Circular No. 27/2011/TT-BTTTT stipulates the network for rescuing internet network incidents in Vietnam, including members such as the VNCERT Center, ISPs, Internet service providers, and state agencies. This circular guides the coordination, handling of incidents, and responsibilities of each entity during the incident rescue process.
적용 범위
The VNCERT Center, ISPs, Internet service providers, state agencies such as the Ministry of Information and Communications, Provincial Departments of Information and Communications, organizations providing information security services, individuals and organizations using the Internet.
핵심 사항
- The VNCERT Center is the Coordination Agency, with the authority to mobilize other organizations within the network to rescue incidents.
- ISPs and Internet service providers must report periodically on their activities in receiving and handling incidents.
- When encountering an incident, organizations or individuals using the Internet notify one or more members of the network.
- The Coordination Agency carries out incident handling activities and has the right to request network members to participate in incident rescue.
- Network members must comply with coordination requirements from the Coordination Agency and report on the results of implementation.
🌐 이 문서의 사회적 영향
- Positive impact: Enhance the ability to rescue internet network incidents, protect information security for citizens and businesses.
- Negative impact: May impose burdens on time and resources for network members.
❓ 자주 묻는 질문
What rights does the VNCERT Center have in coordinating incident rescue?
The VNCERT Center has the right to mobilize other organizations within the network to rescue incidents, decide on coordination methods, and be responsible for coordination requests.
What information must ISPs report to the Coordination Agency?
ISPs must report every six months on their activities in receiving and handling incidents, including content according to the reporting form in Appendix 2.
To whom should organizations or individuals using the Internet notify when encountering an incident?
When encountering an incident that cannot be resolved independently, organizations or individuals using the Internet should notify the incident to one or more network members such as the ISP providing Internet services and the Coordination Agency.
What can the Coordination Agency require from network members?
The Coordination Agency may require network members to cooperate, propose international computer emergency response organizations to participate, and mobilize additional resources if necessary.
What obligations must network members fulfill?
Network members must report periodically, handle incident notifications, coordinate with the Coordination Agency, and implement coordination requirements as prescribed.
전문
CIRCULAR
Regulations on coordinating activities to respond to internet security incidents in Vietnam
__________________________
MINISTER OF INFORMATION AND COMMUNICATIONS
Pursuant to the Law on Information Technology dated June 29, 2006;
Based on the Law on Telecommunications dated December 4, 2009;
Pursuant to Decree No. 64/2007/NĐ-CP dated April 10, 2007 of the Government on the application of information technology in state agency activities;
Based on Decree No. 97/2008/NĐ-CP dated August 28, 2008 on management, provision, and use of Internet services and electronic information on the Internet;
BASED ON THE GOVERNMENT DECREE NO. 187/2007/NĐ-CP OF DECEMBER 25, 2007 ON THE FUNCTIONS, TASKS, POWERS, AND ORGANIZATIONAL STRUCTURE OF THE MINISTRY OF INFORMATION AND COMMUNICATIONS;
At the proposal of the Director of the National Cybersecurity Emergency Response Team (VN-CERT),
THE REGULATIONS ARE AS FOLLOWS:
PART I
GENERAL PROVISIONS
Article 1. Scope and Applicability
These Circulars stipulate the emergency response network, coordination of activities to respond to internet security incidents; responsibilities of organizations and individuals related to responding to internet security incidents in Vietnam.
Article 2. Explanation of terms
1. Internet security incident is an event that has occurred, is occurring, or may occur causing information security risks on the Internet, discovered through monitoring, assessment, and analysis by relevant agencies, organizations, or individuals, or warned by experts and organizations in the field of information security both domestically and internationally (hereinafter referred to as an incident).
2. Serious incident is an incident having one or more of the following characteristics: likely to occur on a wide scale and spread rapidly; capable of damaging computer networks and the Internet; potentially causing significant damage or consequences to information systems on the network; requiring substantial national or international resources to resolve.
Chapter II
EMERGENCY RESPONSE NETWORK
Article 3. Emergency Response Network
1. The emergency response network is a collection of agencies, organizations, and enterprises participating in coordinated emergency response activities in Vietnam (hereinafter referred to as the network, agencies, organizations, and enterprises collectively called members of the network and abbreviated as members). The network includes mandatory members and voluntary members who have registered to join the network.
2. Mandatory members include:
a) The coordination agency;
b) Information technology units of Ministries, Ministries-equivalent agencies, and agencies under the Government; Provincial Departments of Information and Communications.
c) Internet Service Providers (ISPs);
d) Vietnam Internet Network Information Center (VNNIC).
3. Voluntary members are agencies, organizations, or enterprises voluntarily participating in the network with a registration form according to Appendix 1 submitted to the Coordination Agency and accepted. It is encouraged for organizations operating in the field of information security to establish departments responsible for emergency response and join the network.
4. The National Cybersecurity Emergency Response Team (VN-CERT) is the Coordination Agency. VN-CERT performs the function of coordinating nationwide emergency response activities and has the authority to mobilize other organizations within the network to cooperate in preventing, handling, and resolving internet security incidents in Vietnam; has the right to decide on the form of coordination of emergency response activities and is responsible for coordination requests; serves as the point of contact for exchanging information on cooperation in emergency response with international cybersecurity emergency response organizations. The activities of the Coordination Agency aim to mobilize network members to cooperate in handling and responding to incidents, which is referred to as coordinated emergency response.
5. Detailed contact information including address, phone number, fax number, email address, and website of network members is publicly announced on the Coordination Agency's website (www.vncert.gov.vn).
Article 4. Emergency Response Point
1. The emergency response point is an individual or department authorized to represent network members in communicating and exchanging information with other network members during emergency response activities.
2. The emergency response point must have professional qualifications and skills to carry out coordinated emergency response activities.
3. The emergency response point must ensure continuous communication capability (24 hours a day, 7 days a week).
Article 5. Principles of Operation for the Emergency Response Network
1. Information exchanged and provided during coordination and handling of incidents must be kept confidential according to the requirements of organizations or individuals experiencing incidents, except when the incident involves multiple users and the Coordination Agency requests a warning or reminder.
2. Information exchange within the network must be conducted through one or more forms such as: official letters, emails, telephone calls, faxes. Network members receiving information must proactively verify the sender to ensure that the received message is reliable.
3. Network members have the right to share information, experiences, participate in emergency response exercise activities, and attend training courses on emergency response activities.
Article 6. Reporting System
1. Network members are responsible for reporting every six months to the Coordination Agency about their activities in receiving and handling incidents.
a) Content of the report follows the periodic report form at Appendix 2. Guidance on the report form is posted on the VNCERT electronic news page;
b) Deadline for submitting reports: before June 15th and before December 15th each year;
c) Form of the report: by official letter and email;
d) Reports sent to VNCERT Center: 18 Nguyen Du, Hanoi; email address: [email protected].
2. Network members are responsible for submitting urgent reports when requested by the Coordination Agency or when they discover serious incidents. The form and address for submitting reports follow the provisions of Clause 1 of this Article.
Chapter III
COORDINATION OF EMERGENCY RESPONSE ACTIVITIES
Article 7. Incident Reporting
1. When encountering an incident that cannot be resolved independently, Internet users or organizations must report the incident to one or more network members as follows:
a) The network member responsible for responding to incidents for that organization or individual (if applicable);
b) ISPs directly providing Internet services to that organization or individual;
c) The Coordination Agency.
2. Upon discovering serious incidents, organizations or individuals must immediately report them to the Coordination Agency.
3. The content of the incident report includes:
a) Incident description information following the incident report form at Appendix 3;
b) Other information as required by the receiving unit.
4. Detailed guidance on incident reporting is posted on the Coordination Agency's electronic news page.
5. Organizations or individuals submitting incident reports must closely cooperate, provide complete and accurate information about the incident to the network members receiving the report, and create favorable conditions for these members and the Coordination Agency to access and study systems and equipment related to the incident to collect and analyze information for incident resolution.
Article 8. Receiving and Handling Incident Reports
1. Network members receiving incident reports must perform:
a) Immediately respond and not exceed 24 hours to organizations or individuals sending the report to confirm receipt of the incident report;
b) Handle incidents within their capacity and responsibility;
c) Report incidents to the Coordination Agency if they cannot be resolved.
2. The Coordination Agency receiving incident reports must perform:
a) Incident handling activities as a network member as stipulated in Clause 1 of this Article;
b) Issue coordination requests to network members to participate in incident response when necessary;
c) Mobilize other resources, invite experts to participate in incident response when necessary;
d) Organize cooperative activities with international computer incident response organizations to respond to cross-border incidents.
Article 9. Coordinating Incident Response
1. The Coordination Agency implements coordination by sending coordination requests to relevant network members involved in the incident, using the coordination request form in Appendix 4.
2. The Coordination Agency has the right to request network members to cooperate and propose international emergency computer incident response organizations to participate in incident response activities.
3. The Coordination Agency informs affected organizations and individuals about coordination requests during the coordination and incident response process.
4. Network members receiving coordination requests must comply with the coordination requests, report, and provide full feedback on the results to the Coordination Agency.
Chapter IV
RESPONSIBILITIES OF ORGANIZATIONS AND INDIVIDUALS
Article 10. Network Members
1. Publish the incident report reception address on their website.
2. Appoint a point person for incident response and ensure the point person complies with the provisions of Article 4.
3. Receive and handle incident reports as prescribed in Article 8.
4. Comply with coordination requests from the Coordination Agency as stipulated in Article 9.
5. Cooperate and support other network members in incident response activities.
6. Report and update the Coordination Agency on the following information:
a) The incident report reception address;
b) Information about the incident response point person including: name, position, contact address, fixed phone number, mobile phone number, fax number, email address.
7. Store incident reports and incident handling minutes, store coordination requests and reports on the implementation of coordination requests for a minimum of one year, including the following information:
a) Content of the incident report, time of report receipt, confirmation send time;
b) Incident handling results, cause of the incident, handling time, and list of organizations and individuals participating in coordinated incident handling (if applicable);
c) Time of incident report sent to the Coordination Agency, time of confirmation received from the Coordination Agency for cases reported to the Coordination Agency.
8. Implement reporting procedures as stipulated in Article 6.
Article 11. Coordination Agency (VNCERT Center)
1. Fulfill network member obligations as stipulated in Clauses 1, 2, 3, 5, and 7 of Article 10, where the document retention period for Clause 7 of Article 10 is implemented according to current state regulations on record retention periods commonly applied in government agency operations.
2. Organize network activities and coordinate incident response activities, develop regulations and guidelines within the network regarding incident response.
3. Directly receive, handle, or coordinate handling of incident reports.
4. Develop and deploy technical systems supporting communication and information exchange within the network and facilitate network member use of the system.
5. Aggregate and publish within the network information on notifications and warnings about vulnerabilities, weaknesses, and attack sources on the Internet.
6. Collect, update, and publish on the VNCERT Center's website information on incident report reception addresses of network members.
7. Collect, update, and publish information on the list of points persons for network members.
8. Provide annual statistical reports on emergency incident response activities.
Article 12. Internet service providers
1. Fulfill membership obligations in accordance with the provisions of Article 10.
2. Guide Internet service users or Internet subscribers (hereinafter referred to collectively as customers) to report incidents.
3. Perform incident handling functions for customers upon receiving reports or detecting incidents.
4. Provide the following information when requested by the Coordination Agency:
a) Information about their own customers related to incidents, technical information about their customers' systems related to incidents (IP address, domain name, access logs, and other relevant information if available);
b) Network structure information, monitoring and statistical information on network data flows related to incidents (if available);
c) Provide software, source code of software causing incidents, data storage related to incidents, information about hardware causing incidents (if available).
5. Pre-install connection ports and backup connection interfaces at important Internet connection points to serve themselves and authorized state agencies to monitor and detect attacks or the spread of malicious software.
6. Facilitate the Coordination Agency's access and research on systems and equipment related to incidents to collect and analyze information for the purpose of incident handling.
7. Implement coordination requirements for the following activities:
a) Disconnect from devices or service systems causing incidents;
b) Temporarily block or redirect IP addresses and domain names causing incidents;
c) Remove or temporarily remove applications or services causing incidents on the Internet.
8. Support resources within their capacity and within a specified time period as required by the Coordination Agency to carry out incident response activities or incident response drills, including:
a) Internet connectivity for cases where denial-of-service attacks exhaust bandwidth resources or require increased readiness for critical service systems;
b) Cybersecurity personnel participating in incident response activities;
c) Security technology equipment (if available).
Article 13. VNNIC Center
1. Fulfill membership obligations in accordance with the provisions of Article 10.
2. Provide information on domain name registrants, IP address management units, network identifiers issued by VNNIC, and other relevant information related to incidents upon request by the Coordination Agency.
3. Implement coordination requirements of the Coordination Agency regarding the handling of incidents related to Vietnam's Internet resources.
Article 14. Specialized units for information technology under Ministries, Agencies equivalent to Ministries, and Government Agencies; Provincial Departments of Information and Communications under central cities
1. Fulfill membership obligations in accordance with the provisions of Article 10.
2. Develop and guide the implementation of incident response activities within their scope of responsibility.
3. Coordinate and support emergency incident response activities within their scope of responsibility and operational area when requested by the Coordination Agency.
Article 15. Other individuals and organizations
1. Organizations providing cybersecurity services
a) Share information and statistics on incident response activities carried out when requested by the Coordination Agency;
b) Support human resources and technological solutions within their capacity when requested by the Coordination Agency.
2. Individuals and organizations using the Internet
a) Proactively apply technical measures and solutions to ensure cybersecurity and scan computers for malware to prevent Internet incidents;
b) Proactively provide information and actively cooperate with members of the incident response network in the detection, prevention, and handling of incidents.
Chapter V
IMPLEMENTATION
Article 16. Effective Date
Circular 249/2025/NĐ-CP takes effect from November 15, 2011.
2. During implementation, if there are any difficulties or new entities arise, relevant organizations and individuals should promptly reflect these issues to the Ministry of Information and Communications (VNCERT Center) for review, supplementation, and amendment./.
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.