Circular No. 31/2015/TT-NHNN on ensuring safety and security of information technology systems in banking activities

Circular No. 31/2015/TT-NHNN stipulates measures to ensure safety and security of information technology systems in banking activities, applicable to the State Bank of Vietnam, credit institutions (excluding grassroots credit funds with assets under VND 10 billion and microfinance organizations), foreign bank branches, and organizations providing intermediary payment services. Notable points include management of IT assets, human resources, physical safety, internal networks, system access, and procedures for handling incidents.

文号31/2015/TT-NHNN
文件类型Circular
发布机关State Bank of Vietnam
签署人Nguyễn Toàn Thắng — Phó Thống đốc
更新24/06/2026
行业Banking
领域Banking Information Technology
发布日期28/12/2015
生效日期01/03/2016
失效日期
状态Expired
✦ 智能摘要

Circular No. 31/2015/TT-NHNN stipulates measures to ensure safety and security of information technology systems in banking activities, applicable to the State Bank of Vietnam, credit institutions (excluding grassroots credit funds with assets under VND 10 billion and microfinance organizations), foreign bank branches, and organizations providing intermediary payment services. Notable points include management of IT assets, human resources, physical safety, internal networks, system access, and procedures for handling incidents.

适用范围

The State Bank of Vietnam, credit institutions (excluding grassroots credit funds with assets under VND 10 billion and microfinance organizations), foreign bank branches, and organizations providing intermediary payment services.

要点

  • Entities must establish regulations on ensuring safety and security of information technology systems and review them at least once a year.
  • Management of IT assets, including mobile devices, portable storage media, and software.
  • Management of human resources, defining responsibilities for ensuring safety and security of information technology systems.
  • Ensuring physical safety and environmental conditions for installation of information technology equipment.
  • Controlling access to internal networks, the Internet, and application information.
  • Managing third-party IT services, including signing contracts and supervising provided services.

🌐 本文件的社会影响

  • Positive impact: Enhancing safety and security of information technology systems helps reduce risks for banks and customers.
  • Negative impact: May increase management and operation costs of information technology systems, requiring high-level specialized human resources.

❓ 常见问题

How should entities establish regulations on ensuring safety and security?

Regulations must be signed and issued by the head of the entity and include basic contents on managing IT assets, managing human resources, ensuring physical safety, managing operations and communications, managing access, and managing third-party IT services.

What regulations should entities implement for mobile devices?

Register mobile devices when connecting to internal networks; limit connection scope and control installed software; protect data on devices.

What measures should entities take to ensure physical safety?

Must identify, assess risk levels, and requirements for availability of physical assets; equip appropriate protective measures for important assets.

How should entities manage access?

Must define responsibilities, manage secret key codes, and limit access rights according to the principle of least privilege. Multi-factor authentication should be used for remote access to critical systems.

How should entities handle incidents?

Must receive incident information, assess impact level and scope, implement corrective measures, record files, and report results. Incident handling procedures and controls must be established to prevent recurrence.

全文

CIRCULAR

Rules on ensuring the safety and security of information technology systems in banking operations

                                  

Based on the Law on the State Bank of Vietnam No. 46/2010/QH12 dated June 16, 2010;

Based on the Law on Credit Institutions No. 47/2010/QH12 dated June 16, 2010;

Based on the Law on Electronic Transactions No. 51/2005/QH11 November 29, 2005;

Based on the Law on Information Technology No. 67/2006/QH11 June 29, 2006;

Pursuant to the Law on Information Security No. 86/2015/QH13 dated November 19, 2015;

Based on Decree No. 156/2013/NĐ-CP dated November 11, 2013 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam; The Governor of the State Bank of Vietnam issues this Circular on ensuring the safety and security of information technology systems in banking operations.

At the proposal of the Director of the Bureau of Information Technology,

1. This Circular stipulates rules on ensuring the safety and security of information technology systems in banking operations.

 

PART I

GENERAL PROVISIONS

 

Article 1. Scope of Regulation and Applicability

2. This Circular applies to the State Bank of Vietnam (the State Bank), credit institutions (excluding grassroots credit funds with assets under 10 billion VND and microfinance organizations), foreign bank branches, and organizations providing intermediary payment services (hereinafter referred to collectively as entities).

1. An information technology system is a structured set of hardware, software, databases, and network systems for producing, transmitting, collecting, processing, storing, and exchanging digital information to serve one or more technical and business activities of the entity.

Article 2. Interpretation of Terms

In this Circular, the following terms are understood as follows:

2. A critical information technology system is an information technology system that, when a failure occurs, will cause serious harm to the entity's operations or damage the interests of customers using the entity's services.

3. A data center includes technical infrastructure (telecommunication stations, cable systems) and computer systems along with auxiliary equipment installed there to centrally store, exchange, and manage data of one or more organizations or individuals.

4. Mobile devices are portable electronic devices with an operating system capable of processing, connecting to networks, and displaying information such as laptops, tablets, and smart mobile phones.

5. Data carriers are material means used to store and transmit electronic information.

6. Information technology risk is the possibility of loss occurring when carrying out activities related to information technology systems. Information technology risks relate to management, use of hardware, software, communication, system interfaces, operation, and human factors.

7. Information technology risk management is a coordinated set of activities aimed at identifying and controlling potential information technology risks.

8. Sensitive data is confidential information or internal circulation information of the entity or managed by the entity, which, if leaked, will negatively impact the reputation, finances, and operations of the entity.

9. A user account is a unique set of information representing a user on an information technology system, used by the user to log in and access authorized resources on that system. A user account must include at least a unique identifier and a secret key.

10. Third parties are organizations or individuals hired or collaborating with the entity to provide goods or technical services for information technology systems.

11. A firewall is a set of components or a system of equipment and software placed between two networks, designed to control all connections from inside to outside the network or vice versa.

12. Malicious software (malware) is software capable of causing abnormal operation of part or all of an information system or performing unauthorized copying, modification, or deletion of stored information in the system.

13. Technical vulnerabilities are positions within an information technology system that can be exploited or taken advantage of when attacked or illegally accessed.

14. Information confidentiality is ensuring that information is only accessed by those with corresponding authorization.

15. Information integrity is protecting the accuracy and completeness of information and ensuring that it can only be changed by those with corresponding authorization.

16. Information availability is ensuring that those with corresponding authorization can access information immediately when needed.

17. Cybersecurity is the protection of information technology systems and information transmitted over networks from unauthorized access, use, disclosure, disruption, alteration, or destruction to ensure the integrity, confidentiality, and availability of information.

1. Each entity must ensure the safety and security of its own information technology system.

Article 3. General Principles

2. Identify critical information technology systems and apply appropriate safety and security policies.

3. Timely identify, classify, assess, and effectively handle potential information technology risks that may occur within the entity.

4. Develop and implement regulations on the safety and security of information technology systems based on balancing the interests, costs, and risk tolerance levels of the entity.

5. Assign dedicated personnel responsible for ensuring the safety and security of information technology systems.

6. Clearly define the authority and responsibilities of the entity's head (or legal representative), each department, and individual within the entity regarding the work of ensuring the safety and security of information technology systems.

6. Clearly define the authorities and responsibilities of the head of the unit (or lawful representative), each department, and individual within the unit regarding the work to ensure the safety and security of information technology systems.

Article 4. Rules on Information Technology System Safety and Security

1. Units must establish rules on information technology system safety and security that are appropriate to their information technology systems, organizational structure, management requirements, and activities. These rules on information technology system safety and security must be signed off and issued by the unit head (or a legally authorized representative), organized for implementation, and rolled out throughout the entire unit.

2. The rules on information technology system safety and security shall cover the following basic contents:

a. Management of information technology assets; management of mobile device usage; management of data carriers usage;

b. Human resource management;

c. Physical and environmental safety assurance;

d. Operation and communication management;

đ) Access management;

e. Management of third-party information technology services;

g) Management of information system reception, development, and maintenance;

h. Incident management of information technology;

i. Assurance of continuous operation of the information technology system;

k. Inspection and reporting of information technology activities.

3. Units must review, amend, and perfect the rules on information technology system safety and security at least once a year, ensuring the completeness of these rules according to the provisions of this Circular. When discovering any inadequacies or unreasonable aspects causing information technology system security breaches or upon request from competent authorities, units must immediately amend and supplement the issued rules on information technology system safety and security.

 

Chapter II

PROVISIONS ON INFORMATION TECHNOLOGY SYSTEM SAFETY AND SECURITY ASSURANCE

INFORMATION TECHNOLOGY SYSTEM

Section 1

MANAGEMENT OF INFORMATION TECHNOLOGY ASSETS

 

Article 5. Management of Information Technology Assets

1. Types of information technology assets include:

a. Physical assets: information technology equipment, communication means, and devices serving the operation of the information technology system;

b. Information assets: data and information in digital form, documents expressed in paper or other media;

c. Software assets: system software, utility software, databases, application programs, and development tools.

2. Units must compile a list of all information technology assets, review, and update this list at least once a year.

3. Based on the classification of information technology assets under Clause 1 of this Article, units shall establish and implement regulations on asset management and utilization as stipulated in Articles 6, 7, 8, 9, and 10 of this Circular.

Article 6. Management of Physical Assets

1. The list of physical assets shall include basic information such as the name of the asset, value, level of importance, installation location, purpose of use, operational status, copyright information (if applicable).

2. Units must identify, assess risk levels, importance, and availability requirements of physical assets to classify and arrange them, and implement appropriate equipping and protective measures. For physical assets that are components of critical information technology systems in the main data center, preventive measures must be taken to ensure high availability for continuous operations.

3. Physical assets must be assigned to individuals or groups responsible for managing and using them.

4. Physical assets taken out of the unit must be approved by the unit head or someone authorized by the head. For physical assets containing sensitive information or data before being taken out of the unit, protective measures must be implemented to keep the stored information and data confidential.

5. Units must develop plans and procedures for maintenance and repair of each type of physical asset according to the State Bank's regulations on maintenance of computer equipment in the banking sector.

6. For physical assets storing sensitive data when changing the purpose of use or disposing of them, units must take measures to erase or destroy the data to ensure it cannot be recovered. In cases where data cannot be destroyed, units must take measures to destroy the storage component of the data on the asset.

7. For physical assets that are mobile devices or data carriers, in addition to the provisions of this Article, units must establish and implement management according to Articles 9 and 10 of this Circular.

Article 7. Management of Information Assets

1. Units must create a directory, define authority and responsibility for accessing and utilizing various types of information assets.

2. Units must classify and assess risk levels based on confidentiality, integrity, and availability requirements for the use of information assets to implement appropriate management and protection measures.

3. For information assets containing sensitive data, units must implement encryption measures to ensure safety and security during exchange and storage.

Article 8. Management of Software Assets

1. The list of software assets shall be established with basic information including: asset name, value, level of importance, purpose of use, scope of use, managing subject, copyright information, version, storage location.

2. The unit must classify and assess the risk level based on the requirements for confidentiality, integrity, and availability for use of software assets to implement appropriate management and protection measures.

3. The unit must develop plans and procedures for maintenance and organize their implementation for each type of software asset in accordance with the State Bank's regulations on the maintenance of IT equipment in the banking sector.

Article 9. Management of Mobile Device Usage

1. Mobile devices connecting to the internal network system of the unit must be registered for control purposes.

2. Limit the connection range from mobile devices to services and information systems of the unit; control connections from mobile devices to permitted information systems within the unit.

3. The unit must define the responsibilities of mobile device users, including the following minimum requirements:

a) Protecting the device against damage, theft, or loss;

b) Controlling installed software; updating software versions and patches on mobile devices;

c) Installing data encryption features; secret key protection software; anti-malware software and other security vulnerabilities;

d) Setting up functions to disable, lock the device, or remotely delete data in case of loss or theft;

e) Backing up data on mobile devices to protect and restore data when necessary;

f) Implementing data protection measures during warranty, maintenance, or repair of mobile devices.

Article 10. Management of Data Carrying Devices

The unit has the responsibility:

1. To control the connection and disconnection of data carrying devices with IT equipment.

2. Implement safety measures for data carriers during transportation and storage.

3. To implement protective measures for sensitive data stored on data carrying devices.

4. When a data carrying device containing sensitive data can no longer be used or is to be used for another purpose, it must be securely erased or destroyed to ensure that the data cannot be recovered.

5. To stipulate the responsibilities of individuals in managing and using data carrying devices.

 

Section 2

HUMAN RESOURCE MANAGEMENT

 

Article 11. Recruitment or Assignment of Tasks

1. Determine the responsibility for ensuring the safety and confidentiality of the IT system for positions requiring recruitment or assignment.

2. When recruiting or assigning personnel to important positions in the IT system such as system administration, security administration, system operation, database administration, the unit must strictly examine and evaluate the moral character and professional qualifications through personal history and criminal record.

3. Require recruited personnel to commit to confidentiality in writing either as a separate agreement or as part of the employment contract. This commitment must include provisions regarding the responsibility for ensuring the safety and confidentiality of the IT system both during and after working at the unit.

4. Newly recruited staff must be trained and informed about the unit's regulations on the safety and confidentiality of the IT system.

Article 12. Management and utilization of human resources

The unit shall be responsible for implementing:

1. Disseminating and updating regulations on information technology system safety and security for all officers and staff.

2. Inspecting the implementation of regulations on information technology system safety and security for individuals and subordinate organizations at least once a year.

3. Applying disciplinary measures against officers and staff of the unit who violate regulations on information technology system safety and security in accordance with the provisions of the law.

4. When installing and configuring important systems and equipment (servers, application software, and cybersecurity systems) in the official environment, officers and staff of the unit must implement monitoring measures. In cases involving databases or situations where third parties carry out the work, there must be officers and staff of the unit to supervise.

5. Separating personnel between:

a) Development and operation management of information technology systems;

b) Database management and application development;

c) Database management and application operation;

d) Management of main information technology systems and backup information technology systems.

6. Implementing measures to manage user accounts of officers and staff on important information technology systems when such individuals are absent from the workplace.

7. Reviewing and inspecting access rights to information technology systems for all officers and staff to ensure that access rights are appropriate to assigned tasks, with periodic reviews at least every three months for important information technology systems and every six months for other information technology systems.

Article 13. Termination or Change of Work

When officers and staff terminate or change their work, the unit must:

1. Clearly define the responsibilities of officers and staff and related parties in managing, operating, and exploiting information technology systems.

2. Prepare a handover record for information technology assets with officers and staff.

3. Revoke access rights to information technology systems of officers and staff who have left their jobs.

4. Adjust access rights to information technology systems of officers and staff who have changed their work to ensure they have just enough rights to perform their assigned tasks.

5. Conduct periodic reviews and checks at least every three months between the human resources management department and the department responsible for granting and revoking access rights to information technology systems to ensure that the accounts of officers and staff who have left their jobs have been revoked.

6. Notify the State Bank (Information Technology Department) of cases where individuals working in the field of information technology are dismissed, forced to leave their positions, or prosecuted under the law due to violations of regulations on information technology system safety and security.

 

Section 3

PHYSICAL AND ENVIRONMENTAL SECURITY FOR THE INSTALLATION OF INFORMATION TECHNOLOGY EQUIPMENT

 

Article 14. General requirements for the installation of information technology equipment

1. Protect with perimeter walls, gates, or other measures to control and limit unauthorized entry risks.

2. Implement preventive measures against fire and flood hazards.

3. Areas with high safety and security requirements, such as areas where servers, storage devices, security devices, and communication devices are installed, must be isolated from common areas, distribution areas, and shipping areas; internal rules, work guidelines, and entry control measures must be established and implemented for these areas.

Article 15. Requirements for data centers

In addition to meeting the requirements set forth in Article 14 of this Circular, the data center must also meet the following requirements:

1. The entrance and exit doors of the data center must be monitored 24/7.

2. The equipment installation area must avoid direct sunlight, prevent water leakage, and flood risks. The entrance and exit doors must be sturdy, fire-resistant, and equipped with at least two different types of locks (mechanical locks, cards, PINs, biometrics).

3. The equipment installation area for critical information technology systems must be protected and monitored 24/7.

4. There must be at least one grid power source and one generator power source. There must be an automatic switching system between the two power sources, and when the grid power is cut off, the generator must automatically start supplying power within a maximum of three minutes. The power supply must pass through an Uninterruptible Power Supply (UPS) system to provide power to the equipment, ensuring that the equipment can continue operating for a minimum of 30 minutes.

5. There must be an air conditioning system capable of continuous operation.

6. There must be a direct lightning strike and surge protection system.

7. There must be an automatic fire detection and suppression system to ensure that firefighting does not damage the installed equipment.

8. There must be a technical floor or an anti-static isolation layer.

9. There must be a surveillance camera system with data storage capability for a minimum of 100 days.

10. There must be a temperature and humidity monitoring and control system.

11. There must be an entry and exit logbook.

Article 16. Safety and Security of Physical Assets

1. Physical assets must be arranged and installed in secure locations and protected to minimize risks from environmental threats and unauthorized intrusions.

2. Physical assets belonging to critical information technology systems must be guaranteed power supply and support systems when the main power is interrupted. Measures must be taken to prevent overloading or voltage drops, protect against lightning surges; there must be grounding systems; backup generator systems and power storage systems must be in place to ensure continuous operation of the equipment.

3. Power cables and communication cables used for data transmission or supporting services must be protected from intrusion or damage.

4. All data storage devices must be checked to ensure that important data and licensed software stored on the device are erased or overwritten without recovery capability before being discarded or reused for other purposes.

5. Equipment used for business operations installed outside the unit's headquarters must have measures in place for monitoring and protecting against illegal access.

 

Section 4

MANAGEMENT AND INFORMATION EXCHANGE

 

Article 17. Management Responsibilities and Operation Procedures of units

1. Establish operation procedures for information technology systems, including at a minimum: System startup and shutdown procedures; data backup and recovery procedures; application operation procedures; incident handling procedures; system monitoring and activity logging procedures. These procedures must clearly define the scope and responsibilities of users and system operators.

2. Control changes to software versions, hardware configurations, and operation procedures: Record all changes; plan, implement testing and trials of changes, report results, and obtain approval before formal implementation. Have contingency plans for system recovery in case changes are unsuccessful or unforeseen incidents occur.

3. Officially operational information technology systems must meet the following requirements:

a) Be separated from development and testing environments;

b) Apply security and safety solutions;

c) Do not install application development tools on officially operational systems.

4. For information technology systems processing customer transactions:

a) Ensure that no single individual handles all aspects of a transaction from initiation to approval;

b) Implement measures to ensure the integrity of transaction data.

c) All actions on the system must be logged and available for inspection and control when necessary.

Article 18. Establishing plans and accepting information technology systems information technology system

1. The unit must establish standards, quotas, and technical requirements to ensure that all existing information technology systems and new systems operate normally before being officially implemented.

2. Based on the established standards, quotas, and technical requirements, the unit shall monitor and optimize the performance of the information technology system; assess the system's capacity to forecast, plan for expansion, and upgrade to ensure future capacity.

3. The unit must review and update standards, quotas, and technical requirements when there are changes to the information technology system. Training and transferring technical knowledge related to these changes must be conducted for relevant personnel.

Article 19. Data backupitself of the National Defense

1. Create a list of data and software that need to be backed up, classified according to their level of importance, storage time, backup time, backup method, and recovery test time from backup data. Important information technology systems' data must be backed up daily.

2. Important information technology systems' data must be backed up onto external storage media (such as magnetic tape, hard disks, optical discs, or other storage media) and securely stored separately from the backup area. External backup data should be tested for recovery at least once every six months.

3. Units with both primary and backup information technology systems located outside Vietnam must back up electronic transaction data stored in Vietnam daily. The unit must ensure the ability to convert original data from backup data. Backup data should be tested and converted at least once every six months.

Article 20. Management of network security and confidentiality, network security

1. Establish regulations on network security management and terminal device management throughout the entire network system.

2. The network system must be divided into different zones based on user groups, usage purposes, and information systems. Critical zones must be equipped with firewalls to control security.

3. Record and store documentation regarding the logical and physical diagrams of computer networks, including wide area networks (WAN/Intranet) and local area networks (LAN).

4. Equip cybersecurity solutions to control, detect, and promptly prevent unauthorized connections and access to the network.

5. Set up and configure all features of the cybersecurity system. Implement measures and solutions to detect technical vulnerabilities and weaknesses in the network system promptly. Regularly check and identify illegal connections, equipment, and software installations on the network.

Article 21. Information exchange TO COLLECT

The unit has the responsibility:

1. Issue regulations on minimum information exchange including: classifying information by sensitivity levels; rights and responsibilities of individuals when accessing information; measures to ensure the integrity and confidentiality of information during transmission, processing, and storage; information preservation procedures.

2. Sensitive information and documents must be encrypted before being exchanged or transmitted through computer networks or portable storage devices.

3. Implement strict management, monitoring, and control measures for online information pages providing services and transactions to customers.

4. Have agreements for information exchange with external parties. Define the legal responsibilities and obligations of participating parties.

5. Implement protective measures for equipment and software used for internal information exchange to limit illegal intrusion and exploitation of sensitive information.

Article 22. Online transaction service management

1. Requirements for information technology systems serving the provision of online transaction services to customers:

a) Must ensure high availability and rapid recovery capability;

b) Data on the transmission path must be encrypted and must be transmitted fully, correctly addressed, avoiding unauthorized modification, disclosure, or duplication;

c) Transaction authentication must use at least two factors. For high-value transactions, strong authentication methods such as biometrics (fingerprint, finger vein, iris, voice, face) or digital signatures must be used;

d) Online transaction webpages must be certified against forgery and must apply measures to prevent unauthorized modifications.

2. Customer transaction authentication must be performed directly within the unit’s information technology system.

3. Strictly control access to the online transaction system from within the internal network.

4. The online transaction service system must be closely monitored to detect and warn about:

a) Suspicious transactions and fraud based on time, geographic location, transaction frequency, transaction amount, number of incorrect authentications, and other unusual signs;

b) Abnormal activities of the system;

c) Denial of Service (DoS) attacks and Distributed Denial of Service (DDoS) attacks.

5. Customers’ sensitive information (PINs and secret keys) must be encrypted at the application layer.

6. Customers must be warned of risks and given safety and security guidelines before using online transaction services.

7. Do not provide online transaction applications over the Internet without first implementing customer safety and security measures.

Article 23. Monitoring and logging of information technology system activities

1. Record and store logs of information technology system operations and users, errors, and incidents of information technology system security breaches. Log data must be stored online for at least three months and backed up for at least one year.

2. Implement monitoring, analysis of logs, risk warnings, handling, and reporting results.

3. Protect the functions and information of log recording, prevent forgery and unauthorized access. System administrators and users shall not delete or modify system logs that record their own activities.

4. Synchronize time between information technology systems.

Article 24. Prevention of Malware

Develop and implement regulations on preventing malware to meet the following basic requirements:

1. Determine the responsibilities of users and relevant departments in the prevention of malware.

2. Deploy measures and solutions for preventing malware across the entire information technology system of the organization.

3. Updating malware samples and new anti-malware software.

4. Checking and removing malware from external data carriers before use.

5. Control software installation to ensure compliance with the organization's security and confidentiality regulations.

6. Controlling suspicious emails, attached files, or links in strange emails.

Section 5

ACCESS CONTROL MEASURES

 

Article 25. Internet TV Business requirements for access control

1. Regulations on access management for users, user groups, devices, and tools used for access must meet business requirements and security and confidentiality requirements, including the following main contents:

a. Registration, issuance, extension, and revocation of user access rights;

b. Limitation and control of accesses using system administrator accounts;

c. Management and issuance of secret access codes for network access, operating systems, information systems, and applications;

d. Review, inspection, and re-evaluation of user access rights;

đ) Security and confidentiality requirements for devices and tools used for access.

2. Regulations on managing secret access codes must meet the following requirements:

a. Secret access codes must be at least six characters long, consisting of numbers, uppercase letters, lowercase letters, and special characters if allowed by the system. Validity checks for secret access codes must be automatically performed when setting up the code;

b. Default secret access codes set by manufacturers on equipment, software, and databases must be changed before use;

c. Access code management software must have the following functions: notify users to change expiring secret access codes; invalidate expired secret access codes; allow immediate changes to exposed or potentially exposed secret access codes or upon user request; prevent reuse of old secret access codes within a specified period.

3. User responsibilities when granted access rights: use secret access codes in accordance with regulations, keep secret access codes confidential, use access devices and tools in accordance with regulations, and log out from the system when not working on it or temporarily not working on it.

Article 26. Network Access Management    

1. Network access and service management regulations include the following main contents:

a) Permitted networks and services, methods, means, and security conditions for access;

b) Responsibilities of administrators and users;

c) Procedures for issuing, changing, and revoking connection rights;

d) Control over administration, access, and use of networks.

2. Implement strict controls on external connections to the organization's internal network to ensure security and confidentiality.

3. Control the installation and use of remote access support software tools.

4. Control access to ports used for configuring and managing network devices.

5. Granting network and service access rights must adhere to the principle of granting just enough rights to perform assigned tasks.

Article 27. Operating System Access Management

1. Each operating system user must have a unique identifier and be authenticated, identified, and logged when accessing the operating system.

2. Require the use of multi-factor authentication, such as username/password and another factor (such as biometrics or token or one-time password, etc.) for remote access to important information technology systems, at minimum including server systems, network devices, and security systems.

3. Regulations limit and strictly control system utilities that can affect other systems and application programs.

4. Automatically terminate sessions after a period of inactivity to prevent unauthorized access.

5. Regulations limit connection times for high-risk applications.

Article 28. Internet Access Management   

1. Internet connection and access management includes the following basic contents:

a) Individual and departmental responsibilities in the exploitation and use of the Internet;

b) Users permitted to access and connect to the Internet;

c) Prohibited and restricted actions;

d) Control of Internet connections and access;

đ) Measures to ensure information security when connecting to the Internet.

2. Centralize and unify management of Internet connection ports throughout the organization. Customer access to the Internet through provided connection ports must be controlled.

3. Deploy cybersecurity solutions at Internet connection ports to protect against Internet-based attacks on the organization's internal network.

4. Use tools to detect and promptly identify vulnerabilities, weaknesses, and illegal intrusions into the organization's internal network through Internet connection ports.

Article 29. Information and Application Access Control

1. Manage and grant access permissions to information and applications to ensure the principle of granting just enough rights for users to perform assigned tasks:

a. Grant access permissions to individual directories and program functions;

b. Grant read, write, delete, and execute permissions for information, data, and programs.

2. Important information systems must be placed in a separate computer network environment. Information systems sharing common resources must be approved by the system administrator.  

Chapter 6

MANAGEMENT OF THIRD-PARTY INFORMATION TECHNOLOGY SERVICES

 

Article 30. Signing Contracts with Third Parties

The unit must implement:

1. Assessing the technical capability, personnel, and financial capacity of the third party before signing a contract for the supply of goods or services.

2. Clearly defining the responsibilities, authorities, and obligations of each party regarding safety and information technology security when signing the contract. Contracts with third parties must include provisions on handling violations and the liability for compensation for damages caused by the third party's violation.

3. Identifying and evaluating potential risks that may arise and applying risk management measures for the unit’s information technology system related to the implementation of the third party's contract.

4. The unit shall not hire a third party to perform all administrative tasks (configuration adjustment, data, log) for important information technology systems.

Article 31. Responsibilities of the Unit in Management of Services Provided by Third Parties

1. Providing, notifying, and requiring the third party to comply with the unit's regulations on information technology system safety and security.

2. Monitoring and inspecting the services provided by the third party to ensure service delivery levels and system operational capabilities meet the agreed terms.

3. Ensuring the deployment and maintenance of safety and security measures for third-party-provided services according to the agreement.

4. Managing changes to third-party-provided services including: Upgrading to new versions; using new techniques, new development tools, and environments. Fully assessing the impact of changes and ensuring safety upon implementation.

5. Determining and clearly stating the security features, security levels, and management requirements in service agreements provided by third parties.

6. Applying strict monitoring measures and limiting third-party access when granting them access to the unit's information technology system.

7. Supervising third-party personnel during contract execution. When third-party personnel violate safety and security regulations, immediately report and coordinate with the third party to apply timely corrective measures.

8. Revoking third-party access rights to the information technology system granted after completing the work or ending the contract, changing passwords and secret keys handed over from the third party.

Article 32. Responsibilities of Third Parties when Providing Information Technology Services

1. Signing and implementing confidentiality commitments throughout the contract implementation process and post-contract completion.

2. Planning, staffing, and allocating other resources to fulfill the contract. Notifying the contracting party of the deployment personnel list and obtaining the unit's approval. Third-party personnel must sign non-disclosure agreements for important information of the contracting party.

3. Disseminating the contracting party's safety and security regulations to deployment personnel and implementing monitoring measures to ensure compliance. Temporarily suspending or stopping activities, revoking access rights, and immediately notifying the contracting party upon discovering personnel violating safety and security regulations. Compensating for damages caused by personnel involved in contract execution.

4. Contract acceptance documentation must include detailed technical reports, installation completion records, software configuration files, and operation guides (if applicable) based on the work performed by the third party.

5. Handing over assets and information technology system access rights provided by the contracting party upon completion of work or contract termination.

Section 7

ACCEPTANCE, DEVELOPMENT, AND MAINTENANCE OF INFORMATION TECHNOLOGY SYSTEMS

 

Article 33. Safety and Security Requirements for Information Technology Systems

When building or upgrading information technology systems, the unit must:

1. Establishing safety and security requirements concurrently with technical and business requirements.

2. Evaluating the level of compliance with safety and security requirements after completing the construction or upgrade of the information technology system. Evaluation results must be documented in a report and approved by the unit head before official operation.

Article 34. Ensuring Safety and Security of Applications

The business application programs must meet the following minimum requirements:

1. Verify the validity of data entered into applications to ensure that the data is accurately and validly inputted.

2. Verify the validity of automatically processed data within applications to detect discrepancies caused by processing errors or intentional information modifications.

3. Implement measures to ensure the authenticity and integrity of data processed within applications.

4. Verify the validity of data output from applications to ensure that the information processing by the applications is accurate and valid.

5. User secret keys in important information technology systems must be encrypted at the application level.

Article 35. Management of Encryption

1. Establish and implement encryption measures according to recognized national or international standards, with key management measures to protect unit information. Use encryption algorithms such as:

a. AES: Advanced Encryption Standard;

b. 3DES: Triple Data Encryption Standard;

c. RSA: Rivest-Shamir-Adleman;

d. Other algorithms.

2. Customer secret key data, user secret key data, and other sensitive data must be encrypted and protected during transmission over networks and when stored.

Article 36. Safety and Security for Source Programs, Testing Data, and System Configuration Files

1. The unit must establish regulations on:

a. Managing and controlling source programs. Access to source programs must be approved by the unit head.

b. Protecting system configuration files.

2. The unit must develop procedures for selecting, managing, and controlling testing data. Real data from officially operating information technology systems should not be used for testing activities without implementing concealment or modification measures for sensitive data.

Article 37. Management of Information Technology System Changes

Issue procedures and measures for managing and controlling changes to information technology systems, including at least:

1. When changing the operating system, review and consider important business applications to ensure stable and secure operation in the new environment.

2. Strictly manage and control modifications to software packages.

3. Closely monitor and manage the purchase of external software.

Article 38. Evaluation of Information Technology System Security

1. The unit must conduct security evaluations of information technology systems with the following basic contents:

a. Assess the system architecture to determine the suitability of installed devices with the overall system architecture and security requirements;

b. Evaluate the operational status and configuration of information technology systems to ensure they operate according to the standards, norms, and technical requirements specified in Clause 1, Article 18 of this Circular;

c. Check the configuration of security devices, automatic access control systems, terminal management systems, and user account lists;

d) Conduct penetration tests to assess network security levels, which must be carried out for information technology systems connected to and providing services on the Internet.

2. Regularly conduct security evaluations of information technology systems, at least as follows:

a) Once every six months for equipment directly communicating with external environments such as the Internet and connections with customers and third parties, based on the contents of Points b, c, and d of Clause 1 of this Article;

b) Once a year for important information technology systems, and once every two years for other information technology systems, based on the contents of Clause 1 of this Article.

3. The evaluation results must be documented in a report submitted to the unit head. For non-compliant contents regarding safety and security in information technology operations (if any), propose remediation measures, plans, deadlines, and solutions.

Article 39. Management of Technical Weaknesses

1. Establish regulations on assessing, managing, and controlling technical weaknesses of currently used information technology systems.

2. The unit must proactively identify technical weaknesses:

a. Regularly update information related to vulnerabilities and technical weaknesses;

b. Conduct scans to detect vulnerabilities and technical weaknesses in currently used information technology systems at least three times a year for systems connected to external environments, and six times a year for other systems.

3. Assess the impact and risks of each detected vulnerability and technical weakness on currently used information technology systems and propose solutions.

4. Develop and implement solutions to handle, rectify, and report the results of handling.

 Section 8

MANAGEMENT OF INFORMATION TECHNOLOGY INCIDENTS

Article 40. Incident Handling Procedures

1. Receive information about incidents occurring.

2. Assess and determine the extent and scope of the incident's impact on the operation of the information technology system. Depending on the severity and scope of the impact, report to corresponding management levels for guidance on handling.

3. Implement measures to handle and resolve incidents.

4. Record incident files and report the results of incident handling.

5. Specify individual and collective responsibilities for reporting, receiving, and handling information technology incidents.

6. Develop templates for recording and storing incident handling files.

Article 41. Control and Rectification of Incidents

1. Incidents involving loss of system safety in information technology must be immediately reported to those with authority and relevant parties to take measures for prompt rectification.

2. Evaluate and determine the cause, and implement preventive measures to avoid recurrence of incidents.

3. The process of handling incidents must be recorded and stored at the unit. Measures to protect, prevent modification and destruction of incident-related documentation must be implemented.

4. Collect, record, preserve evidence and proof for inspection, handling, rectification, and prevention of incidents. In cases where information technology incidents involve violations of laws, units have the responsibility to collect and provide evidence to competent authorities in accordance with legal provisions.

Section 9

ENSURE CONTINUOUS OPERATIONS OF SYSTEMS INFORMATION TECHNOLOGY SYSTEM

 

Article 42. Disaster Recovery System Construction

1. Units must construct disaster recovery systems for important information technology systems that meet the following requirements:

a) The installation location must be at least 20 kilometers away from the main system in a straight line between the two systems and must comply with the requirements stipulated in Article 14 of this Circular;

b) Each disaster recovery system must ensure the capability to replace the main system within a maximum of four hours from the time the main system experiences an unrecoverable incident.

2. Units having only one information technology system located in a single site in Vietnam must construct a disaster recovery system at another location meeting the requirements set forth in Point a Clause 1 of this Article.

3. Plan for construction of disaster recovery systems:

a) For credit organizations and foreign bank branches, it must be completed within six months from the date this Circular takes effect;

b) For organizations providing intermediary payment services, it must be completed within twelve months from the date this Circular takes effect.

Article 43. Development of Procedures and Scenarios Ensuring Continuous Operations

1. Develop procedures for handling situations involving loss of security and interruption of operations of each component in important information technology systems such as servers, network devices, security and confidentiality, and communication.

2. Develop scenarios for switching to the disaster recovery system to replace the main system's operation, including the following basic contents:

a) Content of work, sequence of implementation, estimated completion time;

b) Arrangement and assignment of responsibilities for personnel involved in roles such as directing implementation, monitoring, performing the switch, checking the results of the switch, and trial operation;

c) Resources, means, and necessary requirements for implementation;

d) Measures to ensure safety and confidentiality of information and information technology systems;

đ) Templates for recording results.

3. Units having only one information technology system located in a single site in Vietnam must develop a scenario for switching the operation of the information technology system to the disaster recovery system as stipulated in Clause 2 Article 42 of this Circular.

4. The switching scenario must be disseminated to all participants to understand the tasks to be performed.

5. Procedures and switching scenarios must be tested and updated when there are changes in the information technology system, organizational structure, personnel, and assignment of responsibilities of related departments within the unit.

Article 44. Organization of Continuity Assurance Drills

1. The unit must have a plan and organize the implementation of continuity assurance drills for the information technology system:

a) At least once every three months, conduct inspections and evaluations of the operation of the backup system;

b) At least once every six months, implement drills to transfer operations from the main system to the backup system according to the scenarios established in Article 43 of this Circular. Evaluate the results and update procedures and drill scenarios (if necessary).

2. Notify the State Bank of Vietnam (Department of Information Technology) of the drill plan at least five working days before transferring operations from the main system to the backup system (including units that do not place their main and backup information technology systems in Vietnam).

Section 10

INTERNAL AUDIT AND REGIME REPORT

Article 45. State Audit Office internal audit                  

1. Establish internal audit regulations regarding the work of ensuring the safety and security of information technology operations of the unit.

2. Develop plans and carry out self-organized audits to check compliance with the provisions of this Circular and the unit's regulations on ensuring the safety and security of information technology operations at least once a year.

3. The results of the audit on the work of ensuring the safety and security of information technology operations of the unit must be reported in a report sent to the head of the unit, including recommendations and proposals for handling and rectifying issues that do not comply with the regulations on the safety and security of information technology operations (if any).

4. Organize the implementation and report the results of handling and rectifying issues mentioned in the report as stipulated in Clause 3 of this Article.

Article 46. Reporting System

Units (except the State Bank of Vietnam) are responsible for submitting reports to the State Bank of Vietnam (Department of Information Technology) in Vietnamese as follows:

1. Annual Report

a. Content of the report:

- Implementation of ensuring the safety and security of the information technology system as prescribed in this Circular;

- Any amendments and supplements to the regulations on the safety and security of the information technology system of the unit (if any).

b. Deadline for submission of the report: before January 31 of the following year;

c. Format and template of the report: in accordance with the guidelines of the State Bank of Vietnam (Department of Information Technology).

2. Emergency Reports

a) Incidents involving loss of system safety:

- Deadline for submission of the report: within one day from the time the incident is discovered;

- Content of the incident;

- Time and location where the incident occurred;

- Cause of the incident (if any);

- Risk assessment and impact on the information technology system and business operations at the location where the incident occurred and other related locations;

- Measures taken by the unit to prevent, mitigate, and prevent risks;

- Recommendations and proposals.

b) Deployment, upgrade, and application of important information technology systems:

- Deadline for submission of the report: at least five days before formal implementation;

- Systems and applications planned for deployment;

- Scope of application;

- Results of testing and inspection;

- Implementation plan;

- Assessment of risk and impact of the new system on existing information technology systems of the unit;

- Proposals and recommendations.

c) Other exceptional cases as required by the State Bank of Vietnam.

Chapter III

IMPLEMENTING PROVISIONS

Article 47. Handling Violations

Organizations and individuals violating the provisions of this Circular shall be subject to handling according to the relevant laws depending on the level of violation.

Article 48. Effective Date

1. This Circular takes effect from March 1, 2016, and replaces Circular No. 01/2011/TT-NHNN dated February 21, 2011, issued by the Governor of the State Bank of Vietnam on the issuance of regulations on ensuring the safety and security of information technology systems in the banking industry.

2. In the course of implementation, if any issues arise or difficulties occur, units shall promptly report to the State Bank for consideration, supplementation, and amendment.

Article 49. Responsibility for Implementation

1. The Department of Information Technology is responsible for:

a) Establish technical standards to standardize information technology activities in the banking industry;

b) Monitor, compile, and report to the Governor the situation regarding the implementation of safety and security measures for information technology systems of units as stipulated in this Circular;

c) Annually develop plans and inspect the implementation of this Circular at units;

d) Take the lead and coordinate with related units under the State Bank to handle any difficulties arising during the implementation of this Circular.

2. The Banking Inspection and Supervision Authority shall be responsible for coordinating with the Information Technology Department to inspect the implementation of this Circular at units (excluding the State Bank) and to handle administrative violations according to the relevant laws.

3. The Internal Audit Department shall be responsible for conducting internal audits of units under the State Bank according to Articles 1, 2, and 3 of Clause 45 of this Circular.

4. Heads of related units under the State Bank; Governors of provincial and centrally-administered city branches of the State Bank; Chairmen of Management Boards, Members of Management Councils, General Directors (Directors) of credit organizations, foreign bank branches, and service providers of payment intermediation have the responsibility to organize the implementation of this Circular.

原始文件(PDF)

在新标签页打开PDF ↗