology system and business operations at the location where the incident occurred and other related locations.
- Measures taken by the unit to prevent, mitigate, and prevent risks;
- Recommendations and proposals.
Chapter III
IMPLEMENTING PROVISIONS
Article 38. Violation Handling
Organizations and individuals violating the provisions of this Circular shall be subject to handling according to the relevant laws depending on the level of violation.
Article 39. Effective date
This Circular takes effect forty-five days from the date of issuance and replaces the following documents:
- Decision No. 04/2006/QD-NHNN dated January 18, 2006, of the Governor of the State Bank of Vietnam promulgating the Information Security and Confidentiality Regulations for the Banking Industry;
- Decision No. 14/2000/QD-NHNN16 dated January 7, 2000, of the Governor of the State Bank of Vietnam on the issuance of the Management and Usage Regulations for Information Systems in the Banking Industry;
- Decision No. 864/2003/QD-NHNN dated August 5, 2003, of the Governor of the State Bank of Vietnam on amending and supplementing certain articles of the Management and Usage Regulations for Information Systems in the Banking Industry issued together with Decision No. 14/2000/QD-NHNN16 dated January 7, 2000.
During implementation, if any issues arise or difficulties are encountered, relevant units must promptly reflect them to the State Bank of Vietnam for review, supplementation, and amendment.
Article 40. Responsibility for Implementation
1. The Information Technology Department is responsible for monitoring and inspecting the implementation of this Circular by units.
2. Banking Inspection and Supervision Authorities are responsible for coordinating with the Information Technology Department to inspect the implementation of this Circular by credit institutions and foreign bank branches, and handle administrative violations according to the law.
3. The Internal Audit Department is responsible for conducting internal audits of the implementation of this Circular by units under the State Bank of Vietnam.
4. Heads of relevant units under the State Bank of Vietnam; Governors of State Bank of Vietnam provincial and municipal branches; Chairmen of Boards of Directors, General Managers (Directors) of credit institutions and foreign bank branches are responsible for organizing and inspecting the implementation of this Circular within their respective units in accordance with the provisions of this Circular./.
Văn bản gốc (PDF)
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.
Bản dịch
Văn bản này có sẵn ở các ngôn ngữ sau: