Directive No. 07/2005/CT-NHNN On Strengthening Preventive Work for Business Information Systems in the Banking Sector

Directive No. 07/2005/CT-NHNN requires units under the State Bank of Vietnam and credit organizations to strengthen preventive work for business information systems to ensure uninterrupted banking operations. This directive applies to departments and bureaus under the State Bank of Vietnam, the Banking Technology Bureau, the State Bank of Vietnam Inspectorate, and credit organizations.

문서 번호07/2005/CT-NHNN
문서 유형Directive
발행 기관State Bank of Vietnam
서명자Phùng Khắc Kế — Phó Thống đốc
업데이트29. 06. 2026
산업Banking
분야Uncategorized
발행일08. 12. 2005
발효일30. 12. 2005
효력 만료일
상태In effect
✦ 스마트 요약

Directive No. 07/2005/CT-NHNN requires units under the State Bank of Vietnam and credit organizations to strengthen preventive work for business information systems to ensure uninterrupted banking operations. This directive applies to departments and bureaus under the State Bank of Vietnam, the Banking Technology Bureau, the State Bank of Vietnam Inspectorate, and credit organizations.

적용 범위

Units under the State Bank of Vietnam and credit organizations (excluding grassroots People's Credit Funds).

핵심 사항

  • The Banking Technology Bureau shall review and propose additional equipment for backup systems for important business information systems of the State Bank of Vietnam.
  • Credit organizations shall analyze risks and classify business information systems according to their level of importance to implement appropriate backup plans.
  • For units under World Bank-funded modernization projects, by the end of 2007, they must complete the construction and maintenance of backup data centers.
  • Credit organizations that have not yet organized centralized business processing systems must complete the deployment of backup systems for related business operations directly involving customers by the second quarter of 2007.
  • For dispersed business operations that can be temporarily halted for a certain period, backup measures must be completed by 2006.

🌐 이 문서의 사회적 영향

  • Positive impact: Reducing the risk of interruption in banking operations, enhancing information security, supporting international integration.
  • Negative impact: High investment costs for backup systems affecting credit organizations' capital sources.

❓ 자주 묻는 질문

What should State Bank of Vietnam units do?

The Banking Technology Bureau shall review and propose additional equipment for backup systems for important business information systems of the State Bank of Vietnam. At the same time, it shall study the construction of backup data centers.

What should credit organizations do to maintain continuous operations?

Analyze risks and classify business information systems according to their level of importance, implementing appropriate backup plans. Ensure that backup data centers have sufficient technical capacity to fully replace the main center.

How long does it take to activate the backup center to completely replace the main center?

This duration must not exceed four hours, as per the minimum requirement of the Directive.

How much investment do credit organizations need to build backup systems?

The document only mentions supplementing equipment and does not specify investment costs. Organizations should prioritize resource allocation for this purpose.

Which business operations need to be backed up?

Business operations directly involving customers such as accounting, payment, fund mobilization, lending, and other operations deemed necessary. Dispersed business operations also need to be backed up.

전문

GRACE PERIODFOR BANKSNumber: 07/2005/CT-NHNN

SOCIALIST REPUBLIC OF VIETNAM

Independence - Freedom - Happiness

Regarding the strengthening of preventive work for information systems in the banking sector Hanoi, December 8, 2005

DIRECTIVE

As the reform period began, the banking sector quickly recognized the important role of information technology in the reform process and took appropriate steps, gradually investing in and modernizing banking technology based on advanced information technology platforms. This has helped the banking sector fulfill its role in monetary management and credit, contributing to controlling inflation, stabilizing macroeconomic conditions, while increasing credit capital and total payment means, promoting economic growth, and creating necessary conditions suitable for Vietnam's banks to gradually integrate into regional and international financial communities. Although the construction and implementation of information technology systems have achieved encouraging results as mentioned, according to the statistical survey of the State Bank of Vietnam, the organization and operation of backup information systems of credit institutions and some units of the State Bank still have many shortcomings.

Through surveys at 45 credit institutions, only 19 units have backup data centers. Among them, only three units have a distance of 20 km or more from the main center to the backup center; 12 units are currently building backup centers and plan to put them into operation after 2005; 14 units have only planned to build backup centers. Many existing backup centers only meet the requirements for pure data backup and cannot fully replace the main data center when there is an incident. Specifically, regarding the State Bank system, although initial results have been achieved in preventive work for operational information systems such as equipping backup server systems and data backups between the Department of Banking Information Technology and the Central Bank headquarters; establishing a backup clearing center for inter-bank payment systems in Son Tay, 40 km from Hanoi; equipping backup servers and data backup devices for provincial branches of the State Bank under the central government. However, in reality, at some units, the operation of backup systems is not yet good, and not all major business activities have been fully backed up.

The main reasons for the above situation are that some units under the State Bank and some credit institutions have not fully recognized the importance of preventive work for operational information systems; have not paid adequate attention or invested appropriately, or lack supervision to maintain the operation of this work.

Based on the above reality, to ensure that banking business operations are not interrupted, to prevent and limit risks in the application of information technology, the Governor of the State Bank requests units under the State Bank and credit institutions to immediately implement specific tasks as follows:

1. Units under the State Bank

1.1. Departments and Bureaus of the State Bank within their functional responsibilities shall review and submit to the Governor of the State Bank for amendments and supplements to relevant legal regulations related to state management of safety in banking business operations processed on computers, and propose necessary solutions to ensure that banking business operations organized on computers operate smoothly without interruption. In 2006, they must complete the research and classification of risks of business operations processed on computers and submit to the Governor of the State Bank for issuance of regulations on continuous operation requirements and backup plans for each specific type of business activity: accounting, payments, credit, vault operations, and other business activities if deemed necessary.

1.2. The Department of Banking Information Technology shall review all current backup information technology plans and equipment for State Bank business processing systems to promptly address shortcomings in current backup work; study and submit to the Governor of the State Bank for the provision of additional necessary equipment to ensure that all important business information systems of the State Bank have backup systems. At the same time, they shall study and propose comprehensive solutions for the establishment and implementation of backup data centers for State Bank operations in 2006; study and draft regulations on information technology system security in the banking sector in the first quarter of 2006.

1.3. The Department of General Supervision shall strengthen IT inspection work at State Bank units, focusing on auditing backup work for business operations processed on computers, to promptly correct any deficiencies and shortcomings in compliance with regulations on the provision of backup systems, data backup, and data storage for business operations.

1.4. The Department of Banking Information Technology shall take the lead and coordinate with the State Bank Inspectorate and relevant Departments and Bureaus to conduct surveys at the headquarters of some credit institutions to assess the level of backup for business operations processed on computers, especially those directly related to customers such as accounting, payments, fund raising, credit, vault operations, and other business activities.

1.5. The Governors of provincial and municipal branches of the State Bank under the central government shall be responsible for organizing data backup and safe data storage for their unit's business operations; regularly organize inspections and urge credit institutions in their jurisdiction to comply well with regulations on the provision, operation of backup systems, and data backup for business operations.

2. Credit Institutions

(excluding grassroots People's Credit Funds)

2.1. Units shall base their continuous business operation maintenance strategy, analyze risks, impacts, and classify business information systems according to their level of importance, thereby implementing appropriate backup plans for each business information system. (excluding People's Credit Funds at the grassroots level)

2.1. Units shall base their continuous business operation strategies, analyze risks, impacts, and classify business information systems according to their levels of importance, thereby implementing appropriate contingency plans for each business information system.

2.2. For units within the scope of the World Bank-funded Modernization Project (Vietnam Commercial Joint Stock Bank, Vietnam Foreign Trade Joint Stock Bank, Vietnam Investment and Development Joint Stock Bank, Vietnam Agricultural Joint Stock Bank, Maritime Commercial Joint Stock Bank, and Vietnam Export-Import Commercial Joint Stock Bank) and credit institutions that have established centralized business processing systems, by the end of 2007, they must complete the construction and maintain the effective operation of a backup data center with the following minimum requirements:

a) The backup data center must be located at least 30 kilometers away from the main data center;

b) The backup center must have sufficient capacity in terms of infrastructure, technology, and human resources, ready to assume all roles of the main center when necessary;

c) The power supply system includes national grid, generator, and automatic battery designed to ensure stable and continuous power supply, meeting the requirement of 24 hours/day and 7 days/week operation;

d) Business processing centralized database operations must be immediately backed up from the main center to the backup center;

đ) Organize absolute security and safety for technical equipment and data systems;

e) The time to bring the backup center into full operational replacement of the main center shall not exceed four hours.

2.3. For credit institutions that have not established centralized business processing systems, by the second quarter of 2007, they must complete the deployment of backup systems for business operations directly related to customers such as accounting, payment, fund mobilization, credit, and other relevant operations if deemed necessary. The backup system must meet the following minimum requirements:

a) The backup system must not be located in the same building as the main data system;

b) The backup system must have sufficient technical capacity to assume all roles of the main system when it is out of operation;

c) Design separate power lines from the main system. Equip with generators and batteries to provide stable and continuous power supply, meeting normal operation requirements;

d) Organize absolute security and safety for technical equipment and data systems;

đ) Business processing operational databases must be immediately backed up from the main system to the backup system;

e) The time to bring the backup system into full operational replacement of the main system shall not exceed four hours.

2.4. For business operations organized in a decentralized manner and can be temporarily stopped for a certain period without affecting the unit's activities. Backup arrangements for these types of operations must be completed in 2006 with the following minimum requirements:

a) Have contingency plans for equipment failures, communication lines, software, and other related technical issues during the permitted downtime period;

b) Organize backups to meet data preservation requirements, ready for the restoration of normal business information system operations in case of incidents. Use real-time backup methods for operations requiring continuous activity and end-of-day backups for operations with permitted downtime of 24 hours or more.

2.5. Prioritize resource allocation for the provision of backup systems; strengthen internal inspection and control work, promptly rectify any violations, ensuring compliance with regulations on maintaining the operation of backup data systems and fully backing up data.

This Directive takes effect fifteen days after its publication in the Official Gazette. Heads of units under the State Bank, Governors of State Bank branches in provinces and centrally-administered cities, Chairmen of Management Boards, and General Directors (Directors) of credit institutions are responsible for thoroughly implementing this Directive./.

DIRECTOR

DEPUTY DIRECTOR

(Signed)

PHUNG KHAC KE

이 문서의 원본 파일을 업데이트하는 중입니다. 전문을 먼저 확인하시고 나중에 다시 확인해 주세요.

관계도

07/2005/CT-NHNN
Directive No. 07/2005/CT-NHNN On Strengthening Preventive Work for Business Information Systems in the Banking Sector
In effect

문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.