Circular No. 20/2020/TT-NHNN amends and supplements certain provisions of Circular No. 47/2014/TT-NHNN on technical requirements for security safety regarding equipment serving bank card payments. This document focuses on enhancing encryption standards and measures to protect network information and data.
Scope of application
The State Bank of Vietnam, credit institutions, units under the State Bank, Branch Governors of the State Bank in provinces and centrally administered cities, organizations engaged in card activities
Key points
- Strong encryption algorithms must have a minimum key length of 112 bits (Article 1.1)
- Do not provide internal network addresses and routing information to third parties that have not been approved (Article 1.2)
- Strictly control access from the main card data environment to the Internet (Article 1.3)
- Encrypt all remote management connections using strong encryption methods (Article 1.4)
- Review and ensure that hardware and software equipment is supported technically by the manufacturer (Article 1.5)
🌐 Social impact of this document
- Enhance cybersecurity and information security in card payments
- Increase investment costs for encryption systems and security monitoring
- Reduce the risk of data loss and financial fraud
❓ Frequently asked questions
What is the minimum key length for strong encryption algorithms in this Circular?
The minimum key length is 112 bits.
Is it permissible for users to provide internal network addresses to third parties?
No, unless approved by the competent authority (Article 1.2).
How should access from the main card data environment to the Internet be controlled?
It must be approved and strictly controlled by the competent authority (Article 1.3).
Is it mandatory to encrypt remote management connections using strong encryption methods?
Mandatory, according to Article 1.4.
How should reviews be conducted to ensure that hardware and software equipment is supported technically by the manufacturer?
Regularly review and ensure compliance (Article 1.5).
Full text
CIRCULAR
Amending and supplementing certain articles of Circular No. 47/2014/TT-NHNN dated December 31, 2014
issuedshareholders, regarding technical requirements
for security on equipment serving bank card payments
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010; the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to Decree No. 35/2007/NĐ-CP dated March 8, 2007 of the Government on electronic transactions in banking activities;
Pursuant to Decree No. 101/2012/NĐ-CP dated November 22, 2012 of the Government on non-cash payment; Decree No. 80/2016/NĐ-CP dated July 1, 2016 of the Government amending and supplementing certain articles of Decree No. 101/2012/NĐ-CP dated November 22, 2012 of the Government on non-cash payment;
Decree No. 16/2017/NĐ-CP dated Credit institutions, foreign bank branches restructure repayment terms for the principal balance and/or interest of a debt (including debts within the scope of adjustment under Decree No. 55/2015/NĐ-CP dated June 9, 2015 of the Government on credit policies to serve the development of agriculture and rural areas (as amended and supplemented)) when meeting all of the following conditions: of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Information Technology;
The Governor of the State Bank of Vietnam promulgates this Circular amending and supplementing certain articles of Circular No. 47/2014/TT-NHNN dated December 31, 2014 of the Governor of the State Bank of Vietnam regarding technical requirements for security on equipment serving bank card payments (hereinafter referred to as Circular 47/2014/TT-NHNN).
Article 1. Amending and supplementing certain articles of Circular 47/2014/TT-NHNN
1. Clause 9 of Article 2 shall be amended and supplemented as follows:
"9. Strong encryption is a method of encryption based on algorithms that have been tested and widely accepted worldwide with a minimum key length of 112 (one hundred twelve) bits and appropriate key management techniques. The minimum algorithms include: AES (256 bits); TDES (168 bits); RSA (2048 bits); ECC (224 bits); ElGamal (2048 bits).".
2. Point d of Clause 1 of Article 3 shall be amended and supplemented as follows:
"d) Not providing internal network addresses (IP addresses) and routing information to other organizations without approval from authorized persons. Measures must be taken to conceal internal network addresses and internal routing table information when connecting to third parties;".
3. Point c of Clause 3 of Article 3 shall be amended and supplemented as follows:
"c) Accesses from the main card data environment to the Internet must be approved by authorized persons and strictly controlled.".
4. Clause 5 shall be added to Article 4 as follows:
"5. Encrypt all remote administration access connections using strong encryption methods.".
5. Clause 8 shall be added to Article 5 as follows:
"8. Regularly review to ensure that hardware and software equipment receives technical support from manufacturers.".
6. Clause 1 of Article 6 shall be amended and supplemented as follows:
"1. Access to all components of the information system serving bank card payments must be authenticated using at least one of the following methods: secret key code; authentication device or card; biometrics.".
7. Point e of Clause 4 of Article 6 shall be amended and supplemented as follows:
"e) Revoke or invalidate accounts that are not activated for use, expired, or inactive for a maximum period of 90 days since the last access;".
8. Clause 3 of Article 10 shall be amended and supplemented as follows:
"3. All POS machines must display the contact phone number of the Card Issuing Organization.".
9. Point c of Clause 1 of Article 14 shall be amended and supplemented as follows:
"c) The card number must be concealed appropriately when displayed (only displaying up to the first six digits and the last four digits) and may only be fully displayed to: cardholders, competent state authorities as prescribed by law, some employees as required by work and approved by authorized persons;".
10. Clause 1 of Article 15 shall be amended and supplemented as follows:
"1. Use strong encryption methods and appropriate security protocols to protect card authentication data during transmission over networks connected to external sources (Internet, wireless networks, mobile communication networks, and other networks).".
11. Point b of Clause 1 of Article 17 shall be amended and supplemented as follows:
"b) Use cameras or other suitable surveillance measures to monitor entry and exit to server room areas, printing and issuance areas, data storage and processing areas for main card data. Surveillance data must be stored securely and accessible for a minimum of three months.".
12. Point i shall be added to Clause 1 of Article 18 as follows:
"i) Enact policies and procedures for monitoring all accesses to network resources and main card data and disseminate them to all individuals and departments involved in card operations within the organization.".
Article 2.
Replace the phrase "Information Technology Department" with the phrase "Information Technology Department" in Articles 20, 22, and 23 of Circular 47/2014/TT-NHNN.
This Circular takes effect from December 25, 2025/.
The Director of the Office, the Director of the Information Technology Department, the Heads of units under the State Bank of Vietnam, the Governors of the State Bank of Vietnam branches in provinces and centrally governed cities, and organizations engaged in card activities are responsible for organizing the implementation of this Circular.
Article 4. Implementation provisions
This Circular takes effect from February 15, 2021./.
DEPUTY DIRECTOR
Original document (PDF)
Download
Relations map
Click a document to open. A red border = a relation that changes validity.
Translations
This document is available in the following languages: