This Law stipulates the state management, responsibilities of agencies, organizations, and individuals in protecting cyber security in Vietnam. It includes contents such as selecting, training cyber security protection forces; disseminating knowledge about cyber security; and specific responsibilities of the Ministry of Public Security, the Ministry of National Defense, the Ministry of Information and Communications, the Government Cryptographic Committee, ministries, sectors, and provincial people's committees in implementing state management over cyber security.
适用范围
This Law applies to all agencies, organizations, and individuals related to protecting cyber security in Vietnam.
要点
- State Management of Cyber Security
- Selection, Training of Cyber Security Protection Forces
- Dissemination of Knowledge about Cyber Security
- Responsibilities of the Ministry of Public Security in managing and implementing measures to protect cyber security
- Responsibilities of the Ministry of National Defense in protecting cyber security within their scope of management
- Responsibilities of the Ministry of Information and Communications in coordinating with relevant agencies to protect cyber security
- Responsibilities of the Government Cryptographic Committee in protecting cyber security for cryptographic information systems and cryptographic products under their management
🌐 本文件的社会影响
- Enhancing awareness of the importance of cyber security in modern society
- Improving capabilities to prevent and respond to cyber security threats
- Strengthening coordination among state agencies to protect cyber security
❓ 常见问题
Who is primarily responsible for state management of cyber security?
The Ministry of Public Security is responsible before the Government for implementing state management over cyber security.
What responsibilities do businesses providing services on the internet have?
Businesses must remove illegal information regarding cyber security from services and information systems they manage and comply with other regulations concerning cyber security protection.
What are the responsibilities of the Government Cryptographic Committee in protecting cyber security?
The Government Cryptographic Committee protects cyber security for cryptographic information systems under their management and cryptographic products they provide.
全文
|
OF THE NATIONAL ASSEMBLY |
SOCIALIST REPUBLIC OF VIET NAM |
|
|
Independence - Freedom - Happiness |
|
Law number: 24/2018/QH14
|
|
LAW
CYBERSECURITY
____
On the basis of the Constitution of the Socialist Republic of Vietnam;
The National Assembly promulgates the Cybersecurity Law.
Chapter I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Law stipulates activities for protecting national security and ensuring public order and social safety on cyberspace; responsibilities of agencies, organizations, and individuals related to such activities.
Article 2. Interpretation of Terms
In this Law, the following terms shall be understood as follows:
1. Cybersecurity means ensuring activities on cyberspace do not harm national security, public order, social safety, rights, and legitimate interests of agencies, organizations, and individuals.
2. Cybersecurity protection means preventing, detecting, blocking, and handling acts that infringe upon cybersecurity.
3. Cyberspace is a network of interconnected information technology infrastructure, including telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases; it is a place where people carry out social behaviors without being limited by space and time.
4. National cyberspace is cyberspace established, managed, and controlled by the Government.
5National cyberspace infrastructure is the system of physical and technical facilities to create, transmit, collect, process, store, and exchange information on national cyberspace, including:
a) Transmission systems including the national transmission system, international connection transmission system, satellite system, transmission systems of enterprises providing services on telecommunications networks, the Internet, and additional services on cyberspace;
b) Core service systems including the national traffic management and routing system, national domain name resolution system (DNS), national certification system (PKI/CA), and enterprise Internet connection and access service provision systems on telecommunications networks, the Internet, and additional services on cyberspace;
c) Information technology services and applications including online services; information technology applications with network connections serving management and operation of agencies, organizations, important economic and financial groups; national databases.
Online services include electronic government, e-commerce, electronic information websites, online forums, social networks, blogs;
d) Smart city information technology infrastructure, Internet of Things, hybrid real-virtual systems, cloud computing, big data systems, fast data systems, and artificial intelligence systems.
6. CInternational network connection is the location where activities of signal transmission between Vietnam and other countries and territories take place.
7. Cybercrime is the act of using cyberspace, information technology, or electronic devices to commit crimes as defined in the Penal Code.
8. Cyber Attack is the act of using cyberspace, information technology, or electronic devices to destroy, disrupt the operation of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, and electronic devices.
9. Cyberterrorism is the act of using cyberspace, information technology, or electronic devices to commit terrorist acts or finance terrorism.
10. Cyber espionage is the intentional act of bypassing warnings, access codes, passwords, firewalls, using another person's administrative rights, or other methods to illegally obtain and collect information and information resources on telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, databases, and electronic devices of agencies, organizations, and individuals.
11. Digital account is information used to authenticate, verify, and grant permissions to use applications and services on cyberspace.
12. Cybersecurity threat is a situation where cyberspace exhibits signs threatening national security, causing serious damage to public order and social safety, and rights and legitimate interests of agencies, organizations, and individuals.
13. Cybersecurity incident is an unexpected event occurring on cyberspace that infringes upon national security, public order, social safety, and rights and legitimate interests of agencies, organizations, and individuals.
14. Critical cybersecurity situation is an event occurring on cyberspace when there are severe acts of infringement upon national security, causing extremely serious damage to public order and social safety, and rights and legitimate interests of agencies, organizations, and individuals.
Article 3. State Policy on Cybersecurity
1. Prioritize the protection of cybersecurity in national defense, security, economic and social development, science, technology, and foreign relations.
2. Build a healthy cyberspace that does not harm national security, public order, social safety, and the legitimate rights and interests of agencies, organizations, and individuals.
3. Prioritize resources for building specialized forces to protect cybersecurity; enhance the capacity of cybersecurity protection forces and organizations and individuals participating in cybersecurity protection; prioritize investment in research and development of science and technology for cybersecurity protection.
4. Encourage and create conditions for organizations and individuals to participate in protecting cybersecurity, handling threats to cybersecurity; research and develop technology, products, services, and applications aimed at protecting cybersecurity; coordinate with competent authorities in protecting cybersecurity.
5. Strengthen international cooperation on cybersecurity.
Article 4. Principles of Cybersecurity Protection
1. Adhere to the Constitution and laws; ensure the interests of the State, the rights and legitimate interests of agencies, organizations, and individuals.
2. Be under the leadership of the Communist Party of Vietnam, unified management by the State; mobilize the comprehensive strength of the political system and the entire nation; give full play to the core role of specialized forces protecting cybersecurity.
3. Closely combine the tasks of protecting cybersecurity, protecting important information systems related to national security with the tasks of economic and social development, ensuring human rights, citizens' rights, and creating conditions for agencies, organizations, and individuals to operate in cyberspace.
4. Proactively prevent, detect, block, combat, and defeat all activities using cyberspace to infringe upon national security, public order, social safety, and the legitimate rights and interests of agencies, organizations, and individuals; be ready to counter threats to cybersecurity.
5. Implement cybersecurity protection activities for national cyberspace infrastructure; apply measures to protect important information systems related to national security.
6. Important information systems related to national security must be reviewed and certified to meet cybersecurity conditions before being put into operation and use; regularly inspect and monitor cybersecurity during the usage period and promptly respond to and rectify cybersecurity incidents.
7. All acts violating laws on cybersecurity must be dealt with promptly and strictly.
Article 5. Measures for Cybersecurity Protection
1. Measures for cybersecurity protection include:
a) Cybersecurity assessment;
b) Evaluation of cybersecurity conditions;
c) Cybersecurity inspection;
d) Cybersecurity monitoring;
đ) Response and rectification of cybersecurity incidents;
e) Struggle to protect cybersecurity;
g) Use of cryptographic means to protect network information;
h) Blocking, requesting temporary suspension, or cessation of provision of network information; suspending, temporarily suspending, or requesting cessation of establishment, provision, and use of telecommunications networks, the Internet, production and use of radio transmitters according to the provisions of the law;
i) Requesting removal or accessing to remove illegal information or false information on cyberspace that infringes upon national security, public order, social safety, and the legitimate rights and interests of agencies, organizations, and individuals;
k) Collecting electronic data related to activities infringing upon national security, public order, social safety, and the legitimate rights and interests of agencies, organizations, and individuals on cyberspace;
l) Sealing off, restricting the operation of information systems; suspending, temporarily suspending, or requesting cessation of operation of information systems, reclaiming domain names according to the provisions of the law;
m) Initiating prosecution, investigation, prosecution, and trial according to the provisions of the Criminal Procedure Code;
n) Other measures prescribed by laws on national security and laws on administrative violation handling.
2. The Government shall prescribe procedures and formalities for applying cybersecurity protection measures, except for the measures prescribed in points m and n of Clause 1 of this Article.
Article 6. Protection of National Cyberspace
The State shall apply measures to protect national cyberspace; prevent and handle acts that infringe upon national security, public order, social safety, rights and legitimate interests of agencies, organizations, and individuals on cyberspace.
Article 7. International Cooperation on Cybersecurity
1. International cooperation on cybersecurity shall be carried out based on respecting independence, sovereignty, and territorial integrity, non-interference in each other's internal affairs, equality, and mutual benefit.
2. Contents of international cooperation on cybersecurity include:
a) Researching and analyzing cyber security trends;
b) Establishing mechanisms and policies to promote cooperation between Vietnamese organizations and individuals with foreign organizations and individuals, and international organizations operating in cybersecurity;
c) Sharing information and experiences; supporting training, equipment, and technology for cybersecurity protection;
d) Preventing and combating cybercrime, acts that infringe upon cybersecurity; preventing threats to cybersecurity;
đ) Advising, training, and developing cybersecurity human resources;
e) Organizing international conferences, seminars, and forums on cybersecurity;
g) Signing and implementing international treaties and agreements on cybersecurity;
h) Implementing international cooperation programs and projects on cybersecurity;
i) Other activities of international cooperation on cybersecurity.
3. The Ministry of Public Security shall be responsible before the Government for leading and coordinating the implementation of international cooperation on cybersecurity, except for the international cooperation activities of the Ministry of Defense.
The Ministry of Defense shall be responsible before the Government for implementing international cooperation on cybersecurity within its management scope.
The Ministry of Foreign Affairs shall have the responsibility to coordinate with the Ministry of Public Security and the Ministry of Defense in international cooperation activities on cybersecurity.
In cases where international cooperation on cybersecurity involves the responsibilities of multiple ministries and sectors, the decision shall be made by the Government.
4. International cooperation activities on cybersecurity of other ministries, sectors, and localities must have participation opinions from the Ministry of Public Security in writing before implementation, except for the international cooperation activities of the Ministry of Defense.
Article 8. Prohibited Acts Regarding Cybersecurity
1. Using cyberspace to carry out the following acts:
a) Acts prescribed in Clause 1 of Article 18 of this Law;
b) Organizing, conducting, conspiring, inciting, bribing, deceiving, enticing, training, and instructing people to oppose the Socialist Republic of Vietnam;
c) Distorting history, denying revolutionary achievements, undermining the solidarity of the entire people, insulting religions, discriminating against gender, and racial discrimination;
d) Providing false information causing panic among the people, causing damage to economic and social activities, creating difficulties for state agency operations or public servants, infringing upon the rights and legitimate interests of other agencies, organizations, and individuals;
đ) Engaging in prostitution, social evils, trafficking in persons; posting obscene, pornographic, criminal information; destroying ethnic customs, morals, and community health;
e) Inciting, enticing, and instigating others to commit crimes.
2. Carrying out cyber attacks, cyber terrorism, cyber espionage, cybercrime; causing incidents, attacking, infiltrating, taking control, distorting, interrupting, paralyzing, or destroying important information systems concerning national security.
3. Producing and putting into use tools, means, software, or engaging in acts hindering or disrupting the operation of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, electronic devices; spreading harmful computer programs affecting the operation of telecommunications networks, the Internet, computer networks, information systems, information processing and control systems, electronic devices; illegally accessing telecommunications networks, computer networks, information systems, information processing and control systems, databases, electronic devices of others.
4. Resisting or obstructing the activities of cybersecurity protection forces; unlawfully attacking and rendering ineffective cybersecurity protection measures.
5. Exploiting or misusing cybersecurity protection activities to infringe upon national sovereignty, interests, national security, public order, social safety, rights and legitimate interests of agencies, organizations, and individuals, or for personal gain.
6. Other acts violating the provisions of this Law.
Article 9. Handling Violations of Law on Cybersecurity
Any person who commits acts violating the provisions of this Law shall be subject to disciplinary action, administrative violation handling, or criminal responsibility pursuit, depending on the nature and degree of the violation; if damage is caused, compensation must be provided according to the law.
Chapter II
PROTECTION OF CYBERSECURITY FOR CRITICAL INFORMATION SYSTEMS
RELATED TO NATIONAL SECURITY
Article 10. Critical Information Systems Related to National Security
1. Critical information systems related to national security are information systems that, when encountering incidents, intrusion, control takeover, distortion, disruption, cessation, paralysis, attack, or destruction, will severely infringe upon cybersecurity.
2. Critical information systems related to national security include:
a) Military, security, diplomatic, and cryptographic information systems;
b) Information systems storing and processing state secrets;
c) Information systems serving the preservation and storage of particularly important objects and documents;
d) Information systems serving the preservation of materials and substances particularly dangerous to humans and the ecological environment;
đ) Information systems serving the preservation, production, and management of other particularly important facilities related to national security;
e) Important information systems serving the operations of central agencies and organizations;
g) National information systems in energy, finance, banking, telecommunications, transportation, natural resources and environment, chemicals, healthcare, culture, and press sectors;
h) Automatic control and monitoring systems at critical projects and targets related to national security.
3. The Prime Minister shall issue and amend the List of critical information systems related to national security.
4. The Government shall stipulate the coordination between the Ministry of Public Security, the Ministry of Defense, the Ministry of Information and Communications, the Government Cryptographic Agency, and relevant ministries and sectors in assessing, evaluating, inspecting, supervising, responding, and mitigating incidents concerning critical information systems related to national security.
Article 11. Cybersecurity Assessment for Critical Information Systems Related to National Security
1. Cybersecurity assessment is an activity examining and evaluating cybersecurity aspects to serve the decision-making process for building or upgrading information systems.
2. The subjects of cybersecurity assessment for critical information systems related to national security include:
a) Feasibility study reports and construction design files of investment projects for building information systems before approval;
b) Upgrading project proposals for information systems before approval.
3. The contents of cybersecurity assessment for critical information systems related to national security include:
a) Compliance with cybersecurity regulations and conditions in design;
b) Suitability with protection plans, response measures, and human resource deployment for cybersecurity.
4. The authority to conduct cybersecurity assessments for critical information systems related to national security is as follows:
a) The specialized cybersecurity protection force under the Ministry of Public Security shall conduct cybersecurity assessments for critical information systems related to national security, except for cases specified in points b and c of this clause;
b) The specialized cybersecurity protection force under the Ministry of Defense shall conduct cybersecurity assessments for military information systems;
c) The Government Cryptographic Agency shall conduct cybersecurity assessments for cryptographic information systems under the Government Cryptographic Agency.
Article 12. Evaluation of Cybersecurity Conditions for National Security Information Systems
1. The evaluation of cybersecurity conditions is an activity to examine the cybersecurity compliance of information systems before they are put into operation and use.
2. National security information systems must meet the following conditions regarding:
a) Regulations, procedures, and plans to ensure cybersecurity; personnel operating and managing the system;
b) Ensuring cybersecurity for equipment, hardware, and software components of the system;
c) Technical measures to monitor and protect cybersecurity; measures to protect automatic control and surveillance systems, Internet of Things (IoT), hybrid real-virtual systems, cloud computing, big data systems, fast data systems, artificial intelligence systems;
d) Physical security measures including special isolation, data leakage prevention, signal interception prevention, access control.
3. The authority to evaluate cybersecurity conditions for national security information systems is defined as follows:
a) The specialized force responsible for cybersecurity under the Ministry of Public Security evaluates and certifies that the national security information systems meet cybersecurity conditions, except for cases specified in points b and c of this clause;
b) The specialized force responsible for cybersecurity under the Ministry of National Defense evaluates and certifies that military information systems meet cybersecurity conditions;
c) The Government Cryptographic Agency evaluates and certifies that government cryptographic information systems meet cybersecurity conditions.
4. National security information systems can be put into operation and use after being certified as meeting cybersecurity conditions.
5. The Government shall provide detailed regulations on Clause 2 of this Article.
Article 13. Cybersecurity Inspection of National Security Information Systems
1. Cybersecurity inspection is an activity to determine the current state of cybersecurity of information systems, infrastructure of information systems, or information stored, processed, and transmitted within information systems with the aim of preventing, detecting, and handling cyber threats and proposing solutions and measures to ensure normal operation of the information systems.
2. Cybersecurity inspections of national security information systems are carried out in the following situations:
a) When electronic devices or network security services are put into use in the information system;
b) When there are changes in the status of the information system;
c) Annual periodic inspections;
d) Unscheduled inspections when cybersecurity incidents occur, cybersecurity violations take place, or when there are state management requirements concerning cybersecurity, or when the deadline for addressing weaknesses and security vulnerabilities recommended by the specialized cybersecurity forces has expired.
3. The objects of cybersecurity inspections of national security information systems include:
a) Hardware, software, and digital equipment used in the information system;
b) Regulations and measures to ensure cybersecurity;
c) Information stored, processed, and transmitted within the information system;
d) Emergency response and remediation plans for cybersecurity incidents by the system managers;
đ) Measures to protect state secrets and prevent leaks and losses of state secrets through technical channels;
e) Personnel responsible for cybersecurity.
4. Managers of national security information systems are responsible for conducting cybersecurity inspections of information systems under their management in the situations specified in points a, b, and c of Clause 2 of this Article; they must report the results of the inspections in writing to the specialized cybersecurity forces under the Ministry of Public Security or the specialized cybersecurity forces under the Ministry of National Defense for military information systems before October each year.
5. Unscheduled cybersecurity inspections of national security information systems are defined as follows:
a) Before conducting the inspection, the specialized cybersecurity forces have the responsibility to notify the system managers in writing at least 12 hours in advance in case of cybersecurity incidents or cybersecurity violations; at least 72 hours in advance in case of state management requirements concerning cybersecurity or when the deadline for addressing weaknesses and security vulnerabilities recommended by the specialized cybersecurity forces has expired;
b) Within 30 days from the end of the inspection, the specialized cybersecurity forces will notify the results of the inspection and make demands on the system managers if weaknesses or security vulnerabilities are discovered; they will guide or participate in remediation upon request of the system managers;
c) The specialized cybersecurity forces under the Ministry of Public Security conduct unscheduled cybersecurity inspections of national security information systems, excluding military information systems managed by the Ministry of National Defense, government cryptographic information systems, and cryptographic products provided by the Government Cryptographic Agency to protect information classified as state secrets;
The specialized cybersecurity forces under the Ministry of National Defense conduct unscheduled cybersecurity inspections of military information systems;
The Government Cryptographic Agency conducts unscheduled cybersecurity inspections of government cryptographic information systems and cryptographic products provided by the Government Cryptographic Agency to protect information classified as state secrets;
d) Managers of national security information systems are responsible for cooperating with the specialized cybersecurity forces to conduct unscheduled cybersecurity inspections.
6. The results of cybersecurity inspections are kept confidential according to the provisions of the law.
Article 14. Cybersecurity Surveillance for National Security Information Systems
1. Cybersecurity surveillance is an activity involving the collection and analysis of information to identify cyber threats, cybersecurity incidents, vulnerabilities, security gaps, malware, and harmful hardware in order to issue warnings, address, and handle them.
2. The managers of national security information systems shall take the lead and coordinate with specialized forces responsible for cybersecurity to regularly conduct cybersecurity surveillance on information systems under their management; establish self-warning mechanisms and receive warnings about cyber threats, cybersecurity incidents, vulnerabilities, security gaps, malware, and harmful hardware, and develop emergency response plans.
3. Specialized forces responsible for cybersecurity shall conduct cybersecurity surveillance on national security information systems within their management scope; issue warnings and coordinate with system managers in addressing and handling cyber threats, cybersecurity incidents, vulnerabilities, security gaps, malware, and harmful hardware occurring in national security information systems.
Article 15. Response and Remediation of Cybersecurity Incidents for National Security Information Systems
1. The activities of responding to and remedying cybersecurity incidents for national security information systems include:
a) Identifying and confirming cybersecurity incidents;
b) Protecting the scene and collecting evidence;
c) Containing and limiting the scope of the cybersecurity incident to minimize damage caused by the incident;
d) Determining the targets, subjects, and scope requiring rescue operations;
đ) Verifying, analyzing, evaluating, and classifying cybersecurity incidents;
e) Implementing response and remediation plans for cybersecurity incidents;
g) Verifying the cause and tracing the origin;
h) Investigating and handling according to the provisions of the law.
2. Managers of national security information systems shall develop response and remediation plans for cybersecurity incidents for information systems under their management; implement these plans when cybersecurity incidents occur and promptly report to authorized specialized cybersecurity forces.
3. Coordination of response and remediation activities for cybersecurity incidents for national security information systems is regulated as follows:
a) Specialized cybersecurity forces under the Ministry of Public Security shall lead coordination of response and remediation activities for cybersecurity incidents occurring in national security information systems, except for cases stipulated in points b and c of this clause; participate in responding to and remediating cybersecurity incidents for national security information systems upon request; notify system managers when detecting cyber attacks or cybersecurity incidents;
b) Specialized cybersecurity forces under the Ministry of Defense shall lead coordination of response and remediation activities for cybersecurity incidents occurring in military information systems;
c) The Government Cryptographic Office shall lead coordination of response and remediation activities for cybersecurity incidents occurring in cryptographic information systems under the Government Cryptographic Office.
4. Agencies, organizations, and individuals shall be responsible for participating in responding to and remediating cybersecurity incidents occurring in national security information systems upon request from the coordinating force.
Chapter III
PREVENTION AND HANDLING OF ACTIONS VIOLATING CYBERSECURITY
Article 16. Prevention and handling of information in cyberspace containing propaganda against the Socialist Republic of Vietnam; incitement to cause riots, disrupt public security, disturb public order; defamation and slander; infringement on economic management order.
1. Information in cyberspace containing propaganda against the Socialist Republic of Vietnam includes:
a) Propaganda that distorts and slanders the people's administration;
b) Psychological warfare, incitement to aggressive war, division, and hatred among ethnic groups, religions, and peoples of different countries;
c) Insulting the nation, national flag, emblem, anthem, great men, leaders, and national heroes.
2. Information in cyberspace containing incitement to cause riots, disrupt public security, and disturb public order includes:
a) Calling for, mobilizing, urging, threatening, dividing, conducting armed activities, or using violence against the people's administration;
b) Calling for, mobilizing, urging, threatening, gathering crowds to cause disturbances, opposing public officials, hindering the operations of agencies and organizations, causing instability in public security and order.
3. Information in cyberspace containing defamation and slander includes:
a) Seriously insulting the honor, reputation, and dignity of others;
b) False information that infringes upon the honor, reputation, dignity, or causes damage to the legitimate rights and interests of agencies, organizations, and individuals.
4. Information in cyberspace containing infringement on economic management order includes:
a) False information about products, goods, money, bonds, promissory notes, government securities, checks, and other negotiable instruments;
b) False information in the fields of finance, banking, e-commerce, electronic payments, currency trading, capital raising, multi-level marketing, and securities.
5. Information in cyberspace containing false information causing panic among the people, damaging economic and social activities, hindering the operations of state agencies or public officials, and infringing upon the legitimate rights and interests of agencies, organizations, and individuals.
6. Managers of information systems shall be responsible for implementing technical measures to prevent, detect, block, and remove information with contents as prescribed in Clauses 1, 2, 3, 4, and 5 of this Article from their managed information systems when requested by specialized forces for cyber security protection.
7. Specialized forces for cyber security protection and competent authorities shall apply the measures prescribed in Points h, i, and l Clause 1 of Article 5 of this Law to handle information in cyberspace with contents as prescribed in Clauses 1, 2, 3, 4, and 5 of this Article.
8. Telecommunications network service providers, Internet service providers, value-added services in cyberspace, and managers of information systems shall cooperate with competent authorities to handle information in cyberspace with contents as prescribed in Clauses 1, 2, 3, 4, and 5 of this Article.
9. Organizations and individuals who draft, post, disseminate information in cyberspace with contents as prescribed in Clauses 1, 2, 3, 4, and 5 of this Article must remove such information when requested by specialized forces for cyber security protection and bear responsibility according to the provisions of the law.
Article 17. Prevention and combat of cyber espionage; protection of information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life on cyberspace.
1. Acts of cyber espionage; violation of state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life on cyberspace include:
a) Seizing, buying, selling, holding, intentionally disclosing information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life causing damage to the reputation, prestige, dignity, rights, and legitimate interests of agencies, organizations, and individuals;
b) Intentionally deleting, damaging, losing, or altering information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life transmitted or stored on cyberspace;
c) Intentionally changing, canceling, or rendering ineffective technical measures established and applied to protect information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life;
d) Uploading information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life onto cyberspace contrary to the provisions of the law;
đ) Intentionally listening in, recording audio, or filming conversations illegally;
e) Other intentional acts violating state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life.
2. Managers of information systems have the following responsibilities:
a) Conduct cybersecurity checks to detect and remove malicious code, harmful hardware, address weaknesses, and security vulnerabilities; identify, prevent, and handle illegal intrusion activities or other threats to cybersecurity; harmful, rectify weaknesses, security vulnerabilities; detect, prevent and handle illegal intrusion activities or other threats to cyber security;
b) Implement management and technical measures to prevent, detect, and stop acts of cyber espionage, violations of state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life on information systems and promptly remove related information;information related to such actions;
c) Coordinate and implement requests of specialized cyber security forces;c) Coordinate and implement requests from specialized cybersecurity forces regarding prevention and combat of cyber espionage, protection of information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life on information systems.
3. Agencies drafting and storing information, documents classified as state secrets have the responsibility to protect state secrets drafted and retained on computers, other devices, or exchanged on cyberspace in accordance with the law on protecting state secrets.
4. The Ministry of Public Security has the following responsibilities, except for the provisions of Clause 5 and Clause 6 of this Article:
a) Conduct cybersecurity checks on information systems important to national security to detect and remove malicious code, harmful hardware, address weaknesses, and security vulnerabilities; identify, prevent, and handle illegal intrusion activities;
b) Conduct cyber security checks on devices, products, telecommunications services, digital equipment, electronic devices before their use in national security critical information systems;
c) Monitor cyber security for national security critical information systems to detect and handle unauthorized collection of information classified as state secrets;
b) Conduct cybersecurity checks on communication equipment, products, services, digital devices, electronic devices before their use in information systems important to national security;
d) Participate in research and production of products for storing and transmitting information and documents containing state secret content; encrypted information products on cyberspace according to assigned functions and tasks;
e) Inspect and check the protection of state secrets on cyberspace by state agencies and the protection of cyber security by managers of national security critical information systems;
c) Monitor cybersecurity on information systems important to national security to detect and handle illegal collection of information classified as state secrets;
5. The Ministry of National Defense shall be responsible for implementing the contents prescribed at points a, b, c, d, and e of Clause 4 of this Article for military information systems.
d) Detect and handle acts of uploading, storing, and exchanging illegally information, documents containing content classified as state secrets on cyberspace;
Article 18. Prevention and control of acts using cyberspace, information technology, and electronic means to violate laws on national security, public order, and social safety
1. Acts using cyberspace, information technology, and electronic means to violate laws on national security, public order, and social safety include:
a) Posting, disseminating information on cyberspace containing contents stipulated in Clauses 1, 2, 3, 4, and 5 of Article 16 and the act stipulated in Clause 1 of Article 17 of this Law;
b) Stealing property; organizing gambling, online gambling through the Internet; stealing international telecommunications charges over the Internet; infringing intellectual property rights on cyberspace;
c) Impersonating websites of agencies, organizations, or individuals; forging, circulating, stealing, buying, selling, collecting, illegally exchanging other people's credit card information, bank accounts; issuing, providing, and illegally using payment instruments;
d) Propaganda, advertising, buying, and selling goods and services prohibited under the law;
đ) Guiding others to commit acts violating the law;
e) Other acts using cyberspace, information technology, and electronic means to violate laws on national security, public order, and social safety.
2. Special forces responsible for cyber security shall be responsible for preventing and controlling acts using cyberspace, information technology, and electronic means to violate laws on national security, public order, and social safety.
Article 19. Prevention and control of cyber attacks
1. Acts of cyber attack and related acts include:
a) Disseminating harmful computer programs affecting telecommunication networks, the Internet, computer networks, information systems, information processing and control systems, data bases, and electronic devices;
b) Causing obstruction, disruption, paralysis, interruption, cessation of operations, illegal blocking of data transmission of telecommunication networks, the Internet, computer networks, information systems, information processing and control systems, and electronic devices;
c) Intruding, damaging, and stealing data stored or transmitted through telecommunication networks, the Internet, computer networks, information systems, information processing and control systems, data bases, and electronic devices;
d) Intruding, creating, or exploiting vulnerabilities and security flaws and system services to steal information and gain improper benefits;
đ) Producing, buying, trading, giving away tools, equipment, software with functions to attack telecommunication networks, the Internet, computer networks, information systems, information processing and control systems, data bases, and electronic devices for illegal purposes;
e) Other acts affecting the normal operation of telecommunication networks, the Internet, computer networks, information systems, information processing and control systems, data bases, and electronic devices.
2. Managers of information systems shall be responsible for applying technical measures to prevent and stop acts stipulated in Points a, b, c, d, and e of Clause 1 of this Article within their managed information systems.
3. When a cyber attack infringes upon or threatens to infringe upon sovereignty, interests, national security, causing serious harm to public order and social safety, special forces responsible for cyber security shall take the lead, coordinate with managers of information systems and relevant organizations and individuals to apply measures to determine the origin of the cyber attack, collect evidence; request telecommunications service providers, Internet service providers, and additional services on cyberspace to filter information to stop and eliminate cyber attacks and provide full and timely related information and documents.
4. Responsibilities for prevention and control of cyber attacks are defined as follows:
a) The Ministry of Public Security shall take the lead, coordinate with relevant ministries and sectors to implement preventive, detection, and handling work of acts stipulated in Clause 1 of this Article that infringe upon or threaten to infringe upon sovereignty, interests, national security, causing serious harm to public order and social safety nationwide, except for cases stipulated in Points b and c of this Clause;
b) The Ministry of National Defense shall take the lead, coordinate with relevant ministries and sectors to implement preventive, detection, and handling work of acts stipulated in Clause 1 of this Article concerning military information systems;
c) The Government Cryptographic Agency shall take the lead, coordinate with relevant ministries and sectors to implement preventive, detection, and handling work of acts stipulated in Clause 1 of this Article concerning cryptographic information systems under the Government Cryptographic Agency.
Article 20. Prevention and Combating Cyber Terrorism
1. The competent state agencies shall be responsible for applying measures as prescribed in this Law, Article 29 of the Cybersecurity Law, and laws on prevention and combating terrorism to handle cyber terrorism.
2. The managers of information systems shall regularly review and inspect the information systems under their management to eliminate the risk of cyber terrorism.
3. When signs or acts of cyber terrorism are discovered, agencies, organizations, and individuals must promptly report them to cybersecurity protection forces. The agency receiving the report shall be responsible for fully receiving reports about cyber terrorism and promptly notifying the specialized cybersecurity protection forces.
4. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to implement work on preventing and combating cyber terrorism, apply measures to neutralize sources of cyber terrorism, handle cyber terrorism, and minimize the consequences for information systems to the lowest extent possible, except in cases provided for in Clause 5 and Clause 6 of this Article.
5. The Ministry of National Defense shall take the lead and coordinate with relevant ministries and sectors to implement work on preventing and combating cyber terrorism, apply measures to handle cyber terrorism occurring against military information systems.
6. The Government Cryptographic Office shall take the lead and coordinate with relevant ministries and sectors to implement work on preventing and combating cyber terrorism, apply measures to handle cyber terrorism occurring against cryptographic information systems under the Government Cryptographic Office.
Article 21. Prevention and Handling of Dangerous Situations in Cybersecurity
1. Dangerous situations in cybersecurity include:
a) The appearance of inciting information on cyberspace that poses a risk of riots, disruption of public security, and terrorism;
b) Attacks on important national security information systems;
c) Large-scale, high-intensity attacks on multiple information systems;
d) Cyber attacks aimed at destroying important national security facilities and targets;
đ) Cyber attacks seriously infringing upon national sovereignty, interests, and security; causing particularly serious harm to social order and safety, and the legitimate rights and interests of agencies, organizations, and individuals.
2. Responsibilities for preventing dangerous situations in cybersecurity are stipulated as follows:
a) Specialized cybersecurity protection forces shall cooperate with managers of important national security information systems to implement technical and operational solutions to prevent, detect, and handle dangerous situations in cybersecurity;
b) Telecommunications, Internet, information technology enterprises, service providers on telecommunications networks, the Internet, and additional services on cyberspace, and related agencies, organizations, and individuals shall be responsible for cooperating with specialized cybersecurity protection forces under the Ministry of Public Security in preventing, detecting, and handling dangerous situations in cybersecurity.
3. Measures for handling dangerous situations in cybersecurity include:
a) Immediately implementing preventive and emergency response plans for cybersecurity, blocking, eliminating, or mitigating losses caused by dangerous situations in cybersecurity;
b) Notifying relevant agencies, organizations, and individuals;
c) Collecting related information; continuously monitoring dangerous situations in cybersecurity;
d) Analyzing and evaluating information, forecasting the potential impact range and severity of losses caused by dangerous situations in cybersecurity;
đ) Ceasing to provide network information in specific areas or disconnecting international network gateways;
e) Deploying personnel and means to block and eliminate dangerous situations in cybersecurity;
g) Other measures as prescribed by the National Security Law.
4. Handling of dangerous situations in cybersecurity is stipulated as follows:
a) When a dangerous situation in cybersecurity is detected, agencies, organizations, and individuals must promptly report it to specialized cybersecurity protection forces and immediately apply the measures prescribed in point a and point b of Clause 3 of this Article;
b) The Prime Minister shall consider and decide, or delegate the Minister of Public Security to consider and decide, to handle dangerous situations in cybersecurity nationwide, in specific localities, or for a specific target.
The Prime Minister shall consider and decide, or delegate the Minister of National Defense to consider and decide, to handle dangerous situations in cybersecurity concerning military information systems and cryptographic information systems under the Government Cryptographic Office;
c) Specialized cybersecurity protection forces shall take the lead and coordinate with related agencies, organizations, and individuals to apply the measures prescribed in Clause 3 of this Article to handle dangerous situations in cybersecurity;
d) Agencies, organizations, and individuals related to the matter shall be responsible for cooperating with specialized cybersecurity protection forces to implement measures to prevent and handle dangerous situations in cybersecurity.
Article 22. Struggle to Protect Cybersecurity
1. Struggle to protect cybersecurity is an organized activity carried out by specialized forces for cybersecurity aimed at protecting national security and ensuring social order and safety on cyberspace.
2. The content of struggle to protect cybersecurity includes:
a) Organizing the monitoring of situations related to activities for protecting national security;
b) Preventing and combating attacks and protecting the stable operation of important information systems concerning national security;
c) Paralyzing or limiting the use of cyberspace with the aim of harming national security or causing particularly serious damage to social order and safety;
d) Proactively attacking and neutralizing targets on cyberspace to protect national security and ensure social order and safety.
3. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to implement the struggle to protect cybersecurity.
Chapter IV
CYBERSECURITY PROTECTION ACTIVITIES
Article 23. Implementation of Cybersecurity Protection Activities in State Agencies and Political Organizations at Central and Local Levels
1. The content of implementing cybersecurity protection activities includes:
a) Establishing and perfecting regulations and rules for using internal computer networks and computer networks connected to the Internet; plans to ensure cybersecurity for information systems; plans to respond to and mitigate cybersecurity incidents;
b) Applying and implementing measures, methods, and technologies to protect cybersecurity for information systems and information and documents stored, drafted, and transmitted through information systems under their management;
c) Organizing training on cybersecurity knowledge for civil servants, public officials, employees; enhancing the capacity of cybersecurity protection forces;
d) Protecting cybersecurity in the provision of public services on cyberspace, exchange, collection, and sharing of information with agencies, organizations, individuals within the organization or with other agencies or in other activities as prescribed by the Government;
đ) Investing in building physical infrastructure suitable for conditions to ensure the implementation of cybersecurity protection activities for information systems;
e) Conducting cybersecurity inspections of information systems; preventing and combating violations of laws on cybersecurity; responding to and mitigating cybersecurity incidents.
2. The heads of agencies and organizations are responsible for implementing cybersecurity protection activities under their management.
Article 24. Cybersecurity Inspection of Information Systems of Agencies and Organizations Not Included in the List of Important Information Systems Concerning National Security
1. Cybersecurity inspection of information systems of agencies and organizations not included in the list of important information systems concerning national security shall be conducted in the following cases:
a) When there are acts violating laws on cybersecurity that infringe upon national security or cause serious harm to social order and safety;
b) Upon request from the management body of the information system.
2. The objects of cybersecurity inspection include:
a) Hardware, software, and digital equipment used in the information system;
b) Information stored, processed, and transmitted in the information system;
c) Measures to protect state secrets and prevent and combat leaks and losses of state secrets through technical channels.
3. The management body of the information system has the responsibility to notify the specialized force for cybersecurity under the Ministry of Public Security when discovering acts violating laws on cybersecurity in the information system under its management.
4. The specialized force for cybersecurity under the Ministry of Public Security shall conduct cybersecurity inspections of information systems of agencies and organizations in the cases stipulated in Clause 1 of this Article.
5. At least 12 hours before conducting the inspection, the specialized force for cybersecurity shall notify the management body of the information system in writing.
Within 30 days from the end of the inspection, the specialized force for cybersecurity shall notify the results of the inspection and make demands on the management body of the information system if weaknesses or vulnerabilities in security are discovered; provide guidance or participate in remediation upon request from the management body of the information system.
6. The results of cybersecurity inspections are kept confidential according to the provisions of the law.
7. The Government shall prescribe the procedures and formalities for cybersecurity inspections as stipulated in this Article.
Article 25. Protection of cybersecurity for national cyberspace infrastructure and international network gateways
1. Protection of cybersecurity for national cyberspace infrastructure and international network gateways must ensure a close integration between cybersecurity protection requirements and economic and social development requirements; encourage the establishment of international gateways on Vietnamese territory; encourage organizations and individuals to participate in and invest in building national cyberspace infrastructure.
2. Organizations and individuals managing and operating national cyberspace infrastructure and international network gateways shall have the following responsibilities:
a) Protect cybersecurity within their management authority; be subject to management, inspection, and supervision by competent state agencies and comply with cybersecurity protection requirements set forth by such agencies;
b) Create conditions and implement necessary technical and operational measures to enable competent state agencies to perform cybersecurity protection tasks when requested.
Article 26. Ensuring information security on cyberspace
1. Websites, electronic portals, or specialized pages on social networks of organizations and individuals shall not provide, post, or transmit information containing contents specified in Clauses 1, 2, 3, 4, and 5 of Article 16 of this Law and other information containing contents that infringe upon national security.
2. Domestic and foreign enterprises providing services on telecommunications networks, the Internet, and additional services on cyberspace in Vietnam shall have the following responsibilities:
a) Verify user information when users register for account numbers; secure user information and accounts; provide user information to specialized forces responsible for cybersecurity under the Ministry of Public Security when requested in writing to assist in investigations and handling of violations of laws on cybersecurity;
b) Prevent the sharing of information and remove information containing contents specified in Clauses 1, 2, 3, 4, and 5 of Article 16 of this Law from services or information systems directly managed by them no later than 24 hours from the time of request by specialized forces responsible for cybersecurity under the Ministry of Public Security or competent agencies of the Ministry of Information and Communications and retain system logs to assist in investigations and handling of violations of laws on cybersecurity as prescribed by the Government;
c) Not provide or cease providing services on telecommunications networks, the Internet, and additional services to organizations and individuals posting on cyberspace information containing contents specified in Clauses 1, 2, 3, 4, and 5 of Article 16 of this Law when requested by specialized forces responsible for cybersecurity under the Ministry of Public Security or competent agencies of the Ministry of Information and Communications. under the Ministry of Public Security or competent authorities of the Ministry of Information and Communications.
3. Domestic and foreign enterprises providing services on telecommunications networks, the Internet, and additional services on cyberspace in Vietnam that engage in collecting, exploiting, analyzing, and processing data on personal information, data on relationships of service users, and data created by service users in Vietnam must store this data in Vietnam for the period prescribed by the Government.
Foreign enterprises specified in this Clause must establish a branch or representative office in Vietnam.
4. The Government shall provide detailed regulations on Clause 3 of this Article.
Article 27. Research and Development of Cybersecurity
1. The contents of research and development of cybersecurity include:
a) Building software systems and equipment for cybersecurity protection;
b) Methods to assess software and equipment for cybersecurity protection to meet standards and minimize weaknesses and security vulnerabilities, harmful software;
c) Methods to test hardware and software provided to ensure they perform their intended functions;
d) Methods to protect state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life; the ability to secure information transmission over cyberspace;
đ) Determining the origin of information transmitted over cyberspace;
e) Addressing cyber threats;
g) Establishing cyber training grounds and testing environments for cybersecurity;
h) Technical initiatives to enhance awareness and skills in cybersecurity;
i) Forecasting cybersecurity;
k) Studying practical applications and developing theoretical knowledge on cybersecurity.
2. Relevant agencies, organizations, and individuals have the right to conduct research and development of cybersecurity.
Article 28. Enhancing Self-reliance in Cybersecurity
1. The State encourages and creates conditions for agencies, organizations, and individuals to enhance self-reliance in cybersecurity and improve their capacity to produce, inspect, evaluate, and certify digital devices, network services, and applications.
2. The Government shall implement the following measures to enhance self-reliance in cybersecurity for agencies, organizations, and individuals:
a) Promoting technology transfer, research, mastery, and development of technologies, products, services, and applications for cybersecurity protection;
b) Promoting the application of new and advanced technologies related to cybersecurity;
c) Organizing training, development, and utilization of cybersecurity personnel;
d) Strengthening the business environment and improving competitive conditions to support enterprises in researching, producing products, services, and applications for cybersecurity protection.
Article 29. Protecting Children on Cyberspace
1. Children have the right to be protected, access information, participate in social activities, play, entertain, keep personal privacy, private life, and other rights when participating in cyberspace.
2. System administrators, telecommunications service providers, Internet service providers, and additional service providers on cyberspace are responsible for controlling content on their information systems or services to prevent harm to children, infringement upon children's rights, and promptly remove harmful content; they must also report and cooperate with specialized forces under the Ministry of Public Security to handle such issues.
3. Agencies, organizations, and individuals participating in activities on cyberspace are responsible for cooperating with competent authorities to ensure children's rights on cyberspace and prevent harmful content according to this Law and laws concerning children.
4. Agencies, organizations, parents, teachers, caregivers, and other relevant individuals are responsible for ensuring children's rights and protecting them when participating in cyberspace according to laws concerning children.
5. Specialized forces for cybersecurity and competent authorities are responsible for applying measures to prevent, detect, stop, and strictly deal with acts using cyberspace that cause harm to children, infringe upon children's rights.
Chapter V
ENSURING CYBERSECURITY PROTECTION ACTIVITIES
Article 30. Cybersecurity Protection Forces
1. Specialized forces for cybersecurity protection shall be deployed at the Ministry of Public Security and the Ministry of National Defense.
2. Cybersecurity protection forces shall be deployed at ministries, sectors, provincial People's Committees, and organizations directly managing important information systems concerning national security.
3. Organizations and individuals may be mobilized to participate in cybersecurity protection.
Article 31. Ensuring Human Resources for Cybersecurity Protection
1. Vietnamese citizens with knowledge about cybersecurity, network information security, and information technology are the basic and main resources for cybersecurity protection.
2. The State shall have programs and plans to build and develop human resources for cybersecurity protection.
3. When there is a dangerous situation regarding cybersecurity, cyber terrorism, cyber attacks, cybersecurity incidents, or threats to cybersecurity, competent state agencies shall decide to mobilize human resources for cybersecurity protection.
The authority, responsibility, procedures, and processes for mobilizing human resources for cybersecurity protection shall be implemented in accordance with the provisions of the National Security Law, the Defense Law, the People's Public Security Law, and other relevant laws.
Article 32. Recruitment, Training, and Development of Cybersecurity Protection Forces
1. Vietnamese citizens who meet the standards for moral character, health, qualifications, and knowledge about cybersecurity, network information security, and information technology, and who express a willingness, may be recruited into cybersecurity protection forces.
2. Priority shall be given to training and developing high-quality cybersecurity protection forces.
3. Priority shall be given to developing cybersecurity education institutions that meet international standards; encouraging collaboration and creating opportunities for cooperation on cybersecurity between the public and private sectors, both domestically and internationally.
Article 33. Education and Training on Cybersecurity Knowledge and Skills
1. The content of cybersecurity education and training shall be included in defense and security education courses in schools and the program for defense and security knowledge training as prescribed by the National Defense and Security Education Law.
2. The Ministry of Public Security shall take the lead and coordinate with relevant ministries and sectors to organize cybersecurity skills training for cybersecurity protection forces and civil servants, officials, and workers participating in cybersecurity protection.
The Ministry of National Defense and the Government Cryptographic Office shall organize cybersecurity skills training for those under their management.
Article 34. Dissemination of Cybersecurity Knowledge
1. The State shall have policies to disseminate cybersecurity knowledge nationwide, encouraging state agencies to cooperate with private organizations and individuals to implement educational programs and raise awareness about cybersecurity.
2. Ministries, sectors, agencies, and organizations shall be responsible for building and implementing activities to disseminate cybersecurity knowledge to cadres, civil servants, officials, and workers within their ministries, sectors, agencies, and organizations.
3. Provincial People's Committees shall be responsible for building and implementing activities to disseminate cybersecurity knowledge and raise awareness about cybersecurity for local agencies, organizations, and individuals.
Article 35. Funding for Cybersecurity Protection
1. Funding for cybersecurity protection of state agencies and political organizations shall be guaranteed by the state budget and allocated in the annual state budget estimate. Management and use of funding from the state budget shall be carried out in accordance with the law on the state budget.
2. Funding for cybersecurity protection of information systems of agencies and organizations outside the scope provided for in Clause 1 of this Article shall be self-funded by such agencies and organizations.
Chapter VI
RESPONSIBILITIES OF AGENCIES, ORGANIZATIONS, AND INDIVIDUALS IN THE IMPLEMENTATION OF INSPECTION CONCLUSIONS
Article 36. Responsibilities of the Ministry of Public Security
The Ministry of Public Security shall be responsible before the Government for state management of cybersecurity and shall have the following duties and powers, except for contents within the responsibility of the Ministry of National Defense and the Government Cryptographic Committee:
1. Issuing or submitting to competent state agencies for issuance and guiding the implementation of normative legal documents on cybersecurity;
2. Building and proposing strategies, policies, plans, and solutions to protect cybersecurity;
3. Preventing and combating activities using cyberspace that infringe upon sovereignty, interests, national security, public order, social safety, and cybercrime prevention;
4. Ensuring information security on cyberspace; establishing mechanisms for verifying account registration information; warning and sharing cybersecurity information and threats;
5. Advising and proposing to the Government and the Prime Minister to consider and decide on the division of labor and coordination in implementing measures to protect cybersecurity, prevent, and handle acts infringing upon cybersecurity when such state management involves multiple ministries and sectors;
6. Organizing drills to prevent and combat cyber attacks; organizing response and recovery drills for critical information systems concerning national security;
7. Inspecting, auditing, resolving complaints and denunciations, and handling violations of cybersecurity laws.
Article 37. Responsibilities of the Ministry of National Defense
The Ministry of National Defense shall be responsible before the Government for state management of cybersecurity within its jurisdiction and shall have the following duties and powers:
1. Issuing or submitting to competent state agencies for issuance and guiding the implementation of normative legal documents on cybersecurity within its jurisdiction;
2. Building and proposing strategies, policies, plans, and solutions to protect cybersecurity within its jurisdiction;
3. Preventing and combating activities using cyberspace that infringe upon national security within its jurisdiction;
4. Cooperating with the Ministry of Public Security to organize drills to prevent and combat cyber attacks, organize response and recovery drills for critical information systems concerning national security, and implement cybersecurity protection work;
5. Inspecting, auditing, resolving complaints and denunciations, and handling violations of cybersecurity laws within its jurisdiction.
Article 38. Responsibilities of the Ministry of Information and Communications
1. Cooperating with the Ministry of Public Security and the Ministry of National Defense in protecting cybersecurity.
2. Cooperating with relevant agencies to organize propaganda and refute information containing content opposing the Socialist Republic of Vietnam as stipulated in Clause 1, Article 16 of this Law.
3. Requesting telecommunications service providers, Internet service providers, and value-added services on cyberspace, and managers of information systems to remove information containing violations of cybersecurity laws from their services and systems directly managed by them.
Article 39. Responsibilities of the Government Cryptographic Committee
1. Advising and proposing the Minister of National Defense to issue or submit to competent authorities for issuance and organizing the implementation of normative legal documents, programs, and plans on cryptography to protect cybersecurity within the jurisdiction of the Government Cryptographic Committee.
2. Protecting cybersecurity for cryptographic information systems under the Government Cryptographic Committee and cryptographic products provided by the Government Cryptographic Committee according to this Law.
3. Uniformly managing scientific research and technological development in cryptography; producing, using, and providing cryptographic products to protect classified information stored and exchanged on cyberspace.
Article 40. Responsibilities of Ministries, Sectoral Agencies, and Provincial People's Committees
Within their respective duties and powers, Ministries, sectoral agencies, and provincial people's committees shall be responsible for implementing cybersecurity work concerning information and information systems under their management, and coordinating with the Ministry of Public Security to carry out state management over cybersecurity at the ministry, sectoral agency, and local levels.
Article 41. Responsibilities of Enterprises Providing Services on Cyberspace
1. Enterprises providing services on cyberspace in Vietnam shall have the following responsibilities:
a) Warning about the possibility of cybersecurity incidents when using services provided by them and guiding preventive measures;
b) Developing rapid response plans and solutions for cybersecurity incidents, immediately addressing vulnerabilities, security gaps, malware, cyber attacks, network intrusions, and other cybersecurity risks; upon occurrence of a cybersecurity incident, immediately implementing emergency plans and appropriate response measures while reporting to specialized forces responsible for cybersecurity as stipulated in this Law;
c) Applying technical solutions and other necessary measures to ensure cybersecurity during information collection, preventing leaks, breaches, damage, or loss of data; in cases where leaks, breaches, damage, or loss of user information data occur or are likely to occur, promptly proposing response solutions, simultaneously informing users, and reporting to specialized forces responsible for cybersecurity as stipulated in this Law;
d) Cooperating and creating conditions for specialized forces responsible for cybersecurity in protecting cybersecurity.
2. Enterprises providing telecommunications network services, Internet services, and additional services on cyberspace in Vietnam shall implement the provisions set forth in Clause 1 of this Article, Clause 2, and Clause 3 of Article 26 of this Law.
Article 42. Responsibilities of Agencies, Organizations, and Individuals Using Cyberspace
1. Adhering to legal regulations on cybersecurity.
2. Timely providing information related to cybersecurity protection, cybersecurity threats, and acts of cybersecurity infringement to competent authorities and cybersecurity protection forces.
3. Implementing requirements and guidance from competent authorities in cybersecurity protection; assisting and creating conditions for agencies, organizations, and individuals responsible for conducting cybersecurity protection measures.
Chapter VII
IMPLEMENTING PROVISIONS
Article 43. Effective Date
1. This Law takes effect from January 1, 2019.
2. Information systems currently in operation and use that are included in the List of Important Information Systems for National Security shall, within twelve months from the date this Law takes effect, ensure sufficient cybersecurity conditions, and specialized forces responsible for cybersecurity shall assess cybersecurity conditions according to Article 12 of this Law; in cases requiring extension, it shall be decided by the Prime Minister but not exceeding twelve months.
3. Information systems currently in operation and use that are added to the List of Important Information Systems for National Security shall, within twelve months from the date of addition, ensure sufficient cybersecurity conditions, and specialized forces responsible for cybersecurity shall assess cybersecurity conditions according to Article 12 of this Law; in cases requiring extension, it shall be decided by the Prime Minister but not exceeding twelve months.
This Law was adopted by the National Assembly of the Socialist Republic of Vietnam, the fourteenth session, fifth meeting., June 12, 2018.
|
SPEAKER OF THE NATIONAL ASSEMBLY
(Signed) Nguyễn Thị Kim Ngân
|
关系图
点击文件即可打开。红色边框=改变效力的关系。