This Circular stipulates the activities of monitoring the security of information systems nationwide. It applies to agencies, organizations, enterprises, and individuals participating in or related to such monitoring activities. The managers of information systems must carry out monitoring according to requirements, including collecting, analyzing cybersecurity information, and submitting regular reports.
Scope of application
Agencies, organizations, enterprises, and individuals directly participating in or related to the activities of monitoring the security of information systems nationwide. Particularly, this applies to managers of information systems at level 3 or higher.
Key points
- Managers of information systems at level 3 or higher must carry out monitoring according to requirements, including collecting and analyzing cybersecurity information.
- Monitoring activities are carried out through direct or indirect methods. Information system managers may implement monitoring themselves or hire monitoring services.
- This Circular takes effect from January 15, 2018.
- Telecommunications enterprises and information technology service providers must cooperate with information system managers in implementing monitoring as required by the Ministry of Information and Communications.
- The Ministry of Information and Communications monitors information technology systems and services serving the e-Government.
🌐 Social impact of this document
- Positive impact: Enhances protection of cybersecurity, reduces cyber attack risks, and helps organizations and individuals use information systems more effectively.
- Negative impact: May increase costs for enterprises when implementing monitoring as required by this Circular. Training time is needed to improve monitoring capabilities.
❓ Frequently asked questions
What should information system managers do?
Managers of information systems at level 3 or higher must carry out monitoring according to requirements, including collecting and analyzing cybersecurity information. They need to provide full features for collecting and consolidating information, analysis to detect attacks, risks, and cybersecurity incidents.
What should telecommunications enterprises do?
Telecommunications enterprises must cooperate with information system managers in implementing monitoring as required by the Ministry of Information and Communications. They must provide infrastructure, technical, and network system information and offer technical support when necessary.
When does this Circular take effect?
This Circular takes effect from January 15, 2018.
What systems does the Ministry of Information and Communications monitor?
The Ministry of Information and Communications monitors information technology systems and services serving the e-Government. At the same time, it organizes monitoring of important information systems that require priority cybersecurity assurance.
Are there templates for providing information and reporting monitoring activities?
Yes, this Circular provides templates for information provision for monitoring and reporting on monitoring activities by information system managers.
Full text
|
MINISTRY OF INFORMATION AND COMMUNICATION |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 31/2017/TT-BTTTT |
Hanoidated November 15 of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Industry and Trade; 2017 |
CIRCULAR
Regarding the operation of information system security monitoring
||| Pursuant to the Cybersecurity Law dated November 19, 2015;
Pursuant to Decree No. 72/2013/NĐ-CP dated July 15, 2013 of the Government on managing, providing, and using Internet services and information on networks;
Pursuant to Decree No. 25/2014/NĐ-CP dated April 7, 2014 of the Government on crime prevention and other violations of law using high technology;concerning crimes and other violations of law using advanced technology; to ensure national cybersecurity;
Pursuant to Decree No. 85/2016/NĐ-CP dated July 1, 2016 of the Government on ensuring information security according to levels;
Pursuant to Decree No. 17/2017/NĐ-CP dated February 17, 2017, issued by the Government, on the functions, tasks, powers, and organizational structure of the Ministry of Information and Communications;
Pursuant to Decision No. 05/2017/QĐ-TTg dated March 16, 2017 of the Prime Minister promulgating regulations on the system of emergency response plans for national information security protection;1.6. Internet Protocol (IP) addresses used in the information system:1.7. Network infrastructure equipment serving the information system:□ Switch
Implementing Resolution No. 36a/NQ-CP dated October 14, 2015 of the Government on the National Program on Information Technology Development;Government online;
At the proposal of the Director of the Vietnam Computer Emergency Response Team;
The Minister of Information and Communications issues this Circular on the operation of information system security monitoring.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Circular stipulates the operation of information system security monitoring (hereinafter referred to as monitoring) throughout the country, excluding information systems managed by the Ministry of National Defense and the Ministry of Public Security.
Article 2. Applicability
This Circular applies to agencies, organizations, enterprises, and individuals directly participating in or related to monitoring activities nationwide.
Chapter II
INFORMATION SYSTEM SECURITY MONITORING
Article 3. Principles of Monitoring
1. Ensuring continuous and regular implementation.
2. Proactively observing, analyzing, and preventing to promptly detect and prevent risks and information security incidents.
3. Ensuring stable and confidential operations for information exchanged during the monitoring process.
4. Coordinating closely and effectively between the monitoring activities of the Ministry of Information and Communications and those of the information system managers; gradually building the capability for interconnection between the monitoring system of the Ministry of Information and Communications and the monitoring system of information system managers nationwide.
Article 4. Methods of Monitoring
1. Monitoring can be conducted through direct or indirect methods. Information system managers may implement directly or hire services for monitoring. In necessary cases, based on their capacity, situation, and actual resources, information system managers may request relevant units under the Ministry of Information and Communications to provide appropriate support for monitoring in accordance with actual resources.
2. Direct monitoring involves conducting monitoring by placing devices capable of analyzing data streams (surveillance), directly collecting information from log files, and warning systems being monitored to detect signs of attacks, risks, and information security incidents. Direct monitoring includes the following activities:
a) Analyzing and collecting information on information security:
- Analyzing and surveilling information security on network paths/data flows at Internet connection ports using tools capable of analyzing network paths to detect attacks, risks, and information security incidents such as suitable attack detection/prevention devices (e.g., IDS/IPS/Web Firewall, etc.);
- Collecting log files, warnings reflecting the activities of applications, information systems, and security devices.
b) Consolidating, synchronizing, verifying, and processing information on information security to detect attacks, risks, and information security incidents or eliminate inaccurate information.
3. Indirect monitoring involves implementing techniques to collect information from related sources; inspecting and reviewing the objects to be monitored to assess operational status, responsiveness, and combining with other related factors to analyze and detect attacks, risks, and information security incidents. Indirect monitoring includes the following activities:
a) Collecting, analyzing, and verifying information about attacks, risks, and information security incidents related to the monitored objects from related sources;
b) Remotely or directly inspecting and reviewing the monitored objects to evaluate the status, detect potential attacks, risks, and information security incidents that could be exploited or cause harm.
Article 5. Direct supervision requirements for information system managers
Information system managers have the responsibility to proactively implement supervision in accordance with current regulations. For information systems at level 3 or higher, the supervision activities of the information system manager must meet the following minimum requirements:
1. The central monitoring component of the information system manager must meet the following requirements:
a) Provide all necessary features for collecting and consolidating network security information;
b) Analyze collected information to detect and warn against attacks, risks, and network security incidents that could affect the system's operations or service provision capabilities;
c) Provide an interface convenient for continuous monitoring by supervisory staff;
d) Conduct collection and analysis of the following minimum input information: web server logs (web server) with web applications (for example: electronic portal, online public services, etc.); alerts/logs from base monitoring devices; alerts/logs from firewalls set up to protect Internet connection flows related to monitored objects;
e) The processing capacity of the central monitoring component of the information system manager must be appropriate for the volume, format, and capable of analyzing network security information collected from monitored systems.
2. Network security information collection and base monitoring must meet the following requirements:
a) Collect network security information from logs and alerts of software/devices related to monitored objects to provide to the central monitoring component of the information system manager or as required by competent authorities under the Ministry of Information and Communications. Minimum network security information to collect and provide includes: web server logs of web applications (for example: electronic portal, online public services, etc.); alerts/logs from base monitoring devices; alerts/logs from firewalls set up to protect Internet connection flows related to monitored objects;
b) Base monitoring devices must ensure functions for detecting attacks, risks, and network security incidents; they need to be configured to ensure comprehensive monitoring coverage of all Internet connection paths of monitored objects;
c) Monitoring devices must meet the minimum functions of detection, creation of attack detection rules based on information such as: source IP address, destination IP address, source port address, destination port address, special data segments in transmitted packets. For state agencies and organizations implementing base monitoring devices themselves, priority should be given to using existing attack detection devices (for example: IDS, IPS, Web firewall, etc.) to serve as base monitoring devices;
d) For information systems serving E-Government using encrypted protocols (for example: https), technical solutions must be established to ensure that network security monitoring devices can obtain full information to detect attacks, risks, and network security incidents;
e) Establish and connect base monitoring devices to the monitoring system of the Ministry of Information and Communications according to guidance and requirements of competent authorities.
3. Supervision implementation content:
a) Continuously monitor, establish daily reports, ensuring the information system manager's monitoring system operates stably and continuously, collecting information steadily and continuously;
b) Develop and issue network security monitoring regulations, specifying details about periodic statistics on handling results and report preparation;
c) Monitor and operate base monitoring devices to ensure stability and continuity, making timely adjustments when changes occur, and fully implementing guidance from the Ministry of Information and Communications to ensure effective monitoring;
d) Prepare weekly supervision result reports to inform the information system manager, including the following complete information: monitoring time; list of attacked targets requiring attention (IP addresses, service descriptions, attack times); detected attack techniques and related evidence; attackers; changes in the monitored system and the monitoring system; etc.;
đ) Classify threats, risks, and network security incidents according to specific circumstances;
e) Periodically compile statistics on threat, risk, and network security incident handling results to support storage and reporting work;
g) In cases where the information system manager requests functional units of the Ministry of Information and Communications to perform base monitoring or systems within the Ministry's monitoring responsibility, the information system manager has the responsibility to provide and update information about the system to be monitored and describe the technical deployment plan of the information system manager's monitoring system to the Ministry of Information and Communications according to the information provision form in Appendix 1, which includes the following information:
- Description of the monitored object, including basic information such as: IP address, domain name, provided service, operating system name and version, web application software;
- Location of the information system manager's monitoring system, bandwidth of connections to the monitored object, expected information to be collected and collection protocols, for example IDS alerts, firewall logs (log firewall), web server logs (log web server), etc.
h) Minimum monitoring information storage capacity must reach an average of 30 days of normal operation;
i) Provide periodic or ad hoc monitoring information as required by the Ministry of Information and Communications in accordance with the law;
k) Report on the information system manager's monitoring activities every six months according to the form in Appendix 2.
Article 6. Supervisory Activities of Enterprises
Telecommunication enterprises, information technology service providers, and network security service providers shall be responsible for:
1. Cooperating with system administrators in supervisory activities upon request from the Ministry of Information and Communications.
2. Providing technical and infrastructure information about networks and implementing technical support as requested by the Ministry of Information and Communications to facilitate its supervisory activities.
3. Implementing supervisory tasks as stipulated in Article 7 of Decision No. 05/2017/QĐ-TTg issued by the Prime Minister.
Article 7. Supervisory Contact Points
1. System administrators shall be responsible for appointing individuals or departments as supervisory contact points for cybersecurity to coordinate with functional units of the Ministry of Information and Communications.
2. Supervisory contact points must ensure timely and continuous provision and reception of information. They have the function of conducting supervisory activities within their own information systems.
3. Supervisory contact points shall implement the provision and exchange of information through one or multiple methods such as letters, emails, phone calls, faxes, or specialized communication software to ensure confidentiality.
4. Information on supervisory contact points includes: individual name, department name, position, address, telephone number (landline and mobile), email address, digital signature (if available).
Article 8. Exchange, Provision, and Sharing of Information
1. Encouraging supervisory contact points to exchange and provide information to each other for the purpose of coordinating in monitoring, warning, responding to incidents, and enhancing proactive measures against threats and attack methods targeting organizational and individual cybersecurity.
2. Shared, provided, and exchanged information includes details on cyber attacks, risks, incidents; attack methods, origins, impacts; management and technical measures to handle and mitigate incidents.
3. Principles for exchanging and providing information
a) Timely, accurate, and appropriate application of management and technical measures to secure exchanged information;
b) Proactively verifying exchanged information to ensure its authenticity;
c) Using one or multiple forms of information exchange such as websites, letters, emails, messages, phone calls, faxes;
d) When providing and exchanging information with functional units of the Ministry of Information and Communications, it must be done according to the Ministry's guidelines.
Article 9. Activities to Enhance Supervisory Capabilities
1. Organizing regular meetings and seminars on supervisory activities.
2. Training, practicing, and simulating to enhance supervisory capabilities.
3. Urging and inspecting the implementation of supervisory and warning activities by specialized departments for cybersecurity.
4. Sharing knowledge and experience in supervision, warning, and incident response.
5. Researching and developing tools to support cooperative information exchange in supervisory, warning, and incident response work.
6. Developing specialized products and services for monitoring, analysis, and warnings tailored to specific supervisory targets.
7. Promoting the establishment of bilateral and multilateral cooperation agreements among specialized departments for cybersecurity to enhance supervisory and warning capabilities.
8. Strengthening international cooperation in supervisory, warning, and incident response activities.
Chapter III
SUPERVISORY ACTIVITIES OF THE MINISTRY OF INFORMATION AND COMMUNICATIONS
Article 10. The Ministry of Information and Communications' Monitoring Model
1. Central monitoring activities:
a) Refers to the collection, tracking, detection, analysis, processing, reporting, and evidence gathering on signs of attacks, risks, and cybersecurity incidents based on cybersecurity data/information collected through direct monitoring via observation systems or indirect monitoring, while storing collected data in event form and centrally managing observation systems.
b) Are carried out through the Vietnam Cyber Incident Monitoring System and the Vietnam Internet Attack Handling System managed and operated by competent units of the Ministry of Information and Communications on the principle of data sharing and coordinated operations to enhance monitoring effectiveness.
2. Observation Systems
a) Consist of devices and software capable of monitoring, collecting, analyzing, and providing log information, status, and alerts for central monitoring activities to serve the analysis and detection of cybersecurity incidents, weaknesses, threats, and vulnerabilities.
b) Are provided with appropriate technical conditions and placement locations for operation and data collection from monitored objects according to guidelines issued by competent units of the Ministry of Information and Communications.
c) Are established, managed, and operated by competent units of the Ministry of Information and Communications in collaboration with system administrators in accordance with legal regulations.
d) Devices/software implementing basic observations are set up to connect and serve central monitoring activities based on technical standards, specifications, or operational guidelines of the Ministry of Information and Communications.
Article 11. Monitoring Activities of the Ministry of Information and Communications
1. The Ministry of Information and Communications conducts monitoring of systems and services supporting the electronic government.
2. Upon request from system administrators, the Ministry of Information and Communications organizes monitoring of important systems requiring priority cybersecurity assurance in line with available resources.
3. Central monitoring activities of the Ministry of Information and Communications ensure the capability to receive, analyze monitoring information collected from basic observation systems and equipment/systems serving indirect monitoring.
4. Monitoring activities of the Ministry of Information and Communications include:
a) Selecting, managing, and updating the list of monitored entities as stipulated in this Circular and related legal documents.
b) Tracking, operating the central monitoring center, preparing analytical monitoring reports; inspecting and urging monitoring and surveillance work.
c) Compiling, storing, analyzing, and classifying information and data collected from basic observation systems, equipment/systems serving indirect monitoring, and other information sources.
d) Conducting checks and analyses of evidence and data to detect unusual signs, cybersecurity risks. In cases where risks or incidents have not been clearly verified, additional measures are taken to gather necessary information and data to increase the accuracy of analysis results and warning information.
đ) Conducting investigations and verifications to determine risks and incidents affecting monitored entities. Analyzing and categorizing cyberattacks, risks, and cybersecurity incidents based on specific circumstances. Warning cybersecurity departments, system operators, and system administrators when attacks, risks, or incidents occur against monitored entities.
e) Guiding system administrators in implementing monitoring; organizing and guiding connections from system administrators' monitoring systems to central monitoring systems of the Ministry of Information and Communications. Ensuring the security of cybersecurity data during collection and analysis.
g) Regularly compiling monitoring results, warning situations, and handling of cyberattacks, risks, and cybersecurity incidents for archival and reporting purposes.
h) Guiding and supporting system operators and system administrators to implement emergency response and handling of cyberattacks, risks, and cybersecurity incidents when necessary.
i) Assisting some system operators and system administrators in establishing suitable basic observation systems based on available resources.
k) Competent units of the Ministry of Information and Communications annually prepare budgets and approve, allocate funds for monitoring tasks from state budget and other lawful sources in accordance with legal provisions and guidance from competent authorities for approval by the Minister or authorized authority.
Chapter IV
RESPONSIBILITIES OF ORGANIZATIONS AND ORGANIZATIONS
Article 12. The Cybersecurity Center
1. Manage and operate the Vietnam Internet Attack Handling System to carry out central monitoring activities.
2. Compile monitoring results and information, data on cybersecurity for state management work on cybersecurity.
3. Urge the implementation of basic requirements for ensuring information system security and monitoring according to the levels prescribed by laws on information system security.
4. Take the lead and coordinate with the VNCERT Center to research and develop technical criteria and detailed guidelines for connecting between the Basic Monitoring System and the Vietnam Internet Attack Handling System to be issued by the Minister of Information and Communications.
5. Coordinate or take the lead in monitoring information systems in important fields that require priority cybersecurity assurance upon request from the system managers.
Article 13. The VNCERT Center
1. Manage and operate the Network Security Incident Monitoring System to carry out central monitoring activities.
2. Compile monitoring results and information, data on cybersecurity for coordination and incident response work.
3. Take the lead and coordinate with the Cybersecurity Center to develop monitoring procedures; organize the implementation of activities to enhance monitoring capabilities; urge, follow up, and inspect network security monitoring and warning activities according to the division of labor by the Minister of Information and Communications.
4. Take the lead and coordinate with the Cybersecurity Center to research and develop technical criteria and detailed guidelines for connecting between the Basic Monitoring System and the Network Security Incident Monitoring System to be issued by the Minister of Information and Communications.
5. Take the lead in monitoring and warning cybersecurity for information systems and technology services serving e-Government. Coordinate or take the lead in monitoring information systems in important fields that require priority cybersecurity assurance upon request from the system managers.
6. Compile and report national cybersecurity monitoring and warning results and statistics on cyber attacks, risks, and incidents.
Article 14. Managers of Information Systems
1. Direct the monitoring of information systems under their management, and cooperate with competent units of the Ministry of Information and Communications to implement monitoring according to regulations.
2. Implement guidelines and closely cooperate with competent units of the Ministry of Information and Communications in monitoring activities.
3. Provide information on monitoring activities according to the requirements of the Ministry of Information and Communications.
4. Report monitoring results regularly every six months according to the form at Appendix 2 or when requested by the Ministry of Information and Communications.
5. Prepare connection ports and backup interface connections at Internet access points according to specified technical criteria to establish monitoring points of the Ministry of Information and Communications when necessary.
6. Managers of information systems monitored by the Ministry of Information and Communications shall be responsible for:
a) Identify and list information systems and objects requiring monitoring, and provide related technical information of these systems and objects to the Ministry of Information and Communications;
b) Implement the monitoring system of the information system manager according to this Circular and relevant laws; cooperate in providing information about infrastructure and information systems to be monitored and perform technical support according to the requirements of competent units of the Ministry of Information and Communications;
c) Organize a team to receive warnings and handle cyber attacks, risks, and incidents according to warnings and requests from competent units of the Ministry of Information and Communications;
d) Regularly compile statistics on handling cyber attacks, risks, and incidents for record-keeping and reporting purposes.
7. Annually prepare and approve, allocate budget funds for monitoring tasks from the state budget and other lawful sources according to legal provisions and guidance from competent authorities.
Chapter V
IMPLEMENTATION
Article 15. Effective Date
1. This Circular takes effect from January 15, 2018.
2. During implementation, if there are difficulties or new issues, organizations and individuals concerned should promptly reflect them to the Ministry of Information and Communications for guidance or consideration for supplementation and amendment.
| Place of Receipt: - Prime Minister, Deputy Prime Ministers; - Government Office; - Central Party Office and Party Committees; - General Secretary's Office; - National Assembly's Office; - President's Office; - Ministries, agencies equivalent to ministries, and government agencies; - Supreme People's Court; - Supreme People's Procuracy; - State Audit Agency; - Provincial People's Councils and People's Committees under central jurisdiction; - Central Agencies of Mass Organizations; - National Steering Committee for Information Technology Application; - National Steering Committee on Cybersecurity; - Specialized units on IT and cybersecurity of Ministries, agencies equivalent to ministries, and government agencies; - Provincial Departments of Information and Communications; - Telecommunications and Internet service companies; - Official Gazette, Government Portal; - Legal Documents Supervision Bureau (Ministry of Justice); - Ministry of Information and Communications: Ministers, Deputy Ministers, units under the Ministry, Ministry Portal; - To be filed: VT, VNCERT (250) |
THE MINISTER (Signed) TRUONG MINH TUN |
Appendix 1: Information Provision Form for Monitoring
|
SUPERIOR UNIT |
SOCIALIST REPUBLIC OF VIET NAM |
|
|
………….Date... Month... Year 20... |
INFORMATION PROVISION FORMFOR DAILY REPORTINGON CYBERSECURITY MONITORINGOF INFORMATION SYSTEMS
THE I. Information on the operating unit and information provider contact
- Name of agency/unit managing and operating the information system: ...
- Based on the Law on Information Technology dated June 29, 2006;
- Name of information provider/contact: ...
- Position: ...
- Address: ...
- Phone number: ...
II. Information systems to be monitored
A. Existing information systems:
- Email: …
□ Electronic portal: ...
□ Online public service system: ...
□ Email system: ...
□ Administrative document management system: ...
□ Database system: ...
□ Other systems
(specify)
B. Specific information on information systems to be monitored 1. First information system:õ): ..................................................................................................................
1.1. Name of information system: ...
1.2. Brief description of functions, scale, and scope of service of the information system: ...
1.3. Level of the information system: ...
1.4. Location of the information system: ...
..................................................................................................................
□ Data center of the agency/unit, located at: ...
managed by
(name of the unit managing and operating the data center):
□ Renting hosting outside, at the data center of (name of the unit providing hosting and data center services) ...................................
(location of the data center) 1.5. Domain name, URL of the information system: ...of the Government stipulating functions, tasks, powers, and organizational structure of the Ministry of Home Affairs1.6. Internet IP addresses used in the information system::
in 1.7. Network infrastructure equipment serving the information system:无效 □ Switch(type, model): ..............................................................................................
□ Router
(type, model)
.............................................................................................................................................
□ Router
(type, model) Third-party technique: (Technical description similar to the first attack technique): ..............................................................................................
3.4. Fourth attack technique: (Technical description similar to the first attack technique) Third-party technique: (Technical description similar to the first attack technique): ..............................................................................................
□ IDS/IPS (Intrusion Detection/Prevention Systems) Third-party technique: (Technical description similar to the first attack technique): ............................
□ Firewall (specify type, model)Deputy ministers of ministerial-level agencies,3.5. Fifth attack technique:: .........................................................................
□ Other network devices Third-party technique: (Technical description similar to the first attack technique): ..........................................................................
1.8. Platform software, system software, tools (PMNT), operating systems (OS) used in the information system
□ Server OS: …
□ Application PMNT: …
□ Workstation OS: …
□ Other platform, system software, tools, OS (specify clearly): ......................
1.9. Other technical information about the information system (specify clearly):
..................................................................................................................
1.10. Information security monitoring solutions for the information system:
□ Available (specify the following information clearly) □ Not available
a. Monitoring by the system owner:
□ Self-execution.
□ Service outsourcing (specify the service provider): ................................................................
- Monitoring method (direct or indirect): ....................................................................
- Description of monitoring technology and techniques: …
..................................................................................................................
- Event processing rate (EPS) capability: …EPS.
- Storage capacity for network security events per day (GB/day): …GB/Day.
- Does the monitoring system use correlation rule engines: □ Yes; □ No.
- Level of monitoring (Select from the levels below)billion □ Basic level monitoring (network and perimeter): monitor network devices such as routers, switches, firewalls (Firewall), IDS/IPS.□ Operating system level monitoring: collect and analyze OS logs.:
□ Application level monitoring: collect, analyze, and monitor application service logs (e.g., web server; mail server, etc.).
□ Database level monitoring: collect, analyze, and monitor database service logs.
- Components of the monitoring system
(Select from the components below)
□ Base observation component (such as sensors collecting information, IDS/IPS devices, firewall devices, etc.) □ Data collection/standardization component (Connector):
□ Monitoring data storage component (Logger)
□ Central analysis and monitoring component (ESM)
- Description of base observation components: …
b. Other monitoring solutions
(if applicable, specify the implementing unit, briefly describe the monitoring technology and techniques)
..................................................................................................................
..................................................................................................................
c. Information security monitoring by the Ministry of Information and Communications for the information system: - Request the Ministry of Information and Communications to::
...........................................................................................................................................
..................................................................................................................
..................................................................................................................
□ Deploy connection monitoring;
□ Not request implementation;
□ Other …
- Request support for direct/indirect monitoring by the system owner:
(specify clearly whether direct, indirect, or both)
- Other Requests/Proposals: …
□ Yes 2. Second information system:: ...................................
□ No
(specify as for the first information system)
..................................................................................................................
n. nth information system: III. Human resources for information security monitoring (monitoring)
..................................................................................................................
1. Unit leader directing monitoring work III. Human resources for information security monitoring (monitoring)
..................................................................................................................
(specify full name, position, phone number, email)
2. Head of the monitoring department 3. List of monitoring staff of the unit::......
.................................................................................................................................................................................................................................
(professional qualifications) 3. List of monitoring staff of the unit::..........
..................................................................................................................
..................................................................................................................
Certificates
|
No. |
Full Name |
Training related technical and vocational skills |
4. Recommendations of the unit regarding monitoring work:… Person filling out the form - Column (7): Land area in land allocation decisions, lease decisions, or documents of the competent authority or actual land area managed and used (applicable to assets that are buildings and land). |
|
|
|
|
|
|
|
|
|
|
(Signature, full name, phone number, email)
..................................................................................................................
| Appendix 2: Template for reporting on monitoring activities of the system owner year ….. |
Head of the unit (Signature, stamp) |
PERIODIC REPORT OF THE SYSTEM OWNER
|
SUPERIOR UNIT |
SOCIALIST REPUBLIC OF VIET NAM |
|
|
………….Date... Month... (from date ……… |
REPORT
I. Summary of Monitoring Information- Monitoring period:... hours... minutes on ... to ... hours ... minutes on ...
- Total number of collected information security events:APPLICATION FOR RESIDENCE OUTSIDE )
- Based on the Law on Information Technology dated June 29, 2006;
- Total number of high-risk information security events:
- Information security status: [Severe/Dangerous/Normal/Safe]
- Number of incidents occurred:
- Summary of information security situation during the monitoring period:
II. Monitoring Results
1. List of most frequently detected attack techniques (at least five most frequent attack techniques)
Attack technique
..................................................................................................................
..................................................................................................................
Number of attacks
2. List of most frequently attacked services (at least five most frequently attacked services)
|
Serial number |
Service port/IP address |
3. List of most frequently attacked IP addresses (at least five IP addresses) |
|
1 |
|
|
|
2 |
|
|
|
3 |
|
|
|
4 |
|
|
|
5 |
|
|
IP address
|
Serial number |
Description of device/software with attacked IP address |
Services |
3. List of most frequently attacked IP addresses (at least five IP addresses) |
|
1 |
|
|
|
|
2 |
|
|
|
|
3 |
|
|
|
|
4 |
|
|
|
|
5 |
|
|
|
- Services provided:
|
Serial number |
1. Service name: |
+ Service port number: |
3. List of most frequently attacked IP addresses (at least five IP addresses) |
|
1 |
|
+ Protocol used: + Software, version providing service: + Time 2. Service name: … 4. List of top source IP addresses attacking from within the country (at least five IP addresses) 5. List of top source IP addresses attacking from abroad (at least five IP addresses) III. Typical Attacks |
|
|
2 |
|
|
|
|
3 |
|
|
|
|
4 |
|
|
|
|
5 |
|
|
|
1. Most dangerous types of attacks (at least five):
|
Serial number |
1. Service name: |
3. List of most frequently attacked IP addresses (at least five IP addresses) |
|
1 |
|
|
|
2 |
|
|
|
3 |
|
|
|
4 |
|
|
|
5 |
|
|
. Attack technique 1
|
Serial number |
1. Service name: |
3. List of most frequently attacked IP addresses (at least five IP addresses) |
|
1 |
|
|
|
2 |
|
|
|
3 |
|
|
|
4 |
|
|
|
5 |
|
|
- Name of attack technique: …
- International code (if any): …
1. 1- Targeted objects: …- Indicators: …:
- Description: …
- Quantity and time of occurrence: …
- Severity assessment: …
- Impact: …
- Implemented response measures: …
- Reference materials: …
- Additional notes: …
1.2. Attack technique 2: (Description similar to attack technique 1)
1.3. Attack technique 3: (Description similar to attack technique 1)
1.4. Attack technique 4: (Description similar to attack technique 1)
1.5. Attack technique 5: (Description similar to attack technique 1
.n. Attack technique n: …
2. Most frequently occurring types of attacks (at least five)2.1. Attack technique 1- Indicators: …)
2.2. Attack technique 2: (Description similar to attack technique 1
2.3. Attack technique 3: (Description similar to attack technique 1)
.............................................................................................................................................
12.4. Attack technique 4: (Description similar to attack technique 1)
2.5. Attack technique 5: (Description similar to attack technique 1
2.n. Attack technique n::
- Description: …
- Quantity and time of occurrence: …
- Severity assessment: …
- Impact: …
- Implemented response measures: …
- Reference materials: …
- Additional notes: …
1.2. Attack technique 2: (Description similar to attack technique 1)
1.3. Attack technique 3: (Description similar to attack technique 1)
1.4. Attack technique 4: (Description similar to attack technique 1)
1.5. Attack technique 5: (Description similar to attack technique 1
3. Newly emerging types of attacks (at least five)3.1. Attack technique 1)
3.2. Attack technique 2: (Description similar to attack technique 1))
3.3. Attack technique 3: (Description similar to attack technique 1) 3.4. Attack technique 4: (Description similar to attack technique 1)
3.5. Attack technique 5: (Description similar to attack technique 1)
...........................................................................................................................................
3.n. Attack technique n: ...................................................................................................
IV. Other Information Security Issues During the Monitoring Period
V. Recommendations and Suggestions::
- Description: …
- Quantity and time of occurrence: …
- Severity assessment: …
- Impact: …
- Implemented response measures: …
- Reference materials: …
- Additional notes: …
1.2. Attack technique 2: (Description similar to attack technique 1)
1.3. Attack technique 3: (Description similar to attack technique 1)
1.4. Attack technique 4: (Description similar to attack technique 1)
1.5. Attack technique 5: (Description similar to attack technique 1
- National Cybersecurity Center (VNCERT);
- Cybersecurity Department;(Technical description similar to the first attack technique)
3.n. Attack technique n:
IV. Other issues related to information security during the monitoring period V. Recommendations and suggestions:)
...........................................................................................................................................
- Vietnam National Cybersecurity Incident Response Team (VNCERT);Cybersecurity Bureau; ...................................................................................................
IV. Other issues concerning information security during the monitoring period
...........................................................................................................................................
...........................................................................................................................................
...........................................................................................................................................
V. Recommendations and suggestions:
...........................................................................................................................................
...........................................................................................................................................
|
Place of Receipt: |
Head of the unit |
Original document (PDF)
Download
Relations map
Click a document to open. A red border = a relation that changes validity.
Translations
This document is available in the following languages: