Circular No. 36/2017/TT-NHNN on ensuring safety and security when providing Internet Banking services in Vietnam, replacing Circular No. 29/2011/TT-NHNN. The main contents of the circular include technical requirements, risk management, reporting, and responsibilities of relevant parties.
Đối tượng áp dụng
Credit institutions, foreign bank branches, and payment service providers in Vietnam when providing Internet Banking services.
Các điểm cốt lõi
- Technical requirements: data encryption, setting appropriate access rights for employees, customer database access management
- Risk management: determining transaction limits and corresponding authentication measures, guiding customers on information security
- Reporting: entities must report to the State Bank of Vietnam about the provision of Internet Banking services before formal implementation and in case of system security incidents
- Responsibilities of relevant parties: The State Bank of Vietnam monitors and compiles the implementation of the circular; banking inspection agencies check the enforcement of the circular
- Rights and obligations of customers when using Internet Banking services
🌐 Tác động xã hội từ văn bản này
- Enhancing security for the provision of Internet Banking services, minimizing cyber security risks
- Ensuring the rights of Internet Banking service users through clear publication of terms and safe usage guidelines
❓ Câu hỏi thường gặp
What regulation does this circular replace?
Circular No. 36/2017/TT-NHNN replaces Circular No. 29/2011/TT-NHNN of the State Bank of Vietnam on ensuring safety and security when providing online banking services.
What reports must credit institutions submit before implementing Internet Banking services?
Before officially implementing Internet Banking services, credit institutions must submit a written report to the State Bank of Vietnam (Information Technology Department) including the website address or application store providing the service, current products and services provided, official launch date, Internet Banking system provider, third-party participants in building and operating the system, authentication solutions applied to each type of customer and transaction.
Toàn văn
CIRCULAR
Provisions on safety and security for the provision of
banking services over the Internet
Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12 dated June 16, 2010;
No. 06/2013/UBTVQH13 dated March 18, 2013;
||| Pursuant to Decree No. 63/2018/NĐ-CP dated May 4, 2018 of the Government on public-private partnership investment;
Pursuant to the Law on Information Security No. 86/2015/QH13 dated November 19, 2015;
Pursuant to Decree No. 35/2007/NĐ-CP dated March 8, 2007 of the Government on electronic transactions in banking activities;
Pursuant to Decree No. 156/2013/NĐ-CP dated November 11, 2013, of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Bureau of Information Technology,
The Governor of the State Bank of Vietnam issues this Circular stipulating safety and security requirements for the provision of banking services over the Internet.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation and Applicability
1. This Circular sets forth the requirements to ensure safety and security for the provision of banking services over the Internet.
2. This Circular applies to credit organizations, foreign bank branches, and payment intermediary service providers operating in Vietnam (hereinafter referred to collectively as entities).
Article 2. Definitions and Terms
In this Circular, the following terms are understood as follows:
1. Internet Banking Services are banking services and payment intermediary services provided by entities through the Internet.
2. Internet Banking System is a structured set of hardware, software, databases, communication networks, and security systems designed to produce, transmit, collect, process, store, and exchange digital information for the management and provision of Internet Banking services.
3. Customer Users
4. are one-time password (One Time Password - OTP) is a secret code with a single-use value that is valid for a specific period of time, typically used as a second factor to authenticate user access to applications or to perform Internet Banking transactions.
5. Two-factor authentication Two-factor authentication
6. End-to-End Encryption is an encryption mechanism applied at the sending point before transmission and decrypted only upon receipt at the receiving end during information exchange between applications and devices within the system to minimize the risk of information leakage.
Article 3. General principles for ensuring safety and security of information technology systems for providing Internet banking services
1. The Internet Banking system is classified as a critical information technology system and must comply with the State Bank of Vietnam's regulations on ensuring the safety and security of information technology systems in banking operations.
2. Ensuring the confidentiality of customer information; the integrity of customer transaction data and all financial transactions of customers must be verified with a minimum of two factors, except for low-risk transactions as defined by the Governor of the State Bank of Vietnam.
3. Ensuring the availability of the Internet Banking system to provide continuous service.
4. Conducting regular annual security and security assessments of the Internet banking system.
5. Identifying risks and taking preventive and remedial measures for risks in providing Internet Banking services.
6. Infrastructure technical equipment providing Internet Banking services must have clear copyright, origin, and source; in cases where the manufacturer no longer provides support and there is no capability to upgrade to install new software versions, the entity must develop a plan to upgrade or replace according to the manufacturer's notification.
Chapter II
SPECIFIC PROVISIONS
Section 1
INFRASTRUCTURE OF THE INTERNET BANKING SYSTEM
Article 4. Network Systems, Communication, and Security
The unit must establish network systems, communication, and security meeting the following minimum requirements:
1. The network system shall be divided into zones, at least including: the Internet connection zone, the intermediate zone between the internal network and the Internet (DMZ zone), the user zone, the management zone, and the server zone. Computers providing information on the Internet must be placed within the DMZ zone. Servers storing and processing data must be located within the server zone.
2. Equip security solutions for the Internet Banking system, at a minimum including: firewall devices; anti-virus protection; defense against denial-of-service attacks; application-layer firewall and intrusion prevention.
3. Sensitive data shall not be stored in the Internet connection zone and the DMZ zone.
4. External connections to the Internet Banking system must go through the DMZ zone for security and confidentiality control.
5. Establish policies to limit services and ports connecting to the Internet Banking system to the maximum extent possible.
6. Check security policies; access rights; unauthorized connections, equipment, and software installations in the network system at least once every three months.
7. Do not establish wireless connections to the Internet Banking operational environment.
8. Limit remote connections for system management tasks. In cases where remote connections to the server area are necessary, the unit must use encrypted communication protocols and not store secret keys in utility software.
9. Connections from the Internet to the internal network for system management tasks must comply with the following rules:
a) Must be approved by authorized personnel after reviewing the purpose and method of connection;
b) Must use encrypted communication protocols;
c) Connection devices must be installed with software ensuring security and confidentiality;
d) Must use two-factor authentication when logging into the system.
10. Internet connection lines must ensure availability and must connect to at least two different service providers.
11. Equip solutions to ensure security between network zones: there must be firewall or intrusion prevention devices between different network zones.
Article 5. Server Systems and System Software
1. Requirements for servers
a) Average monthly usage capacity not exceeding 80% of design capacity;
b) High availability feature: the Internet Banking system must have on-site backup servers;
c) Logical or physical separation from other business operation servers.
2. The unit must create a list of permitted software to be installed on servers. Update and check this list regularly, at least once every six months to ensure compliance.
Article 6. Database Management System
1. The database management system must have mechanisms to protect and control access rights to database resources.
2. The Internet Banking system must have a backup database at the disaster recovery center. The backup database must be updated no more than one hour behind the main database. The database must be backed up daily. Backup copies must be securely managed and stored.
3. The unit must implement monitoring and logging of database access and actions taken during database access.
Article 7. Internet Banking Application Software
1. Safety and security requirements must be determined beforehand and organized, implemented during the software application development process: analysis, design, testing, official operation, and maintenance. Documents on safety and security of the software must be systematized and stored, used under the "Confidential" regime.
2. The entity must control the source code of the software with the following minimum requirements:
a) Source code inspection to eliminate harmful code segments and security vulnerabilities.
b) Specific individuals managing the source code of the Internet Banking application software must be designated.
c) Access to the source code must be approved by authorized personnel and monitored, logged.
d) The source code must be securely stored at least two separate locations.
đ) In cases where the source code is not handed over, when signing or accepting contracts, the unit must request the provider to sign a commitment that there are no harmful code segments in the purchased software application.
3. The unit must test and trial the Internet Banking application software to meet the following minimum requirements:
a) Establish and approve a plan and scenario for testing the Internet Banking application software, clearly stating the conditions for safety and security that must be met.
b) Detect and eliminate errors and potential fraud that may occur when entering input data;
c) Evaluate and scan to detect security vulnerabilities and technical weaknesses. Assess the ability to prevent various types of attacks: Injection (SQL, XPath, LDAP...), Cross-site Scripting (XSS), Cross-site Request Forgery (XSRF), Brute-Force.
d) Record errors and the error handling process, especially security and privacy errors in test reports;
đ) Test and trial the safety and security features must be conducted on web browsers (web applications) and mobile device software versions (mobile applications); mechanisms for testing and notifying users running applications on tested and trialed browsers and software versions must be established.
e) Measures to prevent misuse or confusion must be taken regarding data usage during the testing process.
4. Before deploying new software application, the unit must assess risks associated with the deployment process for business operations and related information technology systems, and develop and implement risk mitigation and resolution plans.
5. The unit must manage, change, and upgrade software application versions to meet the following requirements:
a) Analyze and evaluate the impact of changes on the current system and related systems within the unit for each software application change request.
b) All software versions including source code must be centrally managed, stored, secured, and have a mechanism for assigning permissions for each member to operate files.
c) Information about versions, update times, and updaters must be recorded.
d) Each upgraded version must be tested for safety and security features, risk levels, and stability before official deployment.
đ) Upgrading versions must be based on test results and approved by authorized personnel.
e) Successful software application versions after testing must be strictly managed; unauthorized modifications must be prevented, and they must be ready for deployment.
g) Clear instructions on the content of changes, guidance for updating the software application, and other relevant information must be provided and approved by authorized personnel before deploying the new version to customers.
6. Mandatory features of the software application:
a) All data transmitted over the Internet environment must apply end-to-end encryption mechanisms.
b) Ensure the integrity of transaction data, all illegal modifications must be detected during transaction processing and data storage.
c) There must be a session control mechanism and website access time. If the user does not perform any action within a period specified by the unit but not exceeding five minutes, the system will automatically terminate the session or apply other protective measures.
d) A function to hide the display of secret key codes used for logging into the system.
đ) For organizational customers, the software application must be designed to ensure that transactions are carried out in at least two steps: creating and approving transactions, and performed by at least two different people.
Article 8. Mobile Device Application Software
Mobile device Internet Banking application software provided by the entity must ensure compliance with the provisions set forth in Article 7 of this Circular and meet the following requirements:
1. The entity must clearly indicate the web address or app store link for customers to download and install the mobile device Internet Banking application software.
2. The application software must apply protective measures to limit reverse engineering.
3. The application software must authenticate users upon access. In case of incorrect authentication attempts exceeding the number of times specified by the entity, but not more than five times, the application software must automatically lock temporarily, preventing customers from continuing to use it.
Section 2
INTERNET BANKING TRANSACTION AUTHENTICATION
Article 9. Customer Authentication for Internet Banking Services
1. Customers accessing and using Internet Banking services must be authenticated at a minimum by a username and secret code meeting the following requirements:
a) The username must have a minimum length of six characters; it may not consist entirely of repeated characters or consecutive characters in alphabetical or numerical order;
b) The secret code must have a minimum length of six characters, including alphanumeric characters, containing both uppercase and lowercase letters or special characters. The validity period of the secret code shall not exceed twelve months.
2. The Internet Banking application software must have a feature requiring customers to change their secret code immediately upon first login; and lock the account if the customer enters the wrong secret code consecutively more than the number of times specified by the entity, but not more than five times. Account unlocking can only be done when requested by the customer at the service counter.
Article 10. Requirements for Transaction Authentication Solutions
1. The entity must assess the risk level of transactions based on each type of customer, transaction type, and transaction limit to provide appropriate transaction authentication solutions for customers to choose from. The transaction limit shall not exceed the limit prescribed by the Governor of the State Bank of Vietnam during each period.
2. Requirements for transaction authentication using OTP sent via SMS or email:
a) The OTP sent to the customer must include warning information so that the customer can recognize the purpose of the OTP;
b) The OTP shall be valid for a maximum of five minutes.
3. Requirements for transaction authentication using matrix OTP card:
a) The matrix OTP card has a maximum usage period of one year from the date of card registration;
b) The OTP shall be valid for a maximum of two minutes.
4. Requirements for transaction authentication using OTP generated from software installed on a mobile device:
a) The entity must clearly indicate the web address or app store link for customers to download and install the OTP-generating software;
b) The OTP-generating software must use the activation key provided by the entity before use. An activation key can only be used for one mobile device;
c) The OTP-generating software must control access. In case of five consecutive failed access attempts, the software must automatically lock, preventing the customer from using it further;
d) The OTP shall be valid for a maximum of two minutes.
5. Requirements for transaction authentication using OTP generated from a device (OTP token): The OTP shall be valid for a maximum of two minutes.
6. Requirements for transaction authentication using digital signature: The entity must use digital signatures and digital signature verification services provided by organizations operating in accordance with the laws on digital signatures and digital signature verification services.
7. Requirements for transaction authentication using biometric identification features: The biometric identification feature must be unique to each customer and cannot be forged.
Section 3
OPERATIONAL MANAGEMENT
Article 11. Management of Personnel for Supervision, Operation of Internet Banking System
1. The entity shall assign personnel to monitor and oversee the system's operations, detect and handle technical incidents, and cyber attacks.
2. The entity shall assign personnel to receive information, support customers, and promptly contact customers when abnormal transactions are detected.
3. Personnel responsible for managing, supervising, and operating the Internet Banking system must participate in annual training courses to update their knowledge on security and protection.
4. The issuance and allocation of permissions for Internet Banking system management accounts must be monitored and supervised by an independent department from the account issuance department.
Article 12. Management of Operations in the Internet Banking System Operating Environment
1. The entity shall not install or store application development software or source code on the operational environment.
2. Computers used by personnel managing, supervising, and operating the system must be placed within the administrative network zone, installed with antivirus software, and set up with an automatic screen lock policy after a period of inactivity defined by the entity, but not exceeding five minutes.
3. The entity must establish a policy prohibiting internet access for computers used by personnel managing, supervising, and operating the system.
Article 13. Management of Technical Vulnerabilities and Weaknesses
The entity must manage vulnerabilities and weaknesses of the Internet Banking system with the following basic contents:
1. Implement measures to prevent, combat, and detect changes in the website and Internet Banking application.
2. Establish mechanisms to detect and prevent intrusions and cyber attacks on the Internet Banking system.
3. Coordinate with state management units and information technology partners to promptly grasp incidents and situations involving information security breaches to take timely preventive measures.
4. Review and check the updating of software patches for the system software, database management systems, and application software at least once every three months.
5. Conduct a security assessment of the Internet Banking system at least once a year. Organize simulation exercises to test and evaluate the level of security assurance of the system.
Article 14. System for Managing and Monitoring the Internet Banking System
1. The entity must establish a monitoring system to track the operation of the Internet Banking system.
2. The entity must develop criteria and software to identify unusual transactions based on time, geographic location, transaction frequency, transaction amount, excessive failed login attempts, and other abnormal signs.
3. The entity must arrange a separate control room from the common work area to manage, monitor, and track the operation of the Internet Banking system, meeting the following requirements:
a) Personnel entering and exiting the control room must be approved by authorized persons;
b) Access to the system for management, operation, and maintenance tasks must be conducted through devices located in the control room. Remote access or direct access on the device must be approved by authorized persons;
c) External access to devices located in the control room must apply two-factor authentication measures.
Article 15. Management of Security Incidents
The entity must establish measures to record, monitor, and handle security incidents. Every three months, the entity must conduct evaluations, find causes, and proactively implement preventive measures against recurrence.
Article 16. Ensuring Continuous Operation
The entity must establish disaster recovery systems, procedures, and scenarios to ensure continuous operation of the Internet Banking system according to the State Bank of Vietnam’s regulations on ensuring safety and security of information technology systems in banking activities. Additionally, the entity must undertake:
1. Analyze and determine situations that may cause loss of information security and disruption of the Internet Banking system's operations. Assess the risk levels and likelihoods for each situation at least six months apart. List situations with risk levels and likelihoods according to high, medium, acceptable, and low categories.
2. Develop response plans (procedures, scenarios) for handling situations with high and medium risk levels and likelihoods as stipulated in Clause 1 of this Article. Determine the maximum downtime allowed for system recovery and data restoration for each response plan. Disseminate the response plans to relevant personnel to understand their tasks and responsibilities when implementing them.
3. Allocate human resources, financial resources, and technical means to organize regular drills for handling situations with high risk levels and likelihoods at least six months apart.
4. Plan and conduct drills for business continuity measures, retain related records, and organize evaluations of drill results.
Section 4
PROTECTING CUSTOMER RIGHTS
Article 17. Information about Internet Banking Services
1. The entity must provide information about Internet Banking services to customers before they register to use the service, at a minimum including:
a) Methods of providing the service: on the Internet, mobile devices, telecommunications. Access methods for Internet Banking services corresponding to each access method on the Internet, mobile devices, and telecommunications;
b) Transaction limits and transaction authentication measures;
c) Necessary equipment conditions when using the service: OTP generating device, mobile phone number, email, digital certificate, mobile device for software installation;
d) Risks related to the use of Internet Banking services.
2. The entity must inform customers about the contract for providing and using Internet Banking services, at a minimum including:
a) Rights and obligations of customers using Internet Banking services;
b) Responsibilities of the entity in securing personal information of customers; methods of collecting and using customer information; commitment not to sell, disclose, or leak customer information;
c) Commitment to ensure continuous operation of the Internet Banking system;
d) Other contents of the entity regarding Internet Banking services (if any).
Article 18. Guidance for Customers Using Internet Banking Services
1. The entity must develop procedures and documentation for guiding the installation and use of software, applications, and devices to perform Internet Banking transactions, and provide guidance to customers on using these procedures and documents.
2. The entity must guide customers on implementing security and confidentiality measures when using Internet Banking services, at a minimum including the following contents:
a) Protecting the secrecy of secret key codes, OTPs, and not sharing storage devices containing this information;
b) Setting up secret key codes and changing account access secret key codes at least once every year or when they are exposed or suspected to be exposed;
c) Not using public computers to access and perform Internet Banking transactions;
d) Not saving login names and secret key codes on web browsers;
đ) Logging out of the Internet Banking application when not in use;
e) Identifying and taking action to handle certain fraudulent situations and fake websites;
g) Requiring the installation and use of antivirus software on personal devices used for Internet Banking transactions;
h) Selecting authentication solutions with appropriate levels of security and confidentiality that meet customer needs for transaction limits;
i) Warning of risks related to the use of Internet Banking services;
k) Not using unlocked mobile devices to download and use Internet Banking application software or OTP generation software;
l) Promptly notifying the entity upon discovery of unusual transactions;
m) Immediately notifying the entity in cases where OTP generating devices, SMS receiving phone numbers, storage devices for security keys used for digital signatures are lost, damaged, or stolen; being defrauded or suspected of being defrauded; being attacked by hackers or suspected of being attacked by hackers.
3. The entity must provide customers with information about contact points, hotlines, and guide customers through the procedures and methods for coordinating the resolution of errors and incidents during the use of the service.
Article 19. Customer Information Security
The entity must apply measures to ensure the safety and confidentiality of customer databases, at a minimum including:
1. Sensitive customer data stored or transmitted over the Internet must be encrypted or concealed.
2. Establishing access rights according to functions and duties for personnel accessing customer data; having monitoring measures for each access.
3. Having measures to manage access and approach devices and means of storing customer information data to prevent the risk of leaking customer information.
Chapter III
IMPLEMENTING PROVISIONS
Article 20. Reporting System
Entities providing Internet Banking services have the responsibility to submit written reports to the State Bank of Vietnam (Department of Information Technology) as follows:
1. Report on Providing Internet Banking Services:
a) Deadline for submitting the report: At least 10 working days before officially providing Internet Banking services;
b) Content of the report:
(i) Website address or application store providing the service;
(ii) Current products and services provided;
(iii) Official provision date;
(iv) Provider of the Internet Banking system product;
(v) Third parties hired or collaborating to build and operate the Internet Banking system; activities related to the Internet Banking system involving third parties and the forms of participation of these third parties;
(vi) Authentication solutions applied to different types of customers, types of transactions, and transaction limits;
(vii) Other documents about information technology infrastructure and communication, human resources, technical business processes, risk management plans, and other relevant contents as stipulated in Chapter II of this Circular.
2. Ad hoc reports:
a) When security breaches or impacts on the operation of the Internet Banking system occur within five days from the time of occurrence or discovery of the incident, the entity must submit a report with the following content:
(i) Time and location of the incident;
(ii) Brief description of the incident and its status at the time of occurrence;
(iii) Cause of the incident;
(iv) Risk assessment and impact on the Internet Banking system and related systems;
(v) Damage situation;
(vi) Measures taken to resolve the incident, prevent, and mitigate risks;
(vii) Recommendations and proposals.
b) Other sudden reports as required by the State Bank of Vietnam.
3. Annual reports:
Reporting deadlines and contents shall comply with the reporting and statistical regulations of the State Bank of Vietnam applicable to credit organizations and foreign bank branches.
Article 21. Responsibilities of Units under the State Bank
1. The Department of Information Technology is responsible for:
a) Monitoring and summarizing reports to the Governor of the State Bank of Vietnam on the implementation of ensuring the safety and confidentiality of information technology systems providing Internet Banking services by entities as stipulated in Article 20 of this Circular;
b) Taking the lead and coordinating with relevant units under the State Bank of Vietnam to handle issues arising during the implementation of this Circular.
2. The Banking Inspection Agency is responsible for coordinating with the Information Technology Department to inspect and supervise the implementation of this Circular and handle administrative violations according to the provisions of the law for acts of violation.
Article 22. Effectiveness
This Circular takes effect from July 1, 2017, and replaces Circular No. 29/2011/TT-NHNN dated September 21, 2011, issued by the State Bank of Vietnam on ensuring safety and confidentiality for online banking services.
Article 23. Implementation Organization
The Director of the Office, the Head of the Information Technology Department of the State Bank of Vietnam, the Heads of units under the State Bank of Vietnam, the Governors of the State Bank of Vietnam branches in provinces and centrally-administered cities, the Chairmen of the Management Boards, the Chairmen of the Board of Members, and the General Directors (Directors) of credit organizations, foreign bank branches, and service providers of payment intermediation are responsible for organizing the implementation of this Circular./.
Văn bản gốc (PDF)
Tải văn bản
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.