Circular No. 47/2014/TT-NHNN stipulates technical requirements for security and safety concerning equipment serving bank card payments

This Circular sets forth technical requirements for security and safety concerning equipment serving bank card payments in Vietnam, applicable to organizations engaged in card operations. The main contents include management of network security device configurations, development and maintenance of systems, monitoring and protecting card data, ensuring continuous operation of card payment systems.

Document No.47/2014/TT-NHNN
Document typeCircular
Issuing authorityState Bank of Vietnam
Signed byNguyễn Toàn Thắng — Phó Thống đốc
Updated24/06/2026
SectorBanking
FieldBanking Information Technology
Issued date31/12/2014
Effective date01/04/2015
Expiry date
StatusIn effect
✦ Smart summary

This Circular sets forth technical requirements for security and safety concerning equipment serving bank card payments in Vietnam, applicable to organizations engaged in card operations. The main contents include management of network security device configurations, development and maintenance of systems, monitoring and protecting card data, ensuring continuous operation of card payment systems.

Scope of application

Organizations engaged in card operations, including Card Issuing Organizations (CIOs), Payment Service Providers (PSPs), and Payment Gateway Service Providers (PGSPs), have equipment serving bank card payments.

Key points

  • Organizations engaged in card operations must manage network security device configurations and implement technical requirements for security and safety concerning equipment serving bank card payments (Article 3).
  • Security measures for ATMs, including installation, alarm systems, cash drawers, PIN entry keyboards, and quality certification, must be ensured (Articles 7-8).
  • Technical requirements for software, connectivity, and intercommunication for ATMs must also be met (Article 8).
  • Organizations engaged in card operations must establish information security policies, manage access, and monitor the operation of card payment systems (Articles 12-13).
  • Organizations engaged in card operations must take measures to protect card data transmitted over external networks and limit access to card data (Articles 14-16).

🌐 Social impact of this document

  • Positive impact: Minimizing risks of information security breaches, protecting cardholders' rights, enhancing trust in card payment systems.
  • Negative impact: Higher investment and maintenance costs for systems, which may pose difficulties for some small card operation organizations.

❓ Frequently asked questions

To which organizations does this Circular apply?

This Circular applies to Card Issuing Organizations (CIOs), Payment Service Providers (PSPs), and Payment Gateway Service Providers (PGSPs) that have equipment serving bank card payments.

What are the technical security requirements for ATMs specified in this Circular?

ATMs must have origin and quality certifications, alarm systems, cash drawers, and PIN entry keyboards meeting the requirements set out in Article 13 of this Circular.

What measures must organizations engaged in card operations take to protect cardholder data?

They must establish information security policies, manage access, and monitor the operation of card payment systems. Additionally, they must encrypt data transmitted over external networks (Articles 14-16).

How often and when must organizations engaged in card operations submit periodic reports?

Annual reports on compliance with the provisions of this Circular must be submitted by November 15 each year (Article 20).

When does this Circular come into effect?

This Circular takes effect from April 1, 2015 (Article 21).

Full text

STATE BANK OF VIETNAM
VIETNAM

SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness
 

Number: 47/2014/TT-NHNN

Hanoi, December 31, 2014

 CIRCULAR

Regulations on technical requirements for security and safety concerningequipment serving bank card payments

Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12 dated June 16, 2010;

Pursuant to the Law on Credit Organizations No. 47/2010/QH12 dated June 16, 2010;

||| Pursuant to Decree No. 63/2018/NĐ-CP dated May 4, 2018 of the Government on public-private partnership investment;

Pursuant to Decree No. 35/2007/NĐ-CP dated March 8, 2007 of the Government on electronic transactions in banking activities;

BASED ON DECREE NO. 16/2017/NĐ-CP DATED FEBRUARY 17, 2017 OF THE GOVERNMENT ON THE FUNCTIONS, TASKS, POWERS, AND ORGANIZATIONAL STRUCTURE OF THE STATE BANK OF VIETNAM;

Pursuant to Decree No. 156/2013/NĐ-CP dated November 11, 2013, stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;

At the proposal of the Director of the Information Technology Department;

The Governor of the State Bank of Vietnam issues this Circular to stipulate technical requirements for security and safety concerning equipment serving bank card payments.

PART I
GENERAL PROVISIONS

Article 1. Scope of Regulation and Applicability

1. This Circular stipulates technical requirements for security and safety concerning equipment serving bank card payments in Vietnam.

2. This Circular applies to organizations engaged in card activities, including:

a) Card Issuing Organizations (referred to as TCPHT);

b) Card Payment Organizations (referred to as TCTTT);

c) Intermediary Payment Service Providers (referred to as TCTGTT) that have equipment serving bank card payments.

Article 2. Interpretation of Terms

In this Circular, the following terms are understood as follows:

1. Equipment serving card payments includes devices and software used for receiving and processing card transactions.

2. An Automated Teller Machine (ATM) placed outside refers to an ATM located in public places and areas without direct supervision of personnel.

3. A Point Of Sale (POS) machine is a device accepting cards used to perform card transactions at card acceptance units (referred to as ĐVCNT).

4. A Mobile Point Of Sale (mPOS) machine is a POS device comprising specialized software and hardware integrated with mobile communication devices.

5. Bank cards (hereinafter referred to as cards) include magnetic stripe cards and chip cards.

a) Magnetic stripe cards are those where card and cardholder information is encoded and stored on the magnetic strip on the back of the card;

b) Chip cards are those equipped with computer microchips or integrated circuits for identifying, storing cardholder information and transactions, and performing other microprocessing functions.

6. Card number is a series of digits used to identify the issuing organization and the cardholder.

7. Card data includes cardholder data and card authentication data.

a) Cardholder data includes the following main data: card number; cardholder's name (for identification cards); card validity date; service code (three (3) or four (4) digits on the card surface to determine transaction privileges (if applicable));

b) Card authentication data includes the following: all data on the magnetic strip for magnetic stripe cards or data on the microchip or integrated circuit of chip cards; sequence of value numbers or card authentication codes printed on the card; personal identification number (PIN) or PIN block.

8. Cardholder data environment is an environment comprising equipment and processes for handling, transmitting, and storing card data.

9. Strong encryption is a method of encryption based on algorithms widely tested and accepted worldwide, with a minimum key length of 112 (one hundred twelve) bits, and appropriate key management techniques. Minimum algorithms include: AES (128 bits); TDES (112 bits); RSA (2048 bits); ECC (160 bits); ElGamal (2048 bits).

10. Log data are data created by the card payment system or individuals to record transaction processes and system operations in electronic or textual form to serve monitoring, investigation, and complaint resolution activities.

11. Authorized person in this document means the legal representative of an organization or a person authorized by the legal representative of an organization.

12. Card activity support organizations are organizations or individuals with expertise hired or cooperating with card activity organizations to provide goods and technical services for the card payment system.

Chapter II
GENERAL TECHNICAL REQUIREMENTS

Article 3. Establishment and Management of Security Device Configuration

1. Requirements for the establishment and management of security device configuration:

a) The establishment and modification of security device configurations must be tested and approved by authorized persons before implementation;

b) Network system connection diagrams must be designed to meet the requirements:

- Separating the main data zone from other network zones including wireless networks;

- Separating server functions according to the principle that application servers, database servers, and domain management servers should be on different machines (which may be virtual servers on a single physical machine);

- Having firewalls at connection points between zones of the network system;

- The network diagram must describe the entire path of main data flow;

c) Defining responsibilities and authorities for departments and individuals in managing and configuring security devices in writing;

d) Not providing internal network addresses (IP addresses) and routing information to other organizations without approval from authorized persons;

đ) Specifying in writing the ports, services, and protocols used in the network system including those that are unsafe. Implementing comprehensive security solutions when using unsafe ports, services, and protocols;

e) Conducting reviews of security device configuration policies at least twice a year to eliminate unused, expired, or incorrectly set policies, ensuring that the policies implemented on the devices align with those approved by authorized persons;

2. Security device configuration:

a) Limiting access to the main data environment, only accepting necessary and controllable accesses;

b) Limiting access to network devices and security devices consistent with the responsibilities of individuals and departments specified in Point c Clause 1 of this Article;

c) Configuration files must be synchronized with the active configuration of the device and securely stored under confidentiality measures to prevent unauthorized access;

d) Implementing packet status monitoring or automatic data filtering functions on firewall or routing devices to detect invalid packets;

3. Controlling direct access from the Internet to the main data environment:

a) Establishing an intermediary zone providing external Internet services (clearly defining permitted servers, services, IP addresses, ports, and protocols). Connections between the Internet and the main data environment must go through the intermediary service provision zone;

b) Implementing anti-spoofing measures to prevent and eliminate source IP address spoofing possibilities;

c) Not allowing access from the main data environment to the Internet without approval from authorized persons;

4. Requirement to establish firewall software on all devices and personal computers connected to card data:

a) Security policies on firewall software only allow actions sufficient to serve business process needs;

b) Ensuring that firewall software settings are operational;

c) Ensuring users cannot change the firewall software configuration on the device.

Article 4. Modifying, Removing, or Invalidating Parameters and Default Functions in Card Payment Equipment Systems

1. Modify or invalidate parameters and default functions of the system (account, secret key code, operating system parameters, unused software applications; unused POS machine parameters; default character strings in network monitoring protocol (SNMP protocol)).

2. Modify default parameters (wireless network encryption keys; secret key codes; default character strings in SNMP protocols in wireless networks connected to card data).

3. Activate or install default functions (services, protocols, background programs) only when necessary.

4. Remove unnecessary functions, services, files, and drives. Implement additional security measures (SSH, S-FTP, SSL, IPSec VPN technologies) when using unsafe services and protocols for transmitting data over the network (file sharing, NetBIOS, Telnet, FTP).

Article 5. Security Safeguards in Developing and Maintaining Card Payment Equipment

1. Conduct vulnerability identification using scanning tools and information sources from reputable external cybersecurity organizations to determine the impact of new vulnerabilities on the card payment system, including high, medium, and low levels of impact.

2. Ensure that all card payment equipment is updated with published security patch updates from manufacturers. High-level security patches must be installed within the earliest possible time and not later than one month from the manufacturer's announcement.

3. Develop application software in the card field ensuring compliance with legal regulations and widely adopted software development standards in the information technology sector. During the software development cycle, integrate requirements for information security and at least meet the following criteria:

a) Isolate the development and testing environment from the operational environment;

b) Do not use card data in the operational environment for testing purposes;

c) Delete all test data and accounts before deploying the software into operation;

d) Evaluate and review the source code of the application software to detect and fix potential security vulnerabilities before deployment. Personnel conducting evaluations must be independent from those developing the application source code.

4. Implement change control procedures when updating security patches and modifying application software:

a) Prepare documentation assessing the impact on the entire system and obtain approval from authorized personnel before implementation;

b) Do not compromise the security of the system;

c) Perform backups and have contingency plans before making changes.

5. When developing application source code, check and eliminate security vulnerabilities in the application, including:

a) SQL injection, OS injection, and other storage medium injection vulnerabilities;

b) Buffer overflow errors;

c) Insecure data storage encryption errors;

d) Insecure communication errors;

đ) Information leakage through error handling;

e) Risks of code, JavaScript, JScript, DHTML, and HTML tag injections;

g) Incorrect access controls;

h) Cross-Site Request Forgery attacks where a user's authentication on a website is hijacked via a fake website;

i) Errors in session ID management;

k) High-level security vulnerabilities as specified in Clause 1 of this Article.

6. Applications providing services on external network environments (internet, wireless networks, mobile communication networks, and others) must implement measures to address threats and security vulnerabilities, including:

a) Conducting minimum quarterly or post-change security assessments using automatic or manual evaluation tools;

b) Implementing automated detection and prevention of attacks using web application firewalls (WAF).

7. Card payment system software must include features to filter out and reject unauthorized transactions as prescribed by law.

Article 6. Requirements for Issuing Access and Controlling Accounts to the Card Payment System

1. Access to the card payment application must be authenticated using at least one of the following methods: secret key code, device, authentication card, and biometrics.

2. Remote access to the network system must be authenticated using a minimum of two methods specified in Clause 1 of this Article.

3. Encrypt all secret key codes during transmission and storage using strong encryption methods.

4. Implement measures to control operational accounts and administrative accounts:

a) Issue separate access accounts and grant corresponding permissions to each individual responsible for operating and managing devices serving card payments;

b) Control the addition, deletion, and modification of user account identifiers and information in accordance with management objectives;

c) Revoke access rights immediately when a user's usage period expires, changes jobs, or no longer performs operational or administrative tasks;

d) Verify and confirm the identity of the user indirectly through email or telephone before changing or recovering the secret key code of the account;

đ) The initial issued account must set up a secret key code, and that secret key code must differ from other accounts. The account can only operate if the user changes the initial secret key code;

e) Specify and implement procedures for revoking, removing, or invalidating unused, expired, or inactive accounts within a certain period;

g) Remote access accounts issued to organizations supporting card operations must be time-limited, approved by authorized personnel, and monitored;

h) Sharing or jointly using an account to access the system is prohibited;

i) Accounts must change the secret key code at least once every quarter; the secret key code must have a minimum length of seven characters, including both letters and numbers (excluding PINs); the secret key code cannot be reused within the last four changes;

k) The maximum number of incorrect secret key code entries allowed does not exceed three times. There must be automatic account lockout measures when the number of incorrect secret key code entries exceeds the specified limit. The recovery time for a locked account after incorrect entries must be at least thirty minutes or as required;

l) A session working with the card payment system that remains idle for more than fifteen minutes must require re-authentication to access the system;

m) Disseminate and train on policies and procedures for accessing and authenticating accounts in the system, ensuring that relevant organizations and individuals understand their rights and responsibilities upon being granted access accounts;

5. Enact policies and procedures for account access authentication, which must include the following contents:

a) Guidelines for selecting and protecting authentication information and secret key codes;

b) Guidelines for not reusing previously used secret key codes;

c) Guidelines for periodically changing secret key codes or immediately when there is suspicion of a secret key code leak;

6. Database Access Management for Card Payments

a) Only database administrators may directly access the database;

b) Other users accessing the database must do so through controlled application programs that manage viewing, entering, deleting, and modifying information;

c) Application program database access accounts should not be used for personal or other processes;

d) The secret key code of the application database access account must be encrypted within the application and in the database;

đ) All actions on the database must be logged, and logs must be retained for a minimum of one year;

Chapter III
TECHNICAL REQUIREMENTS FOR ATM

Article 7. Technical installation requirements and physical safety for ATMs

1. Installation requirements for ATMs

a) Organizations providing card services that offer ATM services (hereinafter referred to as organizations providing ATM services) must ensure the installation requirements for ATMs according to the regulations of the State Bank of Vietnam on equipping, managing, operating, and ensuring the safe operation of ATMs;

b) For ATMs placed outside

In addition to the requirements set forth in Point a Clause 1 of this Article, organizations providing ATM services must implement additional measures to ensure the safety of ATMs placed outside against the following physical security risks:

- Measures to prevent ATMs from being dragged away illegally;

- Concealing unnecessary components and parts of ATMs from being exposed outside.

2. Alarm system requirements

a) Organizations providing ATM services must equip sensors for ATMs placed outside to warn of thermal impacts from soldering equipment and detect significant or continuous external forces applied to the machine's body;

b) Organizations providing ATM services must equip alarm devices for ATMs to prevent:

- Unauthorized opening of the machine;

- Illegal removal from the installation area;

- Unauthorized destruction of the machine. These alarm devices must not only issue local alarm signals but also send warnings to the monitoring center.

3. Requirements for cash compartments

a) Organizations providing ATM services must equip cash compartments made of materials resistant to large impacts, corrosion, rapid heat dissipation, or slow heat absorption to minimize damage to the compartment shell and internal losses due to external force, chemical, and heat impacts;

b) The cash compartment of ATMs must be equipped with at least two locks, held by two different individuals.

4. The keypad for entering the PIN must meet the requirements specified in Article 13 of this Circular.

5. ATMs must have a certificate of origin and a quality certification from the manufacturer.

Article 8. Technical requirements for software, network connections, and interconnection systems for ATMs

1. Organizations providing ATM services must ensure the software requirements for ATMs

a) The ATM operating system must have a valid license, supported by the provider, and be promptly updated with patches;

b) The installed or configured operating system must ensure separation of different rights: access to external storage devices; permission to change configurations and run applications and services;

c) Transaction software on ATMs must be set up with features to notify users through images or sounds about safety measures before entering the PIN or to inform users about retrieving their card and money after completing transactions;

d) Control device software and transaction software must be set up with features to prevent card information disclosure, financial loss due to errors, fraud, or technical failures, including:

- When the control device payout software or electronic transaction log software does not function, the ATM must automatically stop cash withdrawal functions and report the error to the center;

- Transaction software on ATMs must enforce users to re-enter the PIN for subsequent cash withdrawals; provide reminders about safety measures before entering the PIN and retrieving the card after completing transactions.

2. Network connection requirements for ATMs

Organizations providing ATM services must establish network connections that block Internet access except for connections to the center for transaction processing. Operating system patch updates, antivirus software updates, and other updates at ATMs must be performed locally or through an internal centralized system.

3. Interconnection system requirements for card payment systems

Contracts and agreements for interconnecting card payment systems through ATMs must specify encrypted data and the responsibilities of each party in ensuring the confidentiality of encryption keys. Encryption keys must be changed at least once a year.

Article 9. Requirements for monitoring and system security of ATMs

1. Organizations providing ATM services must equip centralized management software to monitor in real-time the status of ATMs.

2. Organizations providing ATM services shall take technical and administrative measures to strictly manage the ATM system, promptly detect unauthorized access, and prevent the illegal installation of card information copying devices or recording user operations.

a) Have a transaction monitoring system on the card payment network, continuously tracking to identify suspicious card payment transactions, fraud based on time, geographic location, frequency of transactions, transaction amount, exceeding the number of incorrect PIN entries allowed, and other unusual signs to handle and warn cardholders in a timely manner.

b) Camera images recorded must be clear enough to serve the requirements for dispute resolution and complaints.

3. Data logs on ATMs must be accessible for a minimum period of three months and stored for at least one year.

4. Organizations providing ATM services must ensure other requirements for safe ATM operation according to the regulations of the State Bank of Vietnam regarding equipment, management, operation, and ensuring the safety of ATMs.

Chapter IV
TECHNICAL REQUIREMENTS FOR POS DEVICES

Article 10. Requirements for POS devices

1. The Issuing Bank, Acquiring Bank, and Merchant Service Provider must clearly agree on the responsibilities of the Merchant Service Provider, including:

a) Managing, protecting, and installing POS devices in secure locations. Measures to prevent the illegal use, theft of POS devices, and the installation of card data skimming devices on POS devices.

b) Installing power supply and communication lines in accordance with the technical requirements of the manufacturer.

c) POS devices must have the name and logo of the Issuing Bank.

2. POS devices must have a certificate of origin and a quality certification from the manufacturer.

3. All POS devices must display the contact phone number of the Issuing Bank and the service support organization (if applicable).

4. The keypad for entering the PIN must meet the requirements specified in Article 13 of this Circular.

5. The Issuing Bank and Payment Gateway Provider must have a system to monitor and alert abnormal transactions (number, value, time, location of transactions).

Article 11. Requirements for mobile POS devices

1. The Issuing Bank, Acquiring Bank, and Merchant Service Provider must clearly agree on technical standards and the responsibility for supervising the operation of mobile POS devices, meeting at least the following requirements:

a) Requirements for mobile devices installed with mPOS software

- Devices must not be jailbroken or rooted, and unnecessary connections must be disabled for payment purposes.

- Additional security features to prevent loss and theft (GPS tracking, disk encryption) must be set up. At the same time, the Merchant Service Provider must manage information about device serial numbers and software versions.

b) Requirements for mPOS software

- mPOS software must be installed according to the instructions provided by the solution provider or the Issuing Bank.

- mPOS software must not allow payments when the mobile POS device cannot connect to the card payment center and must not store card transactions.

- The mPOS screen must display the readiness status for service so that users can see it.

- Payment invoices must be sent to customers via email, SMS, or printed (upon request), where the card number must be concealed (only displaying up to six initial digits and four final digits).

2. The Issuing Bank must publish a list of registered Merchant Service Providers using mobile POS devices for acceptance of payments on its website or other media (if applicable).

Chapter V
PROTECTION OF CARD DATA

Article 12. Information security policy for card safety

1. Card operating organizations must establish and update a list of equipment serving card payments and describe functions related to the card payment system.

2. Card operating organizations must establish, publish, maintain, and disseminate information security policies throughout the organization. Evaluate the information security policy at least once a year and update the policy when payment service equipment changes.

3. Card operating organizations must implement risk assessment procedures at least once a year and immediately after changes to network diagrams, security, addition of server systems, or modification of business operations.

4. Card operating organizations must develop and implement regulations on the use of high-risk technologies (remote access, wireless networks, mobile devices, email, and Internet). The content of the regulations includes the following requirements:

a) Must be approved by authorized personnel before use;

b) Must be authenticated by account and secret key or other authentication methods before use;

c) List and monitor all activities of devices, technologies, and users with permission to use;

d) Have a method to easily and conveniently identify the owner, contact information, and purpose of use of the device (by labeling, using barcodes, or inventorying devices);

đ) Determine the scope of application of high-risk technologies;

e) Identify the positions in the network system using high-risk technologies;

g) For remote access, automatically disconnect the session after a specific period of inactivity;

h) Activate remote access only for card operation support organizations when necessary and simultaneously disable access immediately after the session ends;

i) When granting remote access to primary card data, technical measures must be taken to prohibit copying, moving, and storing primary card data on hard drives, portable media, and peripheral devices. In special cases where remote access is required for copying, moving, and storing primary card data, clearly define the responsibility for protecting primary card data according to the provisions of this Circular.

5. Card operating organizations must clearly define the responsibility for protecting the security of card data for individuals and organizations within their unit and related parties.

6. Assignment of tasks in managing card information security

a) Monitor and analyze information and security risk warnings and transfer such information to responsible departments for coordinated resolution;

b) Take timely measures to control all situations;

c) Manage user accounts on the system;

d) Supervise and control all access to data;

đ) The assignment must be documented in writing.

7. Card operating organizations must provide training on card security awareness for new employees and conduct such training at least once a year for all employees; they must ensure that employees within the unit are aware of card security policies.

8. Card operating organizations must establish and maintain procedures and policies for managing card operation support organizations sharing data or affecting the security of card data. Procedures and management policies must meet the following minimum requirements:

a) Update the list of card operation support organizations;

b) Card operating organizations must select card operation support organizations before signing contracts or agreements. The selection process must clearly reflect the requirements of the organization for card operation support organizations, and the supporting organization's documentation must comply with card information security requirements;

c) Contracts with card operation support organizations must clearly specify the responsibilities of the support organizations to comply with relevant regulations in this Circular. Written commitments must include terms and responsibilities where the support organization provides services responsibly ensuring card information security in the services provided or stored, processed, or exchanged. Commitments must specify the scope of services provided by the support organization;

d) Card operating organizations must manage and update information about card operation support organizations in accordance with the requirements of this Circular.

9. Card operating organizations must develop and implement emergency response procedures to ensure immediate handling of incidents. Emergency response procedures must meet the following minimum requirements:

a) Roles, responsibilities, communication, and contact of individuals and organizations in case of system breaches;

b) Specific scenarios for responding to emergencies;

c) Recovery and continuous operation scenarios;

d) Data backup scenarios;

đ) Test procedures at least once a year;

e) Assign specific personnel to be ready to respond to emergencies 24/7;

g) Conduct training programs for employees to respond to card security emergencies;

h) Emergency response procedures include system monitoring alerts (intrusion detection systems, firewalls, and file integrity monitoring systems);

i) Improve and refine emergency response procedures through lessons learned and technological advancements.

Article 13. Requirements for the PIN Entry Keyboard

1. The keyboard used to enter the PIN must be capable of self-destructing sensitive information stored therein, including encryption keys, PINs, secret codes, and such information cannot be recovered once physically compromised.

2. The sound produced when pressing a key must not be distinguishable from the sound produced when pressing another key. Additionally, it should not be possible to determine any PIN character entered through electromagnetic or power consumption monitoring.

3. The PIN must be immediately encrypted upon completion of entry (when the user presses Enter). The buffer must be automatically cleared after the transaction ends or after the waiting period expires.

4. The security features of the keyboard shall not be altered by environmental conditions or operational conditions.

Article 14. Protection of Data Storage Areas on Cards

1. Storing, recovering, deleting card data and information

a) Implement policies, procedures, and processes for storing and deleting primary account holder data; limit the amount of data and storage time required to meet business needs and legal requirements for data retention; quarterly identify and securely delete primary account holder data that exceeds the required storage time; comply with regulations regarding the storage of primary account holder data, including retention periods for records and documents in the banking industry;

b) Card authentication data must ensure confidentiality during printing and issuing cards; individuals or organizations handling card authentication data must commit to not disclosing information; card authentication data must not be stored after authentication, including encrypted information at transaction arrival, log files, history files, tracking files, data schema tables, and database contents;

c) The card number must be concealed when displayed and only fully shown upon request from authorized agencies or legitimate cardholders; the card number must ensure unreadability at storage locations;

d) Ensure card numbers are unreadable at storage locations using one of the following methods:

- Using a one-way hash function based on strong encryption algorithms;

- Splitting and truncating data so that the full data cannot be read when stored in files, databases, or log files;

- Using a one-time pad system where the receiving device must remain confidential;

- Strong encryption with key management procedures and processes that must be followed;

- Using disk encryption where file-level encryption is implemented independently and separately from access control and authentication mechanisms on the existing operating system.

2. Encryption of data in the card data storage area

a) Keys used for encryption must be stored and secured to prevent information leakage:

- Limit the number of people who have access to the encryption key;

- Store private keys used for encrypting and decrypting primary account holder data at all times using one of the following methods:

+ Storing in dedicated devices or PIN security devices during transactions;

+ Keeping the key divided into at least two separate parts;

+ Encrypting the key using an algorithm that is equally strong or stronger than the algorithm used to encrypt the data. The key for encrypting the key must be stored separately from the key for encrypting the data;

b) Establish procedures for managing keys and encryption processes to encrypt primary account holder data, including:

- Key generation process;

- Key distribution;

- Key storage;

- Periodic replacement of keys at the end of their lifecycle;

- Replacement or revocation of keys if there is suspicion of leakage or modification.

c) Key management must meet the following minimum requirements:

- If clear text encryption keys are used, they must be divided among at least two people, each holding a part of the encryption key;

- Prevent unauthorized replacement of encryption keys;

- Clearly define the responsibilities of those holding encryption keys.

Article 15. Data Encryption for Card Information on External Network Transmission

1. Employ appropriate encryption methods and security protocols (at least SSL/TLS, SSH, IPSEC protocols) to protect card authentication data during information transmission over networks connected to external sources (internet, wireless networks, mobile communication networks, and other networks).

2. When sending card numbers to users via electronic messages, the numbers must be encrypted using strong encryption methods.

Article 16. Limiting Access Rights to Card Data

1. Accesses and processing of card data must ensure proper authorization at the minimum level necessary for each individual's tasks.

2. Develop policies to limit remote access rights from external networks into the system. Monitor activities and log access times to the system.

3. Granting access rights to card payment systems must be approved in writing by authorized persons.

4. Establish measures and access control systems for all devices serving card payments, ensuring limited access according to assigned responsibilities; unauthorized accesses must be eliminated.

Article 17. Limiting Physical Access to Card Data

1. Implement controls for entry and exit to areas housing card payment systems, card data centers, and physical environments containing card data:

a) Set up controls for wired and wireless network connection points in public areas to limit access. Control physical access to mobile devices, communication devices, network devices, and telephone lines.

b) Use cameras or other means to monitor physical access to server room areas, card issuance printing areas, data storage and processing areas. Surveillance data must be stored for a minimum of three months.

2. Develop procedures to identify employees and external individuals (support organizations, customers) working in these areas including:

a) Procedures to identify new employees and external individuals;

b) Procedures to change access requirements and revoke access rights of employees when they leave, and external individuals when their period ends.

3. Control physical access for employees entering server rooms, card issuance printing areas, and data storage and processing areas as follows:

a) Access must be granted based on each individual's job requirements;

b) Access rights must be revoked immediately upon completion of work, and all access tools (keys, access cards) must be collected or rendered ineffective.

4. Implement procedures to identify and authorize external individuals when entering and exiting data storage and processing areas:

a) External individuals must be permitted before entering and monitored continuously in data storage and processing areas;

b) External individuals must be identified by cards or other methods with expiration dates that can be visually recognized;

c) External individuals must be required to return cards or identification methods before leaving the unit or when their validity period expires;

d) Logs of external individuals' entries and exits must be kept in written or electronic form for a minimum of one year.

5. Backup data storage media for card payment systems must be stored in secure locations. The storage location must be inspected to ensure safety conditions at least once a year.

6. Ensure the safety of physical assets, important information, and records related to card operations, and data-carrying media. Control the transportation of data-carrying media to ensure card data security. Approval by authorized persons is required before transferring, moving, or distributing data-carrying media.

7. Strictly control the storage and access to data-carrying media. Conduct asset inventory and data-carrying media audits at least once a year.

8. Card data reading devices must be monitored and protected to meet the following requirements:

a) Regularly update lists of devices, manufacturer information, device models, device locations, and device codes (serial numbers, product numbers);

b) Periodically inspect device surfaces to detect counterfeits or added components by checking identifying features or device serial numbers;

c) Device managers and users must be trained to recognize counterfeit risks or replacements aimed at stealing card information. Training content includes:

- Verify the identity of support organizations before allowing them to participate in device repair, maintenance, or troubleshooting processes;

- Inspect and verify devices before allowing installation, replacement, or return of devices;

- Recognize potential risks and suspicious behaviors around devices;

- Report counterfeit risks or unauthorized device replacements to authorized persons.

9. Destroy records and documents containing card data by cutting into small pieces, burning, or crushing to ensure card data cannot be read or reconstructed. Electronic data-carrying media containing card information must be destroyed using specialized data deletion programs or physical destruction and degaussing methods to ensure card data cannot be read or recovered.

Article 18. Supervision, protection, and inspection of equipment serving card payments

1. Monitoring and supervising all access to cardholder resource data and information

a) Implement logging of all access to equipment serving card payments to record all user actions;

b) Automatically log access to all equipment serving card payments to re-establish the following events:

c) The log data for each event (as stipulated in Point b Clause 1 of this Article) shall include at least the following information:

d) There must be a time synchronization system for the server system and the ATM system serving card payments;

đ) Protecting log data:

e) Organizations conducting card activities must use tools to monitor the integrity of log file data or software to detect changes in log data;

g) Organizations conducting card activities must review and evaluate log data and security events on all equipment serving card payments to identify abnormal activities and suspicious activities using log-based analysis, exploitation, and alerting tools, specifically as follows:

h) Log data must be stored online for a minimum of three months to be readily accessible and backed up for a minimum of one year.

- All user access to cardholder data;

- All actions of users with privileged accounts;

- Access to all log data;

- Unauthorized attempts to access the system;

- User management (including new account creation and administrative privilege elevation, changes or deletion of administrative accounts);

- Initialization, termination, or suspension of log data recording;

- Initialization or deletion of data, resources, functions, services on equipment serving card payments.

- User identification;

- Event type;

- Date, month, and time;

- Success or failure status;

- Source of the event;

- Name or identifier of the data, resource, or function, service affected by the event.

- Limit viewing of log data to the minimum necessary for job requirements;

- Protect log files from unauthorized modification;

- Back up log data to centralized servers or portable media;

- Organizations conducting card activities must daily review at least the following log data contents:

+ All security-related events;

+ Log data of systems storing, processing, transmitting card information;

+ Log data of security devices for the system (firewalls, intrusion detection systems, intrusion prevention systems, authentication servers);

- Organizations conducting card activities must annually review all log data according to their security policies and risk management regulations. Review log data at least once a year;

- During the log data review process, monitor and handle exceptional and unusual events that have been identified;

2. Security inspections of card payment systems

a) Organizations conducting card activities must control wireless network access points. Maintain a list of permitted wireless access points (if any), clearly explaining their purpose and approved by authorized personnel. Quarterly review wireless network access points connected to the internal network of the organization;

b) Organizations conducting card activities must scan and assess system vulnerabilities from both inside and outside the organizational network at least once every quarter and immediately after any significant changes in the system (including adding new equipment, changing network models, firewall access policy changes, operating system and application upgrades). Immediately address high-level security vulnerabilities identified according to Clause 1 of Article 5 of this Circular;

c) Organizations conducting card activities must organize penetration testing simulations according to the following requirements:

- Test all systems storing and processing cardholder data;

- Conduct penetration tests from both inside and outside the system at least once a year and immediately after any significant system changes or after discovering vulnerabilities through scanning;

- Conduct penetration tests based on guidelines from reputable organizations regarding penetration testing and security;

- Exploit vulnerabilities listed in Clause 5 of Article 5 of this Circular during penetration testing;

- Conduct penetration testing at both the network level and the application level;

- Evaluate and consider threats and vulnerabilities that occurred in the past twelve months;

- Securely store penetration test results and remediation actions;

- Vulnerabilities discovered during penetration testing that can be exploited must be addressed and rechecked to ensure they are resolved;

d) Organizations conducting card activities must use intrusion detection and prevention systems to detect and prevent unauthorized intrusions into the network, monitor all accesses to the cardholder data environment, and alert administrators to potential breaches. Intrusion prevention devices must be updated with new malware signatures from vendors;

đ) Organizations conducting card activities must verify the integrity of critical data (system files, configuration files, content files) at least monthly.

Article 19. Requirements for Ensuring Continuous Operation

1. Organizations conducting card operations shall establish procedures for handling incidents and managing risks related to card payment systems, and regularly review and update these procedures at least once a year.

2. Information technology systems serving card payment activities must ensure on-site backup and disaster recovery capabilities. The disaster recovery system must replace the main system within no more than four hours from the time the main system fails.

3. At least twice a year, the card payment system must be switched from the main system to the backup system to ensure the consistency and readiness of the backup system.

Chapter VI
IMPLEMENTING PROVISIONS

Article 20. Reporting System

Card operation organizations are responsible for submitting reports to the State Bank of Vietnam (Information Technology Department) as follows:

1. Annual periodic reports on the implementation of the provisions of this Circular:

a) Deadline for submission of the report: before November 15 each year;

b) Form and template of the report according to the guidance of the State Bank of Vietnam (Information Technology Department).

2. Ad hoc reports when incidents affecting the security of the card payment system occur:

a) Deadline for submission of the report: within ten days from the date of discovery of the incident;

b) Content of the report includes: date and location where the incident occurred; cause of the incident; risk assessment and impact on the card payment system and business operations at the location of the incident and other related locations;

c) Measures taken by the organization to prevent, address, and mitigate risks; recommendations and proposals.

Article 21. Effective Date

This Circular takes effect from April 1, 2015.

Article 22. Transitional provisions

Card operation organizations with card processing equipment installed before the effective date of this Circular must review and develop remediation plans, specifying non-compliance requirements, measures, and deadlines for compliance with all requirements set out in this Circular, and submit them to the State Bank of Vietnam (Information Technology Department) before July 1, 2015.

The State Bank of Vietnam (Information Technology Department) will examine the remediation plans, require card operation organizations to amend and supplement remediation plans including deadlines for implementation (if deemed insufficient or unfeasible), and supervise the implementation of remediation plans by card operation organizations.

Card operation organizations are responsible for implementing remediation plans, amending and supplementing them, and implementing remediation plans in accordance with the opinions of the State Bank of Vietnam (if any).

Article 23. Responsibility for implementation organization

1. The Information Technology Department is responsible for monitoring and inspecting the implementation of this Circular and sending inspection results to relevant units for handling.

2. Banking supervisory agencies are responsible for inspecting and supervising organizations and individuals involved in the implementation of this Circular and handling violations in accordance with the law.

3. Branches of the State Bank of Vietnam in provinces and centrally-administered cities are responsible for inspecting, supervising, and handling violations within their jurisdiction regarding ATM and POS activities in accordance with the provisions of this Circular and reporting inspection results to the State Bank of Vietnam (through the Information Technology Department).

4. Heads of relevant units under the State Bank of Vietnam; Directors of branches of the State Bank of Vietnam in provinces and centrally-administered cities; Chairmen of the Board of Management, General Managers (Directors) of card operation organizations are responsible for organizing the implementation of this Circular./.

 Place of Receipt:
- As Clause 4, Article 23;
- SBV Leadership;
- Government Office;
- Ministry of Justice (for verification);
- Official Gazette;
- To be filed: Office, ITD, PC.

DIRECTOR
DEPUTY DIRECTOR


Nguyen Toan Thang

Original document (PDF)

Open PDF in a new tab ↗

Relations map

↑ Basis & documents that affect this document
47/2014/TT-NHNN
Circular No. 47/2014/TT-NHNN stipulates technical requirements for security and safety concerning equipment serving bank card payments
In effect

Click a document to open. A red border = a relation that changes validity.