Circular No. 27/2011/TT-BTTTT on the coordination of activities to rescue internet network incidents in Vietnam

Circular No. 27/2011/TT-BTTTT stipulates the network for rescuing internet network incidents in Vietnam, including members such as the VNCERT Center, ISPs, Internet service providers, and state agencies. This circular guides the coordination, handling of incidents, and responsibilities of each entity during the incident rescue process.

Document No.27/2011/TT-BTTTT
Document typeCircular
Issuing authorityMinistry of Science and Technology
Signed byNguyễn Minh Hồng — Thứ trưởng
Updated26/06/2026
SectorInformation and Communications
FieldInformation TechnologyElectronics
Issued date04/10/2011
Effective date15/11/2011
Expiry date01/11/2017
StatusExpired
✦ Smart summary

Circular No. 27/2011/TT-BTTTT stipulates the network for rescuing internet network incidents in Vietnam, including members such as the VNCERT Center, ISPs, Internet service providers, and state agencies. This circular guides the coordination, handling of incidents, and responsibilities of each entity during the incident rescue process.

Scope of application

The VNCERT Center, ISPs, Internet service providers, state agencies such as the Ministry of Information and Communications, Provincial Departments of Information and Communications, organizations providing information security services, individuals and organizations using the Internet.

Key points

  • The VNCERT Center is the Coordination Agency, with the authority to mobilize other organizations within the network to rescue incidents.
  • ISPs and Internet service providers must report periodically on their activities in receiving and handling incidents.
  • When encountering an incident, organizations or individuals using the Internet notify one or more members of the network.
  • The Coordination Agency carries out incident handling activities and has the right to request network members to participate in incident rescue.
  • Network members must comply with coordination requirements from the Coordination Agency and report on the results of implementation.

🌐 Social impact of this document

  • Positive impact: Enhance the ability to rescue internet network incidents, protect information security for citizens and businesses.
  • Negative impact: May impose burdens on time and resources for network members.

❓ Frequently asked questions

What rights does the VNCERT Center have in coordinating incident rescue?

The VNCERT Center has the right to mobilize other organizations within the network to rescue incidents, decide on coordination methods, and be responsible for coordination requests.

What information must ISPs report to the Coordination Agency?

ISPs must report every six months on their activities in receiving and handling incidents, including content according to the reporting form in Appendix 2.

To whom should organizations or individuals using the Internet notify when encountering an incident?

When encountering an incident that cannot be resolved independently, organizations or individuals using the Internet should notify the incident to one or more network members such as the ISP providing Internet services and the Coordination Agency.

What can the Coordination Agency require from network members?

The Coordination Agency may require network members to cooperate, propose international computer emergency response organizations to participate, and mobilize additional resources if necessary.

What obligations must network members fulfill?

Network members must report periodically, handle incident notifications, coordinate with the Coordination Agency, and implement coordination requirements as prescribed.

Full text

CIRCULAR

Regulations on coordinating activities to respond to internet security incidents in Vietnam

__________________________

 

MINISTER OF INFORMATION AND COMMUNICATIONS

Pursuant to the Law on Information Technology dated June 29, 2006;

Based on the Law on Telecommunications dated December 4, 2009;

Pursuant to Decree No. 64/2007/NĐ-CP dated April 10, 2007 of the Government on the application of information technology in state agency activities;

Based on Decree No. 97/2008/NĐ-CP dated August 28, 2008 on management, provision, and use of Internet services and electronic information on the Internet;

BASED ON THE GOVERNMENT DECREE NO. 187/2007/NĐ-CP OF DECEMBER 25, 2007 ON THE FUNCTIONS, TASKS, POWERS, AND ORGANIZATIONAL STRUCTURE OF THE MINISTRY OF INFORMATION AND COMMUNICATIONS;

At the proposal of the Director of the National Cybersecurity Emergency Response Team (VN-CERT),

THE REGULATIONS ARE AS FOLLOWS:

PART I

GENERAL PROVISIONS

Article 1. Scope and Applicability

These Circulars stipulate the emergency response network, coordination of activities to respond to internet security incidents; responsibilities of organizations and individuals related to responding to internet security incidents in Vietnam.

Article 2. Explanation of terms

1. Internet security incident is an event that has occurred, is occurring, or may occur causing information security risks on the Internet, discovered through monitoring, assessment, and analysis by relevant agencies, organizations, or individuals, or warned by experts and organizations in the field of information security both domestically and internationally (hereinafter referred to as an incident).

2. Serious incident is an incident having one or more of the following characteristics: likely to occur on a wide scale and spread rapidly; capable of damaging computer networks and the Internet; potentially causing significant damage or consequences to information systems on the network; requiring substantial national or international resources to resolve.

Chapter II

EMERGENCY RESPONSE NETWORK

Article 3. Emergency Response Network

1. The emergency response network is a collection of agencies, organizations, and enterprises participating in coordinated emergency response activities in Vietnam (hereinafter referred to as the network, agencies, organizations, and enterprises collectively called members of the network and abbreviated as members). The network includes mandatory members and voluntary members who have registered to join the network.

2. Mandatory members include:

a) The coordination agency;

b) Information technology units of Ministries, Ministries-equivalent agencies, and agencies under the Government; Provincial Departments of Information and Communications.

c) Internet Service Providers (ISPs);

d) Vietnam Internet Network Information Center (VNNIC).

3. Voluntary members are agencies, organizations, or enterprises voluntarily participating in the network with a registration form according to Appendix 1 submitted to the Coordination Agency and accepted. It is encouraged for organizations operating in the field of information security to establish departments responsible for emergency response and join the network.

4. The National Cybersecurity Emergency Response Team (VN-CERT) is the Coordination Agency. VN-CERT performs the function of coordinating nationwide emergency response activities and has the authority to mobilize other organizations within the network to cooperate in preventing, handling, and resolving internet security incidents in Vietnam; has the right to decide on the form of coordination of emergency response activities and is responsible for coordination requests; serves as the point of contact for exchanging information on cooperation in emergency response with international cybersecurity emergency response organizations. The activities of the Coordination Agency aim to mobilize network members to cooperate in handling and responding to incidents, which is referred to as coordinated emergency response.

5. Detailed contact information including address, phone number, fax number, email address, and website of network members is publicly announced on the Coordination Agency's website (www.vncert.gov.vn).

Article 4. Emergency Response Point

1. The emergency response point is an individual or department authorized to represent network members in communicating and exchanging information with other network members during emergency response activities.

2. The emergency response point must have professional qualifications and skills to carry out coordinated emergency response activities.

3. The emergency response point must ensure continuous communication capability (24 hours a day, 7 days a week).

Article 5. Principles of Operation for the Emergency Response Network

1. Information exchanged and provided during coordination and handling of incidents must be kept confidential according to the requirements of organizations or individuals experiencing incidents, except when the incident involves multiple users and the Coordination Agency requests a warning or reminder.

2. Information exchange within the network must be conducted through one or more forms such as: official letters, emails, telephone calls, faxes. Network members receiving information must proactively verify the sender to ensure that the received message is reliable.

3. Network members have the right to share information, experiences, participate in emergency response exercise activities, and attend training courses on emergency response activities.

Article 6. Reporting System

1. Network members are responsible for reporting every six months to the Coordination Agency about their activities in receiving and handling incidents.

a) Content of the report follows the periodic report form at Appendix 2. Guidance on the report form is posted on the VNCERT electronic news page;

b) Deadline for submitting reports: before June 15th and before December 15th each year;

c) Form of the report: by official letter and email;

d) Reports sent to VNCERT Center: 18 Nguyen Du, Hanoi; email address: [email protected].

2. Network members are responsible for submitting urgent reports when requested by the Coordination Agency or when they discover serious incidents. The form and address for submitting reports follow the provisions of Clause 1 of this Article.

Chapter III

COORDINATION OF EMERGENCY RESPONSE ACTIVITIES

Article 7. Incident Reporting

1. When encountering an incident that cannot be resolved independently, Internet users or organizations must report the incident to one or more network members as follows:

a) The network member responsible for responding to incidents for that organization or individual (if applicable);

b) ISPs directly providing Internet services to that organization or individual;

c) The Coordination Agency.

2. Upon discovering serious incidents, organizations or individuals must immediately report them to the Coordination Agency.

3. The content of the incident report includes:

a) Incident description information following the incident report form at Appendix 3;

b) Other information as required by the receiving unit.

4. Detailed guidance on incident reporting is posted on the Coordination Agency's electronic news page.

5. Organizations or individuals submitting incident reports must closely cooperate, provide complete and accurate information about the incident to the network members receiving the report, and create favorable conditions for these members and the Coordination Agency to access and study systems and equipment related to the incident to collect and analyze information for incident resolution.

Article 8. Receiving and Handling Incident Reports

1. Network members receiving incident reports must perform:

a) Immediately respond and not exceed 24 hours to organizations or individuals sending the report to confirm receipt of the incident report;

b) Handle incidents within their capacity and responsibility;

c) Report incidents to the Coordination Agency if they cannot be resolved.

2. The Coordination Agency receiving incident reports must perform:

a) Incident handling activities as a network member as stipulated in Clause 1 of this Article;

b) Issue coordination requests to network members to participate in incident response when necessary;

c) Mobilize other resources, invite experts to participate in incident response when necessary;

d) Organize cooperative activities with international computer incident response organizations to respond to cross-border incidents.

Article 9. Coordinating Incident Response

1. The Coordination Agency implements coordination by sending coordination requests to relevant network members involved in the incident, using the coordination request form in Appendix 4.

2. The Coordination Agency has the right to request network members to cooperate and propose international emergency computer incident response organizations to participate in incident response activities.

3. The Coordination Agency informs affected organizations and individuals about coordination requests during the coordination and incident response process.

4. Network members receiving coordination requests must comply with the coordination requests, report, and provide full feedback on the results to the Coordination Agency.

Chapter IV

RESPONSIBILITIES OF ORGANIZATIONS AND INDIVIDUALS

Article 10. Network Members

1. Publish the incident report reception address on their website.

2. Appoint a point person for incident response and ensure the point person complies with the provisions of Article 4.

3. Receive and handle incident reports as prescribed in Article 8.

4. Comply with coordination requests from the Coordination Agency as stipulated in Article 9.

5. Cooperate and support other network members in incident response activities.

6. Report and update the Coordination Agency on the following information:

a) The incident report reception address;

b) Information about the incident response point person including: name, position, contact address, fixed phone number, mobile phone number, fax number, email address.

7. Store incident reports and incident handling minutes, store coordination requests and reports on the implementation of coordination requests for a minimum of one year, including the following information:

a) Content of the incident report, time of report receipt, confirmation send time;

b) Incident handling results, cause of the incident, handling time, and list of organizations and individuals participating in coordinated incident handling (if applicable);

c) Time of incident report sent to the Coordination Agency, time of confirmation received from the Coordination Agency for cases reported to the Coordination Agency.

8. Implement reporting procedures as stipulated in Article 6.

Article 11. Coordination Agency (VNCERT Center)

1. Fulfill network member obligations as stipulated in Clauses 1, 2, 3, 5, and 7 of Article 10, where the document retention period for Clause 7 of Article 10 is implemented according to current state regulations on record retention periods commonly applied in government agency operations.

2. Organize network activities and coordinate incident response activities, develop regulations and guidelines within the network regarding incident response.

3. Directly receive, handle, or coordinate handling of incident reports.

4. Develop and deploy technical systems supporting communication and information exchange within the network and facilitate network member use of the system.

5. Aggregate and publish within the network information on notifications and warnings about vulnerabilities, weaknesses, and attack sources on the Internet.

6. Collect, update, and publish on the VNCERT Center's website information on incident report reception addresses of network members.

7. Collect, update, and publish information on the list of points persons for network members.

8. Provide annual statistical reports on emergency incident response activities.

Article 12. Internet service providers

1. Fulfill membership obligations in accordance with the provisions of Article 10.

2. Guide Internet service users or Internet subscribers (hereinafter referred to collectively as customers) to report incidents.

3. Perform incident handling functions for customers upon receiving reports or detecting incidents.

4. Provide the following information when requested by the Coordination Agency:

a) Information about their own customers related to incidents, technical information about their customers' systems related to incidents (IP address, domain name, access logs, and other relevant information if available);

b) Network structure information, monitoring and statistical information on network data flows related to incidents (if available);

c) Provide software, source code of software causing incidents, data storage related to incidents, information about hardware causing incidents (if available).

5. Pre-install connection ports and backup connection interfaces at important Internet connection points to serve themselves and authorized state agencies to monitor and detect attacks or the spread of malicious software.

6. Facilitate the Coordination Agency's access and research on systems and equipment related to incidents to collect and analyze information for the purpose of incident handling.

7. Implement coordination requirements for the following activities:

a) Disconnect from devices or service systems causing incidents;

b) Temporarily block or redirect IP addresses and domain names causing incidents;

c) Remove or temporarily remove applications or services causing incidents on the Internet.

8. Support resources within their capacity and within a specified time period as required by the Coordination Agency to carry out incident response activities or incident response drills, including:

a) Internet connectivity for cases where denial-of-service attacks exhaust bandwidth resources or require increased readiness for critical service systems;

b) Cybersecurity personnel participating in incident response activities;

c) Security technology equipment (if available).

Article 13. VNNIC Center

1. Fulfill membership obligations in accordance with the provisions of Article 10.

2. Provide information on domain name registrants, IP address management units, network identifiers issued by VNNIC, and other relevant information related to incidents upon request by the Coordination Agency.

3. Implement coordination requirements of the Coordination Agency regarding the handling of incidents related to Vietnam's Internet resources.

Article 14. Specialized units for information technology under Ministries, Agencies equivalent to Ministries, and Government Agencies; Provincial Departments of Information and Communications under central cities

1. Fulfill membership obligations in accordance with the provisions of Article 10.

2. Develop and guide the implementation of incident response activities within their scope of responsibility.

3. Coordinate and support emergency incident response activities within their scope of responsibility and operational area when requested by the Coordination Agency.

Article 15. Other individuals and organizations

1. Organizations providing cybersecurity services

a) Share information and statistics on incident response activities carried out when requested by the Coordination Agency;

b) Support human resources and technological solutions within their capacity when requested by the Coordination Agency.

2. Individuals and organizations using the Internet

a) Proactively apply technical measures and solutions to ensure cybersecurity and scan computers for malware to prevent Internet incidents;

b) Proactively provide information and actively cooperate with members of the incident response network in the detection, prevention, and handling of incidents.

Chapter V

IMPLEMENTATION

Article 16. Effective Date

Circular 249/2025/NĐ-CP takes effect from November 15, 2011.

2. During implementation, if there are any difficulties or new entities arise, relevant organizations and individuals should promptly reflect these issues to the Ministry of Information and Communications (VNCERT Center) for review, supplementation, and amendment./.

 

Original document (PDF)

Open PDF in a new tab ↗

Relations map

↑ Basis & documents that affect this document
Based on 11
67/2006/QH11 Luật Công nghệ thông tin số 67/2006/QH11 In effect 64/2007/NĐ-CP Nghị định số 64/2007/NĐ-CP Ứng dụng công nghệ thông tin trong hoạt động của cơ quan nhà nước In effect 97/2008/NĐ-CP Nghị định số 97/2008/NĐ-CP Về quản lý, cung cấp, sử dụng dịch vụ Internet và thông tin điện tử trên Internet Expired 41/2009/QH12 Nghị quyết số 41/2009/QH12 Về chủ trương đầu tư Dự án điện hạt nhân Ninh Thuận Expired 187/2007/NĐ-CP Nghị định số 187/2007/NĐ-CP Quy định chức năng, nhiệm vụ, quyền hạn và cơ cấu tổ chức của Bộ Thông tin và Truyền thông Expired 1293/2017/QĐ-UBND Quyết định số 1293/2017/QĐ-UBND Ban hành Quy chế đảm bảo an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan quản lý nhà nước tỉnh Thanh Hóa In effect 87/2016/QĐ-UBND Quyết định số 87/2016/QĐ-UBND Ban hành quy chế đảm bảo an toàn thông tin mạng trong hoạt động của các cơ quan Nhà nước trên địa bàn tỉnh Nghệ An In effect 37/2016/QĐ-UBND Quyết định số 37/2016/QĐ-UBND Ban hành Quy chế đảm bảo an toàn thông tin mạng trong hoạt động ứng dụng Công nghệ thông tin của cơ quan nhà nước trên địa bàn tỉnh Sơn La In effect 30/2016/QĐ-UBND Quyết định số 30/2016/QĐ-UBND Ban hành quy chế đảm bảo an toàn thông tin trong hoạt động ứng dụng công nghệ thông tin trên địa bàn tỉnh Bình Phước Expired 24/2016/QĐ-UBND Quyết định số 24/2016/QĐ-UBND V/v Ban hành Quy chế đảm bảo an toàn, an ninh thông tin trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Kon Tum In effect 49/2014/QĐ-UBND Quyết định số 49/2014/QĐ-UBND Ban hành Quy định đảm bảo an toàn thông tin trong hoạt động ứng dụng công nghệ thông tin của cơ quan nhà nước trên địa bàn tỉnh Long An Expired
27/2011/TT-BTTTT
Circular No. 27/2011/TT-BTTTT on the coordination of activities to rescue internet network incidents in Vietnam
Expired
↓ Documents affected by this document
Related 5
30/2016/QĐ-UBND Quyết định số 30/2016/QĐ-UBND Về việc điều chỉnh Quyết định số 32/2014/QĐ-UBND ngày 21/12/2014 của Ủy ban nhân dân tỉnh về ban hành Quy định diện tích tối thiểu được phép tách thửa đất đối với các loại đất trên địa bàn tỉnh Khánh Hòa. Expired 37/2016/QĐ-UBND QUYẾT ĐỊNH SỐ 37/2016/QĐ-UBND VỀ VIỆC QUY ĐỊNH TỶ LỆ (%) PHÂN CHIA CÁC NGUỒN THU GIỮA CÁC CẤP NGÂN SÁCH TRÊN ĐỊA BÀN TỈNH PHÚ THỌ GIAI ĐOẠN 2017 - 2020 Expired 49/2014/QĐ-UBND Quyết định số 49/2014/QĐ-UBND Về việc quy định mức thu, quản lý và sử dụng các khoản thu phí, lệ phí thuộc thẩm quyền quyết định của HĐND tỉnh trên địa bàn tỉnh Quảng Trị Expired 24/2016/QĐ-UBND Quyết định số 24/2016/QĐ-UBND Phê duyệt Đề án sắp xếp quy mô, mạng lưới trường, lớp đối với giáo dục mầm non, giáo dục phổ thông trên địa bàn tỉnh Yên Bái, giai đoạn 2016-2020 Expired 87/2016/QĐ-UBND Quyết định số 87/2016/QĐ-UBND Thực hiện Nghị quyết số 45/2016/NQ-HĐND ngày 09 tháng 12 năm 2016 của Hội đồng nhân dân tỉnh về việc quy định mức thu, chế độ thu, nộp các loại lệ phí quản lý nhà nước liên quan đến Quyền và nghĩa vụ công dân; Quyền sở hữu, quyền sử dụng tài sản thuộc thẩm quyền của Hội đồng nhân dân tỉnh Expired

Click a document to open. A red border = a relation that changes validity.