Circular No. 23/2024/TT-NHNN on safety and security for the provision of online banking services (Online Banking) in Vietnam. This Circular takes effect from January 1, 2025, and replaces previous Circulars related to this issue. The main contents include requirements for customer security, risk management regulations, data access control, responsibilities of service providers, and reporting systems.
适用范围
Credit institutions, foreign bank branches, and payment intermediary service organizations in Vietnam
要点
- Requirements for customer security when using Online Banking services.
- Regulations on risk management and data access control by service providers.
- Reporting obligations of service providers to the State Bank of Vietnam.
- Inspection and supervision mechanisms for the implementation of this Circular.
- Effective date from January 1, 2025, with transitional provisions for certain specific clauses.
🌐 本文件的社会影响
- Enhance customer security when using online banking services.
- Minimize cybersecurity risks in the provision of online banking services.
❓ 常见问题
When does this Circular take effect?
Circular No. 23/2024/TT-NHNN takes effect from January 1, 2025, except for certain specific clauses that become effective after this date.
Which entities must comply with this Circular?
Credit institutions, foreign bank branches, and payment intermediary service organizations in Vietnam must comply with Circular No. 23/2024/TT-NHNN.
Are there any transitional provisions for agreements signed before the effective date of this Circular?
Agreements on automatic account debits, e-wallets, and card payments made before the effective date of this Circular will continue to be implemented until the end of their term or until December 31, 2026, if the agreement does not specify a term.
全文
CIRCULAR
activities of calibration, verification, testing security and confidentiality for providing online services in the banking industry
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
||| Pursuant to the Cybersecurity Law dated November 19, 2015;
||| Pursuant to the Cyber Security Law dated June 12, 2018;
Pursuant to the Law on Electronic Transactions dated June 22, 2023;
Pursuant to the Law on Credit Institutions dated January 18, 2024;
Pursuant to Decree No. 102/2022/NĐ-CP dated December 12, 2022 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Information Technology;
The Governor of the State Bank of Vietnam issues this Circular to regulate security and confidentiality for providing online services in the banking industry.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation and Applicability
Thông tư này quy định chi tiết khoản 4 Điều 38 Luật Thủy sản số 18/2017/QH14 đã được sửa đổi, bổ sung tại điểm c khoản 21 Điều 14 Luật số 146/2025/QH15.
This Circular sets forth requirements to ensure security and confidentiality for providing online services in the banking industry, including:
a) Banking activities and other business operations of credit institutions and foreign bank branches;
b) Payment intermediary service provision activities;
c) Credit information activities.
Thông tư này áp dụng đối với tổ chức, cá nhân có liên quan đến hoạt động kinh doanh đối tượng thủy sản nuôi chủ lực trên lãnh thổ Việt Nam.
This Circular applies to credit institutions, foreign bank branches, payment intermediary service providers, and credit information companies (hereinafter referred to collectively as entities).
Article 2. Definitions and Terms
In this Circular, the following terms are understood as follows:
1. Online Banking Service (referred to as Online Banking) is the service defined in Clause 1 of Article 1 of this Circular provided by entities to customers on a network environment to perform electronic transactions (referred to as transactions), excluding direct transactions at acceptance points that accept card payments through point-of-sale terminals and Quick Response Codes (QR Codes) displayed by customers.
2. Online Banking System is a structured set of hardware, software, databases, communication networks, and security systems designed to produce, transmit, collect, process, store, and exchange digital information for managing and providing Online Banking services, established, managed, and operated by entities or third parties.
3. Online Banking Application Software is application software providing Online Banking services.
4. Mobile Banking Application Software is Online Banking application software installed on mobile devices.
5. Online Payment Transaction is a payment transaction conducted electronically through the Online Banking system.
6. Customer is an organization or individual using Online Banking services.
7. Straight-Through Processing Method is a two-way automatic information and data exchange method through secure connections between customer information systems and the Online Banking system.
8. Electronic Transaction Confirmation (hereinafter referred to as transaction confirmation) is an electronic form of confirmation indicating the customer's approval of data messages in electronic transactions.
9. End-to-End Encryption is a secure information encryption mechanism at the sending point before transmission and only decrypted upon receipt at the receiving point during information exchanges between applications and devices within the system to minimize the risk of information leakage during transmission.
10. Database Management System is software designed to manage, store, retrieve, and execute database queries.
Article 3. General Principles for Ensuring Safety and Security of Information Systems for Providing Online Banking Services
1. The Online Banking system must comply with regulations on ensuring safety of information systems at level 3 or higher as stipulated by laws on ensuring safety of information systems according to levels, for information systems providing financial switching services and electronic settlement services, compliance with regulations on ensuring safety of information systems at level 4 or higher is required; compliance with standard TCVN 11930:2017 (Information Technology - Security Techniques - Basic Requirements for Ensuring Safety of Information Systems According to Levels) and regulations of the State Bank of Vietnam on ensuring safety of information systems in banking operations.
2. Ensure the confidentiality and integrity of customer information; ensure the availability of the Online Banking system to provide services continuously.
3. Customer transactions shall be classified and assessed with a minimum risk level based on: customer groups, customer usage behavior, transaction types, transaction limits (if applicable), and compliance with relevant laws. Based on this, the service provider shall offer appropriate transaction confirmation methods for customers to choose from, complying with the following minimum requirements:
a) Apply at least one of the transaction confirmation methods specified in Clause 3, Clause 4, Clause 5, Clause 7, Clause 8, and Clause 9 of Article 11 of this Circular when changing customer identification information.
b) Apply at least one or combine transaction confirmation methods as prescribed in this Circular; In cases where regulatory documents guiding the services specified in Clause 1 of Article 1 of this Circular specify transaction confirmation methods, such regulatory documents shall be followed.
c) For multi-step transactions, transaction confirmation must be carried out at the final approval step.
4. Conduct regular annual inspections and evaluations of the safety and security of the Online Banking system.
5. Continuously identify risks and threats causing risks, determine the causes of risks, and promptly take preventive, control, and handling measures for risks in providing Online Banking services.
6. Information technology infrastructure equipment providing Online Banking services must have clear copyright, origin, and place of manufacture. For equipment nearing the end of its product life cycle and no longer supported by the manufacturer, the unit must develop plans for upgrades and replacements based on the manufacturer's notifications, ensuring that the infrastructure equipment can install new software versions. During the upgrade and replacement period, the unit must implement enhanced measures to ensure the safety and security of the Online Banking system.
7. For systems providing electronic payment gateway services, collection and disbursement support services, compliance with the provisions of Clause 7, Clause 9, and Clause 10 of Article 7 and Section 2 of Chapter II of this Circular is not required.
8. The Online Banking system may only operate to provide services to customers if it ensures safety and security in accordance with this Circular and relevant laws.
Chapter II
SPECIFIC PROVISIONS
Section 1
INFRASTRUCTURE OF THE ONLINE BANKING SYSTEM
Article 4. Network systems, communication, and security
The unit must establish network systems, communication, and security meeting the following minimum requirements:
1. Minimum security and protection solutions include:
a) Application firewall or equivalent protection solution;
b) Database firewall or equivalent protection solution;
c) Solutions to prevent and combat denial of service (DoS - Denial of Service attack) and distributed denial of service (DDoS - Distributed Denial of Service attack) attacks on systems providing direct services on the Internet;
d) Information security event management and analysis system.
2. Customer information (customer identification information, customer transaction information) shall not be stored in the Internet-connected partition and the intermediate partition between the internal network and the Internet (DMZ partition).
3. Establish policies to limit online banking system services and connection ports to the maximum extent possible.
4. External connections to the online banking system for management purposes from outside the internal network can only be carried out in cases where it is impossible to connect from the internal network and ensure security, complying with the following provisions:
a) Must be approved by the competent authority after considering the purpose and method of connection;
b) Must have a secure remote access and management system plan such as using a virtual private network or an equivalent solution;
c) Connection devices must be installed with software ensuring security and protection;
d) Must apply at least two of the authentication methods specified in Clauses 1, 3, 4, 7, 8, and 9 of Article 11 of this Circular when logging into the system;
e) Use secure communication protocols and do not store secret keys in utility software.
5. The network connection channels for service provision must ensure high availability and continuous service provision capability.
Article 5. Server Systems and System Software
1. Requirements for servers:
a) Resource utilization performance of the server including central processing unit (CPU), random access memory (RAM), data storage devices, data retrieval devices when storing or transmitting, average monthly maximum 80% of design capacity;
b) The online banking system must have backup servers to ensure high availability;
c) Logically or physically separate from other operational servers;
d) Must undergo regular security and protection hardening checks for the operating system and frequent updates of patches.
2. The unit must create a list of permitted software to be installed on servers. Regularly update and check at least once every six months to ensure compliance with this list.
Article 6. Database Management System
1. The database management system must have mechanisms to protect and control access rights to database resources.
2. The online banking system must have disaster recovery databases capable of replacing the main database and ensuring complete and intact customer transaction data.
3. The database management system must undergo regular security and protection hardening checks and frequent updates of patches.
4. The unit must implement monitoring and logging of database access and operations during access.
Article 7. Online Banking Application Software
1. Requirements for safety and security must be determined before developing the software and organized, implemented during the development process (analysis, design, construction, testing), official operation, and maintenance of the software. Documents and materials related to safety and security of the software must be systematized, stored, and updated synchronously when there are changes in the system and strictly controlled with restricted access.
2. The entity must control the source code of the software with the following minimum requirements:
a) For source code developed by the entity itself:
(i) Periodically or upon changes in the application software, the entity must inspect the source code to eliminate harmful code segments and security vulnerabilities. Personnel conducting inspections must be independent from those who develop the source code;
(ii) Specifically designate individuals responsible for managing the source code of the Online Banking application software;
(iii) The source code must be securely stored at least two geographically separate locations and measures to protect the integrity of the source code must be in place.
b) In the case of outsourced software source code:
(i) The entity must require the provider to sign a commitment that the source code of the software is legal and not counterfeit; commit to implementing agreements regarding source code modifications during warranty and maintenance periods;
(ii) If the source code is handed over, before final acceptance of the source code, the entity must require the provider to inspect, handle, and rectify security vulnerabilities in the source code. After the source code is handed over, the entity must comply with the provisions set out in point a of this clause;
(iii) If the source code is not handed over, when signing off on product acceptance, the entity must require the provider to scan and remove harmful code segments and sign a commitment that there are no harmful code segments in the application software.
3. The Online Banking application software must be tested and tried before official operation to meet the following minimum requirements:
a) Establish and approve plans and scenarios for testing the Online Banking application software, clearly stating the conditions for safety and security that must be met;
b) Detect and eliminate errors and potential fraud that may occur when entering input data;
c) Evaluate and scan to detect vulnerabilities and weaknesses from a technical perspective. Assess the ability to prevent and combat various types of attacks including but not limited to: Injection (SQL, XPath, LDAP), Cross-site Scripting (XSS), Cross-site Request Forgery (XSRF), Server-Side Request Forgery (SSRF), Brute-Force, and other security flaws such as: access control errors; identification and authentication errors; encryption errors; insecure design and configuration errors; logging and monitoring security errors;
d) Record errors and the error handling process, especially security and privacy errors in test reports;
đ) Security and privacy testing functions must be conducted on popular browsers (applicable to Online Banking application software provided through a web platform) and mobile device operating system software (applicable to Mobile Banking application software). There must be mechanisms to notify customers immediately when using applications on browsers and versions of mobile device operating systems that have been tested and verified for safety.
4. Before deploying new Online Banking application software, the entity must assess risks associated with the deployment process for business operations and related information technology systems, and establish and implement risk mitigation and resolution plans.
5. The entity must manage version changes of the Online Banking application software to meet the following requirements:
a) Develop documentation analyzing and evaluating the impact of changes on the current system and related systems of the entity, and obtain approval from authorized authorities before implementation;
b) Versions of the software, including source code developed by the entity or handed over by providers, must be centrally managed, stored, secured, and have permission mechanisms for each member, with logging of file operations;
c) Information about versions (update time, updater, update instructions, and other relevant information) must be stored;
d) Version upgrades must be based on test results and approved by authorized authorities.
6. Mandatory functions of the Online Banking application software:
a) All data transmitted over the network or exchanged between the Online Banking application software and related devices must apply end-to-end encryption mechanisms;
b) Ensure data transaction integrity, all unauthorized modifications must be detected, warned, prevented, or appropriate measures taken to ensure the accuracy of transaction data during execution and storage;
c) Transaction session control: the system has an automatic mechanism to terminate a session when the user does not operate within a period specified by the entity or applies other protective measures;
d) Have a function to hide the display of secret key codes, PINs used to log into the system;
đ) Have a function to prevent automatic login;
e) In cases where electronic transaction accounts defined in Clause 1, Article 9 of this Circular use PINs or secret keys as confirmation methods, the Online Banking application software must have functions to control PINs and secret keys:
(i) Require customers to change their PINs or secret keys if they were initially issued default PINs or secret keys;
(ii) Notify customers when their PINs or secret keys are approaching their expiration date;
(iii) Invalidate PINs or secret keys upon expiration and require customers to change expired PINs or secret keys when logging in;
(iv) Invalidate PINs or secret keys in cases of consecutive incorrect entries exceeding the number of attempts specified by the entity (but not more than ten times) and notify the customer;
(v) The unit shall only reissue the PIN code or secret key upon the customer's request and must verify the identity of the customer before issuing, ensuring prevention of fraud and forgery.
g) For organizational customers, the application software must be designed to ensure that online payment transactions include at least two steps: transaction creation and approval. In cases where individual business households or micro-enterprises with simplified accounting apply, it is not mandatory to separate these two steps for transaction execution.
h) It must have a function to notify the first login to the Online Banking application software or logging into the Online Banking application software on a device different from the last used device through SMS or other channels registered by the customer (such as telephone, email...), except in the case of organizational customers: logging in on registered devices; or logging in using at least one of the confirmation methods specified in Clause 3, Clause 4, Clause 5, Clause 7, Clause 8, and Clause 9 of Article 11 of this Circular.
7. The Online Banking application software must have a function to store online information about the devices used by customers for transactions, transaction logs, and transaction confirmation logs for a minimum period of three months and backup for a minimum period of one year, including:
a) Device identification information:
(i) For mobile devices: unique device identification information (for example: IMEI number or Serial number or WLAN MAC or Android ID or other unique identification information);
(ii) For computers: unique computer identification information (for example: MAC address or a combination of information related to the computer that can uniquely identify the computer).
b) Transaction log must include at a minimum: transaction code, customer code, transaction initiation time, transaction type, transaction value (if applicable);
c) Transaction confirmation log must include at a minimum: transaction confirmation method, transaction confirmation time. In cases where transaction confirmation is done through biometric information matching, the unit must store the customer's biometric information when conducting transactions for a minimum of the ten most recent transactions of that customer.
8. Requirements for end-to-end processing methods:
a) The unit shall only provide Online Banking services using end-to-end processing methods to organizational customers. The unit has the responsibility to select, evaluate, supervise, manage, and agree with the customer when providing Online Banking services using end-to-end processing methods;
b) The Online Banking application software must have a function to authenticate the connection with the customer organization's software to prevent fraud and forgery;
c) It is not mandatory to apply the provisions set out in Point c, Point d, Point e, Point g, and Point h of Clause 6 and Point a of Clause 7 of this Article.
9. Organizations issuing bank cards that provide online payment services using bank cards must have an Online Banking application software with the following minimum features:
a) Allow or prohibit online payments;
b) Set daily limits for online payments using bank cards;
c) Allow or prohibit overseas payments at point-of-sale terminals or automated teller machines;
d) Allow customers to choose whether they want to actively confirm or agree to allow the card issuing organization to confirm all or part of the online bank card transactions (online card transactions) when using the confirmation method specified in Clause 10 of Article 11 of this Circular.
10. The Online Banking application software must have a function to notify customers about generated transactions via SMS messages, emails, Mobile Banking applications, or other communication channels registered by the customer.
Article 8. Mobile Banking Application Software
The Mobile Banking application software provided by the entity must ensure compliance with the provisions set out in Article 7 of this Circular and the following requirements:
1. It must be registered and managed in the official app store of the operating system provider for mobile devices and clear installation instructions must be provided on the entity's website for customers to download and install the Mobile Banking application software. In cases where, due to objective reasons, the Mobile Banking application software cannot be registered and managed in the official app store of the operating system provider for mobile devices, the entity must have methods to guide, notify, and support the installation of the Mobile Banking application software to ensure safety and security for customers and report to the State Bank of Vietnam (Information Technology Department) before providing the service.
2. It must apply measures to protect against reverse engineering of the source code.
3. It must have measures to protect against interference with data exchange flows within the Mobile Banking application and between the Mobile Banking application and the server providing Online Banking services.
4. Implement solutions to prevent, combat, and detect unauthorized interventions into the Mobile Banking application installed on the customer's mobile device.
5. It shall not allow the function of remembering access secret key codes.
6. For individual customers, there must be a customer verification function when the customer accesses for the first time or when the customer accesses from a different device than the one last used to access the Mobile Banking application software. Customer verification must at least include:
a) Matching the correct SMS OTP or Voice OTP through the phone number registered by the customer or Soft OTP/Token OTP;
b) Matching the correct biometric information as prescribed in Clause 5, Article 11 of this Circular, in cases where relevant specialized laws governing the services provided on the Mobile Banking application software stipulate the collection and storage of customer biometric information.
Section 2
CONFIRMATION OF ELECTRONIC TRANSACTIONS THROUGH THE ONLINE BANKING SYSTEM
THROUGH THE ONLINE BANKING SYSTEM
Article 9. Accessing the Online Banking Application Software
1. Customers who register to use the Online Banking application software must be identified by the entity and provided with an electronic transaction account. An electronic transaction account includes a username and at least one of the confirmation methods prescribed in Clauses 1, 2, 3, 4, 5, 6, 7, 8, and 9 of Article 11 of this Circular.
2. Customers access the Online Banking application software using an electronic transaction account provided by the entity or access via single sign-on (SSO) through another system's electronic transaction account that has been integrated by the entity according to the customer's registration.
Article 10. Transaction Confirmation
1. For online payment transactions:
a) For payment transactions using a payment account or e-wallet or transferring money from a debit card, prepaid card, or credit card, the entity classifies transactions into groups of transaction types as prescribed in Appendix 01 issued together with this Circular and applies the confirmation methods prescribed in Appendix 02 issued together with this Circular, except for the provisions in points b, c, d, and đ of this clause;
b) For payment transactions carried out through continuous processing, the entity confirms the transaction at minimum by one of the confirmation methods prescribed in Clauses 7, 8, and 9 of Article 11 of this Circular;
c) For online card payment transactions (excluding money transfers), the entity classifies transactions into groups of transaction types as prescribed in Appendix 03 issued together with this Circular and applies the confirmation methods prescribed in Appendix 04 issued together with this Circular;
d) For transactions where the entity initiates a withdrawal from a payment account, withdraws from an e-wallet, or makes a payment from the customer's card based on an agreement with the customer, it is not necessary to apply the transaction confirmation methods prescribed in point a and point c of Clause 1 of this Article;
đ) For online payment transactions on the National Public Service Portal, paying into the state budget, it is not mandatory to apply the transaction confirmation methods prescribed in point a and point c of Clause 1 of this Article.
2. For automatic withdrawal transactions from a payment account, automatic withdrawal from an e-wallet, or automatic payments from the customer's card, the entity applies at least one of the confirmation methods prescribed in Clauses 3, 4, 5, 7, 8, and 9 of Article 11 of this Circular.
3. For other transactions, outside those specified in Clauses 1 and 2 of this Article, based on risk assessment and compliance with relevant laws, the entity selects appropriate confirmation methods as prescribed in Article 11 of this Circular to provide for customers who register to use them and is responsible for this selection.
4. In cases where the customer is a person with disabilities, the entity bases its provision and guidance for persons with disabilities to choose suitable confirmation methods on its own conditions and capabilities, without being required to apply the provisions of Clauses 1, 2, and 3 of this Article, but must ensure that customer approval is verified and confirmed in accordance with the laws on electronic transactions and this Circular when conducting transactions.
Article 11. Forms of Confirmation
1. Confirmation by password (Password): customers use a string of characters as a password to confirm their access rights to information systems, applications, services, or to confirm that they are performing transactions. The confirmation form using a password must meet the following requirements:
a) The password must be at least 08 characters long and include at least the following types of characters: numbers, uppercase letters, lowercase letters;
b) The validity period of the password shall not exceed 12 months, for the default password issued for the first time: the maximum validity period is 30 days.
2. Confirmation by PIN code (Personal Identification Number) is a confirmation form using a password where the password is created from a series of digits. The confirmation form using a PIN code (except for the case where the PIN code is attached to a physical card) must meet the following requirements:
a) The PIN code must be at least 06 characters long;
b) The validity period of the PIN code shall not exceed 12 months, for the default PIN code issued for the first time: the maximum validity period is 30 days.
3. Confirmation by one-time password (One Time Password - OTP) is a confirmation form using a password where the password has a single-use value and is valid for a specific period of time, including the following forms:
a) SMS OTP is a confirmation form through an OTP sent via SMS (Short Message Services) or through basic telecommunications services on the Internet. SMS OTP must meet the following requirements:
(i) The OTP sent to the customer must be accompanied by information to notify the customer of the purpose of the OTP;
(ii) The OTP is valid for a maximum of 05 minutes.
b) Voice OTP is a confirmation form through an OTP sent via a voice call or through basic telecommunications services on the Internet. Voice OTP must meet the following requirements:
(i) The OTP sent to the customer must be accompanied by information to notify the customer of the purpose of the OTP;
(ii) The OTP is valid for a maximum of 03 minutes.
c) Email OTP is a confirmation form through an OTP sent via email. Email OTP must meet the following requirements:
(i) The OTP sent to the customer must be accompanied by information to notify the customer of the purpose of the OTP;
(ii) The OTP is valid for a maximum of 05 minutes.
d) Matrix Card OTP is a confirmation form through an OTP determined from a two-dimensional table (rows, columns), each row and column corresponds to an OTP. The matrix card OTP must meet the following requirements:
(i) The matrix card OTP has a maximum usage period of 01 year from the date of registering the card;
(ii) The OTP is valid for a maximum of 02 minutes.
đ) Soft OTP is a confirmation form through an OTP generated by software installed on the customer's mobile device, the Soft OTP software can be independent software or integrated with the Mobile Banking application software.
Soft OTP has 02 types: (i) Soft OTP basic type: The OTP is randomly generated according to time, synchronized with the Online Banking system; (ii) Soft OTP advanced type: The OTP is created in combination with the transaction code, when performing a transaction, the Online Banking system generates a transaction code to inform the customer or transmit it to the Soft OTP software, the customer or the Soft OTP software automatically enters the transaction code into the Soft OTP software to generate the OTP.
Soft OTP must meet the following requirements:
(i) In the case where the Soft OTP software is independent of the Mobile Banking application software, it must be registered and managed in the official app store of the operating system provider for mobile devices and clear installation instructions must be provided on the website of the registration unit for customers to download and install the Soft OTP software;
(ii) The Soft OTP software must require activation before use. The activation code for using Soft OTP is provided by the service provider to the customer and can only be used to activate on one mobile device. The activation code must have a set validity period;
(iii) The Soft OTP software must have access control functionality. In the event of continuous incorrect access attempts exceeding the number specified by the unit (but not more than 10 times), the Soft OTP software must automatically lock and prevent further use by the customer. The unit will unlock the Soft OTP software only upon request by the customer and must verify the identity of the customer before unlocking, ensuring fraud prevention and forgery protection.
(iv) In the case where the Soft OTP software is independent of the Mobile Banking application software, it must have a function to check individual customers before allowing them to use it for the first time or before using it on a different device from the last used device. Customer verification must include at minimum: (i) matching the correct SMS OTP or Voice OTP through the phone number registered by the customer, (ii) and matching the customer's biometric information;
(v) The OTP is valid for a maximum of 02 minutes.
e) Token OTP is a confirmation form through an OTP generated by a dedicated device. Token OTP has 02 types: (i) Basic Token OTP: The OTP is randomly generated according to time, synchronized with the Online Banking system; (ii) Advanced Token OTP: The OTP is created in combination with the transaction code. When performing a transaction, the Online Banking system generates a transaction code to inform the customer, the customer enters the transaction code into the Token OTP device to generate the OTP. The Token OTP is valid for a maximum of 02 minutes.
4. Two-factor authentication is a confirmation form when the customer performs a transaction, the Online Banking system sends transaction confirmation information to the customer's mobile device via a voice call or through basic telecommunications services on the Internet or via a quick message USSD (Unstructured Supplementary Service Data) or through specialized software, the customer responds directly through the connected channel to confirm or not confirm the transaction. The confirmation requirement of the two-factor authentication method is valid for a maximum of 05 minutes.
5. Biometric Information Matching Confirmation is the process of comparing and verifying to ensure that the biometric information of the customer performing the transaction matches the biometric information of the customer collected and stored by the unit in accordance with the Governor of the State Bank of Vietnam. The biometric information matching confirmation form must meet at least the following requirements:
a) In the case of applying the biometric information matching confirmation form using facial recognition:
(i) Has accuracy determined according to international standards as follows (or equivalent): A false rejection rate < 5% and a false acceptance rate < 0.01% according to the FIDO Biometric Requirement standard (applicable to a minimum sample set of 10,000 samples);
(ii) Possesses the ability to detect attacks on live biometric information (Presentation Attack Detection - PAD) based on international standards (such as NIST Special Publication 800-63B Digital Identity Guidelines: Authentication and Lifecycle Management or ISO 30107 - Biometric Presentation Attack Detection or FIDO Biometric Requirements) to prevent and combat fraud and impersonation through images, videos, or 3D masks;
b) In cases where other correct matching forms of biometric information are applied, it must ensure prevention and combating of fraud and impersonation according to equivalent standards;
c) The solution for detecting attacks on live biometric information (Presentation Attack Detection - PAD) as stipulated in point a of this clause, whether implemented by the unit itself or provided by a third party, must be certified by an organization/laboratory recognized by the FIDO Alliance (FIDO Alliance);
d) In cases where customers confirm transactions using correct matching of biometric information more than the number of consecutive failed attempts as defined by the unit (but not exceeding 10 times): lock the function of confirming transactions using correct matching of biometric information, unlock only upon customer request and must verify the customer before execution, ensuring prevention of fraud and impersonation;
đ) The time to perform correct matching of biometric information shall not exceed three minutes;
6. The form of confirmation by correct matching of device biometric information is the process of comparing and ensuring that the biometric information of the customer conducting the transaction matches the stored biometric information of the customer on their mobile device. The form of correct matching of device biometric information must meet the following requirements:
a) It shall only allow activation for use after obtaining the customer's consent and the customer has successfully completed at least one transaction using another form of confirmation;
b) The time to perform correct matching of biometric information shall not exceed two minutes;
7. Confirmation form FIDO (Fast IDentity Online) is a confirmation method based on the standard for transaction authentication using asymmetric key algorithms (including a private key and a public key, wherein the private key is used for digital signing and the public key is used for verifying digital signatures) issued by the FIDO Alliance (FIDO Alliance). The FIDO confirmation method must meet the following requirements:
a) The private key must be securely stored on the customer's device. Customers use a PIN code or correct matching of device biometric information to access and use the private key when performing transactions;
b) The public key must be securely stored by the unit and linked to the customer's electronic transaction account;
c) Solutions implemented by the unit itself or provided by a third party must be certified by an organization recognized by the FIDO Alliance (FIDO Alliance);
8. Confirmation by electronic signature as prescribed by the law on electronic signatures (excluding secure electronic signatures prescribed in Clause 9 of this Article);
9. Confirmation by electronic signature secure electronic signature is a confirmation method using an electronic signature, wherein the electronic signature is a specialized secure electronic signature or a digital signature or a foreign electronic signature recognized in Vietnam under the law on electronic signatures;
10. Confirmation based on risk assessment for online card payment transactions according to the EMV 3-D Secure standard (hereinafter referred to as the EMV 3DS confirmation method). The EMV 3DS confirmation method must meet the following requirements: Card issuing organizations, card payment organizations, and merchant units must implement the EMV 3-D Secure standard;
11. Confirmation through actions indicating the customer's confirmation of data messages when performing transactions such as accepting, approving, sending, or similar activities in the Online Banking application software. The confirmation method through actions indicating the customer's confirmation of data messages during transactions must meet the following requirements:
a) Confirmation actions must be logged to enable querying related information about these confirmation actions;
b) The customer is an organization and has logged into the Online Banking application software using a confirmation method prescribed in this Article except for Clause 1, Clause 2, Clause 6, and Clause 10;
Section 3
OPERATIONAL MANAGEMENT
Article 12. Management of Personnel for the Operation and Administration of the Online Banking System
1. The entity shall assign personnel to monitor and oversee the activities of the Online Banking system, detect and handle technical issues, and cyber attacks.
2. The entity shall assign personnel to receive information, support customers, and promptly contact customers when abnormal transactions are detected.
3. Personnel managing, monitoring, and operating the Online Banking system must participate in annual training courses to update their knowledge on security and confidentiality.
4. The issuance and allocation of permissions for administrative accounts of the Online Banking system must be monitored and supervised by an independent department from the account issuance department.
Article 13. Management of the Operational Environment for the Online Banking System
1. The entity shall not install or store application development software or source code on the operational environment.
2. Management, monitoring, and operation activities must meet the following requirements:
a) Computers used by personnel managing, monitoring, and operating the system may only have permitted software installed and must have anti-malware software installed, which must be regularly updated with new malware recognition models and must not allow the anti-malware software to be self-deactivated;
b) Administrative, monitoring, and operational connections to the system must go through intermediary servers or secure centralized management systems, and direct connections from personnel's computers are not allowed;
c) Usage of administrative accounts must be limited to the time necessary to perform tasks and must be immediately revoked upon completion of the work session;
d) Measures must be taken to monitor the usage of administrative accounts, monitoring, and operational accounts, and alerts must be issued when there are unusual impacts on databases or applications.
3. The entity must establish policies for computers used for managing, monitoring, and operating the Online Banking system, allowing them to connect only to the Online Banking system or other information systems within the entity for management, monitoring, and operational purposes.
Article 14. Management of Technical Vulnerabilities and Weaknesses
The entity must manage vulnerabilities and weaknesses of the Online Banking system with the following basic contents:
1. Implement measures to prevent, combat, and detect unauthorized changes to the Online Banking application software.
2. Establish mechanisms to detect and prevent cyber intrusions and attacks on the Online Banking system.
3. Coordinate with state management units and information technology partners to promptly grasp incidents and situations involving information security breaches to take timely preventive measures.
4. Update information on newly disclosed security vulnerabilities related to system software, database management systems, and application software according to information from the Common Vulnerability Scoring System version 4 (CVSS v4 or equivalent).
5. Conduct vulnerability and weakness scans of the Online Banking system at least once a year or whenever new vulnerability or weakness information is received. For components directly connected to the Internet, conduct scans at least every three months. Assess the impact and risk level of each discovered technical vulnerability or weakness of the system and develop plans and strategies for handling them.
6. Implement timely deployment of security patches or preventive measures based on the assessment of impact and risk levels:
a) For critical-level security vulnerabilities: within one day for components directly connected to the Internet; within one month for other components after the vulnerability is disclosed or discovered.
b) For high-level security vulnerabilities: within one day for components directly connected to the Internet; within two months for other components after the vulnerability is disclosed or discovered.
c) For medium or low-level security vulnerabilities: implementation within a timeframe determined by the entity.
Article 15. Monitoring and Surveillance System for Online Banking Activities
1. The entity must establish a monitoring and surveillance system for Online Banking activities. The monitoring and surveillance system for Online Banking activities must collect complete logs of all components within the Online Banking system to detect, investigate unusual events or cyber attack behaviors.
2. The entity must develop criteria and software to alert on abnormal transactions based on time, geographic location, transaction frequency, transaction amount (if applicable), number of failed login attempts exceeding regulations, and other unusual signs.
Article 16. Ensuring Continuous Operation
The entity must establish a disaster recovery system, procedures, and scenarios to ensure continuous operation for the Online Banking system in accordance with the State Bank's regulations on ensuring the safety and security of information technology systems in banking operations. Additionally, the entity must carry out:
1. Analyze and determine situations that may cause information security breaches and interruptions to Online Banking system operations. Assess the risk level and likelihood of occurrence for each situation at least once every six months. List situations with risk levels and likelihoods according to high, medium, acceptable, and low categories.
2. Develop plans including procedures and scenarios to handle situations with high and medium risk levels and likelihoods as stipulated in Clause 1 of this Article. Determine the maximum downtime for system recovery and data restoration for each handling scenario. Organize dissemination of handling plans to relevant personnel to understand their tasks and responsibilities when handling such situations.
3. Allocate human resources, financial resources, and technical means to organize regular drills for handling situations with high risk levels and likelihoods at least once every year.
4. Plan and conduct drills for measures to ensure continuous business operations, retain related records, and organize evaluations of drill results.
Section 4. PROTECTING CUSTOMER RIGHTS
Article 17. Information about Online Banking Services
1. The entity must publish information about Online Banking services, ensuring customers can access this information before or at the time of service registration. The published information must minimally include:
a) Methods of providing services and methods of accessing Online Banking services corresponding to each access method;
b) Transaction limits (if applicable) and transaction confirmation methods;
c) Necessary equipment for using the service and conditions for using such equipment;
d) Risks associated with using Online Banking services.
2. The entity must inform customers about terms in the agreement for providing and using Online Banking services, minimally including:
a) Rights and obligations of customers using Online Banking services;
b) Types of customer data collected by the entity, purposes for using customer data, and the entity's responsibility for protecting customer data in accordance with the law, except where the entity and customer have agreed otherwise in compliance with the law;
c) Commitment to ensure the continuous operation of the Online Banking system, minimally including: downtime for service provision in one instance, total downtime for service provision in one year, excluding force majeure cases or system maintenance and upgrades already announced by the entity;
d) Other contents of the entity regarding Online Banking services (if applicable).
3. The entity shall not send SMS messages or emails to customers containing links (Hyperlinks) to electronic news pages, except upon customer request.
Article 18. Guidance for Customers to Use Online Banking Services
1. The entity must establish procedures and documentation for installing and using software, applications, and devices to conduct electronic transactions, and provide guidance to customers on using these procedures and documents.
2. The entity must guide customers on measures to ensure safety and security when using Online Banking services, including at least the following contents:
a) Protecting the confidentiality of secret keys, PINs, OTPs, and not sharing storage devices containing this information;
b) Principles for setting up secret keys, PINs, and changing secret keys, PINs of electronic transaction accounts;
c) Not using public computers to access and conduct transactions; not using public Wi-Fi networks when using Online Banking services;
d) Not saving login names and secret keys, PINs on browsers;
đ) Logging out of the Online Banking application software when not in use;
e) Identifying and handling certain fraudulent situations involving fake electronic news pages and Online Banking application software;
g) Installing all security patch updates for operating systems and Mobile Banking application software; considering installation of anti-malware software and updating the latest malware recognition models on personal devices used for transactions;
h) Selecting transaction confirmation methods that meet the required level of security and confidentiality according to regulations and customer needs regarding transaction limits;
i) Warning customers about risks related to the use of Online Banking services;
k) Not using unlocked mobile devices to download and use Online Banking application software and OTP generation software;
l) Not installing unknown software, unlicensed software, or software of unknown origin;
m) Promptly notifying the entity upon discovery of unusual transactions;
n) Immediately notifying the entity in cases of loss, misplacement, damage to OTP generating devices, SMS receiving phone numbers, storage devices for security keys for digital signatures; being defrauded or suspected of being defrauded; being attacked by hackers or suspected of being attacked by hackers.
3. The entity must provide customers with information on contact points, hotlines, and instructions for customers on the process and methods for coordinating in resolving errors and incidents during the use of Online Banking services.
4. The entity must explain to customers specific situations where the entity will contact them, the methods and means of communication during the use of Online Banking services.
Article 19. Customer Information Security
The entity must apply measures to ensure the safety and security of customer data, including at least the following:
1. Customer data must be secured and kept confidential in accordance with legal provisions.
2. Information used to confirm transactions, including secret keys, PINs, biometric information, when stored must be encrypted or concealed to ensure confidentiality.
3. Establish appropriate access rights for personnel performing tasks related to accessing customer data; implement monitoring measures for each access attempt.
4. Implement management measures for accessing and approaching devices and means of storing customer data to prevent data leaks and breaches.
5. Notify customers when incidents occur that result in data leaks or breaches, and promptly report to the State Bank of Vietnam (Information Technology Department).
Chapter III
IMPLEMENTING PROVISIONS
Article 20. Reporting System
Entities providing Online Banking services have the responsibility to submit written reports to the State Bank of Vietnam (Information Technology Department) as follows:
1. Report on Providing Online Banking Services:
a) Deadline for submitting the report: At least 10 working days before officially providing Online Banking services;
b) Content of the report:
(i) Website address or app store providing the service;
(ii) Official launch date;
(iii) Customer access verification solutions for Online Banking services; transaction confirmation methods applied to each type of transaction and transaction limit (if applicable);
(iv) Copies of certification documents regarding security assurance, fraud prevention, and counterfeiting as stipulated in Clause 5, Clause 7, Article 11 of this Circular.
2. Ad hoc reports as requested by the State Bank of Vietnam.
Article 21. Responsibilities of Units under the State Bank
1. The Information Technology Department shall be responsible for monitoring, inspecting, and coordinating with relevant units to resolve any issues arising during the implementation of this Circular.
2. The Banking Inspection and Supervision Authority shall be responsible for inspecting and supervising the enforcement of this Circular and handling violations according to the provisions of the law.
3. The State Bank branch in provinces and cities shall be responsible for inspecting and supervising the implementation of this Circular at payment intermediary service organizations within their jurisdiction (except for Vietnam National Payment Corporation) and handling violations according to the provisions of the law.
Article 22. Effectiveness
1. This Circular shall take effect from January 1, 2025, except for the cases specified in Clause 2, Clause 3, and Clause 4 of this Article.
2. Point b of Clause 1, Article 4, point d of Clause 9, Article 7, Clause 3, and Clause 4 of Article 8 shall take effect from July 1, 2025.
3. Point b of Clause 1, Article 10 shall take effect from January 1, 2026.
4. Point c of Clause 5, Article 11, point c of Clause 7, Article 11, and point b (iv) of Clause 1, Article 20 shall take effect from July 1, 2026.
5. The following documents shall cease to be effective from the date this Circular takes effect:
a) Circular No. 35/2016/TT-NHNN dated December 29, 2016, issued by the Governor of the State Bank of Vietnam on information security for Internet banking services;
b) Circular No. 35/2018/TT-NHNN dated December 24, 2018, issued by the Governor of the State Bank of Vietnam amending and supplementing certain articles of Circular No. 35/2016/TT-NHNN dated December 29, 2016, issued by the Governor of the State Bank of Vietnam on information security for Internet banking services.
6. Abolish Article 25 of Circular No. 09/2020/TT-NHNN dated October 21, 2020, issued by the Governor of the State Bank of Vietnam on information system safety in banking operations.
Article 23. Transitional Provisions
1. Automatic debit transactions from deposit accounts, automatic debit transactions from e-wallets, and automatic payments from customer cards that were initiated before the date this Circular takes effect shall continue to be executed until the expiration of the agreement; if the agreement does not specify a term, it shall continue to be executed until December 31, 2026. Any amendment, supplementation, or extension of the agreement must comply with the provisions of Clause 2, Article 10 of this Circular.
2. Secret keys and PINs being used before the date this Circular takes effect may continue to be used until the customer changes them or until the end of their validity period. From the date this Circular takes effect, any changes to secret keys and PINs must comply with the provisions of Clause 1 and Clause 2, Article 11 of this Circular.
Article 24. Implementation Organization
The Director of the Office, the Head of the Information Technology Department, and the Heads of units under the State Bank of Vietnam, the Chairmen of the Management Boards, the Chairmen of the Member Councils, the General Directors (Directors) of credit institutions, foreign bank branches, payment intermediary service organizations, and credit information companies are responsible for organizing the implementation of this Circular./.
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。