This Circular details the work of ensuring information security in banking and credit institution activities in Vietnam. It includes requirements for risk management, access control, password management, software development, system operation, incident response, disaster recovery, continuous operation assurance, internal audit, and reporting procedures. Banking and credit institutions must comply with these regulations to ensure information security in their operations.
Scope of application
Credit institutions and banks in Vietnam
Key points
- Information security risk management
- Access control and password management
- Software development for information security assurance
- Information system operation
- Cybersecurity incident response
- Disaster recovery
- Assurance of continuous information system operation
- Internal audit and reporting procedures
🌐 Social impact of this document
- Enhancing security for banking and credit information systems
- Minimizing cybersecurity risks in the financial sector
- Improving the efficiency of credit institutions and banks' operations
❓ Frequently asked questions
What regulations must organizations comply with regarding information security assurance?
Organizations must comply with requirements for risk management, access control, software development, system operation, incident response, disaster recovery, and continuous operation assurance as stipulated in this Circular.
Is there any need to report to the State Bank of Vietnam?
Organizations must report on cybersecurity incidents and risk assessments when outsourcing information system management at level 2 or higher as specified in this Circular.
Full text
CIRCULAR
Provisions on information system security
in banking operations
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010 and the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to the Law on Cybersecurity dated November 19, 2015;
Pursuant to Government Decree No. 16/2017/NĐ-CP dated February 17, 2017 on the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Information Technology;
The Governor of the State Bank of Vietnam issues this Circular stipulating information system security in banking operations
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation and Applicability
1. This Circular stipulates measures to ensure information system security in banking operations.
2. This Circular applies to credit organizations (excluding people's credit funds and microfinance institutions), foreign bank branches, and organizations providing intermediary payment services (hereinafter referred to collectively as organizations).
Article 2. Interpretation of Terms
In this Circular, the following terms are understood as follows:
1. Information system is a set of hardware, software, databases, and network systems for creating, transmitting, collecting, processing, storing, and exchanging digital information to serve one or more technical and business activities of the organization.
2. Confidentiality of information means ensuring that information can only be accessed by those with corresponding authorization.
3. Integrity of information means protecting the accuracy and completeness of information, and ensuring that information can only be changed by those with corresponding authorization.
4. Availability of information means ensuring that authorized persons can access information immediately when needed.
5. Information security is the protection of digital information and information systems from unauthorized access, use, disclosure, interruption, modification, or destruction to ensure confidentiality, integrity, and availability of information.
6. Information technology risk is the possibility of loss occurring when carrying out activities related to information systems. Information technology risks relate to management, use of hardware, software, communication, system interfaces, operation, and human factors.
7. Cybersecurity incident is an event where digital information or information systems are attacked or harmed, affecting confidentiality, integrity, and availability.
8. Technical vulnerability is a component within an information system that can be exploited or taken advantage of when attacked or illegally intruded upon.
9. Data center includes technical infrastructure (telecommunication station, cable system) and computer systems along with auxiliary devices installed there to process, store, exchange, and centrally manage data.
10. Mobile device is a digital device designed to be portable without affecting its operational capability, having an operating system, capable of processing, connecting to networks, and displaying information such as laptops, tablets, and smart mobile phones.
11. Storage medium is a physical means used to retain and transmit digital information.
12. Firewall is a set of components or a system of equipment and software placed between two networks to control all connections from inside to outside the network or vice versa.
13. Untrusted network is an external network connected to the organization's network and not under the organization's management or a foreign credit organization that the organization has a relationship with as a subsidiary or commercial presence in Vietnam.
14. Cloud computing service is a service providing computing resources through a network environment allowing multiple users to utilize, adjust, and pay according to usage needs.
15. User account (account) is a unique set of information representing a user on the information system, used for logging in and accessing permitted resources on that system.
16. Third party is individuals or businesses (excluding foreign credit organizations and members of foreign credit organizations in cases where the organization is a subsidiary or commercial presence in Vietnam of a foreign credit organization) who have a written agreement (referred to collectively as service use contracts) with the organization to provide information technology services.
17. Authorized person is a position or individual delegated management, assigned tasks, or authorized in writing by the legal representative of the organization to perform one or more functions or duties of the organization.
Article 3. General Principles
1. Organizations are responsible for ensuring information security based on clearly defined authority and responsibility for each department and individual within the organization.
2. Classify information systems according to their level of importance and apply appropriate information security policies.
3. Timely identify, classify, assess, and effectively handle potential information technology risks that may occur within the organization.
4. Develop and implement information security regulations based on provisions of this Circular and balance interests, costs, and risk tolerance levels of the organization.
Article 4. Classification of information and information systems
1. Information processed and stored through information systems shall be classified according to their confidential attributes as follows:
a) Public information is information made public to all subjects without the need to identify the specific identity or address of those subjects;
b) Internal information is information of an organization that is managed and exploited for one or a group of identified subjects within the organization;
c) Confidential information is information: (i) Classified at the Secret level according to the organization's regulations and restricted to certain subjects; (ii) Secret, Top Secret, and Absolute Secret according to the laws on protecting state secrets.
2. Criteria for classifying the importance levels of information systems of organizations:
a) Ordinary information system (level 1) is an information system serving internal activities of the organization or serving customers but does not process confidential information.
b) Important information system (level 2) is an information system meeting one of the following criteria: (i) The information system processes confidential information; (ii) The information system serves daily internal activities of the organization and cannot accept downtime exceeding four working hours; (iii) The information system serves customers requiring 24/7 operation and cannot accept downtime without prior planning; (iv) The information system provides online transaction services to customers.
c) Particularly important information system (level 3) is an information system meeting one of the following criteria: (i) National information system in the banking sector serving the development of electronic government, requiring 24/7 operation and cannot accept downtime without prior planning; (ii) Common information infrastructure in the banking sector serving the activities of agencies and organizations nationwide, requiring 24/7 operation and cannot accept downtime without prior planning.
d) In cases where an information system includes multiple component systems, each component system corresponds to a different level of importance, the classification of the information system is determined based on the level of importance of the component system providing core technical and business operations.
3. Organizations implement the classification of information systems according to the importance levels specified in Clause 2 of this Article. The list of information systems by importance level must be approved by the legal representative.
Article 5. Information Security Regulations
1. Organizations establish information security regulations appropriate to their information systems, organizational structure, management requirements, and operational needs. Information security regulations must be signed and issued by the legal representative and implemented throughout the organization.
2. Minimum information security regulations shall include the following basic contents:
a) Management of information technology assets;
b) Human resource management;
c) Physical and environmental safety assurance;
d) Operation and information exchange management;
đ) Access management;
e) Management of third-party information technology service usage;
g) Management of information system reception, development, and maintenance;
h) Information security incident management;
i) Assurance of continuous information system operation;
k) Internal audit and reporting procedures.
3. Organizations review the minimum information security regulations annually to ensure their completeness according to the provisions of this Circular. When discovering inadequacies or inconsistencies causing information security breaches or upon request from competent authorities, organizations promptly revise and supplement the issued information security regulations.
Chapter II
PROVISIONS ON INFORMATION SECURITY ASSURANCE
Section 1
MANAGEMENT OF INFORMATION TECHNOLOGY ASSETS
Article 6. Management of Information Technology Assets
1. Types of information technology assets include:
a) Information assets: data and information in digital form processed and stored through information systems;
b) Physical assets: information technology equipment, communication means, carriers of information, and devices serving the operation of information systems;
c) Software assets: system software, utility software, middleware, databases, application programs, source code, and development tools.
2. Organizations shall establish a list of all information technology assets associated with each information system in accordance with Clause 3, Article 4 of this Circular. They shall review and update the list of information technology assets on a regular annual basis.
3. Based on the level of importance of the information system, organizations shall implement appropriate management and protection measures for each type of information technology asset.
4. Based on the classification of information technology assets under Clause 1 of this Article, organizations shall develop and implement regulations on the management and use of assets as stipulated in Articles 7, 8, 9, 10, and 11 of this Circular.
Article 7. Management of Information Assets
1. For each information system, a list of information assets must be established, along with provisions regarding the authority and responsibility of individuals or units within the organization to access, exploit, and manage such assets.
2. Information assets must be classified according to Clause 1 of Article 4 of this Circular.
3. Information assets classified as confidential information must be encrypted or protected by other means to ensure confidentiality during creation, exchange, and storage.
4. Information assets on information systems at Level 3 must apply measures to prevent data loss.
Article 8. Management of Physical Assets
1. For each information system directly managed by the organization, a list of physical assets must be established, including basic information such as the name of the asset, value, installation location, managing subject, purpose of use, usage status, and corresponding information system.
2. Physical assets must be assigned to individuals or units responsible for their management and use.
3. When physical assets containing confidential information are taken out of the organization's premises, approval from the competent authority is required, and protective measures must be implemented to safeguard the stored information.
4. When physical assets storing confidential information change their purpose of use or are disposed of, measures to destroy or erase such confidential information must be carried out to ensure irrecoverability. In cases where destruction is not possible, the organization must implement measures to destroy the data storage components of the asset.
5. Mobile devices and carriers of information, in addition to the provisions of this Article, must be managed in accordance with Articles 10 and 11 of this Circular.
Article 9. Management of Software Assets
1. For each information system, a list of software assets must be established, including basic information such as the name of the asset, value, purpose of use, scope of use, managing subject, copyright information, version, and corresponding information system.
2. Software assets must be assigned to individuals or units responsible for their management.
3. Software assets must be regularly reviewed and updated with security patch versions.
4. When software assets are stored on carriers of information, they must comply with the provisions of Article 11 of this Circular.
Article 10. Management and Use of Mobile Devices
1. Mobile devices must be registered for control when connecting to the internal network system of the organization.
2. Limit the scope of connection from mobile devices to services and information systems of the organization; control connections from mobile devices to permitted information systems within the organization.
3. Specify individual responsibilities within the organization when using mobile devices for work purposes.
4. Mobile devices used for work purposes must apply the following minimum technical measures:
a) Establish functions to disable, lock the device, or remotely delete data in case of loss or theft;
b) Backup data on mobile devices to protect and restore data when necessary;
c) Implement data protection measures during maintenance, repair, or warranty service of mobile devices.
5. For mobile devices that are assets of the organization, in addition to applying the provisions of Clause 4 of this Article, the following minimum technical measures must also be applied:
a) Control software installation; update software versions and patches on mobile devices;
b) Utilize features to protect internal and confidential information (if applicable); set secret passwords; install anti-malware software and other security patches.
Article 11. Management and Use of Data Carriers
1. Control the connection and disconnection of data carriers with information system equipment.
2. Implement safety measures for data carriers during transportation and storage.
3. Protect confidential information contained in data carriers.
4. Specify individual responsibilities in managing and using data carriers.
Section 2
HUMAN RESOURCE MANAGEMENT
Article 12. Organizing Human Resources
1. The legal representative must directly participate in directing and be responsible for building strategies and plans to ensure information security and respond to cybersecurity incidents occurring within the organization.
2. Organizations directly managing information systems at level 2 or higher shall implement the following:
a) Establish or designate a specialized department responsible for ensuring information security and responding to cybersecurity incidents for the organization;
b) Establish or designate a specialized department to manage the operation of the cybersecurity command center as required under Article 46 of this Circular (this does not apply to foreign bank branches, organizations providing payment intermediary services, and non-bank financial institutions);
c) Separate personnel between tasks: (i) Development and system management; (ii) Development and system operation; (iii) System management and operation; (iv) Information security testing with development, management, and operation of the information system.
Article 13. Recruitment and Assignment of Tasks
Recruitment and assignment of tasks shall be carried out as follows:
1. Determine the responsibility for ensuring information security of the position to be recruited or assigned.
2. Review and assess the moral character and professional qualifications through background checks and criminal records before assigning personnel to important positions in the information system such as operating level 3 information systems or managing information systems.
3. Require recruited individuals to commit to confidentiality in writing or as part of their employment contract. This commitment must include terms regarding the responsibility for ensuring information security both during and after working at the organization.
4. Train and disseminate the organization's regulations on information security to newly recruited personnel.
Article 14. Management and Utilization of Human Resources
The management of human resources shall be carried out as follows:
1. Disseminate and update information security regulations for all individuals within the organization at least once a year.
2. Inspect compliance with information security regulations for individuals and subordinate units at least once a year.
3. Apply disciplinary measures against individuals and units that violate information security regulations in accordance with the provisions of the law and the organization's regulations.
Article 15. Termination or Change of Work
When an individual within the organization terminates or changes their work, the organization shall implement the following:
1. Determine the responsibilities of the individual when terminating or changing work.
2. Require the individual to hand over information technology assets.
3. Immediately revoke access rights to the information system for employees who have left.
4. Timely change access rights to the information system for individuals changing jobs to ensure the principle of minimum necessary access to perform assigned tasks.
5. Regularly review and check, at least every six months, between the personnel management department and the access control department to ensure compliance with Clause 3 and Clause 4 of this Article.
6. Notify the State Bank (Information Technology Department) of cases where individuals working in the organization's information technology field are dismissed, forced to resign, or prosecuted under the law due to violations of information security regulations.
Section 3
PHYSICAL AND ENVIRONMENTAL SECURITY FOR THE INSTALLATION OF INFORMATION TECHNOLOGY EQUIPMENT
Article 16. General Requirements for Installation Sites of Information Technology Equipment
1. Protect with perimeter walls, gates, or other measures to control and limit unauthorized entry risks.
2. Implement preventive measures against fire and flood hazards.
3. Areas with high safety and confidentiality requirements such as server installation areas, storage devices, security equipment, communication devices must be isolated from common areas, distribution, and delivery zones; issue internal rules, work guidelines, and apply entry and exit control measures in those areas.
Article 17. Requirements for Data Centers
In addition to meeting the requirements set forth in Article 16 of this Circular, data centers must also meet the following requirements:
1. The entrance and exit of the data center building must be controlled 24/7.
2. The doors to the data center must be secure, fire-resistant, equipped with at least two different types of locks, and must have protection and surveillance measures 24/7.
3. The equipment installation area must avoid direct sunlight, water leakage, and flooding. The installation area for information systems at level 2 or higher must be protected and monitored 24/7.
4. There must be at least one grid power source and one generator power source. An automatic switching system between the two power sources must be installed, and when grid power is cut off, the generator must automatically start and supply power. Power must be connected through a battery backup system to supply power to the equipment, ensuring continuous operation of the information system.
5. There must be an air conditioning system capable of continuous operation.
6. There must be a direct lightning strike and surge protection system.
7. There must be an automatic fire detection and extinguishing system to prevent damage to internal equipment during firefighting.
8. There must be technical floor systems or isolation layers to prevent electrical interference; grounding systems.
9. There must be a surveillance camera system with data storage capability for at least 100 days.
10. There must be a temperature and humidity monitoring and control system.
11. There must be a logbook for controlling entry and exit to the data center.
Article 18. Physical asset safety
1. Physical assets must be arranged and installed at safe locations and protected to minimize risks from environmental threats and unauthorized intrusions.
2. Physical assets belonging to information systems at level 2 or higher shall be secured with power supply and support systems when the main power source is interrupted. Measures against overload or voltage drop, lightning surge protection, grounding system, backup generator system, and uninterruptible power supply system ensuring continuous operation of equipment shall be implemented.
3. Power cables and communication cables used for data transmission or supporting information services shall be protected from intrusion or damage.
4. Equipment used for business operations installed outside the organization's workplace shall have measures for monitoring and protecting against illegal access.
Section 4
MANAGEMENT, OPERATIONS AND INFORMATION EXCHANGE
Article 19. Management responsibility and operational procedures of organizations
1. Organizations shall issue operational procedures for information systems at level 2 or higher, including at least: system startup and shutdown procedures; data backup and recovery procedures; application operation procedures; incident handling procedures; system monitoring and activity logging procedures. The scope and responsibilities of users and system operators shall be clearly defined. At least once a year, organizations shall review, update, and supplement operational procedures for information systems to align with current realities.
2. Organizations shall implement these procedures to all participants involved in operations and supervision to ensure compliance with issued procedures.
3. The operational environment of information systems at level 2 or higher must meet the following requirements:
a) Separation from development, testing, and trial environments;
b) Application of solutions to ensure information security;
c) No installation of application development tools or means;
d) Removal or deactivation of unused features or utility software on the information system.
4. For information systems processing customer transactions, the following requirements must be met:
a) No single individual shall simultaneously perform both initiation and approval of a transaction;
b) Measures to ensure the integrity of transaction data shall be applied;
c) All actions on the system must be logged and available for inspection and control when necessary.
Article 20. Planning and acceptance of information systems
1. Organizations shall establish standards, norms, and technical requirements to ensure normal operation for all existing information systems and other information systems before their official implementation.
2. Based on established standards, norms, and technical requirements, organizations shall monitor and optimize the performance of information systems; assess the system's ability to meet requirements, operational status, and configuration to forecast and plan for expansion and upgrades to ensure future capacity.
3. Organizations shall review and update standards, norms, and technical requirements when changes occur in information systems; conduct training and transfer technical knowledge related to changes to relevant personnel.
Article 21. Backup and Disaster Recovery
Organizations shall implement backup and disaster recovery to ensure data security as follows:
1. List information systems according to their level of importance that require backup, including storage time, regular backup schedule, backup method, and system recovery test time from backup data.
2. Data of information systems at level 2 and above must have an automatic backup plan suitable for the frequency of data changes and ensure that newly generated data must be backed up within 24 hours. Backup data must be stored on external storage media (such as magnetic tape, hard disk, optical disc, or other storage media) and securely kept separate from the installation area of the source information system.
3. For information systems at level 2 and above, check and restore backup data from external storage media at least once every six months.
4. Organizations with both primary and backup systems located outside Vietnam must store personal information and customer transaction data in Vietnam in accordance with Vietnamese laws.
Article 22. Management of Network Security and Confidentiality
Organizations shall manage network security and confidentiality as follows:
1. Establish regulations on network security and confidentiality management and management of end devices for the entire network.
2. Create and store records about the logical and physical diagrams of the network system, including wide area networks (WAN/Intranet) and internal networks (LAN).
3. Build the organization's network to meet the following minimum requirements:
a) Segregate into different network zones based on user type, purpose, and information system, at a minimum: (i) A dedicated network zone for servers of information systems at level 2 and above; (ii) An intermediate network zone (DMZ) to provide services on the Internet; (iii) A dedicated network zone to provide wireless network services;
b) Have firewall devices to control connections and access to important network zones;
c) Have firewall and intrusion detection/prevention devices to control connections and access from untrusted networks to the organization's network system;
d) Have solutions to control, detect, and promptly block unauthorized connections and access to the organization's internal network with information systems at level 2 and above;
đ) Have load balancing plans and denial-of-service attack response plans for information systems at level 2 and above providing services on the Internet.
4. Set up and configure features according to the design of cybersecurity equipment; implement measures and solutions to detect technical vulnerabilities and weaknesses in the network system; regularly check and detect illegal connections, equipment, and software installations on the network.
Article 23. Information Exchange
Responsibilities of organizations in exchanging information with customers and third parties:
1. Issue regulations on minimum information exchange including: types of exchanged information; rights and responsibilities of individuals when accessing information; means of information exchange; measures to ensure the integrity and confidentiality of information during transmission, processing, and storage; information retention policies.
2. When exchanging internal information and confidential information externally, there must be a written agreement specifying the responsibilities and obligations of all parties involved in using and ensuring the security of information.
3. Confidential information must be encrypted or secure information measures applied before exchange.
4. Implement protective measures for equipment and software serving information exchange to limit illegal intrusion and exploitation.
5. Implement management, monitoring, and strict control measures for online information and service provision websites to facilitate customer transactions.
Article 24. Management of online transaction services
1. Requirements for the information system of organizations providing online transaction services to customers:
a) Ensuring the integrity of data exchanged with customers in online transactions;
b) Data on transmission lines must ensure confidentiality and be transmitted fully, to the correct address, and have protective measures to prevent unauthorized modification or duplication;
c) Assessing the level of risk in online transactions based on customer type, transaction type, transaction limit to provide appropriate transaction authentication solutions as prescribed by the State Bank;
d) The online transaction electronic information site must apply measures to authenticate and prevent forgery and unauthorized modification.
2. Customer transaction verification must be carried out directly within the organization's information system. In cases where the organization uses third-party authentication services, the organization must manage at least one authentication factor.
3. The online transaction service system must apply measures to closely monitor and detect, warn about:
a) Suspicious transactions based on minimum criteria including: transaction time, transaction location (geographical position, IP address), transaction frequency, transaction amount, number of incorrect authentication attempts;
b) Abnormal activities of the system;
c) Denial of Service (DoS) attacks and Distributed Denial of Service (DDoS) attacks.
4. Organizations shall guide customers on measures to ensure information security and warn of risks before using online transaction services and periodically thereafter.
5. When providing online transaction application software on the Internet, measures to ensure the integrity of the software must be applied.
Article 25. Monitoring and Logging of System Activities
Organizations shall implement monitoring and logging of system activities as follows:
1. Recording and storing logs regarding system activities and users, errors occurring, and information security incidents. Logs of systems from level 2 and above must be stored online for a minimum of three months in a centralized manner and backed up for a minimum of one year.
2. Protecting logging functions and log information against forgery and unauthorized access; ensuring that system administrators and users cannot delete or modify logs recording their own activities.
3. Synchronizing time between systems.
Article 26. Prevention of Malware
Organizations shall establish and implement regulations on preventing malware as follows:
1. Determining the responsibilities of individuals and relevant departments in malware prevention work.
2. Implementing malware prevention measures and solutions for the entire organizational information system.
3. Updating malware samples and new anti-malware software.
4. Checking and removing malware from external data carriers before use.
5. Controlling software installation to comply with the organization's information security policy.
6. Controlling suspicious emails, attached files, or links in strange emails.
Section 5
ACCESS MANAGEMENT
Article 27. Requirements for Access Control
1. The organization shall establish regulations on access management for users, user groups, devices, and tools used to access information systems, ensuring compliance with business requirements and information security requirements, including the following basic contents:
a) Registration, issuance, extension, and revocation of user access rights;
b) Each system access account must be assigned to a single user; in cases where shared accounts are used to access information systems, such usage must be approved by authorized authorities and individual responsibilities must be determined at each point of use;
c) For information systems at level 2 or higher, access using accounts with administrative privileges must be limited and controlled: (i) Establish mechanisms to control the creation of administrative accounts to ensure that no account can be used without authorized approval; (ii) Measures to monitor the use of administrative accounts must be implemented; (iii) The use of administrative accounts must be limited to the time necessary to perform tasks and must be revoked immediately upon completion of the work;
d) Management and issuance of secret key access codes for information systems;
đ) Review, inspection, and re-evaluation of user access rights;
e) Information security requirements for devices and tools used for access.
2. The organization shall establish regulations on managing secret key access codes meeting the following requirements:
a) Secret keys must have a length of six characters or more, consisting of numbers, uppercase letters, lowercase letters, and other special characters if allowed by the system; automatic checks for valid secret key requirements must be performed when setting up secret keys;
b) Default secret keys set by manufacturers on equipment, software, and databases must be changed before use;
c) Secret key management software must include the following functions: (i) Require users to change their secret key upon first login (except for one-time secret keys); (ii) Notify users to change their secret key before its expiration; (iii) Invalidate expired secret keys; (iv) Invalidate secret keys when users enter them incorrectly beyond the permitted number of attempts; (v) Allow immediate changes to secret keys that have been exposed or are at risk of exposure, or at the user's request; (vi) Prevent the reuse of old secret keys within a specified period.
3. The organization shall establish regulations on the responsibilities of users when granted access rights, including: using secret keys in accordance with regulations; keeping secret keys confidential; using devices and tools for access; logging out of the system when not working or temporarily not working on the system.
Article 28. Management of Internal Network Access
The organization shall develop and implement internal network access management policies meeting the following requirements:
1. Develop and implement regulations on network access and network service management, including the following basic contents:
a) Permitted networks and network services, methods, means, and information security conditions for access;
b) Responsibilities of administrators and users;
c) Procedures for issuing, changing, and revoking connection rights;
d) Control over administration, access, and use of networks.
2. Implement strict controls on connections from untrusted networks to the organization's internal network to ensure information security.
3. Control the installation and use of remote access support software tools.
4. Control access to ports used for configuring and managing network devices.
5. Granting network and service access rights must adhere to the principle of granting only the minimum necessary rights to perform assigned tasks.
6. Connections from the Internet to the organization's internal network for work purposes must use virtual private networks and multi-factor authentication.
Article 29. Management of Access to Information Systems and Applications
Organizations shall establish and implement access management that meets the following requirements:
1. Control utility software that can affect information systems.
2. Specify access times to applications corresponding to business and service operation hours. Automatically terminate user sessions after a period of non-use to prevent unauthorized access.
3. Manage and allocate access rights to information and applications ensuring that users are granted sufficient permissions to perform assigned tasks:
a) Allocate access rights to individual directories and program functions;
b) Allocate read, write, delete, and execute permissions for information, data, and programs.
4. Information systems using shared resources must be approved by the competent authority.
5. For servers belonging to information systems at level 2 or higher, secure connection protocols must be used and automatic login prevention measures implemented.
Article 30. Management of Internet Connections
Organizations shall define and implement Internet connection management meeting the following requirements:
1. Internet connection and access management includes the following basic contents:
a) Individual and departmental responsibilities in the exploitation and use of the Internet;
b) Permitted entities to access and connect to the Internet;
c) Prohibited and restricted actions;
d) Control of Internet connections and access;
đ) Measures to ensure information security when connecting to the Internet.
2. Implement centralized and unified management of all Internet connection ports within the organization.
3. Deploy cybersecurity solutions at Internet connection ports to protect against threats from Internet attacks on the organization's internal network.
4. Utilize tools to detect and promptly identify vulnerabilities, weaknesses, and illegal intrusions into the organization's internal network through Internet connection ports.
Chapter 6
MANAGEMENT OF THIRD-PARTY INFORMATION TECHNOLOGY SERVICES USE
OF THE THIRD PARTY
Article 31. General Principles for Using Third-Party Services
When using third-party information technology services, organizations shall ensure the following principles:
1. Not reduce the organization's ability to provide continuous service to customers.
2. Not diminish the organization's control over business processes.
3. Not alter the organization's responsibility for ensuring information security.
4. Third-party information technology services must comply with the organization's information security regulations.
Article 32. Requirements for Using Third-Party Services
Before using third-party services, organizations shall undertake the following:
1. Conduct minimum technological and operational risk assessments including the following contents:
a) Identify risks, analyze, estimate the extent of damage, and threats to information security;
b) The ability to control business processes, provide continuous service to customers, and fulfill obligations to provide information to state agencies;
c) Clearly define the roles and responsibilities of related parties in ensuring service quality;
d) Develop measures to mitigate risks, preventive measures, emergency response, and corrective actions;
đ) Review and adjust risk management policies (if applicable).
2. In cases where cloud computing services are used, in addition to the requirements set out in Clause 1 of this Article, organizations shall undertake the following:
a) Classify activities and business operations planned for deployment on cloud computing based on their impact on organizational activities;
b) Develop contingency plans for components of information systems at level 2 or higher. Contingency plans must be tested and ready to replace deployed activities and operations on cloud computing;
c) Establish criteria for selecting third parties that meet the requirements stipulated in Article 33 of this Circular;
d) Review, supplement, and apply the organization's information security measures, limiting access from cloud computing to the organization's information systems.
3. In cases where third parties are hired to manage information systems at level 2 or higher, organizations shall conduct risk assessments as prescribed in Clause 1 of this Article and submit risk assessment reports to the State Bank (Information Technology Department).
Article 33. Criteria for selecting third-party providers of cloud computing services
The criteria for selecting third-party providers shall include at least the following contents:
1. The third party must be a business entity.
2. It must have information technology infrastructure corresponding to the cloud computing service used by the organization, meeting the following requirements:
a) Legal provisions of Vietnam;
b) Possess valid international certification on ensuring information security.
Article 34. Contract for using services with third parties
The contract for using services signed with third parties must contain at least the following contents:
1. Commitment of the third party regarding the assurance of information security including:
a. Meeting the requirements stipulated in Article 33 of this Circular;
b. Not copying, altering, using, or providing the data of the organization using the service to individuals or organizations other than in cases required by competent state agencies according to the law; in such cases, the third party must notify the organization using the service before providing the data, except when the notification would violate Vietnamese law;
c. Disseminating to third-party personnel involved in implementing the contract the regulations on ensuring information security of the organization, implementing measures to monitor compliance.
2. Specific provisions on the maximum possible downtime for the service and the time to resolve incidents, related requirements for ensuring continuous operation (on-site backup, data backup, disaster recovery), related requirements concerning processing capacity, computing power, storage, measures to be taken when the service quality is not guaranteed.
3. In case the third party uses subcontractors, it does not change the third party's responsibility for the service used by the organization.
4. Data generated during the use of the service is the property of the organization. Upon termination of the service:
a) The third party shall return all deployed data and data generated during the use of the service;
b) The third party commits to completing the deletion of all the organization's data within a specified period.
5. The third party must inform the organization when discovering personnel violating the regulations on information security for the service used by the organization.
6. The cloud computing service contract, in addition to the contents prescribed in Clauses 1, 2, 3, 4, and 5 of this Article, must also include the following additional contents:
a) The third party must provide an annual audit report on compliance with information technology standards conducted by an independent auditing organization during the contract period;
b) The third party must provide: cloud service quality control tools; monitoring and controlling cloud service quality procedures;
c) The third party must disclose the locations (city, country) where external data centers outside the territory of Vietnam deploying services for the organization are located;
d) Responsibility for protecting data and preventing unauthorized access to data through the service distribution channel from the third party to the organization;
đ) The third party must support and cooperate in investigations upon requests from competent Vietnamese state agencies according to the law;
e) The organization's data must be separated from the data of other customers using the same technical platform provided by the third party.
Article 35. Responsibilities of organizations during the process of using third-party services
1. Provide, notify, and require third parties to comply with the organization's information security regulations.
2. Establish procedures and allocate resources to monitor and control third-party services to ensure service quality as agreed in the signed contracts. For cloud computing services, monitoring and controlling service quality must be conducted.
3. Apply the organization's information security regulations to equipment and services provided by third parties that are deployed on infrastructure managed and used by the organization.
4. Manage changes to third-party services including: changing providers, changing solutions, changing versions, and changes stipulated in Point 40 of this Circular; thoroughly assess the impact of such changes and ensure safety before implementation.
5. Implement strict monitoring measures and limit third-party access when granting third parties access to the organization's information systems.
6. Supervise third-party personnel during the performance of contracts. In case of discovering violations of information security regulations by third-party personnel, the organization must report and cooperate with the third party to promptly apply appropriate measures.
7. Revoke third-party access rights to the information system immediately upon completion of work or termination of the contract, and change keys and secret codes handed over from the third party.
8. For information systems at level 2 or higher or those using cloud computing services, the organization must evaluate third-party compliance with information security regulations according to the signed agreements. Such evaluations should be conducted annually or ad hoc as needed. Compliance assessments may utilize independent audit results.
Section 7
MANAGEMENT OF INFORMATION SYSTEM ACQUISITION, DEVELOPMENT, AND MAINTENANCE
Article 36. Requirements for Safety and Security of Information Systems
When establishing new or upgrading information systems directly managed by the organization, the organization must classify these systems according to their importance as specified in Clause 2, Article 4 of this Circular. For systems at level 2 or higher, the organization shall implement:
1. Develop design documentation describing methods to ensure system security. Security and confidentiality requirements must be developed concurrently with technical and operational requirements.
2. Develop inspection and verification plans to ensure that implemented systems comply with design documents and security requirements prior to acceptance. Inspection results must be reported and approved by the competent authority before official operation.
3. Strictly manage the procurement of external software according to Article 35 of this Circular.
Article 37. Ensuring Application Security and Confidentiality
Business application programs must meet the following minimum requirements:
1. Verify the validity of data entered into applications, ensuring accurate and valid data entry.
2. Verify the validity of automatically processed data within applications to detect discrepancies caused by processing errors or intentional information modifications.
3. Implement measures to ensure the authenticity and integrity protection of processed data within applications.
4. Verify the validity of data output from applications, ensuring accurate and valid information processing.
5. User secret keys in information systems at level 2 or higher must be encrypted at the application layer.
Article 38. Management of Encryption Codes
The management of encryption codes shall be carried out as follows:
1. Establish and implement encryption measures according to national technical standards for data encryption used in the banking sector or internationally recognized standards.
2. Implement measures to manage encryption keys to protect information of the organization.
Article 39. Safety and Security during Software Development Processes
1. The organization shall manage the software development process as follows:
a) Manage and control source code programs. Access to and contact with source code programs must be approved by the competent authority;
b) Manage and protect system configuration files.
2. The organization shall select and control test and trial data. Real data from the operational information system shall not be used for testing activities until measures to conceal or alter customer information and confidential information have been implemented.
Article 40. Management of System Information Changes
The organization shall issue procedures and measures to manage and control changes to system information, including at least the following:
1. Record changes; plan changes; conduct testing and trials of changes, report results; approve change plans before officially applying software version changes, hardware configuration parameters, system software parameters, operational processes. Have contingency plans for system recovery in case changes are unsuccessful or unforeseen incidents occur.
2. Evaluate impacts to ensure that the information system operates stably and safely on new environments for systems at level 2 or higher when changing versions or operating systems, databases, middleware.
Article 41. Evaluation of Information System Security
1. The content of the security evaluation of the organization's information system must include the following:
a) Assessing the system architecture to determine the suitability of installed equipment with the overall system architecture and security requirements;
b) Checking the configuration of security devices, automatic access control systems, terminal management systems, account lists;
c) Conducting penetration tests to assess network security levels, which must be mandatory for information systems connected to and providing services on the Internet, connecting to customers and third parties (excluding third parties within the same group).
2. The organization shall conduct security evaluations of information systems at level 2 or higher according to the provisions of Clause 1 of this Article before officially putting them into operation.
3. During the operation of information systems, the organization shall periodically conduct security evaluations at least as follows:
a) Once every six months for level 3 information systems according to the contents of Clause 1 of this Article;
b) Once a year for level 2 information systems and communication equipment directly interfacing with external environments such as the Internet, connecting to customers and third parties according to the contents of Clause 1 of this Article;
c) Once every two years for level 1 information systems.
4. Evaluation results must be documented in a report submitted to the legitimate representative and the competent authority. For non-compliant content regarding information security (if any), proposals for remediation measures, plans, deadlines for resolution must be made.
Article 42. Management of technical vulnerabilities
The management of technical vulnerabilities shall be carried out as follows:
1. Establish regulations on the assessment, management, and control of technical vulnerabilities of currently used information systems.
2. Proactively identify technical vulnerabilities through activities including:
a) Regularly updating information related to vulnerabilities and technical weaknesses;
b) Conducting scans to detect malicious codes, vulnerabilities, and technical weaknesses of currently used information systems at least as follows: (i) Every three months for level 3 information systems or information systems connected to the Internet; (ii) Every six months for other information systems.
3. Assess the impact level and risk of each vulnerability and technical weakness discovered in currently used information systems and develop plans to address them.
4. Develop and implement solutions to handle, rectify, and report the results of handling.
Article 43. Management of Information System Maintenance
The management of information system maintenance shall be carried out as follows:
1. Issue maintenance regulations for information systems immediately upon their official operation. Minimum maintenance regulations shall include the following contents:
a) Scope and objects subject to maintenance;
b) Timing and frequency of maintenance;
c) Technical procedures and scripts to perform maintenance for each component and the entire information system;
d) Report to the competent authority if any incident is discovered during maintenance;
đ) Assign and determine the responsibilities of the department responsible for maintenance and supervision of maintenance.
2. Carry out maintenance according to the provisions of Clause 1 of this Article for information systems directly managed by the organization.
3. Review minimum maintenance regulations annually or when there are changes in the information system.
Section 8
INFORMATION SECURITY INCIDENT MANAGEMENT
Article 44. Incident Handling Procedures
The management of incidents shall be carried out as follows:
1. Issue incident handling procedures for information security incidents including the following minimum contents:
a) Receiving information about incidents occurring;
b) Evaluating the severity and scope of impact of the incident on the operation of the information system. Depending on the severity and scope of impact of the incident, report to corresponding management levels for guidance on handling;
c) Implement measures to handle and rectify the incident;
d) Record the file and report the results of incident handling.
2. Specify the responsibilities of individuals and groups in reporting, receiving, and handling information security incidents.
3. Develop templates to record and store incident handling files.
Article 45. Control and Rectification of Incidents
The control and rectification of incidents shall be carried out as follows:
1. Compile a list of information security incidents and incident handling plans for information systems from level 2 and above; review and update the list and rescue plans at least every six months.
2. Immediately report to the competent authority and relevant persons when an information security incident occurs to take corrective measures as soon as possible.
3. During the inspection, handling, and rectification of incidents, collect, record, protect evidence, and store it within the organization.
4. Determine the cause and implement preventive measures to avoid recurrence of incidents after rectification.
5. In cases where information security incidents involve violations of laws, the organization has the responsibility to collect and provide evidence to the competent authorities in accordance with the provisions of the law.
Article 46. Cybersecurity Operations Center
The cybersecurity operations center shall perform the following tasks:
1. Proactively monitor, collect, and receive information and warnings about potential risks and security threats from both internal and external sources.
2. Establish a system for managing and analyzing security information events (SIEM), and implement centralized collection and storage of at least the following information: logs from information systems at level 2 and above; warnings and logs from network security equipment (firewalls, IPS/IDS).
3. Analyze information to detect and warn about cyber attack risks and security incidents, and must send warnings to system administrators when incidents related to the following systems are detected: (i) Customer service information systems requiring 24/7 operation; (ii) Online transaction systems; (iii) Information systems at level 3.
4. Organize coordination for incident response and containment, mitigate impact, and minimize damage to information systems when incidents occur.
5. Investigate, determine the origin, methods, and means of attacks, and implement preventive measures to avoid recurrence of incidents.
6. Provide information upon request of the State Bank of Vietnam to support cyber security monitoring in the banking sector.
Article 47. Incident Response Activities
1. The banking sector's incident response network (Network) has the responsibility to coordinate resources within and outside the sector to effectively respond to cyber security incidents, contributing to ensuring the safe operation of the banking system.
2. The Network includes:
a) A Network Management Board established by the Governor of the State Bank of Vietnam;
b) The Coordination Agency is the Department of Information Technology (State Bank of Vietnam);
c) Network members: the Department of Information Technology (State Bank of Vietnam), credit organizations (dedicated units for information security), and voluntary participants in the Network are agencies and organizations that voluntarily join.
3. Principles in coordinating and responding to incidents
a) Organizations as stipulated in point c Clause 2 of this Article must have the responsibility to provide resources and become members of the Network;
b) When encountering cyber security incidents, members must report to the Coordination Agency according to Clause 1 of Article 53 of this Circular;
c) When encountering serious incidents that cannot be resolved on their own, members must request assistance from the Coordination Agency;
d) Based on each incident, the Coordination Agency will request support from Network members or relevant state authorities with jurisdiction to assist and respond.
4. Principles for managing and using information in coordinating and responding to incidents:
a) Information exchanged and provided during coordination and incident response activities is confidential information;
b) Strictly prohibit organizations and individuals from using information exchanged during coordination and incident response activities to affect the reputation and image of the information provider.
Section 9
ENSURING CONTINUOUS OPERATION OF INFORMATION SYSTEMS
Article 48. Principles for Ensuring Continuous Operation
1. Implement the following minimum requirements:
a) Assess the impact and evaluate risks associated with the interruption or cessation of information system operations;
b) Develop procedures and scenarios for ensuring continuous operation of information systems as prescribed in Article 50 of this Circular;
c) Organize implementation of continuous operation assurance as prescribed in Article 51 of this Circular.
2. Based on the impact assessment and risk evaluation under point a Clause 1 of this Article, the organization shall establish a list of information systems that need to ensure minimum continuous operation including:
a) Information systems serving daily internal operations of the organization and not accepting more than 4 hours of downtime;
b) Systems serving customers requiring 24/7 operation;
c) Systems providing online transactions to customers;
d) Information systems at level 3.
3. Information systems that need to ensure continuous operation as stipulated in Clause 2 of this Article must ensure high availability and have disaster recovery systems.
Article 49. Construction of Disaster Prevention Systems
1. Organizations must construct disaster prevention systems that meet the following requirements:
a) Assess risks and consider the possibility of disasters affecting both the main information system and the disaster prevention information system simultaneously when selecting locations for the disaster prevention system, such as natural disasters like earthquakes, floods, typhoons, pandemics; human and technological factors like power grid failures, fires, traffic accidents, cyber security attacks;
b) The location of the disaster prevention system must comply with the requirements stipulated in Article 16 of this Circular;
c) The disaster prevention system must ensure the ability to replace the main system within the following timeframes: (i) four hours for: internal daily operations information systems of the organization that cannot tolerate more than four hours of downtime, customer service systems requiring 24/7 operation, online transaction provision systems for customers, level 3 information systems; (ii) twenty-four hours for other systems.
2. Organizations with only one office in Vietnam must have a backup office at a separate location and equipped to ensure continuous operation as a replacement for their main office.
Article 50. Construction of Procedures and Scenarios Ensuring Continuous Operation
Organizations must construct procedures and scenarios ensuring continuous operation as follows:
1. Develop procedures for handling situations involving loss of safety and disruption of operations of each component in the information system from level 2 onwards.
2. Develop scenarios for switching to the disaster prevention system to replace the main system's operations, including content, implementation sequence, and estimated completion time, meeting the following requirements:
a) Having resources, means, and necessary requirements to implement;
b) Having forms to record results;
c) Arranging and assigning responsibilities to personnel participating in roles such as directing implementation, monitoring, switching, formal operation, and result verification;
d) Applying measures to ensure information security;
e) Having plans to ensure continuous operation when the switch is not successful.
3. Organizations with only one office in Vietnam must develop scenarios for switching operations to the backup office.
4. Switching procedures and scenarios must be tested and updated when there are changes in the information system, organizational structure, personnel, and responsibility allocation of related departments within the organization.
Article 51. Organization of Implementation to Ensure Continuous Operation
1. Organizations must have plans and organize the implementation of continuous operation of information systems according to the following requirements:
a) At least once every six months, conduct inspections and evaluations of the disaster prevention system's operations;
b) Annually, perform the official switch from the main system to the disaster prevention system for a minimum of one working day for each information system listed in Clause 2 of Article 48 of this Circular; evaluate the results and update switching procedures and scenarios (if applicable).
2. Organizations with only one office in Vietnam must organize regular annual exercises to ensure continuous operation.
3. Notify the State Bank of Vietnam (Information Technology Department) of the exercise plan for switching operations to ensure continuous operation at least five working days before implementation.
Section 10
INTERNAL AUDIT AND REPORTING REGIME
Article 52. Internal Inspection
The organization shall implement internal inspection as follows:
1. Establish internal inspection regulations concerning information security assurance work of the organization.
2. Develop plans and conduct self-inspection of compliance with the provisions of this Circular and the organization's internal regulations on information security assurance at least once a year.
3. The results of the inspection regarding the information security assurance work of the organization must be compiled into a report sent to the legal representative and competent authority, wherein issues that have not been resolved to ensure compliance with information security regulations (if any) must include a handling plan and implementation schedule.
4. The organization shall implement and report the results of addressing the issues mentioned in the report in accordance with Clause 3 of this Article.
Article 53. Reporting System
The organization is responsible for sending reports to the State Bank of Vietnam (Information Technology Department) on the following contents:
1. Report on cyber incidents within 24 hours from the time of discovery and five working days after completing the incident resolution according to the Appendix attached to this Circular to the email address [email protected].
2. Submit a risk assessment report in accordance with Clause 3, Article 32 of this Circular directly or via postal service to the State Bank of Vietnam (Information Technology Department, 64 Nguyen Chi Thanh Street, Hanoi) at least ten working days before outsourcing all system management work from level 2 onwards.
Chapter III
IMPLEMENTING PROVISIONS
Article 54. Responsibilities of units under the State Bank of Vietnam
1. The Information Technology Department is responsible for:
a) Monitoring and compiling reports to the Governor of the State Bank of Vietnam on the implementation situation of organizations in accordance with this Circular;
b) Annually developing plans to inspect the implementation of this Circular;
c) Taking the lead and coordinating with related units under the State Bank of Vietnam to handle any difficulties arising during the implementation of this Circular.
2. Banking inspection agencies are responsible for coordinating with the Information Technology Department to inspect the implementation of this Circular at organizations and handle administrative violations according to the law.
Article 55. Effectiveness and Implementation
1. This Circular takes effect from January 1, 2019, except for the case stipulated in Clause 2 of this Article and replaces Circular No. 31/2015/TT-NHNN dated December 28, 2015 issued by the Governor of the State Bank of Vietnam on Regulations on Ensuring Safety and Secrecy of Information Technology Systems in Banking Activities and Decision No. 29/2008/QD-NHNN dated October 13, 2008 issued by the Governor of the State Bank of Vietnam on Provisions on Maintenance of Computer Equipment Systems in the Banking Industry.
2. Point b, Clause 2, Article 12 takes effect from January 1, 2020.
3. The Director of the Information Technology Department, heads of related units under the State Bank of Vietnam, Chairmen of the Board of Directors, Members of the Board of Management, General Directors (Directors) of credit institutions, foreign bank branches, and organizations providing intermediary payment services are responsible for implementing this Circular./.
Original document (PDF)
Relations map
Click a document to open. A red border = a relation that changes validity.
Translations
This document is available in the following languages: