Circular No. 29/2011/TT-NHNN on safety and security for the provision of banking services over the Internet

Circular No. 29/2011/TT-NHNN stipulates safety and security requirements for providing banking services over the Internet in Vietnam, applicable to credit institutions and foreign bank branches. The Circular focuses on management requirements for systems, human resources, communication networks, hardware and software, data encryption, log management, incident handling, customer guidance, and reporting.

文号29/2011/TT-NHNN
文件类型Circular
发布机关State Bank of Vietnam
签署人Nguyễn Toàn Thắng — Phó Thống đốc Ngân hàng Nhà nước Việt Nam
更新26/06/2026
领域Uncategorized
发布日期21/09/2011
生效日期04/11/2011
失效日期01/07/2017
状态Expired
✦ 智能摘要

Circular No. 29/2011/TT-NHNN stipulates safety and security requirements for providing banking services over the Internet in Vietnam, applicable to credit institutions and foreign bank branches. The Circular focuses on management requirements for systems, human resources, communication networks, hardware and software, data encryption, log management, incident handling, customer guidance, and reporting.

适用范围

Credit institutions and foreign bank branches providing banking services over the Internet in Vietnam.

要点

  • Ensuring confidentiality of account information, deposits, and transactions of customers; using two-factor authentication for important transactions.
  • Establishing and maintaining cybersecurity systems, including network segmentation, intrusion detection, malware prevention, and contingency plans.
  • Managing human resources, ensuring cross-check controls in system administration and software development tasks.
  • Authenticating customers and transactions through two-factor authentication; protecting personal information of customers.
  • Ensuring database security, conducting regular vulnerability patch reviews, and developing backup contingency plans.

🌐 本文件的社会影响

  • Positive impact: Enhancing security and safety for online banking transactions, reducing risks of personal information loss.
  • Negative impact: Higher investment costs in cybersecurity systems; requirement for specialized human resource training.

❓ 常见问题

Which entities must comply with this Circular?

Credit institutions and foreign bank branches providing banking services over the Internet in Vietnam.

What customer information does the Circular require to be secured?

Securing customer account information, deposits, and transactions; using two-factor authentication for important transactions.

Does the Circular contain requirements for managing human resources?

Yes, it requires selecting staff with appropriate moral character and qualifications, clearly assigning responsibilities, and implementing cross-check controls for critical activities.

How does the Circular regulate database management?

Only licensed database management systems may be used; vulnerability patches must be reviewed and updated at least every six months; contingency backup plans must be developed.

Are there periodic reporting requirements under the Circular?

Yes, service providers must submit Internet Banking service reports, annual reports, and emergency reports when incidents occur.

全文

CIRCULAR

Provisions on safety and security for providing online banking services

________________________

 

Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12 dated June 16, 2010;

Pursuant to the Law on Credit Organizations No. 47/2010/QH12 dated June 16, 2010;

||| Pursuant to Decree No. 63/2018/NĐ-CP dated May 4, 2018 of the Government on public-private partnership investment;

Pursuant to Decree No. 35/2007/NĐ-CP dated March 8, 2007 of the Government on electronic transactions in banking activities;

Pursuant to Decree No. 64/2001/NĐ-CP dated September 20, 2001 of the Government on payment activities through service providers;

Pursuant to Decree No. 26/2007/NĐ-CP dated February 25, 2007 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and certification services for digital signatures;

Pursuant to Decree No. 96/2008/NĐ-CP dated August 26, 2008 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;

Pursuant to Decree No. 97/2008/NĐ-CP dated August 28, 2008 of the Government on management, provision, and use of Internet services and electronic information on the Internet;

The State Bank of Vietnam provides provisions on safety and security for providing online banking services as follows:

PART I

GENERAL PROVISIONS

Article 1. Scope of Regulation and Applicability

1. This Circular sets forth the requirements to ensure safety and security for the provision of banking services over the Internet.

2. This Circular applies to credit institutions, foreign bank branches providing online banking services (hereinafter referred to as service providers) in Vietnam.

Article 2. Definitions and Terms

In this Circular, the following terms are understood as follows:

1. Online banking service (Internet Banking service): includes banking services provided through the Internet, including:

a) Information about the service provider and its services.

b) Information inquiry services such as customer information inquiries, account inquiries, balance inquiries, and other information inquiries.

c) Execution of online financial transactions such as account services, transfers, credit issuance, and payments via accounts.

d) Other services as prescribed by the State Bank of Vietnam.

2. Internet Banking System: is a structured set of hardware, software, databases, communication networks, and security systems serving the management and provision of online banking services.

3. Customer: refers to organizations and individuals related to the use of Internet Banking services.

4. Two-factor authentication: is a method of authentication that requires two different factors to verify the identity of a user. Two-factor authentication relies on information that the user knows, such as customer ID numbers and passwords, together with something the user has, such as one-time password (OTP), random grid matrix, biometric identifiers, or other supporting devices to prove identity.

5. Privileged Account: is an access account to the information technology system for performing special tasks or accessing sensitive data. A privileged account is typically used for configuring equipment, managing the system, operating system management, database management, or application management (for example, root, supervisor, system, administrator accounts).

Article 3. General Principles for Providing Online Banking Services by Service Providers

1. Ensuring Confidentiality

a) Ensuring confidentiality of information related to accounts, deposits, entrusted assets, and customer transactions in accordance with the law.

b) Customer passwords, encryption keys, and other codes must be encrypted during transactions, over transmission channels, and stored at the service provider.

2. Ensuring Availability

a) Publicly committing to the continuous operation of the Internet Banking system clearly and explicitly, and specifying this commitment in the service provision contract with customers. This commitment must minimally include the total downtime of the system in a year, daily service provision time, and system recovery time after incidents.

b) Ensuring sufficient resources in terms of information technology infrastructure and personnel to continuously provide Internet Banking services as committed by the service provider to customers.

c) Establishing, issuing, and adhering to the procedures of the Internet Banking system.

d) Using monitoring tools to track the performance of the main system and backup system to ensure continuous operation.

3. Ensuring Integrity

a) Ensuring the integrity of information during processing, storage, and transmission between the service provider and customers.

b) Combining administrative and technical security measures in:

- Physical access;

- Logical access;

- Data entry, processing, transmission, extraction, storage, and recovery processes.

4. Customer Authentication and Transaction Verification

a) Ensuring the authentication and identification of customers when they access and use Internet Banking services.

b) Using two-factor authentication on the Internet Banking system when executing payment transactions and important transactions such as establishing connections between accounts, registering third-party payments, changing daily transaction limits, and changing personal data-related account information (such as workplace or home address, contact phone number, email address, and other information for customer verification).

5. Protecting Customers

a) Providing full information about customer rights and obligations before signing a service provision contract with customers. In the service provision contract, it must specify that the service provider ensures the provisions outlined in this Article for customers. The service provider is responsible for fully implementing the terms under its responsibility as stipulated in the service provision contract signed with customers.

b) In the service provision contract, the service provider must clearly state its responsibility for securing customer personal information when using Internet Banking services; specify how the bank collects and uses customer information, and commit not to sell, disclose, or leak such information.

c) Implementing measures to ensure safety and security when the service provider distributes software to customers through the Internet environment.

d) Being responsible for inspecting, warning, and implementing measures to prevent and combat fake websites providing Internet Banking services of the service provider; simultaneously informing customers of the methods to identify genuine websites.

PART I

SPECIFIC PROVISIONS

Article 4. Policy on system safety and security

Develop and promulgate safety and security regulations for the Internet Banking system in accordance with state regulations on the safety and security of information technology systems, banking industry regulations, and the information technology safety and security rules of the entity. At least once a year, the entity must review, amend, and perfect these regulations to ensure their appropriateness, completeness, and effectiveness.

Article 5. Human Resource Management

1. Select staff members who have the necessary moral character, qualifications, and capabilities to meet the requirements of professional expertise and technology when assigning tasks related to the Internet Banking system.

2. System management tasks; software application development, maintenance, and system operation must be assigned to different departments and individuals. Cross-checking control must be ensured, and no single individual should have full authority over the system or be able to initiate or interfere with transactions within the Internet Banking system independently. Clear responsibilities and permissions must be defined for each group and individual mentioned above. Special access accounts on the Internet Banking system must be designed to only be accessible with keys from at least two people and must be strictly controlled for all activities of this account.

3. Specific and clear provisions must be established and fully implemented for managing and supervising third-party personnel accessing the Internet Banking system. Requirements for safety, security, and agreements must be clearly defined in contracts with third parties.

Article 6. Communication Network

1. Measures must be taken to separate network zones to ensure control over system accesses.

2. Measures must be implemented to detect and prevent intrusions and the spread of harmful malware to the system.

3. Develop and implement contingency plans for critical positions that significantly impact the network system or could cause a complete shutdown of the unit's network system in case of an incident.

4. Wireless connections must use secure authentication measures.

5. Ensure bandwidth requirements for providing Internet Banking services.

6. Update system patches, configure network devices, and security devices at least every six months. In cases where system errors are detected, immediate updates must be carried out.

7. Network equipment, security, and protection devices, antivirus software, and network analysis and management tools installed in the unit's network must have clear copyright and origin.

Article 7. Hardware and Software Systems

1. Ensure sufficient capacity and performance of server infrastructure and accompanying devices serving the Internet Banking system (hereinafter referred to as the Internet Banking server) to meet customer service processing speed requirements.

2. Requirements for the Internet Banking server

a) Have high availability features and flexible backup mechanisms to ensure continuous operation.

b) Be located in a secure area and closely monitored.

c) Be logically or physically separated from other operational servers.

3. Requirements for system software:

a) Regularly review and update system software patch versions according to the supplier's recommendations at least every six months.

b) Maintain a list of software permitted to be installed on the Internet Banking server and periodically, at least every three months, update and check to ensure compliance with this list.

Article 8. Application Software

1. General Requirements

a) Security and confidentiality requirements of business operations must be determined beforehand and organized, implemented throughout the entire software development process from analysis and design to deployment and maintenance.

b) Documentation on security and confidentiality of software must be systematized and stored, used under the "Confidential" regime.

c) Before deploying new application programs, risks associated with the deployment process for business operations, related information technology systems must be assessed, and measures to mitigate and address these risks must be established and implemented.

d) It is necessary to identify and record abnormal activities and transactions occurring within the system.

2. Testing and Trial of Application Software

a) Develop and approve test plans and scenarios for Internet Banking applications, clearly stating the conditions regarding security and confidentiality that must be met.

b) Detect and eliminate errors and potential fraud when entering input data and security vulnerabilities during the testing process.

c) Record errors and the error handling process, particularly those related to security and confidentiality, in test reports.

d) Test security and confidentiality features on popular browsers such as Internet Explorer, Mozilla, Firefox, and Google Chrome.

đ) Conduct testing in a separate environment without affecting normal business operations. Prepare a report of the test results for approval by the competent authority before putting it into use.

e) The use of data for testing purposes must have preventive measures to avoid misuse or confusion.

3. Management and Version Upgrades

a) For each software change request, analyze and assess the impact of the change on current systems, business operations, and related information technology systems.

b) Software versions including source code must be centrally managed, stored, secured, and have a mechanism for granting permissions to individual members for file manipulation.

c) Information about versions, update times, and version updaters must be recorded.

d) Each upgraded version must be tested for security and confidentiality features and stability before official deployment.

đ) Version upgrades must be based on test results and approved by the competent authority.

e) Successful software versions after testing must be strictly managed; prevent unauthorized modifications and be ready for deployment.

g) Accompanying new software versions must include clear instructions on changes, software update guidance, and other relevant information, and must be approved by the competent authority before deployment to customers.

4. Source Code Control

a) Review source code to eliminate harmful code segments and security vulnerabilities (back-doors).

b) Specifically designate individuals responsible for managing the source code of the Internet Banking system.

c) Access to source code must be approved by the competent authority and monitored, logged.

d) Source code must be securely stored at least two separate locations.

đ) In cases where service providers purchase software from third parties without receiving the source code, service providers must require third parties to commit to not having harmful code segments in the delivered application software.

Article 9. Database Security

1. Only databases management systems with clear copyright and origin, and which have been tested through actual operational activities of similar organizations within or outside the country, may be used.

2. The database management system used for the Internet Banking system must meet requirements for stable operation; handle and store large volumes of data according to business needs; have mechanisms for protecting and managing access rights to database resources.

3. Review and update patches and bug fixes for the database management system at least once every six months or immediately upon recommendation from the provider.

4. Develop backup and contingency plans for the database to ensure continuous operation of Internet Banking systems in case of database failure.

5. Implement strict access control measures for each individual accessing the database. Logging must be conducted for all database accesses and configuration operations.

6. Have solutions to prevent various forms of database attacks.

Article 10. Data Encryption

1. Select encryption algorithms that meet the requirements for ensuring confidentiality and processing capabilities of the Internet Banking system.

2. Regularly review and assess the security level of the encryption algorithm being used at least once a year, and promptly address any vulnerabilities identified.

3. Do not allow a single individual to perform the entire key generation process for encryption. Encryption keys must be created, changed, distributed, and stored securely.

4. Ensure that encrypted information can be recovered when necessary.

5. Establish strict regulations on the revocation of encryption keys, including both key destruction and recovery procedures.

Article 11. Log Management

1. Record the following events for the Internet Banking system:

a) Access processes.

b) System configuration operations.

c) Authentication events.

d) Events related to granting and revoking access rights and service usage.

e) Transaction processing.

f) Abnormal accesses.

2. Record customer transactions and monitor financial transactions on the Internet Banking system.

3. Internet Banking system logs must be stored securely, protected, and accessible when needed. The minimum retention period for logs is three years.

4. Check access logs at least once a month to detect and prevent abnormal and unauthorized accesses.

Article 12. Incident Management

1. Develop an incident management procedure, clearly defining the responsibilities of relevant departments, detailing the steps to be taken, including notifying customers and reporting to the State Bank.

2. The incident management procedure must be reviewed and updated with incidents and response plans at least once every six months.

3. Apply technical solutions to detect and promptly address denial-of-service attacks, such as using firewalls; intrusion detection and prevention devices; specialized warning and traffic diversion devices; packet filtering during attacks.

4. Require third-party providers to supply incident handling procedures for services related to the Internet Banking system provided by them.

Article 13. Guidance for Customers

1. Issue regulations clearly stating the rights and obligations of customers and service providers regarding the provision and use of Internet Banking services.

2. Guide customers on self-protection measures during the use of Internet Banking services such as:

a) Methods to set and protect passwords.

b) Not sharing password storage devices or digital signatures.

c) Not setting web browser options to save usernames and passwords.

d) Logging out of the Internet Banking system when not in use.

đ) Being cautious and limiting the use of public computers and wireless networks to access the Internet Banking system.

e) Methods to access the application address of Internet Banking services provided by the entity.

g) Reporting errors and incidents encountered during the use of services to the service provider.

h) Warning about other risks.

Chapter III

REPORT

Article 14. General Requirements

Service providers have the responsibility to submit reports to the State Bank of Vietnam (Department of Information Technology) in accordance with Articles 15 and 16 of this Circular.

Article 15. Types of Reports

1. Report on Providing Internet Banking Services:

a) For entities that have provided services before the effective date of this Circular: Entities must submit reports within ten working days from the date this Circular becomes effective.

b) For entities providing services after the effective date of this Circular: Entities must submit reports at least ten working days prior to officially providing Internet Banking services.

2. Annual Report:

Service providers must submit the Annual Report before March 15th each year.

3. Emergency Report:

Service providers must submit an Emergency Report within five days from the occurrence or discovery of security incidents affecting the operation of the Internet Banking system.

Article 16. Content of Reports

1. The report on the provision of Internet Banking services includes the following contents:

a) Website address for service provision.

b) Products and services currently being provided.

c) Date of official provision.

d) Provider of the Internet Banking system product.

đ) Third parties hired or collaborating in building and operating the Internet Banking system; related activities involving third parties and their forms of participation.

e) Documentation including: information technology infrastructure and communication, human resources, technical business procedures, risk management plans, and other relevant issues as stipulated in Chapter II of this Circular.

2. The annual report includes the following contents:

a) Internet Banking products and services currently being provided.

b) Changes in Internet Banking products and services since the last report.

c) Changes in documentation specified in Point e, Clause 1, Article 16 since the last report.

d) Number of customers using Internet Banking services and customer growth rate compared to the same period in the previous year.

đ) Incidents that occurred during the period. Risk incidents are reported by risk group, damages, and applied remedial measures.

e) Recommendations and proposals.

3. The emergency report includes the following contents:

a) Date and location where the incident occurred.

b) A brief description of the incident and its status at the time of occurrence.

c) Cause of the incident.

d) Risk assessment and impact on the Internet Banking system and related systems.

đ) Damage situation.

e) Measures taken by the entity to resolve the incident, prevent, and mitigate risks.

g) Recommendations and proposals.

Chapter IV

IMPLEMENTING PROVISIONS

Article 17. Effective Date

1. This Circular takes effect from November 4, 2011.

2. Circular No. 09/2003/TT-NHNN dated August 5, 2003, issued by the Governor of the State Bank of Vietnam guiding the implementation of certain provisions in Decree No. 55/2001/NĐ-CP dated August 23, 2001, of the Government on the management, provision, and use of the Internet, and Circular No. 01/2008/TT-NHNN dated March 10, 2008, amending and supplementing Circular No. 09/2003/TT-NHNN, shall cease to be effective from the date this Circular takes effect.

3. During the implementation process, if any issues arise or difficulties occur, organizations and individuals concerned should promptly reflect them to the State Bank of Vietnam (Department of Information Technology at 64 Nguyen Chi Thanh Street, Dong Da District, Hanoi) for consideration and resolution.

Article 18. Responsibility for Implementation

1. The Department of Information Technology is responsible for monitoring and inspecting the implementation of this Circular by service providers. Annually, through the reports submitted by entities or on-site inspections, it evaluates compliance with regulations and ensures the safety and confidentiality of Internet Banking systems of entities; compiles and reports to the Governor on the safety and confidentiality of Internet Banking services in the banking system of Vietnam.

2. Banking inspection and supervision agencies are responsible for coordinating with the Department of Information Technology to inspect and supervise the implementation of this Circular and handle administrative violations according to the law.

3. The Head of the Office, Director of the Department of Information Technology, Heads of units under the State Bank of Vietnam, Governors of the State Bank branches in centrally governed cities and provinces; Chairmen of the Board of Directors, Chairmen of the Board of Members, General Managers (Directors) of credit organizations and foreign bank branches providing Internet Banking services are responsible for implementing this Circular./.

原始文件(PDF)

在新标签页打开PDF ↗

关系图

29/2011/TT-NHNN
Circular No. 29/2011/TT-NHNN on safety and security for the provision of banking services over the Internet
Expired

点击文件即可打开。红色边框=改变效力的关系。