Circular No. 35/2018/TT-NHNN amends and supplements certain provisions of Circular No. 35/2016/TT-NHNN on safety and security for the provision of banking services over the Internet. This document provides more detailed regulations on general principles, transaction authentication measures, security system testing and evaluation, and other technical requirements to ensure information security in online banking activities.
适用范围
The State Bank of Vietnam, credit institutions, foreign bank branches, and organizations providing intermediary payment services
要点
- Internet Banking service providers must ensure the confidentiality and integrity of customer information and maintain system availability to provide continuous service (Article 3).
- Implement multi-factor authentication when changing customer identification information (Article 3)
- Customer information shall not be stored in the Internet-connected zone and the DMZ zone (Clause 3, Article 4).
- There must be a disaster recovery database capable of replacing the main database (Clause 2, Article 6).
- Application software must authenticate users upon access and not remember login passwords, automatically locking temporarily after a number of failed login attempts as specified by the organization (Clause 3, Article 8).
🌐 本文件的社会影响
- Enhance customer information security in online banking activities.
- Minimize cybersecurity risks for credit institutions and customers using Internet Banking services.
- Higher technical requirements for the information technology systems of service providers, leading to additional investment costs for system upgrades.
- Customers can feel more secure when conducting online transactions.
❓ 常见问题
How is customer information stored in the Internet Banking system?
Customer information shall not be stored in the Internet-connected zone and the DMZ zone (Clause 3, Article 4).
What kind of disaster recovery database must Internet Banking service providers have?
The disaster recovery database must be able to replace the main database and ensure that no online transaction data of customers is lost (Clause 2, Article 6).
What are the requirements for user authentication in Internet Banking application software?
Application software must authenticate users upon access and not remember login passwords, automatically locking temporarily after a number of failed login attempts as specified by the organization (Clause 3, Article 8).
How must Internet Banking service providers conduct security and system testing evaluations?
Conduct regular annual security and system testing evaluations for Internet Banking (Article 3).
What requirements are there for updating information about security vulnerabilities?
Information about security vulnerabilities related to system software, database management systems, and application software must be updated according to CVSS v3 (Clause 6, Article 13).
全文
CIRCULAR
Amending and supplementing certain Articles of Circular No. 35/2016/TT-NHNN dated December 29, 2016 of the Governor of the State Bank of Vietnam on safety and security for providing Internet banking services
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010 and the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to the Law on Electronic Transactions dated November 29, 2005;
Pursuant to the Law on Cybersecurity dated November 19, 2015;
Pursuant to Government Decree No. 16/2017/NĐ-CP dated February 17, 2017 on the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
Pursuant to Decree No. 35/2007/NĐ-CP dated March 8, 2007 of the Government on electronic transactions in banking activities;
Pursuant to Decree No. 117/2018/NĐ-CP dated September 11, 2018 of the Government on keeping customer information confidential and providing such information to credit organizations and foreign bank branches;
At the proposal of the Director of the Department of Information Technology;
The Governor of the State Bank of Vietnam hereby issues this Circular amending and supplementing certain Articles of Circular No. 35/2016/TT-NHNN dated December 29, 2016 of the Governor of the State Bank of Vietnam on safety and security for providing Internet banking services (Circular No. 35/2016/TT-NHNN).
Article 1. Amending and supplementing certain Articles of Circular No. 35/2016/TT-NHNN
1. Clause 3 shall be amended and supplemented as follows:
"Article 3. General principles for ensuring safety and security of information technology systems for providing Internet banking services
1. The Internet banking system is an important information system according to the regulations of the State Bank of Vietnam on the safety of information systems in banking operations.
2. Ensuring the confidentiality and integrity of customer information; ensuring the availability of the Internet banking system to provide services continuously.
3. Customer transaction information is assessed for risk level based on each customer group, type of transaction, transaction limit, and accordingly provides appropriate transaction authentication methods for customers to choose from. Transaction authentication methods must meet:
a) Applying at least multi-factor authentication when changing customer identification information;
b) Applying authentication measures for each customer group, type of transaction, and transaction limit according to the decision of the Governor of the State Bank of Vietnam during each period;
c) For transactions involving multiple steps, applying at least authentication at the final approval step.
4. Conducting regular annual security and security assessments of the Internet banking system.
5. Continuously identifying risks, threats causing risks, and determining the causes of risks, promptly taking preventive, control, and handling measures for risks in providing Internet banking services.
6. Infrastructure technical equipment for providing Internet banking services must have clear copyright, origin, and place of manufacture. For equipment nearing the end of its product life cycle and no longer supported by the manufacturer, the unit must have a plan to upgrade or replace it according to the manufacturer's notification, ensuring that infrastructure equipment has the capability to install new software versions.
2. Clause 3 of Article 4 is amended and supplemented as follows:
"3. Customer information shall not be stored in the Internet-connected partition and the DMZ partition."
3. Clause 10 of Article 4 is amended and supplemented as follows:
"10. The Internet connection for providing services must ensure high availability and continuous service provision capability."
4. Clause 2 of Article 6 is amended and supplemented as follows:
"2. The Internet banking system must have a disaster recovery database capable of replacing the main database and ensuring no loss of online transaction data for customers."
5. Point c and point đ of Clause 6 of Article 7 are amended and supplemented as follows:
"c) Session control: the system has an automatic mechanism to terminate the session when the user does not operate within a time period specified by the unit or applies other protective measures;"
"đ) For organizational customers, the application software is designed to ensure transaction execution includes at least two steps: creating and approving transactions, performed by different individuals. In cases where organizational customers are allowed by law to apply simplified accounting procedures, transaction execution is similar to individual customers."
6. Clause 3 of Article 8 is amended and supplemented as follows:
"3. Application software must authenticate users upon access and does not have a feature to remember login passwords. If incorrect authentication is attempted more than the number of times specified by the unit, the application software must automatically lock out the user temporarily."
7. Adding point c to Clause 1 of Article 9 as follows:
"c) For accessing the Internet banking system through a browser, the unit must have measures to prevent automatic login."
8. Clause 2 of Article 9 is amended and supplemented as follows:
"2. Internet banking application software must force customers to change their secret code immediately upon first login; lock the account if the secret code is entered incorrectly consecutively more than the number of times specified by the unit. The unit will unlock the account only upon the customer's request and must verify the customer before unlocking the account, ensuring fraud prevention and counterfeiting."
9. Clause 3 of Article 12 is amended and supplemented as follows:
"3. The unit must establish policies to restrict Internet access for computers managing and monitoring the Internet banking system. In cases where Internet connection is necessary for work, the unit must:
a) Assess risks associated with Internet connection;
b) Apply control measures for Internet connection;
c) The implementation plan must be approved by authorized personnel within the unit."
10. Adding Clause 6 to Article 13 as follows:
"6. Updating information on security vulnerabilities published related to system software, database management systems, and application software according to information from the Common Vulnerability Scoring System version 3 (CVSS v3). Implementing timely updates of security patches or preventive measures meeting the following criteria:
a) Within one month after publication for security vulnerabilities rated as critical (equivalent to CVSS v3 score of 9.0 or higher);
b) Within two months after publication for security vulnerabilities rated as high (equivalent to CVSS v3 score of 7.0 to 8.9);
c) Within a timeframe determined by the unit for security vulnerabilities rated as medium or low (equivalent to CVSS v3 score below 7.0)."
11. Clause 1 of Article 19 is amended and supplemented as follows:
"1. When storing confidential customer information, encryption or masking measures must be applied to ensure confidentiality."
Article 2
1. Repeal Clause 7 of Article 4 and Clause 1 of Article 10 of Circular 35/2016/TT-NHNN.
2. Replace the phrase "Cục Công nghệ tin học" with the phrase "Cục Công nghệ thông tin" in Articles 20, 21, and 23 of Circular 35/2016/TT-NHNN.
This Circular takes effect from December 25, 2025/.
The Head of the Office, the Director of the Information Technology Department, the Heads of units under the State Bank, the Governors of the State Bank branches in provinces and centrally-administered cities, the Chairpersons of the Management Councils, the Chairpersons of the Board of Members, the General Directors (Directors) of credit organizations, foreign bank branches, and service providers of payment intermediation shall be responsible for implementing this Circular.
Article 4. Effective date
This Circular takes effect from July 1, 2019./.
DEPUTY DIRECTOR
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。
译本
本文件提供以下语言版本: