This Decision details the management of information security for banking information systems, including contents such as: Information security risk management; user and access management; password management; terminal device management; network management; database management; software management; service provider management; information system procurement and deployment management; business cooperation and information sharing management; external service usage management; online banking service usage information security management; mobile device usage information security management; cloud computing service usage information security management; external data storage service usage information security management; information security contract and agreement management; third-party information system management; third-party service usage management; cybersecurity management; physical security management; information security management during information system procurement and deployment; information security incident management and cybersecurity operations center management.
适用范围
This Decision applies to credit organizations, foreign bank branches, payment intermediary service providers, asset management companies of credit organizations, and other entities within the banking sector.
要点
- Information security risk management
- User and access management
- Password management
- Terminal device management
- Network management
- Database management
- Software management
- Service provider management
- Information system procurement and deployment management
- Business cooperation and information sharing management
- External service usage management
- Online banking service usage information security management
- Mobile device usage information security management
- Cloud computing service usage information security management
- External data storage service usage information security management
- Information security contract and agreement management
- Third-party information system management
- Third-party service usage management
- Cybersecurity management
- Physical security management
- Information security incident management and cybersecurity operations center management
🌐 本文件的社会影响
- Enhance information security risk management for banking information systems
- Ensure the confidentiality and stability of information systems when using external services and online services
- Improve the ability to respond to information security incidents
❓ 常见问题
To which entities does this Decision apply?
This Decision applies to credit organizations, foreign bank branches, payment intermediary service providers, asset management companies of credit organizations, and other entities within the banking sector.
What are the main contents of this Decision?
The main contents include information security risk management; user and access management; password management; terminal device management; network management; database management; software management; service provider management; information system procurement and deployment management; business cooperation and information sharing management; external service usage management; online banking service usage information security management; mobile device usage information security management; cloud computing service usage information security management; external data storage service usage information security management; information security contract and agreement management; third-party information system management; third-party service usage management; cybersecurity management; physical security management; information security incident management and cybersecurity operations center management.
全文
CIRCULAR
Regulations on Information System Security in Banking Activities
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
On the basis of the Law on Credit Institutions dated June 16, 2010, and the Law Amending and Supplementing Some Provisions of the Law on Credit Institutions dated November 20, 2017;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to the Law on Information Technology dated June 29, 2006;
||| Pursuant to the Cybersecurity Law dated November 19, 2015;
||| Pursuant to the Cyber Security Law dated June 12, 2018;
Pursuant to the Decree No. 85/2016/NĐ-CP dated July 1, 2016 of the Government on ensuring information system security by level;
Pursuant to Government Decree No. 16/2017/NĐ-CP dated February 17, 2017 on the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Information Technology;
The Governor of the State Bank of Vietnam promulgates this Circular on information system security in banking activities.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation and Applicability
Article 1. This Circular stipulates the minimum requirements for ensuring information system security in banking activities.
Article 2. This Circular applies to credit organizations, foreign bank branches, organizations providing intermediary payment services, credit information companies, Vietnam National Payment Corporation, Vietnam Asset Management Company, National Note Printing Factory, Deposit Insurance of Vietnam (hereinafter referred to collectively as the organization) that establish and use information systems serving one or more technical or business operations of the organization.
Article 2. Interpretation of Terms
In this Circular, the following terms are understood as follows:
Point 1. Information technology risk is the possibility of loss occurring when carrying out activities related to information systems. Information technology risks relate to management, use of hardware, software, communication, system interfaces, operation, and personnel.
Point 2. Information security incident is the situation where digital information or information systems are attacked or endangered, affecting the integrity, confidentiality, or availability of information.
Point 3. Technical vulnerability is a component within an information system that can be exploited or taken advantage of when attacked or illegally intruded.
Point 4. Data center includes technical infrastructure (station house, cable system) and computer systems along with auxiliary equipment installed there to process, store, exchange, and centrally manage data.
Point 5. Mobile device is a digital device designed to be portable without affecting its operational capability, having an operating system, capable of processing, connecting to networks, and displaying information such as laptops, tablets, smart mobile phones.
Point 6. Information carrier is material means used to store and transmit digital information.
Point 7. Firewall is a set of components or one or several systems of devices and software placed between two networks, aimed at controlling all connections from inside to outside the network or vice versa.
Point 8. Untrusted network is an external network connected to the organization's network and not under the organization's management or not under the management of a foreign credit institution if the organization is a subsidiary or commercial presence in Vietnam of a foreign credit institution.
Point 9. Cloud computing service is a service providing computing resources (including computing resources, network connection resources, storage resources, software resources, and other computing resources) through a network environment allowing multiple users to access, adjust, and pay according to usage needs.
Point 10. User account (account) is a set of information uniquely representing a user on an information system, used to log in and access authorized resources on that information system.
Point 11. Third party is individuals or businesses (excluding foreign credit institutions and members of foreign credit institutions in cases where the organization is a subsidiary or commercial presence in Vietnam of a foreign credit institution) who have a written agreement (collectively called service use contracts) with the organization to provide information technology services.
Point 12. Legal representative of the organization is the legal representative of the credit organization or enterprise, General Director (Director) of foreign bank branch.
Point 13. Competent authority is the position or person delegated by the legal representative of the organization in writing to manage, assign, or authorize to perform one or more functions or tasks of the organization.
Point 14. Multi-factor authentication is a method of authentication requiring at least two factors to prove the correctness of an identity. Authentication factors include: (i) Information known by the user (PIN number, secret key code, etc.); (ii) What the user possesses (smart card, token device, mobile phone, etc.); (iii) Biometric characteristics of the user.
Article 3. General Principles
Article 1. The organization is responsible for ensuring information security based on clearly defining the rights and responsibilities of each department and individual within the organization.
Article 2. Information systems are classified according to the levels specified in Article 5 of this Circular and apply appropriate information security policies.
Article 3. Information technology risks that may occur in the organization are identified, classified, evaluated promptly, and handled effectively.
Article 4. The development and implementation of information security regulations are carried out based on the provisions of this Circular and harmonize the interests, costs, and risk acceptance levels of the organization.
Article 4. Classification of Information
Information processed and stored through information systems shall be classified according to their confidentiality attributes as follows:
1. Public information is information made available to all subjects without the need to identify specific identities or addresses of those subjects.
2. Private (or internal) information is information managed and exploited with permission for one or a group of identified subjects.
3. Personal information includes customer identification information and the following information: account information, deposit information, entrusted asset information, transaction information, and other related information.
4. Confidential information is: (i) Secret, Top Secret, and Absolute Secret information as defined by laws on state secrecy protection; (ii) Restricted access information as defined by organizations.
Article 5. Classification of Information Systems
1. For information systems providing online services to customers, organizations shall classify them according to the provisions of Decree No. 85/2016/NĐ-CP dated July 1, 2016 of the Government on ensuring the security of information systems by level. For other information systems, classification shall be carried out according to the provisions of Clauses 2, 3, 4, 5, 6, and 7 of this Article.
2. Level 1 information system is an information system serving internal activities of the organization and only processes public information.
3. Level 2 information system is an information system meeting one of the following criteria:
a) An information system serving internal activities of the organization that processes private information, personal information of users, restricted access information as defined by the organization but does not process state secrets information.
b) An information system serving customers that does not require 24/7 operation.
c) An information infrastructure system serving the activities of certain units within the organization or of microfinance institutions, grassroots credit funds.
4. Level 3 information system is an information system meeting one of the following criteria:
a) An information system processing state secrets information at the Secret level.
b) An information system serving daily internal activities of the organization and does not accept more than four working hours of downtime from the time of shutdown.
c) An information system serving customers requiring 24/7 operation and does not accept downtime without prior planning.
d) Third-party payment systems used for transactions outside the organization's system.
đ) A shared information infrastructure system serving the activities of the organization and the banking industry.
5. Level 4 information system is an information system meeting one of the following criteria:
a) An information system processing state secrets information at the Top Secret level.
b) An information system serving customers that processes and stores data of ten million customers or more.
c) A national information system in the banking industry requiring 24/7 operation and does not accept downtime without prior planning.
d) Important payment systems in the banking industry as defined by the State Bank.
đ) A shared information infrastructure system serving the activities of the banking industry requiring 24/7 operation and does not accept downtime without prior planning.
6. Level 5 information system is an information system meeting one of the following criteria:
a) An information system processing state secrets information at the Absolute Secret level.
b) A national information system in the banking industry serving the connection and integration of Vietnam's activities with international activities.
c) A national information infrastructure system in the banking industry serving the connection and integration of Vietnam's activities with international activities.
7. In cases where an information system consists of multiple component systems, each component system corresponds to a different level, the level of the information system is determined as the highest level among the levels of the component systems.
8. Organizations shall classify information systems according to the levels specified in Clauses 1, 2, 3, 4, 5, 6, and 7 of this Article. The dossier and procedures for reviewing and approving information systems by level must comply with the provisions of Decree No. 85/2016/NĐ-CP. For dossiers proposing Level 4 and Level 5 information systems, organizations shall submit the dossiers to the State Bank (Information Technology Department) for comments.
9. The list of information systems by level must be established and reviewed and updated after the system is deployed and annually thereafter.
Article 6. Information Security Regulations
1. Organizations shall establish information security regulations appropriate to their information systems, organizational structure, management requirements, and activities. The information security regulations must be signed and issued by the organization's authorized representative and implemented throughout the organization.
2. Minimum information security regulations shall include the following basic contents:
a) Management of information technology assets;
b) Management of human resources;
c) Physical and installation environment safety assurance;
d) Operation and information exchange management;
đ) Access management;
e) Management of third-party information technology service usage;
g) Acceptance, development, and maintenance system management;
h) Information security incident management;
i) Assurance of continuous operation of the information system;
k) Internal audit and reporting procedures.
3. Organizations shall review the minimum information security regulations annually to ensure their completeness according to the provisions of this Circular. When any inadequacies or inconsistencies causing information security breaches are discovered or upon request from competent authorities, organizations shall immediately revise and supplement the issued information security regulations.
Chapter II
PROVISIONS ON INFORMATION SECURITY ASSURANCE
Section 1
INFORMATION TECHNOLOGY ASSET MANAGEMENT
Article 7. Information Technology Asset Management
1. Types of information technology assets include:
a) Information assets: data and information in digital form processed and stored through information systems;
b) Physical assets: information technology equipment, communication means, carriers of information, and devices serving the operation of information systems;
c) Software assets: system software, utility software, middleware, database management systems, application programs, source code, and development tools.
2. Organizations shall maintain a list of all information technology assets associated with each information system as stipulated in Clause 9, Article 5 of this Circular. Annually, they shall review and update the list of information technology assets.
3. Based on the level of the information system, organizations shall implement appropriate management and protection measures for each type of information technology asset.
4. Based on the classification of information technology assets under Clause 1 of this Article, organizations shall establish and implement regulations on the management and use of assets as provided for in Articles 8, 9, 10, 11, and Article 12 of this Circular.
Article 8. Information Asset Management
1. For each information system, organizations must create a list of information assets and define the authority and responsibility of individuals or units within the organization for accessing, exploiting, and managing these assets.
2. Information assets must be classified according to the types of information specified in Article 4 of this Circular.
3. Information assets belonging to confidential information categories must be encrypted or protected with measures to secure information during creation, exchange, and storage.
4. Information assets on information systems at Level 3 or higher must apply data loss prevention solutions.
Article 9. Physical Asset Management
1. Mobile devices and carriers of information, in addition to the provisions of this Article, must be managed according to Articles 11 and 12 of this Circular.
2. For each information system directly managed by the organization, the organization must create a list of physical assets including the following basic information: asset name, value, installation location, managing subject, purpose of use, usage status, corresponding information system.
3. Physical assets must be assigned to individuals or units responsible for managing and using them.
4. Physical assets taken out of the organization's premises must be approved by the competent authority and protective measures must be implemented to secure information stored on the asset if it contains confidential information.
5. Physical assets storing confidential information when changing the purpose of use or being disposed of must be destroyed or have the confidential information erased to ensure irrecoverability. In cases where confidential information cannot be destroyed, the organization shall implement destruction measures for the data storage components on the asset.
Article 10. Management of Software Assets
1. For each information system directly managed by an organization, a list of software assets must be established with basic information including: asset name, value, purpose of use, scope of use, managing subject, copyright information, version, component information system (if any).
2. Software assets must be assigned responsibility to individuals or management units.
3. Organizations must periodically review and update security patches for software assets.
4. When storing software assets on portable media, they must comply with the provisions set forth in Article 12 of this Circular.
Article 11. Management of Mobile Device Usage
1. Mobile devices connecting to the internal network system of the organization must be registered for control purposes.
2. Limit the scope of connection from mobile devices to services and information systems of the organization; control connections from mobile devices to permitted information systems within the organization.
3. Specify the responsibilities of individuals within the organization when using mobile devices for work purposes.
4. Mobile devices used for work purposes must apply the following minimum technical measures:
a) Establish functions to disable, lock the device, or remotely delete data in case of loss or theft;
b) Backup data on mobile devices to protect and restore data when necessary;
c) Implement data protection measures during maintenance, repair, or warranty of mobile devices.
5. For mobile devices that are organizational assets, in addition to applying the provisions of Clause 4 of this Article, organizations must also apply the following minimum technical measures:
a) Control installed software; update software versions and security patches on mobile devices;
b) Utilize features to protect personal information, internal information, confidential information (if any); set secret passwords; install anti-malware software and other security patches.
Article 12. Management of Portable Media Usage
Organizations must manage the usage of portable media according to the following regulations:
1. Control the connection and disconnection of portable media with equipment belonging to the information system.
2. Implement safety measures for portable media during transportation and storage.
3. Implement protective measures for confidential information contained in portable media.
4. Specify the responsibilities of individuals in managing and using portable media.
Section 2
HUMAN RESOURCE MANAGEMENT
Article 13. Human Resource Organization
1. The legal representative must directly participate in directing and be responsible for building strategies and plans to ensure information security and respond to information security incidents occurring within the organization.
2. Organizations with information systems at level 2 or below shall designate a responsible unit to ensure information security.
3. Organizations directly managing information systems at level 3 or above shall implement:
a) Establish or designate a specialized unit for information security with the function and responsibility to ensure information security and respond to information security incidents for the organization;
b) Separate personnel between tasks: (i) Development and system management; (ii) Development and system operation; (iii) System management and operation; (iv) Information security testing from development, management, and operation of the information system.
Article 14. Recruitment and Assignment of Tasks
The organization shall recruit personnel and assign tasks in accordance with the following provisions:
1. Determine the responsibility for ensuring information security at positions to be recruited or assigned.
2. Examine and assess the moral character and professional qualifications through personal history and judicial records before assigning personnel to work at important positions within the information system such as operating information systems at level 3 or higher or managing information systems.
3. Require the recruited person to commit to confidentiality in writing or as part of the labor contract. This commitment must include provisions on the responsibility for ensuring information security during and after working at the organization.
4. Train and disseminate the organization's regulations on information security to newly recruited personnel.
Article 15. Management and Utilization of Human Resources
The organization shall manage human resources as follows:
1. Disseminate and update regulations on information security for all individuals in the organization at least once a year.
2. Inspect compliance with information security regulations for individuals and subordinate units at least once a year.
3. Apply disciplinary measures against individuals and units that violate information security regulations according to the law and organizational regulations.
Article 16. Termination or Change of Work
When an individual in the organization terminates or changes their job, the organization shall implement the following:
1. Determine the responsibilities of the individual when terminating or changing their job.
2. Require the individual to hand over information technology assets.
3. Immediately revoke access rights to the information system for the departing employee.
4. Timely change access rights to the information system for the individual changing jobs to ensure the principle of minimum necessary access to perform assigned tasks.
5. Regularly review and check at least every six months between the human resource management department or system and the access control management department to ensure compliance with Clause 3 and Clause 4 of this Article.
6. Notify the State Bank (Information Technology Department) of cases where individuals working in the organization's information technology field are disciplined with dismissal, forced resignation, or prosecuted for crimes stipulated in Section 2 Chapter XXI of the Penal Code (Crimes in the Information Technology and Telecommunications Field).
Section 3
PHYSICAL AND ENVIRONMENTAL SAFETY FOR THE INSTALLATION OF INFORMATION TECHNOLOGY EQUIPMENT
Article 17. General Requirements for Installation Sites of Information Technology Equipment
1. Protect with perimeter walls, gates, or other measures to control and limit unauthorized intrusion risks.
2. Implement measures to prevent fire and flood hazards.
3. Areas with high safety and confidentiality requirements such as server installation areas, storage devices, security and confidentiality equipment, communication equipment of information systems at level 3 or higher must be isolated from common use, distribution, and transportation areas; issue internal rules, work guidelines, and apply entry and exit control measures for those areas.
Article 18. Requirements for Data Centers
In addition to meeting the requirements set forth in Article 17 of this Circular, data centers must meet the following requirements:
1. The entrance and exit of the data center building must be controlled 24/7.
2. The doors to the data center must be secure, fire-resistant, use at least two different types of locks, and have 24/7 protection and surveillance measures.
3. The equipment installation area must avoid direct sunlight, water leakage, and flooding. The equipment installation area of information systems at level 3 or higher must be protected and monitored 24/7.
4. There must be at least one grid power supply and one generator power supply. An automatic switching system between the two power sources must be installed, and the generator must automatically start when grid power is cut off. Power must be connected through a battery backup system to provide power to the equipment, ensuring continuous operation of the information system.
5. There must be an air conditioning system to ensure continuous operation.
6. There must be a direct lightning protection and surge suppression system.
7. There must be an automatic fire detection and extinguishing system. The fire extinguishing system must ensure that it does not damage the installed equipment, except in cases where the organization has a backup system that ensures absolute data safety and can completely replace the main system within one hour.
8. There must be a technical floor or isolation layer to prevent electrical interference; a grounding system.
9. There must be a surveillance camera system with data storage for at least 90 days.
10. There must be a temperature and humidity monitoring and control system.
11. There must be a logbook for controlling entry and exit to the data center.
Article 19. Physical Asset Safety
1. Physical assets must be arranged and installed at safe locations and protected to minimize risks from environmental threats and unauthorized intrusions.
2. Physical assets belonging to information systems at level 3 or higher must be secured with power supply and support systems when the main power source is interrupted. Measures against overloading or voltage drops, lightning surge protection, grounding systems, backup generator systems, and uninterruptible power supply systems ensuring continuous operation of equipment must be implemented.
3. Power cables and communication cables used for data transmission or supporting information services must be protected from intrusion or damage.
4. Equipment used for business operations installed outside the organization's workplace must have monitoring and safety protection measures to prevent illegal access.
Section 4
MANAGEMENT AND INFORMATION EXCHANGE
Article 20. Management Responsibility and Operation Procedures of Organizations
1. Organizations shall issue operational procedures and documents for information systems at level 3 or higher, including at least the following contents: system startup and shutdown procedures; data backup and recovery procedures; application operation procedures; incident handling procedures; system monitoring and activity logging procedures. The scope and responsibilities of users and system operators must be clearly defined. At least once a year, organizations shall review, update, and supplement operational procedures for information systems to ensure they are up-to-date with current conditions.
2. Organizations shall implement these procedures to all participants involved in operation and supervision to ensure compliance with issued procedures.
3. The operating environment of information systems at level 3 or higher and those processing personal customer information must meet the following requirements:
a) Separation from development, testing, and trial environments;
b) Application of security measures;
c) No installation of application development tools;
d) Removal or deactivation of unused features and software utilities on the information system.
4. For information systems processing customer transactions, the following requirements must be met:
a) A single individual should not simultaneously perform both initiation and approval of a transaction;
b) Multi-factor authentication must be applied at the final approval stage when conducting financial transactions involving inter-bank electronic fund transfers of 100 million VND or more (except for end-to-end payment systems that already have automatic transaction verification between interconnected systems);
c) Measures to ensure the integrity of transaction data must be applied;
d) All actions on the system must be logged and available for inspection and control when necessary.
Article 21. Planning and Acceptance of Information Systems
1. Organizations shall establish standards, norms, and technical requirements to ensure normal operation for all existing information systems and other information systems before officially implementing them.
2. Based on established standards, norms, and technical requirements, organizations shall monitor and optimize the performance of information systems; assess their capacity, operational status, and configuration to forecast and plan for expansion and upgrades to ensure future capacity.
3. Organizations shall review and update standards, norms, and technical requirements when changes occur in information systems; conduct training and transfer technical knowledge related to changes to relevant personnel.
Article 22. Backup and Data Recovery
Organizations shall implement backup and data recovery to ensure data security as follows:
1. Compile a list of information systems at different levels of importance that require backup, including storage time, regular backup schedule, backup methods, and system recovery testing time from backup data.
2. Data from information systems at level 3 and above must have an automatic backup plan suitable for the frequency of data changes and ensuring that newly generated data must be backed up within 24 hours; other information systems shall perform periodic backups according to the organization's regulations.
3. Backup data from information systems at level 3 and above must be stored on external storage media (such as magnetic tape, hard disk, optical disc, or other storage media) and securely kept separate from the installation area of the source information system immediately following the next working day after completing the backup process.
4. Regularly check and recover data from external storage media at least once every:
a) Year for information systems at level 3 and above;
b) Two years for other systems.
Article 23. Network Security Management
Organizations shall implement network security management as follows:
1. Develop regulations on network security management and terminal device management throughout the entire network system.
2. Create and store records about the logical and physical diagrams of the network system, including wide area networks (WAN/Intranet) and local area networks (LAN).
3. Build the organization's network system to meet the minimum requirements as follows:
a) Divide into different network zones based on user objects, usage purposes, and information systems, at a minimum: (i) A dedicated network zone for application servers and databases of information systems at level 3 and above; (ii) An intermediate network zone (DMZ) to provide services on the Internet; (iii) A dedicated network zone to provide wireless network services;
b) Have firewall devices to control connections and access to important network zones;
c) Have firewall devices with intrusion detection functions to control connections and access from untrusted networks to the organization's network system;
d) Have solutions to control, detect, and promptly prevent unauthorized connections and access to the organization's internal network with information systems at level 3 and above;
đ) Have load balancing plans and denial-of-service attack response plans for information systems at level 3 and above providing services on the Internet.
4. Set up and configure security features according to the design of network equipment; implement measures and solutions to detect technical weaknesses and vulnerabilities of the network system; regularly check and detect illegal connections, equipment, and software installations on the network.
Article 24. Information Exchange
When exchanging information with customers and third parties, organizations have the responsibility to:
1. Issue regulations on minimum information exchange including: types of information exchanged; rights and responsibilities of individuals when accessing information; means of information exchange; measures to ensure the integrity and confidentiality of information during transmission, processing, and storage; information retention policies.
2. When exchanging personal information, internal information, and confidential information with external parties, organizations must have written agreements defining the responsibilities and obligations of all participating parties regarding the use and security of the information.
3. Confidential information must be encrypted or apply information security measures before being exchanged. For information systems at level 5, organizations must use secure network connections and specialized devices and means to encrypt and decrypt confidential information and when exchanging information.
4. Implement protective measures for equipment and software serving information exchange to limit illegal intrusion and exploitation.
5. Implement strict management, monitoring, and control measures for online information provision, service, and transaction websites provided to customers.
1. The information system providing online services to customers must comply with the standard TCVN 11930:2017 (Information Technology - Security Techniques - Basic Requirements for Information System Security at Levels) and the following requirements:
a) Ensuring the integrity of data exchanged with customers in online transactions;
b) Data on transmission lines must ensure confidentiality and must be transmitted fully, correctly addressed, and have measures to protect against unauthorized changes or copying;
c) Assessing the risk level in online transactions based on customer type, transaction type, transaction limit to provide appropriate transaction authentication solutions as prescribed by the State Bank;
d) The electronic transaction information page must apply measures to authenticate and prevent counterfeiting and unauthorized modification.
2. The online transaction service system must apply measures to closely monitor and detect and warn about:
a) Suspicious transactions based on minimum criteria including: transaction time, transaction location (geographical position, IP address), transaction frequency, transaction amount, number of incorrect authentication attempts;
b) Abnormal activities of the system;
c) Denial of Service (DoS) attacks and Distributed Denial of Service (DDoS) attacks.
3. Organizations shall guide customers on measures to ensure information security and warn of risks before participating in using online transaction services and periodically thereafter.
4. When providing online transaction application software on the Internet, organizations must apply measures to ensure the integrity of the software.
Article 26. Supervision and Logging of System Information Activities
Organizations shall implement supervision and logging of system information activities from Level 2 and above as follows:
1. Recording and storing logs regarding system information activities and users, errors generated, and information security incidents if supported, at a minimum including:
a) Network connection information (firewall log);
b) Login information;
c) Configuration change information;
d) Important data and service access information (if applicable);
đ) Error information generated during operation;
e) Warning information from devices;
g) Device performance information (for systems from Level 3 and above).
2. Logs of Level 2 information systems must be stored online for a minimum of one month and backed up for a minimum of six months. Logs of information systems from Level 3 and above must be stored online for a minimum of three months in a centralized manner and backed up for a minimum of one year.
3. There must be a monitoring and warning plan when there is a change in confidential information stored on storage systems/media of information systems from Level 4 and above.
4. Protect logging functions and logging information from counterfeiting, alteration, and unauthorized access; ensure that system administrators and users cannot delete or modify logs recording their own activities.
5. Synchronize time between information systems.
Article 27. Prevention of Malware
Organizations shall establish and implement regulations on preventing malware as follows:
1. Determine the responsibilities of individuals and relevant departments in the work of preventing malware.
2. Implement measures and solutions to prevent malware for the entire information system of the organization.
3. Regularly update samples of malware and new anti-malware software: set up automatic updates or scheduled daily updates.
4. Check and remove malware from data carriers before use.
5. Control software installation to ensure compliance with the organization's information security regulations.
6. Control unknown emails, attached files, or links in unknown emails.
Section 5
ACCESS MANAGEMENT
Article 28. Requirements for Access Control
1. The organization shall establish regulations on access management for users, user groups, devices, and tools used to access the information system, ensuring business requirements and information security requirements, including the following basic contents:
a) Registration, issuance, extension, and revocation of user access rights;
b) Each system access account must be assigned to a single user; in cases where shared accounts are used to access the information system, they must be approved by the competent authority and individual responsibility must be determined at each point of use;
c) For accounts for applications and services that connect automatically, they must be assigned to an individual manager and their access rights limited according to the purpose of use; the individual manager may not use the account for other purposes;
d) For information systems at level 3 and above and those processing customer personal information, access using administrative accounts must be limited and controlled: (i) Establish a mechanism to control the creation of administrative accounts to ensure that no account can be used without approval from the competent authority; (ii) There must be measures to monitor the use of administrative accounts; (iii) The use of administrative accounts must be limited to the time necessary to perform tasks and must be revoked immediately upon completion of the task; (iv) Administrative system connections must go through intermediary servers or centralized management systems, not directly from the administrator's workstation;
đ) Management and issuance of secret access codes for information systems;
e) Review, inspect, and re-examine user access rights;
g) Security requirements for devices and tools used for access.
2. The organization shall establish regulations on managing secret access codes meeting the following requirements:
a) Secret codes must be at least six characters long, consisting of numbers, uppercase letters, lowercase letters, and special characters if allowed by the system; valid secret code requirements must be automatically checked when setting the secret code;
b) Default secret codes set by manufacturers on equipment and software must be changed before use;
c) Secret code management software must have the following functions: (i) Require changing the secret code on first login (not applicable to one-time secret codes); (ii) Notify users to change the secret code before its expiration; (iii) Invalidate expired secret codes; (iv) Invalidate secret codes when the number of incorrect entries exceeds the permitted limit; (v) Allow immediate change of exposed or potentially exposed secret codes or at the user's request; (vi) Prevent the reuse of old secret codes within a certain period.
3. The organization shall establish regulations on the responsibilities of users when granted access rights, including the following contents: using secret codes in accordance with regulations; keeping secret codes confidential; using devices and tools for access; logging out of the system when not working or temporarily not working on the system.
Article 29. Management of Access to Internal Networks
Organizations shall establish and implement access management policies for internal networks that meet the following requirements:
1. Establish and implement regulations on network access and network services including the following basic contents:
a) Permitted networks and network services, methods, means, and information security conditions for access;
b) Responsibilities of administrators and users;
c) Procedures for issuing, changing, and revoking connection rights;
d) Control over administration, access, and use of networks.
2. Implement strict control measures for connections from untrusted networks to the organization's internal network to ensure information security.
3. Control the installation and use of software tools supporting remote access.
4. Control access to ports used for configuring and managing network devices.
5. Granting network and service access rights must ensure the principle of sufficient privileges necessary to perform assigned tasks.
6. Connections from the Internet to the organization's internal network for work purposes must use virtual private networks and multi-factor authentication.
Article 30. Management of Access to Information Systems and Applications
Organizations shall establish and implement access management meeting the following requirements:
1. Control utility software that can affect information systems.
2. Specify access times to applications corresponding to business and service operation times. Automatically disconnect user sessions after a period of inactivity to prevent unauthorized access.
3. Manage and grant access permissions to information and applications ensuring the principle of sufficient privileges necessary for users to perform assigned tasks:
a) Grant access permissions to individual directories and program functions;
b) Grant read, write, delete, and execute permissions for information, data, and programs.
4. Information systems using shared resources must be approved by authorized authorities.
5. For servers belonging to information systems at level 3 or higher and information systems processing customer personal information must use secure connection protocols and have anti-automatic login solutions.
6. For information systems at level 4 or higher, multi-factor authentication must be applied when accessing administrative controls of servers, applications, and important network security devices.
Article 31. Management of Internet Connections
Organizations shall establish and implement Internet connection management meeting the following requirements:
1. Regulations on Internet connection and access management include the following basic contents:
a) Individual and departmental responsibilities in the exploitation and use of the Internet;
b) Authorized persons and entities permitted to connect and access the Internet;
c) Prohibited and restricted actions;
d) Control over Internet connections and access;
e) Measures to ensure information security when connecting to the Internet.
2. Centralize and unify the management of Internet connection ports throughout the organization.
3. Deploy cybersecurity solutions at Internet connection ports to protect against Internet-based attacks on the organization's internal network.
4. Use tools to detect and promptly identify vulnerabilities, weaknesses, and illegal attacks and accesses to the organization's internal network through Internet connection ports.
Chapter 6
MANAGEMENT OF THIRD-PARTY INFORMATION TECHNOLOGY SERVICES USE
Article 32. General Principles for Using Third-Party Services
When using third-party information technology services, organizations must ensure the following principles:
1. Not to reduce the organization's ability to continuously provide services to customers.
2. Not to reduce the organization's control over business processes.
3. Not to change the organization's responsibility for ensuring information security.
4. Third-party information technology services must comply with the organization's regulations on ensuring information security.
Article 33. Requirements for Using Third-Party Services
Before using third-party services deployed for information systems at level 3 or higher and those processing customer personal information, organizations shall perform the following:
1. Conduct a minimum risk assessment for information technology and operational risks, including the following contents:
a) Identifying risks, analyzing, estimating the level of damage, threats to information security;
b) The ability to control business processes, the ability to provide continuous service, the ability to fulfill obligations to provide information to state agencies;
c) Clearly defining the roles and responsibilities of all parties involved in ensuring service quality;
d) Developing measures to minimize risks, preventive measures, emergency response, and remediation;
đ) Reviewing and adjusting risk management policies (if applicable).
2. In cases where cloud computing services are used, in addition to the requirements under Clause 1 of this Article, organizations shall perform the following:
a) Classify activities and operations planned to be implemented on cloud computing based on the impact assessment of such activities and operations on the organization's operations;
b) Develop contingency plans for components of information systems at level 3 or higher. Contingency plans must be tested and evaluated to be ready to replace the activities and operations implemented on cloud computing;
c) Develop criteria for selecting third parties that meet the requirements stipulated in Article 34 of this Circular;
d) Review, supplement, and apply the organization's information security assurance measures, limiting access from cloud computing to the organization's information systems.
3. In cases where third parties are hired to perform the entire system management work for information systems at level 3 or higher and those processing customer information, organizations shall conduct risk assessments according to the provisions of Clause 1 of this Article and submit the risk assessment report to the State Bank (Information Technology Department).
Article 34. Criteria for Selecting Third Parties Providing Cloud Computing Services
Selection criteria include the following minimum contents:
1. The third party must be a business enterprise.
2. Have corresponding information technology infrastructure for the services used by the organization, meeting the following requirements:
a) Legal regulations of Vietnam;
b) Possess valid international certification regarding information security assurance.
Article 35. Service Usage Contracts with Third Parties
Service usage contracts signed with third parties deploying for information systems at level 3 or higher and those processing customer personal information must include at least the following contents:
1. The third party's commitment to ensuring information security includes:
a) Not copying, altering, using, or providing the organization's data to other individuals or organizations, except when required by authorized state agencies according to the law; in such cases, the third party must notify the organization before providing the data, unless notification would violate Vietnamese law;
b) Disseminating to third-party personnel participating in the contract the organization's regulations on ensuring information security, implementing monitoring measures to ensure compliance.
2. Specific maximum downtime periods for service interruptions and fault resolution times, related requirements for ensuring continuous operation (on-site backup, data backup, disaster recovery), related requirements for processing capacity, computing, storage, measures to implement when service quality is not assured.
3. In cases where the third party uses subcontractors, it does not change the third party's responsibility for the services used by the organization.
4. Data generated during the use of services is the property of the organization. Upon termination of service use:
a) The third party must return or assist in transferring all deployed data and data generated during service use back to the organization;
b) The third party commits to completing the deletion of all the organization's data within a specified period.
5. The third party must notify the organization when discovering personnel violating information security regulations for the services used by the organization.
6. Cloud computing service usage contracts, in addition to the contents stipulated in Clauses 1, 2, 3, 4, and 5 of this Article, must also include the following additional contents:
a) The third party must provide annual independent audit reports on compliance with information technology standards during the contract period;
b) The third party must provide: cloud service quality control tools; monitoring and controlling cloud service quality procedures;
c) The third party must disclose locations (city, country) of data centers outside Vietnam's territory deploying services for the organization;
d) Responsibility for protecting data and preventing unauthorized access to data through service distribution channels from the third party to the organization;
đ) The third party must support and cooperate in investigations upon requests from authorized Vietnamese state agencies according to the law;
e) The organization's data must be separated from other customers' data using the same technical platform provided by the third party.
Article 36. Responsibilities of organizations during the use of third-party services
When using third-party services, organizations shall have the following responsibilities:
1. Provide, notify, and request third parties to comply with the organization's information security regulations.
2. Have procedures and allocate resources to monitor and control third-party provided services to ensure service quality as agreed in the signed contracts. For cloud computing services, monitoring and controlling service quality is required.
3. Apply the organization's information security regulations to equipment and services provided by third parties that are deployed on infrastructure managed and used by the organization.
4. Manage changes to third-party provided services including: changing providers, changing solutions, changing versions, and changes stipulated in Point 41 of this Circular; conduct a comprehensive impact assessment of such changes and ensure safety before implementation.
5. Implement strict monitoring measures and limit third-party access rights when granting third-party access to the organization's information systems.
6. Supervise third-party personnel during contract execution. In case of discovering violations of information security regulations by third-party personnel, the organization must report and cooperate with the third party to promptly apply appropriate measures.
7. Revoke third-party access rights to the information system granted upon completion of work or termination of the contract, and change passwords and secret keys handed over from the third party immediately thereafter.
8. For information systems at level 3 or higher, customer information processing systems, or information systems using cloud computing services, the organization must evaluate third-party compliance with information security regulations according to the signed agreements. Such evaluations should be conducted annually or ad hoc as needed. Compliance assessments may utilize independent audit firm’s IT audit results.
Section 7
MANAGEMENT OF INFORMATION SYSTEM ACCEPTANCE, DEVELOPMENT, AND MAINTENANCE
Article 37. Requirements for Safety and Security of Information Systems
When establishing or upgrading information systems directly managed by the organization, the organization must classify these systems according to levels specified in Article 5 of this Circular. For information systems at level 2 or higher, the organization shall implement:
1. Develop design documentation describing information system security assurance plans. Security and confidentiality requirements must be developed concurrently with technical and operational requirements.
2. Develop inspection and verification plans for deployed systems to ensure compliance with design documentation and information security requirements prior to acceptance. Inspection results must be reported and approved by authorized authorities before official operation.
3. Strictly monitor and manage the procurement of external software according to Article 36 of this Circular.
Article 38. Ensuring Application Safety and Security
Business application programs must meet the following minimum requirements:
1. Verify the validity of data input into applications, ensuring accurate and valid data entry.
2. Verify the validity of automatically processed data within applications to detect discrepancies caused by processing errors or intentional information modifications.
3. Implement measures to ensure data authenticity and integrity processed within applications.
4. Verify the validity of data output from applications, ensuring accurate and valid information processing by applications.
5. User secret keys in information systems at level 2 or higher must be encrypted at the application layer.
Article 39. Management of Encryption Codes
The management of encryption codes shall be carried out as follows:
1. To establish and put into use encryption measures according to national technical standards for data encryption used in the banking sector or internationally recognized standards.
2. To have measures to manage encryption keys to protect information of the organization.
Article 40. Safety and Security during Software Development Processes
1. The organization shall manage the software development process as follows:
a) Manage and control source code. Access to and contact with the source code must be approved by the competent authority;
b) Manage and protect system configuration files;
c) Require third parties to provide source code for outsourced software for information systems at level 2 or higher.
2. The organization must select and control test and trial data. Real data from officially operating information systems should not be used for testing activities until measures to conceal or change customer information and confidential information have been implemented.
Article 41. Management of Information System Changes
The organization shall issue procedures and measures for managing and controlling changes to information systems, including at least the following:
1. Record changes; plan changes; conduct testing and trials of changes, report results; approve the change plan before officially applying software version changes, hardware configuration parameters, system software parameter settings, operational processes. Have contingency plans for system recovery in case of unsuccessful changes or unforeseen incidents.
2. Evaluate the impact of changes to ensure that information systems operate stably and safely on new environments for information systems at level 3 or higher when changing versions or operating systems, database management systems, middleware software.
Article 42. Inspection and Evaluation of Information Security
1. The content of inspection and evaluation of information security must include at least the following:
a) Inspect compliance with legal regulations on ensuring information system security according to levels;
b) Evaluate the effectiveness of information system security measures;
c) Evaluate and detect malware, vulnerabilities, technical weaknesses as stipulated in Article 43 of this Circular;
d) Conduct penetration tests (Penetration Test) which must be mandatory for information systems connected to and providing services on the Internet, connecting to customers and third parties;
e) Inspect the configuration of security devices, automatic access control systems, terminal management systems, account lists.
2. The organization shall inspect and evaluate information security for information systems at level 3 or higher and information systems processing personal customer information according to the contents specified in Clause 1 of this Article before officially putting them into operation.
3. During the operation of information systems, the organization shall inspect and evaluate information security according to the provisions of Clause 1 of this Article periodically as follows:
a) Once every six months for level 5 information systems;
b) Once a year for level 4 and level 3 information systems and equipment directly communicating with external environments such as the Internet and connections with third parties;
c) Every two years to conduct comprehensive inspections and evaluations of information security and manage information security risks in organizational operations.
4. The evaluation results must be documented in a report submitted to the legitimate representative and the competent authority. For non-compliant contents regarding information security (if any), proposals for measures, plans, deadlines for handling and rectification must be made.
Article 43. Management of Technical Weaknesses
The management of technical weaknesses shall be carried out as follows:
1. Establish regulations on the assessment, management, and control of technical weaknesses in operational information systems.
2. Regularly update information related to vulnerabilities and technical weaknesses.
3. Conduct periodic vulnerability scans of operational information systems according to the provisions of Clause 3, Article 42, or upon receipt of new vulnerability-related information.
4. Evaluate the impact level and risk of each discovered technical weakness in operational information systems and develop plans for handling them.
5. Develop and implement solutions for addressing and resolving technical weaknesses, and report on the results of such actions.
Article 44. Management of Information System Maintenance
The management of information system maintenance shall be carried out as follows:
1. Issue maintenance regulations immediately after the official operation begins. Minimum maintenance regulations must include the following contents:
a) Scope and objects subject to maintenance;
b) Timing and frequency of maintenance;
c) Technical procedures and scripts for performing maintenance on individual components and the entire information system;
d) Report to the competent authority if any issues arise during maintenance;
đ) Assign responsibilities for the maintenance team and supervisory personnel.
2. Implement maintenance according to the provisions of Clause 1 of this Article for information systems directly managed by the organization.
3. Review minimum maintenance regulations at least once a year or when there are changes in the information system.
Section 8
INFORMATION SECURITY INCIDENT MANAGEMENT
Article 45. Incident Handling Procedures
The management of incidents shall be carried out as follows:
1. Issue incident handling procedures for information security that include the following minimum contents:
a) Receiving information about incidents occurring;
b) Assessing the level and scope of impact of the incident on the operation of the information system. Depending on the level and scope of impact, report to corresponding management levels for guidance on handling;
c) Implement measures to handle and resolve the incident;
d) Record the file and report the results of incident handling.
2. Define the responsibility of individuals and groups in reporting, receiving, and handling information security incidents.
3. Develop templates for recording and storing incident handling files.
Article 46. Control and Resolution of Incidents
The control and resolution of incidents shall be carried out as follows:
1. List information security incidents and response plans for information systems at Level 3 and above and those processing customer personal data; review and update the list and response plans at least every six months.
2. Immediately report to the competent authority and relevant parties when an information security incident occurs to take corrective measures as soon as possible.
3. During the inspection, handling, and resolution of incidents, collect, record, protect evidence, and store it within the organization.
4. Determine the cause and implement preventive measures to avoid recurrence of incidents after resolution.
5. In cases where information security incidents involve violations of laws, the organization has the responsibility to collect and provide evidence to the competent authorities in accordance with the law.
6. Annually organize drills for handling plans to ensure information security for at least one of the information systems at Level 3 and above, and rotate if there are two or more such systems.
Article 47. Cybersecurity Operations Center
1. Organizations directly managing information systems at level 3 or higher must establish or designate a specialized department to manage and operate the Cybersecurity Operations Center (this does not apply to foreign bank branches, service providers for intermediary payment services, non-bank credit institutions, microfinance organizations, grassroots people's credit funds, credit information companies, Vietnam Asset Management Company, National Banknote Printing Works).
2. The Cybersecurity Operations Center shall perform the following tasks:
a) Proactively monitor, collect, and receive information and warnings about security risks and threats from both internal and external sources.
b) Establish a system for managing and analyzing security events (SIEM), implement centralized collection and storage of at least the following information: logs of information systems at level 3 or higher and information systems processing customer personal data; warnings and logs of cybersecurity equipment (firewalls, IPS/IDS).
c) Analyze information to detect and warn about security risks and cyber attack threats, and must send warnings to system administrators when incidents related to information systems at level 3 or higher and information systems processing customer personal data are detected.
d) Organize incident response coordination, containment, prevention, and mitigation of impacts and damages to information systems when incidents occur.
đ) Investigate, determine the origin, method, and approach of attacks, and implement preventive measures to avoid recurrence of incidents.
e) Provide information upon request of the State Bank of Vietnam to support cyber surveillance in the banking sector.
Article 48. Incident Response Activities for Information Security
1. The incident response network in the banking sector (the network) includes:
a) The network management board established by the Governor of the State Bank of Vietnam;
b) The coordinating agency is the Department of Information Technology (State Bank of Vietnam);
c) Network members: the Department of Information Technology (State Bank of Vietnam), credit institutions (specialized departments for information security), and voluntary participants in the network are agencies and organizations voluntarily joining.
2. The network has the task of coordinating resources within and outside the sector to effectively respond to information security incidents, contributing to ensuring the safe operation of the banking system.
3. Principles in the operation and incident response activities
a) The network management board is responsible for: (i) Approving the strategy and annual operational plan of the network; (ii) Managing the network operations (incident response, drills and training, incident response training); (iii) Evaluating the network's performance and reporting annually to the Governor of the State Bank of Vietnam;
b) Organizations as stipulated in point c, Clause 2 of this Article must have the responsibility to provide resources and participate as network members;
c) When encountering information security incidents, members must report to the coordinating agency according to Clause 1, Article 54 of this Circular;
d) When encountering serious incidents that cannot be resolved independently, members must submit assistance requests to the coordinating agency;
đ) Based on each incident, the coordinating agency will report to the network management board and request support or rescue from network members or competent state agencies.
4. Principles for managing and using information in incident response activities:
a) Information exchanged and provided during the coordination and incident response process is confidential information;
b) It is strictly prohibited for organizations and individuals to use information exchanged during the coordination and incident response process to affect the reputation and image of the information provider.
Section 9
ENSURING CONTINUOUS OPERATION OF INFORMATION SYSTEMS
Article 49. Principles for Ensuring Continuous Operation
1. Organizations shall implement the following minimum requirements:
a) Analyze impacts and assess risks related to interruptions or cessation of information system operations;
b) Develop procedures and scenarios for ensuring continuous operation of information systems in accordance with Article 51 of this Circular;
c) Organize the implementation of continuous operation assurance in accordance with Article 52 of this Circular.
2. Based on the impact analysis and risk assessment under point a, Clause 1 of this Article, organizations shall establish a list of information systems that need to ensure minimum continuous operation, including information systems at level 3 and above.
3. Information systems required to ensure continuous operation under Clause 2 of this Article must ensure high availability and have disaster recovery systems.
Article 50. Building Disaster Recovery Systems
1. Organizations shall build disaster recovery systems meeting the following requirements:
a) Assess risks and consider the possibility of disasters affecting both the main information system and the disaster recovery information system simultaneously when selecting the location for the disaster recovery system: natural disasters such as earthquakes, floods, typhoons, pandemics; human and technological factors such as power grid failures, fires, traffic accidents, cyber security attacks;
b) The location for the disaster recovery system must meet the requirements stipulated in Article 17 of this Circular;
c) The disaster recovery system must ensure the ability to replace the main system within the following timeframes: (i) 4 hours for information systems at level 3 and above (excluding state secret information processing systems); (ii) 24 hours for state secret information processing systems; (iii) In accordance with the organization's regulations for other systems.
2. Organizations having only one office in Vietnam (except microfinance organizations and grassroots credit funds) must have a backup office at a separate location from their main office and equipped to ensure continuous operation as a replacement for the main office.
Article 51. Developing Procedures and Scenarios for Ensuring Continuous Operation
Organizations shall develop procedures and scenarios for ensuring continuous operation as follows:
1. Develop procedures for handling situations involving loss of security and interruptions in the operation of each component in information systems at level 3 and above.
2. For organizations with both main and backup systems located outside Vietnam, they must develop contingency plans for ensuring continuous operation in case of disruptions in connection with the main and backup systems.
3. Develop scenarios for switching to the backup system to replace the main system's operations, including content, sequence of execution, and estimated completion time, meeting the following requirements:
a) Having necessary resources, means, and requirements to carry out the tasks;
b) Having templates to record results;
c) Assigning responsibilities to personnel involved in roles such as directing, supervising, performing the switch, operating officially, and checking results;
d) Applying measures to ensure information security;
e) Having contingency plans for ensuring continuous operation if the switch is not successful.
4. Organizations having only one office in Vietnam (except microfinance organizations and grassroots credit funds) must develop scenarios for switching operations to the backup office.
5. Procedures and scenarios for switching must be tested and updated when there are changes in the information system, organizational structure, personnel, and division of responsibilities among relevant departments within the organization.
Article 52. Organization of Continuous Operation Assurance
1. Organizations must have plans and organize to ensure continuous operation of information systems (excluding primary and backup information systems operating concurrently) according to the following requirements:
a) At least once every six months, conduct inspections and evaluations of the backup system's operations;
b) Implement switching activities from the primary system to the backup system and operate officially on the backup system for at least one working day of each information system listed in Clause 2, Article 49 of this Circular, once a year for information systems at level 4 and above, and once every two years for information systems at level 3 and below; evaluate results and update procedures and transition scenarios (if any). In cases where it is not possible to switch operations within a working day, the backup system must be set up with the same capacity and configuration as the primary system and annual switching and testing of the backup system's readiness must be conducted.
2. Organizations that have only one office in Vietnam (except microfinance organizations and grassroots credit funds) must organize regular annual exercises to ensure continuous operation.
3. Organizations must notify the State Bank of Vietnam (Information Technology Department) of their exercise plan, content, and transition scenario scripts at least five working days before implementation via the email address [email protected].
Section 10
INTERNAL AUDIT AND REPORTING REGIME
Article 53. Internal Audit
Organizations shall implement internal audit as follows:
1. Establish internal audit regulations regarding information security work of the organization.
2. Annually, develop plans and carry out self-inspection of compliance with provisions of this Circular and internal regulations of the organization concerning information security. For commercial banks and foreign bank branches, internal audits must be conducted by risk management departments or compliance departments at least once a year, and by internal audit departments or independent auditing organizations at least once every three years.
3. The results of the audit on information security work of the organization must be compiled into reports sent to the legal representative and competent authority, including solutions and implementation plans for issues that remain unresolved and do not comply with information security regulations (if any).
4. Organizations must implement and report on the resolution of issues mentioned in the report as stipulated in Clause 3 of this Article.
Article 54. Reporting Regime
Organizations are responsible for submitting reports to the State Bank of Vietnam (Information Technology Department) on the following contents:
1. Information security incident reports (as per Appendix 01 attached to this Circular) within 24 hours from the time the incident is discovered and Incident Resolution Completion Reports (as per Appendix 02 attached to this Circular) within five working days after the incident has been resolved. Reports should be sent to the email address [email protected].
2. Risk assessment reports as prescribed in Clause 3, Article 33 of this Circular directly or through postal service to the State Bank of Vietnam (Information Technology Department) at least ten working days prior to outsourcing all system management work at level 3 and above and customer information processing systems.
3. Reports on disciplinary actions taken against individuals working in the organization’s information technology field as prescribed in Clause 6, Article 16 of this Circular directly or through postal service to the State Bank of Vietnam (Information Technology Department) within five working days from the date of the disciplinary decision.
Chapter III
IMPLEMENTING PROVISIONS
Article 55. Responsibilities of Units under the State Bank
1. The Information Technology Department shall be responsible for:
a) Monitoring and compiling annual reports to the Governor of the State Bank on the implementation status of organizations as stipulated in this Circular;
b) Preparing an annual plan to inspect the implementation of this Circular;
c) Taking the lead and coordinating with relevant units under the State Bank to resolve issues arising during the implementation of this Circular.
2. The Payment Department shall be responsible for coordinating with the Information Technology Department to inspect the implementation of this Circular at organizations providing intermediary payment services.
3. Banking Inspection and Supervision Authorities shall be responsible for inspecting the implementation of this Circular at organizations and handling administrative violations according to the provisions of the law for acts violating this Circular.
4. Branches of the State Bank in provinces and cities shall be responsible for inspecting the implementation of this Circular at organizations within their jurisdiction and handling administrative violations according to the provisions of the law for acts violating this Circular.
Article 56. Effective Date
1. This Circular shall take effect from January 1, 2021, except as provided in Clause 2 of this Article, and shall replace Circular No. 18/2018/TT-NHNN dated August 21, 2018, issued by the Governor of the State Bank regarding regulations on information system security in banking operations.
2. Point b of Clause 4 of Article 20 shall take effect from January 1, 2022.
Article 57. Organization and Implementation
The Director of the Information Technology Department, Heads of relevant units under the State Bank, Governors of State Bank branches in centrally governed provinces and cities, credit institutions, foreign bank branches, organizations providing intermediary payment services, credit information companies, Vietnam National Payment Corporation, Vietnam Asset Management Company Limited, National Currency Printing Factory, Deposit Insurance of Vietnam shall be responsible for organizing the implementation of this Circular./.
DEPUTY DIRECTOR
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。