Decision No. 2615/QD-BTC Issuing Regulations on Ensuring Information Security on Computer Environments and Computer Networks

These regulations set out specific requirements for ensuring information security on computer environments and computer networks for the Ministry of Finance’s agencies, units under the Ministry's system, Department of Finance, and other units connected to the Ministry's internal network. They include provisions on managing information technology accounts, ensuring safety in system management work, information security management, responsibilities of units and individuals.

Document No.2615/QĐ-BTC
Document typeDecision
Issuing authorityMinistry of Finance
Signed byPhạm Sỹ Danh
Updated16/06/2026
SectorUnclassified
FieldFinancial Miscellaneous
Issued date19/10/2012
Effective date19/10/2012
Expiry date
StatusIn effect
✦ Smart summary

These regulations set out specific requirements for ensuring information security on computer environments and computer networks for the Ministry of Finance’s agencies, units under the Ministry's system, Department of Finance, and other units connected to the Ministry's internal network. They include provisions on managing information technology accounts, ensuring safety in system management work, information security management, responsibilities of units and individuals.

Scope of application

The Ministry of Finance’s agencies, units under the Ministry's system, Department of Finance, and other units connected to the Ministry's internal network.

Key points

  • Allocation of personnel for information security management
  • Issuance of specific procedures for detecting, reporting, handling, and managing activities to address incidents related to information security at the unit
  • Regularly extract monthly or quarterly reports from the cybersecurity system to monitor and evaluate issues within the system.
  • Organize the dissemination and implementation of these regulations at the Ministry of Finance’s agencies and units connected to the Ministry's internal network.
  • Unit heads are responsible under the law for organizing, directing, inspecting staff members of their units to comply with the regulations.

🌐 Social impact of this document

  • Help protect confidential information and data of the finance sector.
  • Improve the ability to respond to cybersecurity incidents.
  • Enhance awareness about information security among civil servants, public officials, and employees.

❓ Frequently asked questions

Who does this regulation apply to?

It applies to the Ministry of Finance’s agencies, units under the Ministry's system, Department of Finance, and other units connected to the Ministry's internal network.

What must unit heads do to ensure compliance with these regulations?

Disseminate to each civil servant, public official, employee, and staff member of the unit; regularly inspect the implementation of these regulations at the unit and report periodically.

What responsibilities do units under the Ministry of Finance have in ensuring information security?

Guide and inspect the implementation of regulations by subordinate units; implement emergency response activities according to plans approved and directed by the Ministry.

Full text

MINISTRY OF FINANCE

Number: 2615/QD-BTC

SOCIALIST REPUBLIC OF VIETNAM

Independence - Freedom - Happiness

Hanoi, October 19, 2012

Pursuant to …;

Issuing Regulations on Ensuring Information Security

in Computer Environments and Computer Networks

THE MINISTER OF FINANCE

Pursuant to the Decree No. 118/2008/NĐ-CP dated November 27, 2008 of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Finance;

Pursuant to Decree No. 64/2007/ND-CP dated April 10, 2007 of the Government on the application of information technology in state agency activities;

Pursuant to Decree No. 33/2002/ND-CP dated March 28, 2002 of the Government on detailed implementation of the Ordinance on Protection of State Secrets;

Pursuant to Decision No. 196/2003/QD-BTC dated December 2, 2003 of the Minister of Finance on the issuance of the Regulation on Protection of State Secrets in the Finance Sector;

At the proposal of the Director of the Department of Information Technology and Financial Statistics,

DECISION:

Article 1: Issued together with this Decision are the Regulations on Ensuring Information Security in Computer Environments and Computer Networks.

Article 2: This Decision takes effect from the date of signature.

Article 3: The Director of the Department of Information Technology and Financial Statistics, the Head of the Ministry's Office, the Heads of administrative agencies, public service units under the Ministry of Finance, Provincial Departments of Finance under centrally governed cities and provinces, Planning and Finance Departments of localities, and relevant organizations and individuals shall be responsible for implementing this Decision.

Place of Receipt:

- Ministry of Planning and Investment Portal;

- Units under the Ministry;

- Provincial Departments of Finance under central cities;

- To be filed: VT, Department of IT and Statistics.

DEPUTY MINISTER

DEPUTY MINISTER

Pham Sy Danh

MINISTRY OF FINANCE

SOCIALIST REPUBLIC OF VIETNAM

Independence - Freedom - Happiness

REGULATIONS

On Ensuring Information Security

in Computer Environments and Computer Networks

(Issued together with Decision No. 2615/QD-BTC dated October 19, 2012 of the Minister of Finance

PART I
GENERAL PROVISIONS

1. Principles, criteria, and allocation standards for state budget investment capital development phase 2016-2020 serve as the basis for planning medium-term and annual investment plans from the state budget for the period 2016-2020 at the national level, at all levels, and in all sectors and units using state budget funds. They also serve as the basis for managing, supervising, inspecting, and auditing the implementation of medium-term and annual investment plans.

Article 1. Scope of Application:

These regulations include minimum conditions that must be adhered to in order to ensure information security in computer environments, computer networks, and systems capable of accessing digital information within the finance sector. The information protected includes all types of information of the Ministry of Finance and its affiliated units, information at local financial agencies under the management of the Ministry of Finance, and information sent to the Ministry of Finance and its affiliated units from other agencies and organizations.

第二条 组织和实施奖励工作的支出水平,如政府第152/2025/NĐ-CP号决定关于分级授权和奖励领域的分权规定

a) Units under the Ministry of Finance and their staff members: fully implement these regulations.

b) Provincial Departments of Finance, Planning and Finance Departments, and their staff members: apply these regulations to computers, computer networks, and applications serving the specialized activities of units under the management of the Ministry of Finance.

c) Agencies, organizations, and individuals engaged in information exchange with units under the Ministry of Finance (advisors, constructors, implementers, supporters, operators, testers of information technology systems; agencies, organizations, and individuals connected to networks for exchanging information with units in the finance sector): apply these regulations in their information exchanges with the finance sector.

Definitions

1. "Ensuring information security" means ensuring the confidentiality, integrity, and availability of information, wherein:

a) Confidentiality: information is not disclosed to unauthorized entities.

b) Integrity: information is not altered to distort its content.

c) Availability: information is provided to authorized users.

2. "Internal network of the Ministry of Finance": the computer network system at the headquarters of the Ministry of Finance, extensions of this network to the headquarters of units under the Ministry located outside the Ministry's headquarters, and the Representative Office of the Ministry of Finance in Ho Chi Minh City.

3. "Unified communication infrastructure of the finance sector": a wide area network connecting the computer networks of units within the finance sector.

4. "Complex password": a password meeting the following requirements:

- At least 8 characters.

- Includes at least three of the four types of characters: uppercase letters (A-Z), lowercase letters (a-z), digits (0-9), and other keyboard characters (~, !, etc.).

5. "Secure encryption algorithm" refers to an encryption algorithm according to Vietnamese or international standards that, at the time of application, has not been cracked or if it can be cracked, the time required to crack it exceeds the duration for which the data needs to be protected in encrypted form.

6. "State secret": information belonging to the List of State Secrets at the top-secret, highly confidential, and confidential levels of the finance sector as stipulated currently, and state secrets from other agencies and units sent to the Ministry of Finance.

7. "Unit": units within the scope of application of these regulations.

8. "System unit under the Ministry": General Taxation Department, General Customs Department, National Reserve Administration, State Treasury, Securities Commission, Finance Academy.

9. "User": staff members of units who are allowed to use computers at their units to process work tasks.

General Principles for Ensuring Information Security

1. Ensuring information security is a mandatory requirement during the creation, processing, use of information, and in the design, construction, operation, upgrade, and decommissioning of technical infrastructure for information technology.

2. Units and users involved in the processes mentioned in Clause 1 of Article 1 must ensure information security in accordance with national regulations and those of the Ministry of Finance, and follow guidance from competent authorities in the field of information security.

3. Users must be trained in general knowledge about information security in computer environments and networks, and advanced knowledge about information security appropriate to their assigned tasks.

4. Information classified as state secrets in computer environments and networks must be protected in accordance with national regulations, the Regulation on Protection of State Secrets in the Finance Sector, and corresponding provisions in these regulations.

Chapter II
SPECIFIC PROVISIONS

Physical Security Assurance

1. The following areas must be controlled for physical access to prevent unauthorized or inappropriate access: Data centers, server and storage device areas, network cabinets and connections, power supply equipment and emergency backup power, operation and control (management) rooms. Management units of these equipment zones must have internal rules or guidelines for working in these areas.

2. Subjects using mobile data storage devices (laptops, handheld digital devices, USB memory cards, external hard drives, magnetic tapes, etc.) to store information within the scope of protection as prescribed in Article 1 shall be responsible for protecting these devices and the information stored on them, preventing loss or disclosure of such information. Information from agencies and the State not related to the content of work performed abroad shall not be taken out of the country. Strictly prohibited is the use of personal equipment to store state secrets.

3. Storage devices no longer used for unit work (disposed of, given away, or donated) must have their contents erased using software or specialized data destruction equipment or physically destroyed.

Ensuring computer work safety

1. Computers serving work (including servers, management computers, and user work computers at the unit):

a) Work computers may only be installed with software listed in the software catalog established by the unit and managed by the unit's information technology department, or provided through information technology application programs of the Ministry of Finance or other competent state agencies, updated with security system patches, and installed with antivirus software and the latest virus detection models.

b) The unit's information technology department is responsible for installing software on work computers. Users may not interfere (installing new software, changing, uninstalling, etc.) without the consent of the unit's information technology department.

c) Users must lock their computers (using built-in features) when leaving the workstation and turn off the computers when leaving the agency.

2. Strictly prohibited is the connection of personal computers not installed with antivirus software and updated virus detection models to the internal network system of the unit and financial sector networks.

Ensuring computer network system safety

1. Broadband connections must be established and operated according to the Management, Operation, and Usage Regulations of the Unified Financial Sector Communication Infrastructure issued by Decision No. 109/QD-BTC dated January 15, 2009 of the Minister of Finance and any subsequent amendments or updates to these regulations.

2. Internal networks must be protected by firewalls meeting the following requirements:

a) Dividing the internal network into zones based on access range and controlling access between zones using firewalls.

The internal network of the Ministry of Finance and its affiliated units at the central level must be divided into the following zones at minimum:

- A zone for accessing from the Internet (applicable to units with electronic portals, public services, or applications provided on the Internet located within the unit).

- An Internet access zone (transferring Internet access requests from users or servers);

- An internal server zone;

- A system management zone (all system management activities must be conducted through this zone);

- A user zone, which separates wired and wireless connection zones.

- A guest zone (applicable to units allowing visitors to access the unit's network system to use the Internet).

b) Disable all unused services in each zone;

c) Conceal and prevent direct access to internal network addresses from outside (Internet, financial sector communication infrastructure).

d) Install timely updates and patches for firewalls to address critical security vulnerabilities; Maintain warranty or backup equipment to ensure continuous operation of the firewall.

3. The internal network of the Ministry of Finance and its affiliated units at the central level must be monitored by a detection and defense system against attacks.

4. Wireless networks (if any) must meet the following minimum conditions:

a) Hardware must have Wi-Fi certification (certification by the Wi-Fi Alliance (www.wi-fi.org) for products meeting the 802.11 standard);

b) Apply data transmission encryption using secure encryption algorithms;

c) Wireless users must be provided with unique identification and authenticated through an encrypted channel;

d) Wireless access points must be protected against unauthorized access.

5. For remote access to the internal network:

a) Computers used to connect to the unit's network must comply with the safety measures stipulated in Article 5;

b) Remote access connections must use channel encryption;

c) Remote access for system management purposes must apply multi-factor authentication.

Ensuring Internet connection safety

1. Units must implement necessary measures to ensure information security in users' Internet connection activities, at least meeting the following requirements:

a) Have a firewall to control Internet access;

b) Filter out and prohibit access to web pages suspected of containing malicious code or inappropriate content (subversive or contrary to local customs and traditions);

c) Computers containing important data or having access to important financial sector data and applications may not open web pages or Internet applications directly on these machines or may only be allowed to access web pages on the Internet that serve the unit's work.

The Department of Information Technology and Statistics of the Ministry of Finance bases on legal provisions and opinions of units at the Ministry of Finance headquarters to determine and submit to the Ministry for approval a list of important data and applications on the internal network system of the Ministry of Finance that need to be protected during Internet connections.

For affiliated units under the Ministry and provincial finance departments, unit leaders decide on the types of important data and applications of the unit that need to be protected during users' Internet connections.

d) Internet connections for users' work computers at the unit will be restricted in scope or disconnected in the following cases:

- There is a letter from the Ministry of Finance requesting to restrict the scope of Internet connections or disconnect Internet connections (applied in emergency situations).

- The unit leader must limit the scope of internet connection or completely disconnect the working computers' internet connection to ensure the safety of the unit's network system and minimize other impacts of the internet on the unit's operations.

d) Users are not allowed to use personal devices (3G modems, mobile phones, etc.) to connect their working computers to the internet without the information technology department's consent.

2. For servers and other IT equipment, internet connections shall only be established for systems that require communication with the internet (servers, devices providing internet interfaces for electronic news sites, public services, email; devices updating operating system patches, antivirus models, security vulnerability models, attack models, etc.).

3. Strictly prohibit computers used for drafting, printing, storing state secrets from connecting to the internet.

Ensuring application-level security

1. Requirements for ensuring information security must be incorporated into all stages related to applications (design, development, deployment, operation, use, etc.).

2. Applications developed or contracted out by the unit must meet the following requirements:

- Encrypting sensitive or confidential information using secure encryption algorithms.

- Validating input and output data to ensure accuracy and appropriateness.

- Implementing procedures to control software installation on servers, users' computers, and active network devices within the internal network system.

- Limiting access to program source code and placing the source code in a secure environment managed by a specialized department.

- Conducting detection and remediation of application security vulnerabilities before use and at least once every six months during use.

3. For packaged applications:

- Monitoring and regularly updating security patches for the application based on new security vulnerabilities.

- In cases where a security vulnerability has been identified but there is no patch provided by the software manufacturer, risk assessment and appropriate preventive measures must be implemented.

Ensuring data-level security

1. Confidential, important, or sensitive contents stored on mobile devices or transmitted over the network must be encrypted, including:

- State secrets of the Finance sector must be encrypted using solutions provided or approved for use in the Finance sector by the Government Cryptographic Authority; if there is no guidance from the Government Cryptographic Authority, it must be agreed upon by the Ministry of Finance and comply with national cryptographic regulations.

- Applying channel encryption for the following activities: system management; network and application login; automatic data exchange between servers; data entry and editing; searching for confidential and sensitive data.

- Encouraging the use of digital signatures to authenticate and secure data, especially when it is necessary to ensure non-repudiation of data origin.

- Electronic documents containing restricted content but not classified as state secrets should utilize the encryption feature (password protection) of office applications (word processing, reading, file compression software), but must use secure encryption algorithms.

2. Individuals responsible for drafting, sending, and receiving data must determine the level of confidentiality or sensitivity of the data to implement appropriate protective methods or request guidance and support from the information technology department when necessary.

3. Only use email systems and information exchange tools directly managed by the unit or provided by state agencies and authorized organizations for exchanging work-related information and documents. Public information exchange means on the internet must not be used for this purpose.

Ensuring security in information exchange with organizations and individuals outside the Finance sector

1. Organizations and individuals within the scope defined in point c, Clause 2, Article 1 must commit to protecting the unit's and the Finance sector's information before commencing work under the contract or agreement between both parties.

2. When exchanging unit and Finance sector information requiring security through the network system (email, file transfer, etc.), encryption must be performed prior to exchange according to Article 9 of these Regulations.

4. For cases where external organizations or individuals establish network connections with the unit:

a) A risk analysis for information security must be conducted before establishing a network connection between the unit and external organizations or individuals, and measures to control these risks must be implemented.

b) Both parties must agree in writing on specific conditions that external organizations or individuals must meet when establishing a network connection to the unit and periodically check compliance with these agreements.

The conditions that organizations and individuals outside must meet at a minimum include: the network segment of organizations and individuals outside used to connect to the unit's network system must be controlled by a firewall; computers within this network segment must be updated with operating system patches, antivirus models; access system accounts must apply complex passwords; internet connection is only allowed when it serves the work of units under the Finance sector.

Backup and disaster prevention

1. Units must have equipment and procedures, personnel to serve data backup work to prevent disasters; regularly check the effectiveness of backup data and test system recovery from backup data.

2. For important network systems and applications, measures for equipment and software backup must be taken to ensure continuous operation of the system.

Information technology account

1. User account:

a). Each user using the unit's network system and applications and those of the Finance sector must be assigned a unique login account linked to the user. In cases where a shared account is used by a group of people or a unit, there must be a mechanism to identify the responsible individuals managing the account.

b) Network access accounts of users shall not have administrative rights on connected computers. Administrative computer accounts can only be used for software installation on computers. Desktop administrative accounts must be held by the unit's information technology department. For laptops, users must be guided on how to properly use administrative accounts and are responsible for following the guidance.

c) Decisions and notifications regarding user job transfers, resignation, or leave must simultaneously be transferred to the information technology account management department to adjust, reclaim, or cancel the user's usage rights for the unit's network system and applications and those of the Finance sector.

2. System administration account (for devices, networks, applications, databases) must be separate from network and application access accounts as regular users. System administration accounts must be assigned to specific individuals performing system administration tasks. Sharing of system administration accounts is strictly prohibited.

Account authentication methods:

a) Complex passwords must be applied to all access, usage, and system management accounts on the internal computer network system and those of the Finance sector.

b) Passwords for user accounts must be changed periodically, at least once every three months, while system administration accounts must be changed at least once every two months.

c) Users and system administrators are responsible for protecting their assigned account information, not disclosing passwords or providing others with account authentication means except in urgent situations requiring unit work processing; or when providing, transferring information and documents managed by individuals to other units. Account holders must change passwords immediately after completing these tasks.

Ensuring security in system management work

1. Computers used for system management must only install necessary software for system management operations, placed in a network area dedicated to system management tasks, and access rights must be granted only to individuals assigned responsibility for system management.

2. Change the default system administrator account name and password provided when the system is set up.

3. Use secure communication channels (with encryption) for system management access.

Information security management

1. Units must assign personnel to manage information security on computer environments and networks (including monitoring and checking compliance with this regulation within the unit).

2. Units must issue specific procedures for detecting, reporting, handling, and managing activities to address information security incidents within the unit.

3. Cybersecurity systems (operating system patch updates, computer antivirus protection, firewalls, attack detection and prevention, etc.) must be monitored regularly to ensure system effectiveness and early detection and resolution of information security issues. Monthly or quarterly reports must be extracted from cybersecurity systems to monitor and evaluate system issues.

4. Users must be trained in information security knowledge appropriate to their scope of work and level of computer usage; guided and supported by the unit's information technology department to provide necessary tools to fulfill their information security responsibilities as prescribed.

Chapter III
RESPONSIBILITIES OF UNITS AND INDIVIDUALS

Responsibilities of units

1. Department of Information Technology and Financial Statistics:

a) Organize the dissemination and implementation of this Regulation at the Ministry of Finance agencies and units connected to the internal network of the Ministry of Finance.

b) Submit to the Ministry for approval and organize the implementation of emergency response plans (in case of discovery of state secrets theft attacks on the Finance sector through the network, important information systems of the Finance sector being taken over...).

c) Guide and inspect the implementation of this Regulation by affiliated units of the Ministry, provincial finance departments, and units exchanging information with the internal network of the Ministry of Finance.

d) Guide and inspect units under the Ministry of Finance on the implementation of requirements from competent state agencies regarding information security on computer environments and networks.

đ) Summarize and report to the Ministry quarterly on the information security work of the entire Finance sector according to the contents of this Regulation and information security issues on computer environments and networks arising during the reporting period.

e) Submit to the Ministry for amendments and supplements to this Regulation to suit current circumstances and practical conditions.

2. Affiliated units of the Ministry of Finance, provincial finance departments:

a) Organize the implementation of this Regulation at the unit.

b) Implement emergency response activities according to the plan approved by the Ministry and the guidance of the Department of Information Technology and Financial Statistics.

c) Units under the Ministry of Finance shall guide and inspect the implementation of regulations by subordinate units. Departments of Finance shall guide and inspect the implementation of regulations by Planning and Finance Rooms within the same province or city.

d) Carry out requirements and guidelines on information security in computer environments and networks issued by competent state agencies and the Department of Information Technology and Financial Statistics.

đ) Report to the Ministry (through the Department of Information Technology and Financial Statistics) quarterly on the status of information security work at the unit in accordance with the contents of this Regulation and any issues related to information security in computer environments and networks that arise during the reporting period.

e) Reflect difficulties, suggestions for amending and supplementing this Regulation during its implementation to the Department of Information Technology and Financial Statistics.

3. Units participating in using the internal network system of the Ministry of Finance

a) Coordinate with the Department of Information Technology and Financial Statistics in implementing regulations applicable to users at the unit.

b) Coordinate with the Department of Information Technology and Financial Statistics to implement emergency attack response plans related to the unit.

c) Reflect needs and difficulties encountered during the implementation of information security assurance at the unit to the Department of Information Technology and Financial Statistics.

Responsibilities of individuals

1. Heads of units subject to this Regulation shall be responsible for disseminating it to each staff member of the unit; regularly inspect the implementation of this Regulation at the unit, and report quarterly to the Ministry (through the Department of Information Technology and Financial Statistics), and bear responsibility under the law and before the leadership of the Ministry of Finance for any violations or loss of confidential information and data within the unit's management scope due to inadequate organization, direction, and strict inspection of unit staff's compliance with regulations.

2. Staff members of the Ministry of Finance, units under the Ministry, and other units subject to this Regulation shall be responsible under the law and before their unit leadership for any violations or loss of confidential financial data due to non-compliance with regulations./.

DEPUTY MINISTER

DEPUTY MINISTER

Phạm Sỹ Danh

The original file of this document is being updated. Please read the full text and check back later.

Relations map

↑ Basis & documents that affect this document
Based on 13
196/2003/QĐ-BTC Quyết định số 196/2003/QĐ-BTC của Bộ trưởng Bộ Tài chính về việc ban hành Quy chế bảo vệ bí mật Nhà nước của ngành Tài chính Expired 33/2002/NĐ-CP Nghị định số 33/2002/NĐ-CP Quy định chi tiết thi hành Pháp lệnh Bảo vệ bí mật nhà nước Expired 64/2007/NĐ-CP Nghị định số 64/2007/NĐ-CP Ứng dụng công nghệ thông tin trong hoạt động của cơ quan nhà nước In effect 118/2008/NĐ-CP Nghị định số 118/2008/NĐ-CP Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Bộ Tài chính Expired 43/2008/QĐ-UBND Quyết định số 43/2008/QĐ-UBND Về việc Giao dự toán thu, chi ngân sách nhà nước năm 2009 cho các huyện, thị xã Expired 04/2009/QĐ-UBND Quyết định số 04/2009/QĐ-UBND Về việc Giao dự toán thu ngân sách nhà nước năm 2009 cho các doanh nghiệp trên địa bàn tỉnh Expired 21/2008/NQ-HĐND Nghị quyết số 21/2008/NQ-HĐND về Dự toán thu ngân sách nhà nước trên địa bàn, chi ngân sách địa phương năm 2009 Expired 83/2008/QĐ-UBND Quyết định số 83/2008/QĐ-UBND Về giao chỉ tiêu dự toán thu - chi ngân sách nhà nước năm 2009. Expired 108/2008/NQ-HĐND Nghị quyết số 108/2008/NQ-HĐND Về phê chuẩn dự toán thu ngân sách nhà nước, chi ngân sách địa phương và phương án phân bổ ngân sách cấp tỉnh năm 2009. In effect 107/2008/NQ-HĐND Nghị quyết số 107/2008/NQ-HĐND Về kế hoạch đầu tư phát triển năm 200 In effect 16/2008/NQ-HĐND Nghị quyết số 16/2008/NQ-HĐND Về dự toán và phương án phân bổ ngân sách tỉnh Bến Tre năm 2009 In effect 4126/QĐ-UBND Quyết định số 4126/QĐ-UBND Về việc ban hành một số chủ trương, biện pháp điều hành kế hoạch phát triển kinh tế - xã hội và dự toán ngân sách Nhà nước năm 2009 trên địa bàn tỉnh. In effect 4301/2008/QĐ-UBND Quyết định số 4301/2008/QĐ-UBND Về việc giao dự toán thu NSNN, chi NSĐP năm 2009 In effect
2615/QĐ-BTC
Decision No. 2615/QD-BTC Issuing Regulations on Ensuring Information Security on Computer Environments and Computer Networks
In effect

Click a document to open. A red border = a relation that changes validity.