Directive No. 03/2007/CT-BBCVT of the Ministry of Posts and Telecommunications requires agencies, organizations, and enterprises to strengthen information security assurance on the Internet to mitigate potential negative consequences. This directive focuses on reviewing and inspecting systems, establishing procedures for ensuring information security, coordinating with relevant agencies, and raising awareness about this issue.
적용 범위
State agencies, organizations, and enterprises participating in activities on the Internet and providing cybersecurity services.
핵심 사항
- Agencies and organizations must strictly comply with laws on postal services, telecommunications, and the Internet; they have the responsibility to ensure information security in Internet activities (Article 1).
- Review and inspect systems serving storage, provision, and transmission of information; assess the current status of protection systems and measures to ensure information security. Prioritize domestic connections and the domain name '.vn' (Article 2a).
- Establish procedures and regulations to ensure information security for information systems, referring to the management standards TCVN 7652, ISO 27001; ensure traceability and recovery capabilities of information (Article 2b).
- Coordinate with relevant authorities to update the latest measures for ensuring information security (Article 2c).
- Telecommunication and Internet enterprises must closely monitor equipment under their management; systems and software put into use must comply with regulations (Article 3).
🌐 이 문서의 사회적 영향
- Positive impact: Minimize the risk of information security breaches and protect electronic administrative services and e-commerce. Enhance community awareness of this issue.
- Negative impact: Costs for system upgrades and staff training may significantly increase.
❓ 자주 묻는 질문
What should agencies and organizations do to ensure information security?
Agencies and organizations must review, inspect, and evaluate systems serving storage, provision, and transmission of information; establish procedures and regulations to ensure information security (Article 2).
What should telecommunication and Internet enterprises do?
Enterprises must closely monitor equipment under their management; systems and software put into use must comply with regulations (Article 3).
Who needs to be notified in case of information security incidents?
Units and individuals need to report incidents and risks of information security breaches to local Posts and Telecommunications Departments and the Vietnam National Cybersecurity Incident Response Team (VNCERT) (Article 5).
What should Internet value-added service providers do?
Enterprises must implement measures to ensure information security (Article 4).
What responsibilities does VNCERT have?
VNCERT promptly deploys a system for collecting information and providing online advice; takes the lead in coordinating the development of training plans for information security skills (Article 8).
전문
|
POST AND TELECOMMUNICATIONS MINISTRY No.: 03/2007/CT-BBCVT |
SOCIALIST REPUBLIC OF VIETNAM Independence - Freedom - Happiness Hanoi, February 23, 2007 |
DIRECTIVE
On Strengthening Information Security on the Internet
___________________________
In recent times, the situation regarding information security on the Internet has become complicated. Many websites have been attacked,their contents altered. Not a few Vietnamese websites using international domain names have been lost or redirected; viruses and spam have proliferated strongly. Briefly describe technical improvements, production processes, raw materials, designs; new technology applications such as automation, digitalization, clean technology; management, marketing, distribution solutions; products winning awards or certifications related to innovation…):…Some networks with Vietnamese IP addresses have been banned from international connections and electronic transactions due to the dissemination of viruses or spam. Preliminary surveys show that up to 80% of online news sites still have significant vulnerabilities in ensuring information security; many information systems have deficiencies that have not been updated or adequately addressed, leading to unfortunate incidents affecting e-government services, e-commerce, and other applications of information technology. The awareness of the risk of losing information security and the damage that can occur when network incidents happen among many agencies, organizations, and businesses is limited.
To strengthen information security on the Internet, to minimize negative consequences for online news sites, especially those of state agencies, organizations, and businesses nationwide, the Minister of Post and Telecommunications requests the following from agencies, organizations, and businesses:
1. Strictly comply with laws on post, telecommunications, and the Internet, the Law on Information Technology, and the Law on Electronic Transactions; take responsibility for ensuring information security in Internet activities; implement requirements for information security set forth by the Ministry of Post and Telecommunications, the Ministry of Public Security, and other competent state agencies as prescribed by law.
2. Agencies and organizations participating in activities on the Internet must:
a) Review, inspect, and evaluate systems and equipment serving the storage, provision, and transmission of information; assess the current status of protection systems and measures to ensure information security. Prioritize the use of domestic connections and ".vn" domains to ensure the safety of online news sites.
b) Develop procedures and regulations to ensure information security for information systems, referring to management standards TCVN 7652, ISO 27001. Ensure traceability and recovery capabilities for information in case of incidents.
c) Regularly coordinate with relevant authorities and service providers of secure networks to update the latest security measures.
3. Telecommunication and Internet enterprises must strengthen inspections and strict monitoring of equipment under their management; they may not be exploited or allow others to exploit them to disrupt social order; systems and software deployed on the Internet must comply with the provisions of Clause 2b.
4. Enterprises providing value-added services on the Internet (hosting, mail, FTP…) must have measures to ensure information security.
5. Units and individuals need to report incidents and risks of information security breaches to local Post and Telecommunications Departments and the Vietnam National Center for Cybersecurity Response (VNCERT) under the Ministry of Post and Telecommunications.
6. Organizations and businesses participating in activities on the Internet or providing cybersecurity services must strictly follow the coordination of VNCERT in responding to Internet network incidents in Vietnam, cooperate with VNCERT in assessing the capacity for cybersecurity within their units when there are signs or risks of cybersecurity breaches.
7. Units under the Ministry of Post and Telecommunications, according to their functions and tasks, are responsible for assigning capable staff to collaborate with VNCERT in combating attacks on the network; conducting training and updating skills in information security for agencies, organizations, and individuals who require it.
8. VNCERT must quickly deploy an information collection and consultation system through the Internet; lead and coordinate with related agencies to develop and implement training plans for cybersecurity skills that meet the practical needs of agencies, organizations, and businesses; enhance publicity efforts to raise community awareness about the responsibility for ensuring information security in telecommunication and Internet activities.
9. The Vietnam National Internet Network Information Center (VNNIC) is responsible for strengthening management of national domain names ".vn" and IP addresses as prescribed; enhancing security for the national domain name server system; coordinating with functional units to provide information on domain names and addresses as required.
10. Local Post and Telecommunications Departments must strengthen state management over information security in Internet activities within their jurisdiction; guide telecommunications and Internet enterprises and Internet agents in their areas to strictly comply with laws on post, telecommunications, and the Internet; intensify inspection, supervision, and timely, resolute handling of violations concerning information security; improve organizational structure and enhance the capabilities of staff to meet requirements.
Heads of units under the Ministry, local Post and Telecommunications Departments, and organizations participating in activities on the Internet are responsible for organizing and implementing this Directive and submitting reports on its implementation to the Ministry of Post and Telecommunications (VNCERT) by the end of the first quarter of 2007; during the implementation process, if any issues arise, they should report to the Ministry of Post and Telecommunications for consideration and resolution.
The Vietnam National Center for Cybersecurity Response is responsible for checking and urging the implementation of this Directive and reporting to the Minister.
|
THE MINISTER (Signed) Do Trung Ta |
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.