Based on the provided materials, this is a list of information security standards recommended for use in various fields such as web communication, email services, file transfer, data encryption, user authentication, public key management, public key infrastructure, and web service security. Each standard has a specific version and intended purpose.
适用范围
Organizations and businesses must comply with regulations on information security and cybersecurity, especially in the increasingly complex digital environment.
要点
- Web Communication Standards: HTTPS, FTPS, SFTP
- Email Service Standards: SMTPS, POP3S, IMAPS
- Secure File Transfer Standards: SSH v2.0, TLS V1.2
- Data Encryption Standards: AES, 3DES, ECC
- User Authentication Standards: SAML v2.0
- Public Key Management Bulletin XML Standard: XKMS v2.0
- Public Key Infrastructure Standards: PKCS#7 vl.5, PKCS#15 vl.l, PKCS#8 VI.2, PKCS#11 V2.20, PKCS#12 vl.l
🌐 本文件的社会影响
- Enhance information security and cybersecurity
- Reduce risks of data loss and privacy breaches
- Improve the efficiency of digital system operations
❓ 常见问题
Why is it necessary to comply with information security standards?
Compliance with security standards helps ensure the integrity, security, and continuous operation capability of information systems.
Which standards are recommended for secure file transfer?
FTPS, SFTP, and SSH v2.0 are the recommended standards for secure file transfer.
What standard should be used for data encryption?
AES, 3DES, and ECC are the recommended encryption algorithms.
全文
| MINISTRY OF INFORMATION AND COMMUNICATION |
SOCIALIST REPUBLIC OF VIET NAM Independence - Freedom - Happiness |
| Number: 39/2017/TT-BTTTT | Hanoi, December 15, 2017 |
CIRCULAR
Issuing the List of Technical Standards
on Information Technology Applications in Government Agencies
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to Decree No. 64/2007/NĐ-CP dated April 10, 2007 of the Government on the application of information technology in state agency activities;
Pursuant to Decree No. 102/2009/NĐ-CP dated November 6, 2009 of the Government on Management of Investment in Information Technology Applications Using State Budget Funds;
Pursuant to Decree No. 17/2017/NĐ-CP dated February 17, 2017 of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Information and Communications;
Pursuant to the proposal of the Director of the Science and Technology Department,
The Minister of Information and Communications hereby issues this Circular stipulating the List of Technical Standards on Information Technology Applications in Government Agencies.
Article 1. Attached herewith is the List of Technical Standards on Information Technology Applications in Government Agencies (hereinafter referred to as the List).
Article 2. This List includes technical standards that must be applied or recommended for application in government agency information systems to ensure seamless, synchronized, and secure sharing and exchange of information between government agencies and between government agencies and organizations and individuals.
This List shall also be applied as a basis for activities related to investment in information technology applications and hiring information technology services using state budget funds.
Article 3. Within one year from the date this Circular takes effect, existing government agency information systems need to be reviewed and plans and timelines for conversion and upgrading in accordance with the provisions of this Circular shall be established.
Article 4. The Department of Science and Technology shall be responsible for leading and coordinating with relevant units to periodically review and update the List stipulated in this Circular.
The Directorate of Informationization shall be responsible for guiding the application of technical standards included in the List stipulated in this Circular.
Article 5. This Circular shall take effect from July 1, 2018 and replace Circular No. 22/2013/TT-BTTTT dated December 23, 2013 issued by the Minister of Information and Communications on the List of Technical Standards on Information Technology Applications in Government Agencies.
Article 6. The Director of the Office, Heads of the Department of Science and Technology, the Director of the Directorate of Informationization, Heads of agencies and units under the Ministry, Directors of Provincial Departments of Information and Communications, and related organizations and individuals are responsible for implementing this Circular./.
|
THE MINISTER (Signed) TRUONG MINH TUN |
LIST OF TECHNICAL STANDARDS
ON INFORMATION TECHNOLOGY APPLICATIONS IN GOVERNMENT AGENCIES
(Attached herewith is Circular No. 39/2017/TT-BTTTT dated December 15, 2017
of the Minister of Information and Communications
|
Number No. |
Type of standard | Standard Code | Full name of standard | Application Provisions |
| 1 | Connection standard | |||
| 1.1 | Hyper Text Transfer | HTTP v1.1 | Hypertext Transfer Protocol version 1.1 | Must be applied |
| HTTP v2.0 | Hypertext Transfer Protocol version 2.0 | Recommended for application | ||
| 1.2 | File transfer | FTP | File Transfer Protocol | Must apply one or both standards |
| HTTP v1.1 | Hypertext Transfer Protocol version 1.1 | |||
| HTTP v2.0 | Hypertext Transfer Protocol version 2.0 | Recommended for application | ||
| WebDAV |
Web-based Distributed Authoring and Versioning |
Recommended for application | ||
| 1.3 | Audio/Video streaming | RTSP |
Real-time Streaming Protocol |
Recommended for application |
| RTP | Real-time Transport Protocol | Recommended for application | ||
| RTCP | Real-time Control Protocol | Recommended for application | ||
| 1.4 | Data access and sharing | OData v4 | Open Data Protocol version 4.0 | Recommended for application |
| 1.5 | Email transmission | SMTP/MIME | Simple Mail Transfer Protocol/Multipurpose Internet Mail Extensions | Must be applied |
| 1.6 | Email access service | POP3 | Post Office Protocol version 3 | Must apply both standards for servers |
| IMAP 4rev1 |
Internet Message Access Protocol version 4 revision 1 |
|||
| 1.7 | Directory access | LDAP v3 |
Lightweight Directory Access Protocol version 3 |
Must be applied |
| 1.8 | Domain name service | DNS | Domain Name System | Must be applied |
| 1.9 | Connected network transport | TCP | Transmission Control Protocol | Must be applied |
| 1.10 | Unconnected network transport | UDP | User Datagram Protocol | Must be applied |
| 1.11 | Local Area Network/Wide Area Network interconnection | IPv4 | Internet Protocol version 4 | Must be applied |
| IPv6 | Internet Protocol version 6 | Must be applied for devices connected to the Internet | ||
| 1.12 | Wireless local area network |
||| IEEE IEEE 802.11g |
Institute of Electrical and Electronics Engineers Standard (IEEE) 802.11g | Must be applied |
|
||| IEEE IEEE 802.11n |
Institute of Electrical and Electronics Engineers Standard (IEEE) 802.11n | Recommended for application | ||
| 1.13 | Wireless internet access | WAP v2.0 | Wireless Application Protocol version 2.0 | Must be applied |
| 1.14 | SOAP-based web service | SOAP v1.2 |
Simple Object Access Protocol version 1.2 |
Must apply one, two, or all three standards |
|
WSDL v2.0 Web Services Description Language version 2.0 |
UDDI v3 | |||
| Universal Description, Discovery and Integration version 3 | RESTful web service | |||
| 1.15 | Representational State Transfer | Web service description | WS-BPEL v2.0 | Recommended for application |
| 1.16 | Web Services Business Process Execution Language Version 2.0 | WS-I Simple SOAP Binding Profile Version 1.0 | Simple SOAP Binding | Recommended for application |
| Profile Version 1.0 |
WS-Federation v1.2 Web Services Federation |
Recommended for application | ||
| Language Version 1.2 |
WS-Addressing v1.0 Web Services Addressing 1.0 |
Recommended for application | ||
|
Coordination Version 1.2 |
Web Services Coordination | Recommended for application | ||
|
Coordination WS-Policy v1.2 OASIS Web Services Business Activity Version 1.2 |
Web Services Business Activity Version 1.2 OASIS Web Services Business Activity Version 1.2 |
Recommended for application | ||
| Discovery |
Web Services Business Activity Version 1.2 OASIS Web Services Business Activity Version 1.2 |
Recommended for application | ||
| Version 1.1 | Web Services Dynamic Discovery Version 1.1 | Recommended for application | ||
|
Coordination MetadataExchange Web Services Metadata Exchange |
Time synchronization service | Recommended for application | ||
|
Coordination NTPv3 |
Network Time Protocol version 3 | Recommended for application | ||
| 1.17 | Must apply one of two standards | NTPv4 | Network Time Protocol version 4 | Text formatting language standard |
| XML v1.0 (5th Edition) | Extensible Markup Language version 1.0 (5th Edition) |
| 2 | XML v1.1 | Article | ||
| 2.1 | Extensible Markup Language version 1.1 | Text formatting language for electronic transactionsISO/TS 15000:2014 Electronic Business Extensible Markup Language (ebXML) | Definition of schemas in XML documentsth Electronic Business Extensible Markup Language (ebXML) | Text formatting language standard |
| XML Schema v1.1tháng 3 năm 1993 của Chính phủ quy định chức năng, nhiệm vụ và quyền hạn của các Bộ, cơ quan ngang Bộ trong quản lý nhà nước; Electronic Business Extensible Markup Language (ebXML) |
XML Schema version 1.1 Data transformation |
|||
| 2.2 | XSL | Extensible Stylesheet | Language | Must be applied |
| 2.3 | Must apply the latest version. |
Object modeling UML v2.5 |
Unified Modeling Language version 2.5 | Must be applied |
| 2.4 | Data resource model | RDF |
Resource Description Framework OWL |
Web Ontology Language |
| 2.5 | Character set display | UTF-8 | 8-bit Universal Character Set | Recommended for application |
| 2.6 | Transformation Format | Geographic information exchange format | GML v3.3 | Recommended for application |
| Geography Markup | Language version 3.3 | Recommended for application | ||
| 2.7 | Geographic information access and update | WMS v1.3.0 |
OpenGIS Web Map Service version 1.3.0 WFS v1.1.0 Web Feature Service version |
Must be applied |
| 2.8 | XML document description data exchange | XMI v2.4.2 |
XML Metadata Interchange version 2.4.2 Metadata registry (MDR) |
Must be applied |
| 2.9 | ISO/IEC 11179:2015 | Metadata registry (Metadata registries - MDR) | Dublin Core metadata element set | Must be applied |
| ISO 15836-1:2017 |
Metadata element set 1.1.0 |
Must be applied | ||
| 2.10 | Dublin Core | XMI V2.4.2 | XML Metadata Interchange version 2.4.2 | Recommended for application |
| 2.11 | metadata registration book (MDR) | ISO/IEC 11179:2015 | metadata registration book (Metadata Registries - MDR) | Recommended for application |
| 2.12 | Dublin Core Metadata Elements | ISO 15836-1:2017 |
metadata elements Dublin Core |
Recommendation for application |
| 2.13 | JavaScript Object Notation Description Format for Business Process Model | JSON RFC7159 | JavaScript Object Notation | Recommended for application |
| 2.14 | Business Process Modeling Language | BPMN 2.0 |
Business Process Model and Notation version 2.0 |
Recommended for application |
| 3 | Information Accessibility Standards | |||
| 3.1 | Web Content Standard | HTML V4.01 | Hypertext Markup Language version 4.01 | Must be applied |
| WCAG 2.0 | W3C Web Content Accessibility Guidelines (WCAG) 2.0 | Recommended for application | ||
| HTML 5 | Hypertext Markup Language version 5 | Recommended for application | ||
| 3.2 | Extended Web Content Standard | XHTML vl.l | Extensible Hypertext Markup Language version 1.1 | Must be applied |
| 3.3 | User Interface | CSS2 |
Cascading Style Sheets Language Level 2 |
Mandatory application of one of three standards |
| CSS3 |
Cascading Style Sheets Language Level 3 |
|||
| RDF | Extensible Stylesheet Language version | |||
(*) For objects within the scope of Circular No. 24/2011/TT-BTTTT, the provisions of Circular No. 24/2011/TT-BTTTT shall still be applied.
| 3.4 | Document | (.txt) | Plain Text (.txt) format: Suitable for basic unstructured documents | Must be applied |
| (.rtf)vl.8, V 1.9.1 | Rich Text (.rtf) format versions 1.8, 1.9.1: Suitable for documents that can be exchanged between different platforms | Must be applied | ||
| (.docx) | Microsoft Word Document (.docx) format | Recommended for application | ||
| (,pdf) vl.4, vl.5, vl.6, vl.7 | Portable Document (.pdf) format versions 1.4, 1.5, 1.6, 1.7: Suitable for read-only documents | Mandatory application of one, two, or all three standards | ||
| (.doc) | Microsoft Word Document (.doc) format | |||
| (.odt) vl.2 |
Open Document Text (.odt) format version 1.2 |
|||
| 3.5 | Spreadsheet | (.csv) | Comma Separated Values/Delimited (.csv) format: Suitable for spreadsheets that need to be exchanged between different applications | Must be applied |
| (.xlsx) | Microsoft Excel Spreadsheet (.xlsx) format | Recommended for application | ||
| (.xls) | Microsoft Excel Spreadsheet (.xls) format | Must apply one or both standards | ||
| (.ods) vl.2 | Open Document Spreadsheets (.ods) format version 1.2 | |||
| 3.6 | Presentation | (.htm) | Hypertext Document (.htm) format: Suitable for presentations that can be exchanged through different web browsers | Must be applied |
| (.pptx) | Microsoft PowerPoint Presentation (.pptx) format | Recommended for application | ||
| (.pdf) | Portable Document (.pdf) format: Suitable for presentations stored in read-only format | Must apply one, two, or all three standards | ||
| (.ppt) | Microsoft PowerPoint (.ppt) format |
| (.odp) vl.2 | Open Document Presentation (.odp) format version 1.2 | |||
| 3.7 | Graphic Image | JPEG | Joint Photographic Expert Group (.jpg) | Mandatory application of one, two, three, or all four standards |
| GIF v89a | Graphic Interchange (.gif) format version 89a | |||
| TIFF | Tagged Image File (.tif) | |||
| PNG | Portable Network Graphics (.png) | |||
| 3.8 | Geographical Coordinate Image | GEO TIFF | Tagged Image File Format for GIS Applications | Must be applied |
| 3.9 | Film and Sound | MPEG-1 | Moving Picture Experts Group-1 | Recommended for application |
| MPEG-2 |
Moving Picture Experts Group-2 |
Recommended for application | ||
| MPEG-4 |
Moving Picture Experts Group-4 |
Recommended for application | ||
| MP3 | MPEG-1 Audio Layer 3 | Recommended for application | ||
| Advanced Audio Coding | Advanced Audio Coding | Recommended for application | ||
| 3.10 | Film and Sound Stream | (.asf), (.wma), (.wmv) | Microsoft Windows Media Player formats (.asf), (.wma), (.wmv) | Recommended for application |
| (.ra), (.rm), (.ram), (.rmm) | Real Audio/Real Video formats (.ra), (.rm), (.ram), (.rmm) | Recommended for application | ||
| (.avi), (.mov), (.qt) | Apple Quicktime formats (.avi), (.mov), (.qt) | Recommended for application | ||
| 3.11 | Animation | GIF v89a | Graphic Interchange (.gif) format version 89a | Recommended for application |
| (.swf) | Macromedia Flash (.swf) format | Recommended for application | ||
| (.swf) | Macromedia Shockwave (.swf) format | Recommended for application | ||
| (.avi), (.qt), (.mov) |
Apple Quicktime formats (.avi), (.qt), (.mov) |
Recommended for application |
| 3.12 | Mobile Device Content Standard | WML v2.0 | Wireless Markup Language version 2.0 | Must be applied |
| 3.13 | Character Set and Encoding | ASCII | American Standard Code for Information Interchange | Must be applied |
| 3.14 | Vietnamese Character Set and Encoding | TCVN 6909:2001 | TCVN 6909:2001 "Information Technology - 16-bit Vietnamese Character Set" | Must be applied |
| 3.15 | Data Compression | Zip | Zip (.zip) format | Mandatory application of one or both standards |
| .gz v4.3 | GNU Zip (.gz) format version 4.3 | |||
| 3.16 | Client-side Scripting Language | ECMA 262 | ECMAScript version 6th Electronic Business Extensible Markup Language (ebXML) | Must be applied |
| 3.17 | Web Content Sharing | RSS vl.o | RDF Site Summary version 1.0 | Mandatory application of one of two standards |
| RSS v2.0 | Really Simple Syndication version 2.0 | |||
| ATOM vl.o | ATOM version 1.0 | Recommended for application | ||
| 3.18 | Application Portal Content Standard | JSR 168 | Java Specification Requests 168 (Portlet Specification) | Mandatory application |
| JSR 286 | Java Specification Requests 286 (Portlet Specification) | Recommended for application | ||
| WSRP vl.o |
Web Services for Remote Portlets version 1.0 |
Must be applied | ||
| WSRP v2.0 | Web Services for Remote Portlets version 2.0 | Recommended for application | ||
| 4 | Information Security Standard | |||
| 4.1 | Email Security | S/MIME v3.2 | Secure Multipurpose Internet Mail Extensions version 3.2 | Must be applied |
| OpenPGP | OpenPGP | Recommended for application | ||
| 4.2 | Transport Layer Security | SSH v2.0 | Secure Shell version 2.0 | Must be applied | |
| TLS V1.2 | Transport Layer Security version 1.2 | Must be applied | |||
| 4.3 | File Transfer Security | HTTPS | Hypertext Transfer Protocol Secure | Must be applied | |
| FTPS | File Transfer Protocol Secure | Recommended for application | |||
| SFTP | SSH File Transfer Protocol | Recommended for application | |||
| 4.4 | Email Security | SMTPS |
Simple Mail Transfer Protocol Secure |
Mandatory application | |
| 4.5 | Service Access Box Security | POP3S | Post Office Protocol version 3 Secure | Must apply one or both standards | |
| IMAPS |
Internet Message Access Protocol Secure |
||||
| 4.6 | Domain Name System Security | DNSSEC | Domain Name System Security Extensions | Recommended for application | |
| 4.7 | Network Security | IPsec - IP ESP | Internet Protocol security with IPESP | Must be applied | |
| 4.8 | Wireless Network Security | WPA2 | Wi-Fi Protected Access 2 | Must be applied | |
| 4.9 | Encryption Algorithm |
TCVN 7816:2007 |
Information Technology - Data Encryption Algorithm AES | Recommended for application | |
| 3DES | Triple Data Encryption Standard | Recommended for application | |||
|
PKCS#1 V2.2 |
RSA Cryptography Standard - version 2.2 | Recommendation for application, use RSAES-OAEP scheme for encryption | |||
| ECC | Elliptic Curve Cryptography | Recommended for application |
| 4.10 | Digital Signature Algorithm |
PKCS#1 V2.2 |
RSA Cryptography Standard - version 2.2 | Mandatory application, use RSASSA-PSS scheme for signing |
| ECDSA | Elliptic Curve Digital Signature Algorithm | Recommended for application | ||
| 4.11 | Hash Algorithm for Digital Signature | SHA-2 | Secure Hash Algorithms-2 | Recommended for application |
| 4.12 | Key Exchange Algorithm | RSA-KEM | Rivest-Shamir-Adleman - KEM (Key Encapsulation Mechanism) Key Transport Algorithm | Must be applied |
| ECDHE | Elliptic Curve Diffie-Hellman Ephemeral | Recommended for application | ||
| 4.13 | User Authentication Solution | SAML v2.0 | Security Assertion Markup Language version 2.0 | Recommended for application |
| 4.14 | XML Message Security | XML Encryption Syntax and Processing | XML Encryption Syntax and Processing | Must be applied |
| XML Signature Syntax and Processing | XML Signature Syntax and Processing | Must be applied | ||
| 4.15 | Public Key Management for XML Messages | XKMS v2.0 | XML Key Management Specification version 2.0 | Recommended for application |
| 4.16 | Personal Information Security Protocol | P3P vl.l |
Platform for Privacy Preferences Project version 1.1 |
Recommended for application |
| 4.17 | Public Key Infrastructure | Recommended for application | |||
| Cryptographic Message Syntax for Signing and Encrypting | PKCS//7 vl.5 (RFC 2315) | Cryptographic message syntax for file-based signing and encrypting version 1.5 | |||
| Token Information Syntax | PKCS#15 vl.l | Cryptographic token information syntax version 1.1 | |||
| Private Key Information Syntax |
PKCS#8 VI.2 (RFC 5958) |
Private-Key Information Syntax Standard version 1.2 |
|||
| Cryptographic Token Interface |
PKCS#11 V2.20 |
Cryptographic token interface standard version 2.20 | |||
| Personal Information Exchange Syntax | PKCS#12 vl.l | Personal Information Exchange Syntax version 1.1 | |||
| Certificate Revocation List Profile | RFC 5280 | Certificate Revocation List Profile | |||
| Digital Certificate Template | RFC 5280 | Public Key Infrastructure Certificate | |||
| Certification Request Syntax | PKCS#10 v1.7 (RFC 2986) | Certification Request Syntax Specification version 1.7 | |||
| Online Certificate Status Protocol | RFC 6960 | Online Certificate Status Protocol | |||
| Timestamping Protocol | RFC 3161 | Timestamping Protocol | |||
| Timestamp Service |
ISO/IEC 18014-1:2008 ISO/IEC 18014-2:2009 ISO/IEC 18014-3:2009 ISO/IEC 18014-4:2015 |
Information Technology Security Techniques - Timestamping Services Part 1: Framework Part 2: Mechanisms Producing Independent Tokens Part 3: Mechanisms Producing Linked Tokens Part 4: Traceability of Time Sources |
||
| 4.18 | Web Service Security | WS-Security v1.1 |
Web Services Security: SOAP Message Security Version 1.1.1 |
Recommended for application |
| 4.19 | Incident Object Description Exchange Format version 2 (IODEF) | RFC 7970 | The Incident Object Description Exchange Format version 2 (IODEF) | Recommended for application |
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。