This Decision stipulates the coordination and emergency response work for ensuring cybersecurity in Vietnam, including contents such as establishing the National Steering Committee, the National Emergency Response Agency, the National Coordination Center, the National Emergency Response Team; assigning responsibilities to relevant agencies; provisions on funding and effectiveness implementation.
적용 범위
Ministries, ministerial-level agencies, central agencies, People's Committees of provinces and centrally governed cities, and related organizations
핵심 사항
- Establishing the National Steering Committee for coordinating emergency response to ensure cybersecurity.
- Assigning responsibilities to the National Emergency Response Agency, the National Coordination Center, the National Emergency Response Team, and related ministries and sectors.
- Provisions on funding for coordinating and emergency response activities to ensure cybersecurity from the state budget, enterprises, and the Vietnam Universal Service Fund.
- Effective from the date of issuance.
- Related organizations must implement this Decision.
🌐 이 문서의 사회적 영향
- Enhancing the ability to respond to cybersecurity incidents at both national and local levels.
- Clearly assigning responsibilities to each agency and unit in coordinating and responding to incidents.
- Ensuring necessary funding for coordinating and responding to incidents.
- Raising awareness about cybersecurity among organizations and individuals.
❓ 자주 묻는 질문
When does this Decision take effect?
This Decision takes effect from the date of issuance.
What must relevant agencies and units do to implement this Decision?
Ministries, ministerial-level agencies, central agencies, People's Committees of provinces and centrally governed cities, and related organizations must implement this Decision.
What role does the Vietnam Universal Service Fund play in coordinating and responding to incidents to ensure cybersecurity?
The Vietnam Universal Service Fund is allocated for certain activities and tasks related to coordinating and responding to incidents to ensure cybersecurity that the state budget does not cover or covers insufficiently.
전문
Pursuant to …;
Issuing regulations on emergency response plans to ensure national cybersecurity
to guarantee national information security
Pursuant to the Law on Government Organization dated June 19, 2015;
Pursuant to the Law on Information Security dated November 19, 2015;
Pursuant to the Decree No. 85/2016/NĐ-CP dated July 1, 2016 on ensuring information system security by level;
At the proposal of the Minister of Information and Communications;
The Prime Minister issues regulations on emergency response plans to ensure national cybersecurity.
Chapter I
GENERAL PROVISIONS
Article 1. Scope of Application
This Decision stipulates on emergency response plans to ensure national cybersecurity.
Information systems managed by the Ministry of National Defense and the Ministry of Public Security are not within the scope regulated by this Decision.
Article 2. Applicability
This Decision applies to agencies, organizations, enterprises, and individuals directly participating or related to emergency response activities for ensuring cybersecurity in Vietnam.
Chapter II
ORGANIZATION AND IMPLEMENTATION OF EMERGENCY RESPONSE TO ENSURE NATIONAL INFORMATION SECURITY
NATIONAL CYBER SECURITY
Article 3. National Steering Committee for Emergency Response to Ensure Information Security
1. The National Information Security Steering Committee shall assume the function of the National Steering Committee for Emergency Response to Ensure Information Security (hereinafter referred to as the National Steering Committee).
2. The National Steering Committee shall be responsible for directing the Ministry of Information and Communications, the Ministry of Public Security, the Ministry of National Defense, and relevant ministries, sectors, and localities in the work of emergency response to ensure national information security.
Article 4. National Office for Emergency Response to Ensure Information Security
1. The Ministry of Information and Communications shall act as the permanent office assisting the National Steering Committee (hereinafter referred to as the Permanent Office) with specific tasks and powers as follows:
a) Decide on selecting emergency response plans and take the lead in directing emergency response activities to ensure national information security;
b) Direct the National Coordination Agency to receive, collect, process information, and report on cyber incidents and propose emergency response plans;
c) Summon and direct the National Cyber Incident Response Team based on the proposal of the National Coordination Agency; direct and assign tasks to specialized units for incident response and network members to implement emergency response plans;
d) Serve as the point of contact or designate the National Coordination Agency as the national point of contact to coordinate with functional units of other countries or international organizations in emergency response and handling cross-border incidents;
e) Inspect, supervise, urge compliance from relevant units, and report to the National Steering Committee on emergency response activities for cyber incidents.
2. In necessary cases, the Ministry of Information and Communications shall take the lead in establishing the National Emergency Response Coordination Board (referred to as the National Emergency Response Coordination Board), consisting of: one leader from the Ministry of Information and Communications as Chairperson, the National Coordination Agency as the permanent office, and members including leaders from departments and bureaus of some relevant ministries, sectors, and organizations.
Article 5. Emergency Response Steering Committees for Cyber Incidents of Ministries, Equivalent Ministries, Government Agencies, and Provincial People's Committees
1. The Information Technology Application Steering Committees of ministries, equivalent ministries, government agencies, and provincial people's committees shall assume the function of Emergency Response Steering Committees for Cyber Incidents within their respective jurisdictions and fields (hereinafter referred to as the Ministry-level and Provincial Steering Committees).
In cases where there is no Information Technology Application Steering Committee or special conditions require it, ministries, equivalent ministries, government agencies, and provincial people's committees may consider establishing Emergency Response Steering Committees for Cyber Incidents within their respective ministries, sectors, and provinces, directly led by a ministry leader or a provincial people's committee leader.
2. Responsibilities and powers of the Ministry-level and Provincial Steering Committees:
a) Direct coordination and emergency response activities for cyber incidents within their respective sectors, fields, and provinces; direct subordinate agencies and units to cooperate and comply with requirements of the National Coordination Agency in coordination and emergency response;
b) Summon and direct the Cyber Incident Response Team or the Cyber Incident Response Unit at the same level based on proposals from specialized incident response units;
c) Report situations and seek opinions from the National Steering Committee through the Permanent Office on issues arising beyond their authority during implementation; be subject to direction and management by the National Steering Committee through the Permanent Office and the National Coordination Agency.
Article 6. Specialized Units for Cyber Incident Response
1. Specialized units for cyber incident response are specialized agencies for information security or information technology of ministries, sectors, provincial People's Committees (hereinafter referred to as Specialized Units for Incident Response).
Telecommunications enterprises, Internet enterprises, organizations, and businesses managing large information systems shall establish or designate specialized units for cyber incident response within their own agencies or organizations.
2. Specialized units for incident response are responsible for establishing and organizing the operation of incident response teams within their respective fields, areas, and scopes of management; participating in emergency response activities to ensure national cybersecurity when requested by the Standing Office or Coordination Agency.
Article 7. National Network for Cyber Incident Response
1. Obligatory members of the national network for cyber incident response (hereinafter referred to as the incident response network) include:
a) Specialized units for incident response, information security, or information technology of ministries, ministerial-level agencies, government agencies, central agencies; Provincial Departments of Information and Communications;
b) Agencies and units with related functions under the Ministry of Information and Communications: Vietnam National Cybersecurity Center (VNCERT), Vietnam Internet Network Information Center (VNNIC);
c) Agencies and units with related functions under the Ministry of Public Security: Cyber Security Bureau; High-Tech Crime Prevention Bureau;
d) Agencies and units with related functions under the Ministry of National Defense: Information Technology Bureau; Government Cryptographic Department;
e) Enterprises providing telecommunications infrastructure services, Internet service providers (ISPs); organizations and enterprises providing data center services, leasing storage space; units managing and operating national databases; specialized units for information security and information technology of banking, financial, treasury, tax, customs organizations;
f) Organizations and enterprises managing and operating important information systems, industrial control systems (SCADA) in the fields of energy, industry, healthcare, natural resources and environment, education and training, population and urban areas.
2. Voluntary members joining the network: Are organizations and enterprises not listed in Clause 1 of this Article, having capabilities in information security or information technology, registering and being approved by the National Coordination Agency to join the network. Encouraging organizations and enterprises operating in the field of information security and information technology; organizations and enterprises managing and operating large-scale information systems, specialized banking and financial information systems, industrial control systems (SCADA); and other units with information security capabilities to register to join the network.
3. The Vietnam National Cybersecurity Center (VNCERT) is the National Coordination Agency for Incident Response (referred to as the National Coordination Agency or Coordination Agency), responsible for:
a) Coordinating national incident response activities; having the authority to mobilize and coordinate network members and related organizations to cooperate in preventing, handling, and mitigating incidents in Vietnam; deciding on the form of coordination for incident response activities and bearing responsibility for coordination orders/requests;
b) Leading the establishment of operational regulations for the network; organizing and directing the operation of the network; compiling and sharing incident information and warnings within the network; proposing and receiving, managing contributions and sponsorships from network members and organizations and individuals, and other legitimate sources to fund network activities; serving as the national point of contact for cooperation with foreign organizations and enterprises in cybersecurity incident response work.
c) The Ministry of Information and Communications establishes a Network Management Board chaired by the head of the Coordination Agency, with members being representatives of some network members to manage, coordinate, and organize activities for the network.
4. Network members are responsible for complying with the operational regulations of the network, adhering to coordination requirements of the Coordination Agency, actively participating and contributing to network activities. Telecommunication enterprises and Internet service providers (ISPs) have the responsibility to store and provide information related to subscriber IP addresses, servers, IoT devices, log files, domain name system (DNS) service logs within their management scope; setting up an environment for installing monitoring equipment, sampling, and providing network data streams to serve surveillance and incident detection according to requests from the National Coordination Agency; establishing a permanent 24/7 contact point, arranging human and material resources ready to cooperate and implement solutions to respond to and mitigate the consequences of incidents when the source of attack is determined to originate from subscribers under their own enterprise or when requested by the National Coordination Agency.
Article 8. The operational unit for national cyber security emergency response
1. The operational unit for national cyber security emergency response (hereinafter referred to as the Emergency Response Operational Unit) shall be convened by the Standing Agency and operate under the direction of the Standing Agency with the participation of the following units:
a) National Coordination Center (Vietnam Computer Emergency Response Team - VNCERT - on standby);
b) Cybersecurity Bureau, Ministry of Information and Communications;
c) Cybersecurity Division, High-Tech Crime Prevention Police Bureau - Ministry of Public Security;
d) Information Technology Bureau, General Staff Department, Ministry of National Defense;
đ) Some specialized units responsible for responding to cybersecurity incidents of ministries, ministerial-level agencies, government-affiliated agencies, provincial people's committees, telecommunications and internet enterprises, and managers of important national information systems.
2. Powers of the Emergency Response Operational Unit
a) To use operational methods, equipment, technical means, and other measures according to assigned functions and duties and in compliance with legal regulations;
b) To request agencies, organizations, and individuals to provide information, documents, and equipment when there is evidence indicating their involvement in incidents to serve emergency response activities;
c) To inspect information systems of agencies, organizations, and individuals when there is evidence indicating their involvement in incidents to serve emergency response activities;
d) To request relevant agencies, organizations, telecommunications and internet enterprises to cooperate in performing necessary tasks for emergency response and incident resolution.
3. Mechanism for coordination and information sharing among participating units in the national cyber security emergency response operational unit in accordance with legal provisions and decisions of the Prime Minister.
Chapter III
EMERGENCY RESPONSE PLAN
Article 9. Classification of Cybersecurity Incidents
A serious cybersecurity incident is an incident that meets all of the following criteria simultaneously:
1. The affected information system is an information system at level 4, level 5, or included in the List of Important National Information Systems and is subject to one of the following incidents:
a) Service interruption of the system;
b) State top-secret or secret data may be disclosed;
c) Important data of the system cannot ensure integrity and cannot be recovered;
d) System control is lost;
đ) The incident has the potential to occur on a wide scale or cause chain effects, damaging other level 4 or level 5 information systems.
2. The manager of the information system lacks the ability to self-monitor and resolve the incident.
Article 10. System of Emergency Response Plans for National Cybersecurity Assurance
1. The national cybersecurity emergency response plan is an emergency response plan for serious cybersecurity incidents meeting the criteria set out in Article 9 and the affected information system is an information system at level 5 or included in the List of Important National Information Systems.
2. The emergency response plan for national cybersecurity of state agencies, political organizations, and political-social organizations is an emergency response plan for serious cybersecurity incidents meeting the criteria set out in Article 9; the affected information system is an information system at level 4 and the manager of the information system belongs to ministries, ministerial-level agencies, government-affiliated agencies, and central state agencies, political organizations, and political-social organizations (collectively referred to as central agencies).
3. The emergency response plan for national cybersecurity of localities is an emergency response plan for serious cybersecurity incidents meeting the criteria set out in Article 9; the affected information system is an information system at level 4 and the manager of the information system belongs to provincial people's committees or Provincial Party Committees, Municipal Party Committees of centrally governed cities (collectively referred to as local agencies).
4. The emergency response plan for national cybersecurity of enterprises is an emergency response plan for serious cybersecurity incidents meeting the criteria set out in Article 9; the affected information system is an information system at level 4 and the manager of the information system is a telecommunications enterprise, a state-owned enterprise managing information systems from level 4 upwards, or an organization or enterprise managing information systems included in the List of Important National Information Systems (collectively referred to as enterprises managing critical information infrastructure).
Article 11. Reporting Cybersecurity Incidents
1. Reporting Cybersecurity Incidents:
a) The entity operating the information system shall be responsible for reporting incidents to the supervisory agency, the specialized incident response unit at the same level, and the National Coordination Center no later than five days from the date of discovering the incident; in cases where it determines that the incident may exceed its capacity to handle, the entity operating the information system must immediately implement the urgent reporting procedures as stipulated in Clauses 2 through 5 of this Article upon discovery of the incident or determination that the incident may exceed its handling capacity.
b) Organizations and individuals, upon detecting signs of attacks or cybersecurity incidents, shall promptly notify the entity operating the information system, the supervisory agency of the relevant information system, the National Coordination Center, and the specialized incident response unit or the member of the incident response network with responsibility.
2. Incident reports must be carried out immediately and maintained throughout the incident response process including: Initial report; situation update report; specific response plan report; request for guidance and command report; request for support and coordination report; final response conclusion report.
3. Reporting formats include formal letters, fax, email, multimedia messages, or through the national cybersecurity incident reporting and warning system; report templates according to coordination response regulations, or as directed by the National Coordination Center.
4. The initial report content includes:
a) Name and address of the entity operating the information system; supervisory agency of the information system; affected information system; time of incident discovery;
b) Contact point for the entity operating the affected system regarding the incident: Name, position, phone number, email;
c) Description of the incident: Type of incident, phenomena, preliminary assessment of the degree of harm, spread level, impact on the normal operation of the organization;
d) Service provider of the information technology infrastructure and telecommunications;
đ) List of measures already implemented or planned to be implemented to address and resolve the incident;
e) Organizations and businesses currently supporting the incident response and resolution results up to the reporting time;
g) Initial incident response results;
h) Recommendations for incident response and resolution strategies (if applicable).
5. Principles for Reporting and Exchanging Information During Incident Response:
a) The entity operating the information system shall report to the supervisory agency of the information system, the specialized incident response unit at the same level, and simultaneously send to the National Coordination Center;
b) The specialized incident response unit shall report to the supervisory agency of the information system, the higher-level Steering Committee, and the National Coordination Center;
c) The Ministry-level and provincial Steering Committees and the National Coordination Center shall report to the Standing Office and the National Steering Committee.
Article 12. Receiving, Detecting, Classifying, and Preliminary Handling of Cybersecurity Incidents
1. The specialized incident response unit or member of the incident response network, upon discovering an incident or receiving a notification or report of a cybersecurity incident within their responsibility, must perform:
a) Recording and accepting notifications and reports of cybersecurity incidents according to the correct procedure;
b) Immediately notifying the National Coordination Center, the entity operating the information system, the supervisory agency of the information system, and related competent agencies about the incident information;
c) Providing feedback to organizations and individuals who have sent the initial notification or report to confirm receipt of the incident notification or report;
d) Reviewing, verifying, and classifying cybersecurity incidents to select appropriate response plans or propose to the higher-level Steering Committee and the National Coordination Center when exceeding authority;
đ) Actively supporting the entity operating the information system in responding to and resolving incidents within its capacity and responsibility;
e) Monitoring the development of the incident response situation and reporting to the higher-level Steering Committee and the National Coordination Center; proposing and seeking guidance in cases not within its authority, scope of responsibility, or beyond its handling capacity;
g) Compiling and reporting to the National Coordination Center on a semi-annual basis and providing ad hoc reports as required.
2. The National Coordination Center is responsible for:
a) Publicizing on its website the hotline phone number, fax number, and email address, and ensuring resources to maintain continuous hotline service to promptly receive and handle incidents;
b) Recording and accepting notifications and reports of cybersecurity incidents according to the correct procedure;
c) Providing feedback to organizations and individuals who have sent the initial notification or report to confirm receipt of the incident notification or report;
d) Providing a separate contact point for serious incidents;
đ) Reviewing, verifying, and classifying incidents to implement warnings, coordinate selection of response plans, organize incident response, and report; proposing to the Standing Office decisions on serious incidents and appropriate emergency response plans; reporting and proposing to the Standing Office and the National Steering Committee issues exceeding authority;
e) Organizing cooperation with international cybersecurity response organizations to receive early warnings, information about incidents, and cyber threats, and coordinating cross-border incident response and attacks;
g) Fulfilling other responsibilities of the National Coordination Center.
3. When the entity operating the information system discovers or receives a notification of an incident affecting the information system under its management, it must perform:
a) Recording and accepting notifications and reports of incidents and collecting related information according to the correct procedure;
b) Providing feedback to organizations and individuals who have sent the initial notification or report to confirm receipt of the incident notification or report;
c) Leading and coordinating with the network security service provider (if any) and related functional units to conduct analysis, verification, evaluation of the situation, preliminary classification of the incident, and immediate implementation of incident response activities and reporting as prescribed;
d) Reporting on the incident, the development of the incident response situation, requesting support for incident response or upgrading the severity of the incident (when necessary) to the supervisory agency of the information system, the National Coordination Center, and the specialized incident response unit at the same level.
Article 13. General Incident Response Process for Cybersecurity Incidents
The general incident response process for cybersecurity incidents shall be carried out in accordance with guiding documents and regulations issued by the Ministry of Information and Communications and the National Coordination Agency.
Article 14. Serious Incident Response Process for Cybersecurity Incidents
The emergency response process for serious cybersecurity incidents set forth below shall be applied to all four emergency response scenarios specified in Article 10 of this Decision, including the following steps:
1. Detection or Reception of the Incident
Leading Unit: Information System Operation Unit; National Coordination Agency.
Supporting Units: Incident Response Specialized Unit; Information System Manager.
Implementation Content: The Information System Operation Unit is responsible for continuously monitoring and detecting attacks and incidents on the systems under its management and operation. The National Coordination Agency is the central unit organizing tracking, surveillance, detection of incidents, and receiving notifications about cybersecurity incidents from various sources.
2. Verification, Analysis, Evaluation, and Classification of the Incident
Leading Unit: National Coordination Agency.
Supporting Units: Information System Manager; Incident Response Specialized Unit; Information System Operation Unit.
Implementation Content:
a) The National Coordination Agency will cooperate with the Information System Manager (or authorized units such as the Incident Response Specialized Unit or the Information System Operation Unit) to verify the incident, including the following information: Status of the incident; severity level; scope of impact; subject and location where the incident occurred.
b) After verifying the incident, the National Coordination Agency is responsible for classifying the incident and proceeding as follows:
- In case the incident is classified as general (not meeting the criteria stipulated in Article 9 of this Decision), the National Coordination Agency will notify relevant parties to continue implementing the general cybersecurity incident response plan;
- In case the incident is classified as serious (meeting the criteria stipulated in Article 9 of this Decision), the National Coordination Agency will report to the Standing Agency regarding the serious incident along with proposals: Response plan; participating units in the response force; necessary resources for responding to the incident; anticipated mobilization of the emergency response operations team and further implementation according to Clause 3 of this Article.
3. The Standing Agency decides on selecting the response plan and convening members of the emergency response operations team.
Leading Unit: Standing Agency.
Implementation Content:
a) Based on the report from the National Coordination Agency, the Standing Agency will consider and decide on selecting the national emergency response plan and convening the emergency response operations team to respond to and handle the incident. Depending on the actual situation, the emergency response operations team will be mobilized from the units specified in Article 8 of this Decision, consistent with the selected response plan and characteristics of the incident.
b) Principles for assigning tasks to implement emergency measures to ensure national cybersecurity are as follows:
- Directing and supervising the response activities and coordinating information sharing: Ministry of Information and Communications, National Emergency Response Coordination Board;
- Collecting, summarizing information and sharing, reporting: National Coordination Agency, Information System Manager (through the Information System Operation Unit and the Incident Response Specialized Unit);
- Analyzing information: National Coordination Agency, Information System Operation Unit, Incident Response Specialized Unit, and participating units in the emergency response operations;
- Blocking and handling the incident: Information System Operation Unit, Incident Response Specialized Unit, National Coordination Agency, and participating units in the emergency response operations;
- Restoring data and normal operations: Information System Manager, units chosen by the Information System Manager;
- Handling aftermath: Information System Manager, participating units in the emergency response operations;
- Announcing and managing information crises: Standing Agency, National Coordination Agency.
4. Implement Initial Response Plan
Leading Unit: National Coordination Agency, Information System Manager.
Implementation Content: The National Coordination Agency will quickly coordinate with the Information System Manager to immediately implement initial response measures, including:
a) Determining the scope, targets, and objectives for response:
- Occurred related incidents;
- Affected entities;
- Scope of impact;
- Priority objectives in resolving the incident (restoration of operations, ensuring data confidentiality; ensuring data integrity);
- Situation developments and attack methods;
- Predicted subsequent developments.
b) Coordinating initial response activities: The Standing Agency directs the National Coordination Agency to coordinate and share information related to the response situation among participating members based on their assigned functions and responsibilities.
c) Warning incidents on the national response network: The National Coordination Agency will issue warnings to network members and related entities or those potentially affected by similar incidents.
d) Implementing temporary restoration measures:
Based on the priority objectives in resolving the incident, the Information System Manager will coordinate with the National Coordination Agency, service providers, and other competent authorities to restore some essential activities, data, or connections to minimize damage to the information system, the reputation of the managing agency, or negative impacts on society.
The Information System Manager must closely cooperate and provide full information for the National Coordination Agency to monitor and track the recovery process and any ongoing attacks or impacts until the incident is fully resolved.
đ) Initial consequence management: The system information manager must promptly implement emergency measures to mitigate the initial consequences and damages caused by cyber attacks that affect citizens, society, other agencies, and organizations, as required by the Standing Office.
e) Preventing and handling discovered actions: The Standing Office coordinates or directs the National Coordination Agency to coordinate relevant functional agencies to deploy support for detecting and handling sources of attacks, preventing external attacks on affected information systems. The Standing Office provides or directs the provision of information and evidence related to criminal acts (if any) to the competent agencies under the Ministry of Public Security for investigation, verification, and prevention of crimes.
5. Implementing the emergency response plan
a) Directing the handling of incidents
Leading unit: The Standing Office, the Central Emergency Response Steering Committee at the ministry or provincial level.
Content: Based on the selected response plan, the Standing Office directs the system information manager, the National Coordination Agency, and the incident response operation team to carry out emergency response and incident handling tasks. During the response process, depending on the actual situation, the Standing Office may decide to supplement participants in the emergency response operation.
b) Coordinating the response work
Leading unit: The National Incident Coordination Board, the National Coordination Agency.
Content: Based on the selected response plan, the National Incident Coordination Board or the National Coordination Agency performs coordination tasks according to their functions and responsibilities, and monitors the cooperation mechanism and information sharing.
c) Press statements and information release
The Standing Office is responsible for designating spokespersons and providing information; deciding on the location, content, and timing of press statements and information releases to mass media outlets, individuals, and organizations related to the incident.
d) Information collection
Leading unit: The National Coordination Agency, the system information manager.
Content: Based on the requirement to provide information to the emergency response operation team components, the National Coordination Agency and the system information manager cooperate to collect, compile, share, and provide information.
đ) Analyzing and monitoring the situation related to the incident
The National Coordination Agency leads and collaborates with the system information manager to continuously monitor the development of the incident and report and update relevant units within the emergency response operation team.
Units within the emergency response operation team base on collected information, utilize available resources, tools, and professional procedures to conduct incident analysis. The analysis results are reported to the Standing Office, the National Coordination Agency, and shared within the emergency response operation team to serve response and recovery efforts.
e) Repairing the incident, removing malicious code
Leading unit: The system information manager.
Supporting unit: The National Coordination Agency, other units within the emergency response operation team.
Implementation Content:
- Back up the system before and after incident handling;
- Eliminate malicious codes and harmful software;
- Restore the system, data, and connections;
- Configure secure system settings;
- Conduct a full system test after incident recovery;
- Address security weaknesses;
- Supplement hardware and software to ensure system security;
- Deploy monitoring, surveillance, and prevention of similar incidents from recurring.
g) Preventing and managing consequences
The system information manager is responsible for managing consequences caused by their own information system incidents affecting citizens, agencies, and organizations.
Units participating in the emergency response operation team, based on analysis results, investigations, utilizing available resources, tools, and professional procedures, take action to prevent actions causing incidents and assist in managing consequences.
h) Verifying causes and tracing origins
Units participating in the emergency response operation team, after analyzing the incident, referring to the incident analysis results of other units, using available information and professional procedures, proactively investigate detailed causes and trace origins, reporting to the Standing Office, the National Coordination Agency for consolidation, verification, and reporting to the National Steering Committee all relevant specific information including:
- The target attacked;
- Attack methods and techniques (processes, technologies, malware);
- Time of attack;
- Occurred losses;
- Attacker;
- Predicted likelihood of similar attacks and losses.
6. Evaluating the implementation results of the national cybersecurity emergency response plan
Leading unit: The National Steering Committee
Content: The Standing Office compiles all relevant analytical reports on the implementation of the national cybersecurity emergency response plan to report to the National Steering Committee and convene meetings to analyze causes, draw lessons from incident handling activities, and propose additional measures for similar incidents.
7. Conclusion
Leading unit: The National Coordination Agency
Supporting unit: The system information manager, units within the emergency response operation team.
Content: Based on the evaluation results of the National Steering Committee, the National Coordination Agency will complete the following tasks to conclude the emergency incident response operations:
- Archiving files and records;
- Summarizing lessons learned and experiences;
- Proposing technical and policy recommendations to minimize damage when similar attacks occur;
- Reporting to higher authorities, holding press conferences, or sending information to the media if necessary.
Chapter IV
MEASURES TO ENSURE IMPLEMENTATION
NATIONAL INFORMATION SECURITY INCIDENT RESPONSE
Article 15. Seizure of property and suspension of communication means for national cybersecurity emergency response
During the implementation of the national cybersecurity emergency response to ensure information security, when requested by the Standing Office, competent authorities as prescribed by law shall carry out the following:
1. Temporarily suspend or suspend the use of communication means or other activities from the information system if there is evidence that these activities cause particularly serious harm to public interests or cause severe, extremely serious damage to national defense and security.
2. Seize communication means, equipment, transportation, and other means, and the persons using or controlling such means in urgent situations to implement emergency response tasks or to prevent social losses that are occurring or are likely to occur.
3. Mobilize resources within their respective sectors, fields, and localities under management to implement emergency response measures.
Article 16. Development and Implementation of Emergency Response Plans for Ensuring Information Security
1. Agencies and units develop and implement emergency response plans for ensuring information security (hereinafter referred to as emergency response plans) to ensure human resources, material resources, financial resources, and necessary conditions to promptly and effectively implement emergency response measures for information security incidents, specifically as follows:
a) The National Coordination Agency develops and submits to the Ministry of Information and Communications for approval to implement the national emergency response plan for ensuring information security and the operation plan of the emergency response network.
b) Specialized units for emergency response of ministries and central agencies develop and submit to the head of the managing agency for approval to implement emergency response plans for ensuring information security for state agencies, political organizations, and socio-political organizations within their respective ministries and sectors.
c) Specialized units for emergency response of provinces and centrally-administered cities develop and submit to the Chairman of the People's Committee of the province for approval to implement emergency response plans for ensuring information security at the local level;
d) Members of the network, organizations, and enterprises managing information systems listed in the National Important Information System Directory, large-scale information systems, and industrial control systems (SCADA) develop, approve, and implement emergency response plans for ensuring information security within their organizations and enterprises.
2. Agencies and units develop emergency response plans for ensuring information security according to the outline in Appendix II of this Decision, focusing on the following contents: Attack scenarios, potential risks and incident situations, response measures for each scenario and anticipated situation, and training and simulation exercises. In cases where necessary, the Ministry of Information and Communications will consider adjusting certain points in the outline to suit the situation and requirements of information security incidents.
3. The National Coordination Agency guides the development and implementation of emergency response plans, preventive emergency measures, and incident handling for information security; organizes regional, national, and international training and simulation activities; periodically inspects and evaluates the implementation of emergency response plans for information security by ministries, sectors, localities, and organizations and enterprises.
Article 17. Funding
1. The funding for implementing plans, activities, coordination, rescue, and remediation of cybersecurity incidents shall be sourced from: central budget; local budget; enterprise funding; and other lawful sources as prescribed.
2. The funding for implementing cybersecurity incident rescue activities shall be allocated within the state budget estimates of ministries, central agencies, and localities (including development expenditure and recurrent expenditure) and shall be managed, utilized, and settled according to the budget levels as stipulated in the State Budget Law and guiding documents. The allocation of funding shall follow the principle that activities and forces under which level of agency shall be funded and utilized from the funding source of that level of agency, specifically:
a) The central budget shall ensure:
- Directing, managing, inspecting, supervising cybersecurity incident rescue activities of the National Steering Committee, the National Coordination Center, and the National Incident Response Agency;
- Activities of the National Coordination Center including: funding for deploying activities related to the responsibilities of the national coordination center as prescribed in Articles 7, 11, 12, 13, 14, and 16 of this Decision; funding for ensuring regular operations; organizing monitoring, warning; training, drills, education; purchasing, upgrading, renewing software licenses, equipment maintenance, tools participating, coordinating international cooperation activities on cybersecurity; funding for developing and implementing contingency plans, funding for emergency response to severe national incidents; supporting ministries, sectors, and localities in coordinating and rescuing incidents; funding for hiring technical services, organizing, and maintaining the incident response expert team and operation unit; funding for managing and organizing activities of the Incident Response Network, propaganda, training, seminars, network meetings, specialized research, maintaining technical expert units, enhancing capabilities, and developing incident response teams; funding for inspection, scanning, evaluating information security; establishing, collecting, analyzing, and sharing information about incidents; supporting the establishment and application of ISO 27xxx standards and other international standards on cybersecurity; implementing special business activities to ensure cybersecurity for important state information systems;
- Ministries and central agencies shall base on the contents prescribed in this Decision to prepare annual budget estimates to implement activities related to their responsibilities as prescribed in Articles 7, 11, 12, 13, 14, and 16 of this Decision; funding for developing and implementing contingency plans within their ministries and sectors; funding for emergency response and handling incidents for information systems under their management; funding for organizing training, drills, and activities of the Incident Response Team; funding for monitoring, inspecting, scanning, evaluating information security; supporting the establishment and application of ISO 27xxx standards and implementing special business activities to ensure cybersecurity for information systems within their scope of management.
b) Local budgets shall ensure the activities of the Steering Committee, dedicated units for incident response, and local incident response teams, including: funding for deploying activities related to local responsibilities as prescribed in Articles 7, 11, 12, 13, 14, and 16 of this Decision; funding for implementing local contingency plans; funding for emergency response and handling incidents for information systems under local management; funding for organizing training, drills, and activities of the Incident Response Team; funding for monitoring, inspecting, scanning, evaluating information security; supporting the establishment and application of ISO 27xxx standards and implementing special business activities to ensure cybersecurity for information systems within their scope of management.
c) Enterprise funding shall ensure the deployment of activities related to enterprise responsibilities as prescribed in Clause 4 of Article 7, Articles 11, 12, 13, 14, and 16 of this Decision; implementing enterprise contingency plans, emergency response and handling incidents for information systems under enterprise management; cooperating in monitoring, providing information, participating in incident response; organizing training, drills, maintaining the operation of the Incident Response Team, and other tasks performed by enterprises and accounted for in business expenses. Telecommunications and Internet enterprises must ensure funding for monitoring and responding to cybersecurity incidents on their Internet connection channels and accounted for in business expenses.
d) System owners must allocate funding to implement plans and schemes for incident response, reserve funds for incident handling, remediate consequences, restore data, and return to normal operations of their information systems.
đ) Funding from the Vietnam Universal Service Fund shall be allocated for certain activities and tasks related to coordination and rescue of cybersecurity incidents that the state budget does not fund or inadequately funds, such as the activities of the national incident response network, hiring technical services, organizing, and maintaining the incident response expert team of the national coordination center, compensating telecommunications and Internet enterprises for losses due to implementing national incident response solutions, and other related activities that the state budget does not fund or inadequately funds.
e) The Ministry of Finance shall take the lead and coordinate with the Ministry of Information and Communications to provide detailed guidance on funding for coordination and rescue of cybersecurity incidents as prescribed in this Article.
Chapter V
IMPLEMENTING PROVISIONS
Article 18. Effective Date
This Decision takes effect from the date of issuance.
Article 19. Implementation
Ministries, ministerial-level agencies, central agencies, provincial People's Committees, centrally-administered city People's Committees, and relevant organizations shall implement this Decision.
During the implementation process, if any difficulties arise or it is deemed necessary to change the contents stipulated in this Decision, relevant agencies and organizations shall submit their opinions in writing to the Ministry of Information and Communications for consolidation and report to the Prime Minister for consideration to amend and supplement./.
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.