This Circular amends and supplements certain provisions of Circular No. 28/2015/TT-NHNN on the issuance, management, and use of digital certificates in the banking system. The main contents include: Amending regulations on new application registration files, information changes, suspension, revocation, or cancellation of digital certificate transactions; supplementing the responsibilities of managing organizations and users; adjusting reporting systems; replacing forms.
적용 범위
Heads of units under the State Bank of Vietnam, credit institutions, foreign bank branches, the National Treasury of Vietnam, the Deposit Insurance Corporation of Vietnam, the National Payment Corporation of Vietnam, and the Asset Management Corporation of Credit Institutions of Vietnam.
핵심 사항
- Amending regulations on new application registration files, information changes, suspension, revocation, or cancellation of digital certificate transactions.
- Supplementing the responsibilities of managing organizations and users.
- Adjusting reporting systems.
- Replacing old forms with new annexes.
- This Circular takes effect from July 1, 2024.
🌐 이 문서의 사회적 영향
- Enhancing the safe and effective management and use of digital certificates in the banking system.
- Reducing risks related to information security in electronic transactions of financial organizations.
- Ensuring transparency and compliance with laws in the issuance, management, and use of digital certificates.
❓ 자주 묻는 질문
Which Circular does this Circular replace?
This Circular replaces Circular No. 10/2020/TT-NHNN dated November 2, 2020 of the Governor of the State Bank of Vietnam amending and supplementing certain provisions of Circular No. 28/2015/TT-NHNN.
When does this Circular take effect?
This Circular takes effect from July 1, 2024.
전문
CIRCULAR
Amending and supplementing certain articles of Circular No. 28/2015/TT-NHNN dated December 18, 2015 of the Governor of the State Bank of Vietnam on the management and use of digital signatures, certificates, and digital signature certification services of the State Bank of Vietnam
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010 and the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No. 130/2018/NĐ-CP dated September 27, 2018 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;
Decree No. "4. The purchase and sale of corporate bonds between credit institutions under special control and supporting credit institutions, and the mandatory transferor shall implement according to the restructuring plan of credit institutions under special control approved by the competent authority."
At the proposal of the Director of the Department of Information Technology; information;
The Governor of the State Bank of Vietnam hereby issues this Circular amending and supplementing certain articles of Circular No. 28/2015/TT-NHNN dated December 18, 2015 of the Governor of the State Bank of Vietnam on the management and use of digital signatures, certificates, and digital signature certification services of the State Bank of Vietnam (hereinafter referred to as Circular 28/2015/TT-NHNN).
Article 1. Amending and supplementing certain articles of Circular 28/2015/TT-NHNN
1. Amending and supplementing Article 1 of Circular 28/2015/TT-NHNN (which has been amended and supplemented by Clause 1, Article 1 of Circular No. 10/2020/TT-NHNN dated November 2, 2020 of the Governor of the State Bank of Vietnam amending and supplementing certain articles of Circular 28/2015/TT-NHNN (Circular 10/2020/TT-NHNN)) as follows:
"This Circular stipulates the management and use of digital signatures, certificates, and specialized digital signature certification services of the State Bank of Vietnam (hereinafter referred to as the State Bank)."
2. Amending and supplementing Clause 1, Article 2 of Circular 28/2015/TT-NHNN (which has been amended and supplemented by Clause 2, Article 1 of Circular 10/2020/TT-NHNN) as follows:
"1. Units under the State Bank; credit organizations; foreign bank branches; the National Treasury of Vietnam; the Deposit Insurance Corporation of Vietnam."
3. Amending and supplementing Clause 5, Clause 11, Clause 12, Clause 13, Clause 14, and Clause 15 of Article 3 of Circular 28/2015/TT-NHNN (which has been amended and supplemented by Clause 3, Article 1 of Circular 10/2020/TT-NHNN) as follows:
"5. "Certificate management organization" means units under the State Bank, credit organizations, foreign bank branches, the National Treasury of Vietnam, the Deposit Insurance Corporation of Vietnam, or other organizations requesting issuance of certificates for their subscribers.
"11. "Activation code" is information provided to the subscriber including reference number and authentication code used to authenticate during the activation process of the certificate.
12. "Certificate activation" is the process of generating a certificate key pair including private key, public key, and storing them in the subscriber's secret key storage device.
13. "Authorized person" is the leadership of the State Bank, the leadership of units under the State Bank, or the legal representative of agencies and organizations specified in Article 2 of this Circular.
14. "Public service system" is the electronic portal providing online public services of the State Bank.
15. "Certificate transaction" is a transaction on information systems where the subscriber can use a certificate to approve or verify. A certificate may be used to approve or verify one or more transactions on one or more information systems. Information systems using State Bank certificates include:
a) Public service system;
b) Inter-bank electronic payment system;
c) State Bank reporting system;
d) Bidding and open market operations system including sub-systems: - Bidding and open market operations; - Issuance, payment, extension, and cancellation of special bonds; - Issuance of State Bank bills; - Capital replenishment.
đ) Deposit Insurance Corporation of Vietnam reporting system;
e) Other systems as decided by the Governor of the State Bank."
4. Amending and supplementing Article 4 of Circular 28/2015/TT-NHNN as follows:
Article 4. Contents of the digital certificate
1. The name of the organization providing digital signature services.
2. Name of the subscriber.
3. Serial Number of the digital certificate.
4. Validity period of the digital certificate.
5. Public key of the subscriber.
6. Digital signature of the organization providing digital signature services.
7. Restrictions on purpose and scope of use of the digital certificate.
8. Restrictions on the legal liability of the organization providing digital signature services.
9. Cryptographic algorithm.
10. Other necessary contents as prescribed by the Ministry of Information and Communications.
5. Amend and supplement Clause 4a of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 4 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 4a. Methods for sending and receiving documents related to digital signature certification services and processing results
1. The subscriber management organization sends documents related to digital certificates and digital signature certification services to the State Bank of Vietnam (Information Technology Department) through one of the following methods:
a) Electronic method via the Public Service System;
b) Paper documents submitted directly at the One-Stop Shop or sent through postal service
c) Electronic documents sent through the State Bank of Vietnam's Document Management and Operation System (applicable to units under the State Bank of Vietnam). The State Bank of Vietnam (Information Technology Department) only accepts and processes paper documents and electronic documents sent through the State Bank of Vietnam's Document Management and Operation System in the following cases:
- The Public Service System encounters technical issues preventing it from operating;
- The subscriber management organization has not been issued a digital certificate with public service functions or the digital certificate has expired or the subscriber's secret key storage device is damaged.
2. Sending documents related to digital certificates and digital signature certification services to the State Bank of Vietnam
a) In case of submitting paper documents: The subscriber management organization has the right to choose to submit original copies or certified true copies or copies accompanied by presentation of the original for verification.
b) In case of submitting electronic documents: All documents (except appendices of this Circular that have been converted into electronic forms on the Public Service System) are sent through the Public Service System, the subscriber management organization sends electronically digitized copies from the original (PDF format file) and signed digitally using the digital certificate of CA-NHNN by the authorized person of the subscriber management organization.
3. The Information Technology Department sends notifications of processing results and reasons for rejection in cases where the application is not approved to the subscriber management organization via the Public Service System. In case the Public Service System encounters technical issues, the notification of processing results will be sent to the subscriber management organization through postal service or email address of the subscriber and the individual or department responsible for managing the digital certificate of the subscriber management organization.
6. Amend and supplement Article 4b of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 5 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 4b. Subscriber Secret Key Storage Device
1. The Information Technology Department is responsible for guiding the types and technical specifications of the subscriber secret key storage devices suitable for the State Bank of Vietnam's digital signature certification system and technological development trends.
2. The Information Technology Department provides secret key storage devices to administrative units under the State Bank of Vietnam. Non-administrative units under the State Bank of Vietnam and other subscriber management organizations equip themselves with secret key storage devices according to the guidance of the Information Technology Department.
3. The sending and receiving of secret key storage devices between the Information Technology Department and administrative units under the State Bank of Vietnam shall be carried out either directly or through postal service.
7. Amend and supplement Article 5 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 6 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 5. Issuance and Supplement of Digital Certificate Functions
1. When there is a need to issue a digital certificate or supplement functions, the subscriber management organization submits one set of application materials including:
a) Issuing and supplementing functions for a digital certificate for an individual who is an authorized person: - Application for issuing and supplementing functions for a digital certificate for an individual as stipulated in Appendix 01 attached to this Circular; - Appointment decision of the authorized person when applying for a new digital certificate (for state agencies).
b) Issuing and supplementing functions for a digital certificate for an individual who is authorized by an authorized person:
- Application for issuing and supplementing functions for a digital certificate for an individual as stipulated in Appendix 01 attached to this Circular;
- Appointment decision of the authorized person when applying for a new digital certificate (for state agencies);
- Authorization letter from the authorized person to the individual being issued a digital certificate or having their functions supplemented, clearly stating that the authorized individual is permitted to represent the organization in signing off on documents, reports, transactions on the corresponding information system based on the functions of the requested digital certificate. The authorized individual may not re-authorize another person to perform these tasks.
c) Issuing and supplementing functions for a digital certificate for an organization:
Application for issuing and supplementing functions for a digital certificate for an organization as stipulated in Appendix 02 attached to this Circular.
2. In case a digital certificate has already been issued and is still valid, and the subscriber management organization requests to supplement functions for the digital certificate, the Information Technology Department will implement the supplementation of functions for the existing digital certificate of the subscriber.
3. In case a new digital certificate needs to be issued after the old one has expired or been revoked and the subscriber wishes to continue using it, the procedure for issuing a new digital certificate shall be carried out as prescribed in Clause 1 of this Article.
4. Time limit for processing and results In a period of three working days from the date of receipt of the application file for issuing a valid digital certificate, the Information Technology Department shall issue the digital certificate or supplement digital certificate services to the subscriber, and send a notification of issuance of the digital certificate and activation code to the subscriber's email address and mobile phone number. For organizational digital certificates, the Information Technology Department shall send a notification of issuance of the digital certificate and activation code to the email address and mobile phone number of the responsible officer for digital certificates at the managing organization.
If the application file is not valid, the Information Technology Department shall refuse to process the file and clearly state the reasons within two working days from the date of receipt of the file. Feedback information and the results of the file processing shall be carried out in accordance with Clause 3, Article 4a of this Circular.
5. The activation code for the digital certificate has a maximum validity period of thirty days from the date of issuance of the digital certificate. For newly issued digital certificates, the subscriber must activate the digital certificate before the expiration date of the activation code. Guidelines for activating and renewing digital certificates issued by the State Bank are published on the State Bank's electronic portal. For digital certificates that have had their services supplemented, the subscriber does not need to activate the digital certificate.
6. The validity period of the digital certificate of the subscriber, as proposed by the managing organization, but not exceeding five years from the date of activation of the digital certificate.
8. Amend and supplement Article 6 of Circular No. 28/2015/TT-NHNN (amended and supplemented by Clause 7, Article 1 of Circular No. 10/2020/TT-NHNN) as follows:
"Article 6. Renewal and change of information in digital certificates
1. Digital certificates requested for renewal or change of information must still be valid.
2. Validity period of digital certificates:a) After renewal, the digital certificate will have a validity period calculated from the successful renewal date but not exceeding five years;b) Changing the information in the digital certificate does not alter its validity period.
3. In cases of renewal or change of information in digital certificates:
a) The managing organization must request the renewal of the subscriber's digital certificate at least ten days before the expiry date of the digital certificate;
b) The managing organization must request changes to the information in the subscriber's digital certificate within five working days from the date of the following changes:
- The subscriber changes their position, title, or department (room/division) but does not change the unit/branch. If the subscriber changes to work at another unit/branch, the managing organization shall carry out procedures to revoke the digital certificate at the old unit/branch and issue a new digital certificate at the new unit/branch if there is a need to continue using it;
- The subscriber changes their identification number (ID card/Citizen Identity Card/Passport);
- The subscriber changes their address, email, or phone number.
4. The managing organization shall submit one set of application files for renewal or change of information in digital certificates, including the Application for Renewal or Change of Information in Digital Certificates according to Appendix 03 issued together with this Circular.
5. Time limit for processing and results of implementation
Within three working days from the date of receipt of a valid application for renewal or change of information in digital certificates, the Information Technology Department shall carry out the renewal or change of information in the digital certificate for the subscriber. If the application file is not valid, the Information Technology Department shall refuse to process the file and clearly state the reasons within two working days from the date of receipt of the file. Feedback information and the results of the file processing shall be carried out in accordance with Clause 3, Article 4a of this Circular.
Upon receiving the notification of approval for renewal of the digital certificate, the subscriber shall proceed with the renewal of the digital certificate according to the activation and renewal guidelines published on the State Bank's electronic portal.
9. Amend and supplement Article 7 of Circular No. 28/2015/TT-NHNN (amended and supplemented by Clause 8, Article 1 of Circular No. 10/2020/TT-NHNN) as follows:
"Article 7. Suspension of digital certificates
1. A subscriber's digital certificate is suspended when one of the following situations occurs:
a) At the request of the managing organization to suspend the digital certificate;
b) At the written request of judicial authorities, police agencies, or the Ministry of Information and Communications;
c) The Information Technology Department discovers any errors or incidents that may affect the subscriber's interests or the security of the digital signature service system.
2. The suspension period of the digital certificate under point a, Clause 1 of this Article, as requested by the managing organization. The suspension period of the digital certificate under point b, Clause 1 of this Article, as requested by judicial authorities, police agencies, or the Ministry of Information and Communications. The suspension period of the digital certificate under point c, Clause 1 of this Article, until such errors or incidents are resolved.
3. The managing organization shall submit one set of application files for suspending the digital certificate, including the Application for Suspension of Digital Certificate according to Appendix 04 issued together with this Circular.
4. Time Limit for Processing and Results
a) Within one working day from the date of receipt of a valid application for suspending the digital certificate as stipulated in point a, Clause 1 of this Article, the Information Technology Department shall suspend the digital certificate of the subscriber and notify the managing organization of the result of the processing. If the application file is not valid, the Information Technology Department shall refuse to process the file and clearly state the reasons within one working day from the date of receipt of the file. Feedback information and the results of the file processing shall be carried out in accordance with Clause 3, Article 4a of this Circular; b) Within one working day from the date of receipt of the information as stipulated in points b and c, Clause 1 of this Article, the Information Technology Department shall suspend the digital certificate and notify the managing organization in writing of the time and reason for the suspension of the digital certificate.
10. Amend and supplement point d, Clause 2, Clause 3, and Clause 4 of Article 8 of Circular No. 28/2015/TT-NHNN (amended and supplemented by Clause 9, Article 1 of Circular No. 10/2020/TT-NHNN) as follows:
"d) The electronic signature certificate has been suspended according to the provisions of point c, Clause 1, Article 7 of this Circular, and such errors or incidents have been rectified."
"3. The organization managing subscribers shall submit one (1) set of application files for restoring the electronic signature certificate in accordance with the provisions of point b, Clause 2, Article of this Circular, including the Application for Restoration of Electronic Signature Certificate as stipulated in Appendix 05 attached hereto."
4. Time Limit for Processing and Results
a) Within one (1) working day from the date of receipt of the application document as prescribed in point a, Clause 2, Article of this Circular or the valid application file for restoring the electronic signature certificate as prescribed in point b, Clause 2, Article of this Circular, the Department of Information Technology shall restore the electronic signature certificate for the subscriber. In case the application file is not valid, the Department of Information Technology shall reject the processing of the file and specify the reasons within one (1) working day from the date of receipt of the file. Feedback information and the results of the processing shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular;
b) Within one (1) working day from the date of receipt of the information as prescribed in points c and d, Clause 2, Article of this Circular, the Department of Information Technology shall automatically restore the electronic signature certificate for the subscriber.
11. Amend and supplement Article 9 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 10, Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 9. Revocation and cancellation of electronic signature services
1. The organization managing subscribers may propose to revoke or cancel one or several electronic signature services of the subscriber. In case of revoking the electronic signature certificate, all electronic signature services of the subscriber shall be canceled.
2. The electronic signature certificate of the subscriber shall be revoked in the following cases:
a) At the request of a competent investigative body, a police agency, or the Ministry of Information and Communications in writing;
b) At the proposal of the organization managing subscribers to revoke the electronic signature certificate;
c) The subscriber management organization has a decision to revoke the operating license, split, merge, dissolve, or declare bankruptcy according to the law;
d) There is sufficient evidence to determine that the subscriber has violated regulations on the management and use of secret keys and key storage devices;
đ) The electronic signature certificate has expired.
3. The organization managing subscribers shall submit one (1) set of application files for revoking or canceling electronic signature services, including the Application for Revocation or Cancellation of Electronic Signature Services as stipulated in Appendix 06 attached hereto.
4. Time Limit for Processing and Results
a) Within one (1) working day from the date of receipt of the application document as prescribed in point a, Clause 2, Article of this Circular or the valid application file for revoking or canceling electronic signature services, the Department of Information Technology shall carry out the revocation or cancellation of electronic signature services for the subscriber. In case the application file is not valid, the Department of Information Technology shall reject the processing of the file and specify the reasons within one (1) working day from the date of receipt of the file. Feedback information and the results of the processing shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular;
b) Within one (1) working day from the date of receipt of the information as prescribed in points c and đ, Clause 2, Article of this Circular, the Department of Information Technology shall automatically revoke the electronic signature certificate of the subscriber;
c) Within one (1) working day from the date of receipt of the information as prescribed in point d, Clause 2, Article of this Circular, the Department of Information Technology shall carry out the revocation of the electronic signature certificate of the subscriber and notify the subscriber in accordance with the provisions of Clause 3, Article 4a of this Circular."
12. Amend and supplement Clause 2, Article 10 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 11, Article 1 of Circular 10/2020/TT-NHNN) as follows:
"2. Subscribers must create a key pair before the expiration date of the activation code as notified in the issuance of the electronic signature certificate. In case the activation code is exposed or suspected to be exposed, or if it exceeds the expiration date specified in the notification of issuance of the electronic signature certificate and the subscriber cannot create a key pair and wishes to continue using the electronic signature certificate, they shall follow the procedures for changing the activation code of the electronic signature certificate as stipulated in Article 10a of this Circular."
13. Supplement Article 10a as follows:
"Article 10a. Changing the Activation Code of the Electronic Signature Certificate
1. The organization managing subscribers shall submit one (1) set of application files for changing the activation code, including the Application for Changing the Activation Code of the Electronic Signature Certificate as stipulated in Appendix 08 attached hereto.
2. Time limit for resolution and implementation results
Within three (3) working days from the date of receipt of the valid application file for changing the activation code of the electronic signature certificate, the Department of Information Technology shall change the activation code of the electronic signature certificate for the subscriber, send the notification of the new activation code to the email address and SMS to the mobile phone number of the subscriber. For organizational electronic signature certificates, the Department of Information Technology shall send the notification of the new activation code to the email address and SMS to the mobile phone number of the responsible officer for electronic signature certificates of the organization managing subscribers.
In case the application file is not valid, the Department of Information Technology shall reject the processing of the file and specify the reasons within two (2) working days from the date of receipt of the file. Feedback information and the results of the processing of the file shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular.
3. The activation code of the electronic signature certificate shall have a maximum validity period of thirty (30) days from the date of the change. The subscriber must activate the electronic signature certificate before the expiration date of the activation code. Guidelines for activating and renewing the electronic signature certificate issued by the State Bank of Vietnam are published on the State Bank of Vietnam's official website."
14. Amend and supplement Article 11 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 12, Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 11. Changing the Key Pair of the Electronic Signature Certificate
1. In case of need to change the key pair of the electronic signature certificate of the subscriber:
The electronic signature certificate of the subscriber is still valid for use, but the key pair stored in the key storage device of the subscriber cannot continue to be used due to damage to the key storage device or because the key pair has been deleted from the device or other causes leading to key pair failure.
2. The organization managing subscribers shall submit one (1) set of application files for changing the key pair of the electronic signature certificate, including the Application for Changing the Key Pair of the Electronic Signature Certificate as stipulated in Appendix 07 attached hereto at least ten (10) working days before the expiration date of the electronic signature certificate."
3. Within three working days from the date of receiving the application file for changing the valid digital certificate key pair, the Department of Information Technology shall implement the change of the key pair, send the notification of the key pair change and activation code of the digital certificate to the email address and mobile phone number of the subscriber. For organizational digital certificates, the Department of Information Technology shall send the notification of the key pair change and activation code of the digital certificate to the email address and mobile phone number of the focal point staff responsible for managing the digital certificate of the organization.
In case the application file is not valid, the Department of Information Technology shall reject the processing of the file and specify the reasons within two (2) working days from the date of receipt of the file. Feedback information and the results of the processing of the file shall be carried out in accordance with the provisions of Clause 3, Article 4a of this Circular.
Upon receipt of the activation code of the digital certificate, the subscriber shall activate the digital certificate to create a new key pair before the expiration date of the activation code according to the activation and renewal guide published on the State Bank of Vietnam's electronic portal.
15. Amend and supplement Clause 3, Clause 4, Clause 7, and Clause 10 of Article 13 of Circular 28/2015/TT-NHNN as follows:
"3. Have an effective contingency plan to ensure the continuous and secure operation of the State Bank of Vietnam’s digital signature certification service.
4. Ensure security and confidentiality throughout the process of issuing and transferring activation information for digital certificates to subscribers. Update and store complete and accurate information about subscribers to serve the management of digital certificates. Comply with legal regulations on personal data protection in the collection, processing, and storage of subscriber information and managed organizations.
"7. Ensure that the electronic channel for receiving requests for digital signature certification services operates 24 hours a day, seven days a week.
"10. Provide and update information about software, guidance documents on the management and use of digital signatures, digital certificates, and digital signature certification services.
"16. Amend and supplement Article 14 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 13 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 14. Responsibilities of the Subscriber Management Organization
1. Designate an individual or department responsible for registering and managing the list of subscribers within the organization, managing related files, documents, and reports concerning digital certificates and digital signature certification services. Notify the Department of Information Technology in writing of the individual/departments initially designated and any subsequent changes.
2. Register and bear full responsibility for the accuracy of all information contained in documents, files, and reports related to subscribers' digital certificates submitted to the Department of Information Technology.
3. Manage, compile, and update the list of subscribers within the organization. At least once a year, conduct a review and verification of the digital certificates issued by the State Bank of Vietnam against actual needs and information within the subscriber management organization. For digital certificates that do not match the information, the subscriber management organization must immediately initiate procedures to change information, suspend, revoke, or cancel the digital certificate operations.
4. Report periodically as prescribed in this Circular.
5. Guide, inspect, and facilitate conditions for subscribers under its management to use digital certificates and secret keys in accordance with the provisions of this Circular.
6. Promptly notify the Department of Information Technology to suspend or revoke the digital certificate of a subscriber in the following cases:
a\. The subscriber's secret key is suspected of being disclosed, leaked, stolen, or used improperly;
b) The subscriber's secret key storage device is lost;
c) The subscriber changes their job position and does not need to use the digital certificate for work purposes;
d\. The subscriber is on temporary leave, has retired, or passed away;
e\. The subscriber belongs to a branch/unit of the subscriber management organization whose bank code has been revoked;
e) Other situations arising from the needs of the subscriber management organization.
7. Digital certificates issued to organizations must be handed over to individuals for management and use. The handover must be documented clearly specifying the roles and responsibilities of the individual managing the certificate. The individual managing the certificate must fulfill the roles and responsibilities of the subscriber as stipulated in this Circular.
8. The subscriber management organization, which is an administrative unit under the State Bank of Vietnam, must promptly recover the secret key storage devices of non-users to reuse them for other subscribers.
17. Amend and supplement Article 15 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 14 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 15. Responsibilities of Subscribers
1. Use digital certificates for the intended purpose as granted.
2. Manage and use secret keys and secret key storage devices:
a) Use the correct type of secret key storage device as guided by the Department of Information Technology;
b) Safeguard and use the access code for the device, secret key, and data within the secret key storage device securely and confidentially during the validity period of the digital certificate and when it is suspended;
c) Do not share or lend the access code for the device or the secret key storage device. When leaving the job, changing positions, or no longer needing the digital certificate for work, destroy the data within the secret key storage device and return the secret key storage device to the subscriber management organization;
d) Do not use any tools, programs, software, or other means to interfere, modify, or change secret key information or data within the secret key storage device or intentionally damage the secret key storage device;
đ) Promptly notify the subscriber management organization if the digital certificate or secret key is no longer secure; if the secret key storage device is lost, faulty, or damaged and cannot be used.
3. Adhere to other regulations regarding the issuance, management, and use of digital certificates.
18. Amend and supplement Clause 3 of Article 16 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 15 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"3. The signer bears full responsibility for the authenticity of the information signed digitally and shall only sign digitally on information systems when the system indicates that the signer's digital certificate is valid.
19. Amend and supplement Article 17 of Circular 28/2015/TT-NHNN (amended and supplemented by Clause 16 of Article 1 of Circular 10/2020/TT-NHNN) as follows:
"Article 17. Reporting System
The subscriber management organization is responsible for submitting regular reports to the State Bank of Vietnam as follows:
1. Report name: Cross-check report of State Bank of Vietnam digital certificates.
2. Content of the report:
a) Statistics on digital certificates and usage status;
b) Compare the list of digital certificates already issued by the Information Technology Department with the usage requirements and actual information at the subscriber management organization, and report on the list of digital certificates that do not match correctly.
3. Subject implementing the provisions: Units under the State Bank of Vietnam, credit organizations, foreign bank branches, the Vietnam Treasury, the Vietnam Deposit Insurance Corporation, and other agencies and organizations using the State Bank of Vietnam's digital signature verification service.
4. Agency or unit receiving the report: Information Technology Department - State Bank of Vietnam.
5. Method of sending and receiving reports: The sending and receiving of reports shall be carried out in accordance with the provisions of Clause 1, Article 4a of this Circular.
6. Frequency and deadline for submitting reports: Annually, no later than December 20 of the reporting year.
7. Time period for finalizing report data: The time period for finalizing report data runs from December 15 of the year preceding the reporting period to December 14 of the reporting period.
Article 2. Replacement of phrases and forms in Circular 28/2015/TT-NHNN
1. Replace the phrase "Information Technology Department" with the phrase "Information Technology Department".
2. Replace Forms 01, 02, 03, 04, 05, 06, 07, 08, 09 issued together with Circular 28/2015/TT-NHNN (which has been replaced by Circular 10/2020/TT-NHNN) with Appendices 01, 02, 03, 04, 05, 06, 07, 08, 09 respectively issued together with this Circular.
This Circular takes effect from December 25, 2025/.
Heads of units under the State Bank of Vietnam, credit organizations, foreign bank branches, the Vietnam Treasury, the Vietnam Deposit Insurance Corporation, the National Payment Corporation of Vietnam, and the Vietnam Asset Management Corporation are responsible for organizing the implementation of this Circular.
Article 4. Implementation provisions
1. This Circular takes effect from July 1, 2024.
2. This Circular abolishes Circular No. 10/2020/TT-NHNN dated November 2, 2020, issued by the Governor of the State Bank of Vietnam amending and supplementing certain articles of Circular 28/2015/TT-NHNN.
DEPUTY DIRECTOR
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.
번역본
이 문서는 다음 언어로 제공됩니다: