Decree No. 53/2022/NĐ-CP detailing certain provisions of the Cybersecurity Law

Decree No. 105/2022/NĐ-CP detailing certain provisions and measures for implementing the Cybersecurity Law, including contents on data storage, establishment of branches or representative offices in Vietnam by foreign enterprises; ensuring cybersecurity in the operations of state agencies and political organizations at central and local levels; funding for cybersecurity implementation. The Decree takes effect from October 1, 2022.

Document No.53/2022/NĐ-CP
Document typeDecree
Issuing authorityMinistry of Public Security
Signed byVũ Đức Đam — Phó Thủ tướng Chính phủ
Updated12/06/2026
FieldUncategorized
Issued date15/08/2022
Effective date01/10/2022
Expiry date
StatusIn effect
✦ Smart summary

Decree No. 105/2022/NĐ-CP detailing certain provisions and measures for implementing the Cybersecurity Law, including contents on data storage, establishment of branches or representative offices in Vietnam by foreign enterprises; ensuring cybersecurity in the operations of state agencies and political organizations at central and local levels; funding for cybersecurity implementation. The Decree takes effect from October 1, 2022.

Scope of application

Ministries, sectors, domestic enterprises, and foreign enterprises operating in Vietnam

Key points

  • Requirement to store user service data in Vietnam within Vietnam
  • Establishing branches or representative offices in Vietnam for foreign enterprises when required by competent authorities
  • Ensuring cybersecurity in the operations of state agencies and political organizations at central and local levels
  • Funding for cybersecurity implementation is allocated in the state budget
  • Minimum data retention period is 24 months

🌐 Social impact of this document

  • Strengthening management and supervision of foreign enterprises' activities in Vietnam
  • Protecting personal information and rights of users of services in Vietnam
  • Ensuring cybersecurity in the operations of state agencies

❓ Frequently asked questions

What data must foreign enterprises store?

Personal information data, service usage time, credit card information, email addresses, phone numbers registered with accounts or data and relationships of users of services in Vietnam

What is the minimum data retention period?

24 months

Who is responsible for enforcing this Decree?

Ministers, Heads of ministerial-level agencies, Heads of government-affiliated agencies, Chairpersons of provincial and centrally-administered city People's Committees

Full text

THE GOVERNMENT

SOCIALIST REPUBLIC OF VIET NAM
Independence – Freedom – Happiness

Number: 53/2022/NĐ-CP
Hanoi, August 15, 2022

DECREE

Detailed provisions on certain articles of the Cybersecurity Law

Pursuant to the Law on Organization of the Government dated June 19, 2015; the Law Amending and Supplementing Certain Provisions of the Law on Organization of the Government and the Law on Organization of Local Administration dated November 22, 2019;

Pursuant to the National Security Law dated December 3, 2004;

||| Pursuant to the Cyber Security Law dated June 12, 2018;

||| Pursuant to the Cybersecurity Law dated November 19, 2015;

The Government promulgates this Decree on regulations regarding entry, exit, and residence policies for foreigners at the International Financial Center in Vietnam.

The Government promulgates this Decree to provide detailed provisions on certain articles of the Cybersecurity Law.

PART I

GENERAL PROVISIONS

Article 1. Scope of Regulation

This Decree provides detailed provisions on points a, b, c, d, đ, g, i, k, l Clause 1 Article 5, Clause 4 Article 10, Clause 5 Article 12, Clause 1 Article 23, Clause 7 Article 24, Clauses 2 and 4 Article 26, Clause 5 Article 36 of the Cybersecurity Law, including the following contents:

1. Measures for cybersecurity protection: cybersecurity assessment; cybersecurity condition evaluation; cybersecurity inspection; cybersecurity monitoring; response and remediation of cybersecurity incidents; use of cryptographic means to protect network information; requests to remove illegal information or false information on cyberspace that infringe upon national security, public order, social safety, rights and legitimate interests of agencies, organizations, and individuals; collection of electronic data related to activities that infringe upon national security, public order, social safety, rights and legitimate interests of agencies, organizations, and individuals on cyberspace; suspension, temporary suspension, or cessation of operation of information systems; revocation of domain names.

2. Basis, procedures, and processes for establishing and cooperation among relevant ministries and sectors in cybersecurity assessment, evaluation, inspection, monitoring, response, and remediation of cybersecurity incidents for important information systems concerning national security.

3. Cybersecurity conditions for important information systems concerning national security.

4. Contents of implementing cybersecurity protection activities within state agencies and political organizations at central and local levels.

5. Procedures and processes for cybersecurity inspection of information systems of agencies, organizations, and individuals not included in the List of Important Information Systems Concerning National Security as provided for in Clause 1 Article 24.

6. Data storage and establishment of branches or representative offices in Vietnam for enterprises as stipulated in Clause 3 Article 26.

7. Allocation and coordination in implementing cybersecurity measures, prevention, and handling of acts infringing upon cybersecurity when the scope of state management involves multiple ministries and sectors.

Article 2. Interpretation of Terms

In this Decree, the following terms are understood as follows:

1. Personal data is data in the form of symbols, writing, numerals, images, sounds, or similar forms that identify an individual.

2. Service user is an organization or individual participating in using services on cyberspace.

3. Service user in Vietnam is an organization or individual using cyberspace on the territory of the Socialist Republic of Vietnam.

4. User relationship data is data in the form of symbols, writing, numerals, images, sounds, or similar forms reflecting and identifying the relationships of service users with others on cyberspace.

5. Data created by service users in Vietnam is data in the form of symbols, writing, numerals, images, sounds, or similar forms reflecting the process of participation, activities, and use of cyberspace by service users and information about devices and network services used to connect to cyberspace on the territory of the Socialist Republic of Vietnam.

6. Telecommunication network services include telecommunication services and telecommunication application services as prescribed by law.

7. Internet services include Internet services and content provision services on the Internet as prescribed by law.

8. Value-added services on cyberspace include value-added telecommunication services as prescribed by law.

9. Specialized forces for cybersecurity protection include:

a) The Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security;

b) The Military Security Protection Department, the General Political Department, and the Cyber Command under the Ministry of Defense.

10. Management authority of important information systems concerning national security is an agency or organization directly managing such systems, including the following cases:

a) Ministries, ministerial-level agencies, and government-affiliated agencies;

b) People's Committees of provinces and centrally-administered cities;

c) Central-level political organizations;

d) Authority having the right to decide on investment projects for construction, establishment, upgrading, and expansion of important information systems concerning national security.

11. Domestic enterprise is an enterprise established or registered to be established according to Vietnamese law and having its headquarters in Vietnam.

12. Foreign enterprise is an enterprise established or registered to be established according to foreign law.

Chapter II

ESTABLISHING THE LIST, COOPERATION MECHANISM, AND CYBERSECURITY CONDITIONS TO PROTECT IMPORTANT INFORMATION SYSTEMS CONCERNING NATIONAL SECURITY

Section 1. ESTABLISHING THE LIST OF CRITICAL INFORMATION SYSTEMS FOR NATIONAL SECURITY

Article 3. Basis for establishing critical information systems for national security

Critical information systems for national security are information systems of state agencies and political organizations of the Socialist Republic of Vietnam, including:

1. National critical information systems as prescribed by the Law on Cybersecurity.

2. Information systems serving the guidance and management of important works related to national security as prescribed by law.

3. Information systems serving the guidance, management, and control of the operation of important telecommunications works related to national security as prescribed by law.

4. Information systems in fields as prescribed in Clause 2, Article 10 of the Cybersecurity Law when encountering incidents such as intrusion, takeover, distortion, disruption, paralysis, attack, or destruction will result in one of the following consequences:

a) Directly affecting the independence, sovereignty, unity, and territorial integrity of the country, the existence of the Socialist Republic of Vietnam regime and State;

b) Causing serious consequences to national defense, national security, foreign relations, weakening the country's defensive and protective capabilities;

c) Causing serious consequences to the national economy;

d) Causing disasters to human life and ecological environment;

đ) Causing serious consequences to the operation of special-grade construction works as classified by laws on construction;

e) Causing serious consequences to the formulation of policies within the scope of state secrets;

g) Seriously affecting the direct guidance and management of central Party and State agencies.

Article 4. Establishing a dossier to propose inclusion of information systems in the List of Critical Information Systems for National Security

1. The managing body of the information system shall be responsible for reviewing and comparing with the provisions of Clause 4, Article 3 of this Decree, and establishing a dossier to propose the inclusion of the information system under its management authority in the List of Critical Information Systems for National Security.

2. For information systems included in the List of National Critical Information Systems:

a) The Ministry of Information and Communications shall be responsible for sending the dossier of the national critical information system to the Ministry of Public Security;

b) In the case stipulated in point a, Clause 2 of this Article, the managing body of the national critical information system does not need to establish a dossier to propose the inclusion of the system in the List of Critical Information Systems for National Security;

c) The Ministry of Public Security shall be responsible for including national critical information systems in the List of Critical Information Systems for National Security according to the prescribed procedures and formalities; notifying the managing bodies of these information systems about their inclusion in the List of Critical Information Systems for National Security and performing corresponding responsibilities.

3. In cases where during the assessment of the level of cybersecurity, it is found that there are sufficient grounds to include the information system in the List of Critical Information Systems for National Security, the Ministry of Information and Communications shall be responsible for transferring the dossier to the Ministry of Public Security for review of the proposal to include the information system in the List of Critical Information Systems for National Security.

4. Specialized forces for cyber security protection shall base on their assigned functions and tasks to review information systems that meet the criteria as prescribed in Article 3 of this Decree and request the managing bodies of the information systems to establish a dossier to propose the inclusion of the information system under their management authority in the List of Critical Information Systems for National Security.

5. Dossier to propose inclusion of information systems in the List of Critical Information Systems for National Security:

a) A document proposing the inclusion of the information system in the List of Critical Information Systems for National Security (Model No. 01 in the Appendix);

b) A document providing a complete list of all information systems of the agency or organization (Model No. 02 in the Appendix);

c) Supporting documents, including: Documents describing and generally explaining the information system; design and construction documents approved by competent authorities or equivalent documents; documents proving compliance with the basis for proposing the inclusion of the information system in the List of Critical Information Systems for National Security; documents explaining the information system protection plan (infrastructure security assurance plan; server security; application security; database security; management policy; organization and personnel; design and construction management; operation management; testing, evaluation, and risk management).

6. The dossier to propose inclusion of information systems in the List of Critical Information Systems for National Security shall be established in one original copy and sent to:

a) The Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security, except for the provisions in points b and c of this clause;

b) The Command of Cyber Operations under the Ministry of Defense for military information systems;

c) The Government Cryptographic Agency for cryptographic information systems under the Government Cryptographic Agency.

7. The agency receiving the dossier under Clause 6 of this Article shall be responsible for providing feedback in writing on the received dossier (Model No. 03 in the Appendix).

Article 5. Examination of the application dossier for inclusion in the List of Information Systems of National Security Importance

1. The Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security shall examine the application dossier for inclusion in the List of Information Systems of National Security Importance in accordance with the provisions herein, except for cases stipulated in Clause 2 and Clause 3 of this Article.

2. The Cyber Command under the Ministry of National Defense shall guide the preparation of the dossier, accept and examine the application dossier for inclusion in the List of Information Systems of National Security Importance for military information systems.

3. The Government Cryptographic Board shall examine the application dossier for inclusion in the List of Information Systems of National Security Importance for cryptographic information systems under the Government Cryptographic Board.

4. The Examination Council for the application dossier for inclusion in the List of Information Systems of National Security Importance:

a) For national security information systems related to multiple sectors or fields, or where examination requires opinions from multiple competent ministries and agencies;

b) The Examination Council operates on a part-time basis and dissolves itself upon completion of its tasks. Depending on the nature and role of the information system, members of the Examination Council may include the Ministry of Public Security, the Ministry of National Defense, the Ministry of Information and Communications, the Government Cryptographic Board, and other relevant agencies and units. In specific cases, the Examination Council may invite the management body of the information system to attend the examination meeting;

c) The Examination Council is responsible for examining the level of information system security and the application dossier for inclusion in the List of Information Systems of National Security Importance.

5. The results of the Examination Council's meetings shall be used collectively to serve cybersecurity and information security work.

6. Where it is necessary to verify information in the dossier and the actual status of the information system mentioned in the dossier, the examining agency specified in Clause 1, Clause 2, and Clause 3 of this Article shall organize surveys and inspections to examine the application for inclusion in the List of Information Systems of National Security Importance. The survey period shall not exceed twenty days. Survey results shall be recorded in a protocol confirmed by the examining agency and the management body of the information system.

7. The management body of the information system shall be responsible for cooperating and creating conditions for the examination, survey, inspection, and supplementation of the dossier according to the requirements of the examining agency.

8. Time and procedure for examining the dossier:

a) The examination period for the dossier is thirty days from the date of receipt of a complete and valid application dossier for inclusion in the List of Information Systems of National Security Importance or the end of the survey process as stipulated in Clause 6 of this Article;

b) The confirmation period for a complete and valid dossier is three working days after receipt of the application dossier for inclusion in the List of Information Systems of National Security Importance;

c) Upon completion of the examination period, the examining agency shall finalize the proposal dossier to submit to the Minister of Public Security and the Minister of National Defense;

d) The Minister of Public Security and the Minister of National Defense may decide to extend the examination period. The extension period shall not exceed twenty days.

9. The Ministry of Public Security shall take the lead and coordinate with the Ministry of National Defense and the Government Cryptographic Board to unify the submission mechanism.

Article 6. Removing Information Systems from the List of Important National Security Information Systems

1. When the management subject considers that the important national security information system under its management no longer meets the criteria stipulated in Article 3 of this Decree, the management subject of the important national security information system shall prepare a dossier to request the removal of the information system from the List of Important National Security Information Systems.

2. Annually, specialized forces responsible for protecting cybersecurity shall review, based on their functions and tasks, information systems that no longer meet the criteria specified in Article 3 of this Decree and require the management subjects of such information systems to prepare dossiers requesting the removal of the information systems from the List of Important National Security Information Systems within their jurisdiction.

3. The dossier for requesting the removal of an information system from the List of Important National Security Information Systems includes:

a) A proposal document for removing the information system from the List of Important National Security Information Systems (Form No. 05 in the Appendix);

b) Other necessary documents directly related to the request for removing the information system from the List of Important National Security Information Systems.

4. The procedures, formalities, and authority for examining and deciding to remove an information system from the List of Important National Security Information Systems shall be applied according to the regulations on procedures, formalities, and authority for examining and deciding to include an information system in the List of Important National Security Information Systems.

Article 7. Coordination in Assessing, Evaluating, Inspecting, Supervising, Responding to, and Resolving Incidents Related to Important National Security Information Systems

1. Cybersecurity and information security protection for important national security information systems shall be carried out in accordance with laws on cybersecurity and information security.

2. Principles of Coordination

a) Apply provisions of laws on cybersecurity and information security to the assessment, evaluation, inspection, supervision, response, and resolution of incidents related to important national security information systems;

b) In cases requiring coordination among multiple relevant parties, the Ministry of Public Security, the Ministry of Defense, and the Government Cryptographic Agency shall take the lead and coordinate with the Ministry of Information and Communications and other relevant ministries and sectors to organize the assessment, evaluation, inspection, supervision, response, and resolution of cybersecurity incidents for important national security information systems according to their assigned functions and tasks based on the Cybersecurity Law;

c) The coordination process must comply with international treaties and international organization regulations to which Vietnam is a party, the Cybersecurity Law, and related laws, actively, regularly, promptly, and in accordance with assigned functions, tasks, and authorities.

3. Methods of Coordination

a) The Ministry of Public Security shall send a document requesting relevant ministries and sectors to assign members to participate in the assessment, evaluation, inspection, supervision, response, and resolution of cybersecurity incidents for important national security information systems;

b) Relevant ministries and sectors shall have the responsibility to assign members to fully participate in all activities during the assessment, evaluation, inspection, supervision, response, and resolution of cybersecurity incidents for important national security information systems as requested;

c) Dossiers, documents, and materials serving the assessment, evaluation, inspection, supervision, response, and resolution of cybersecurity incidents for important national security information systems shall be copied and sent to participating members according to regulations by the Ministry of Public Security.

4. Coordination in Supervision of Important National Security Information Systems for Cybersecurity Protection and Information Security Protection

a) Specialized forces responsible for protecting cybersecurity shall share data on cybersecurity and information security supervision with each other and with the Information Security Bureau of the Ministry of Information and Communications to serve the performance of their assigned functions and tasks;

b) If cybersecurity supervision has been conducted for important national security information systems, shared supervision data shall be used to serve cybersecurity and information security protection work;

c) Management subjects of important national security information systems shall be responsible for arranging space, technical conditions, establishing, and connecting surveillance systems and equipment of specialized forces responsible for protecting cybersecurity to the information systems under their management to detect and provide early warnings about cybersecurity threats.

Section 2. CONDITIONS FOR CYBER SECURITY OF INFORMATION SYSTEMS CRUCIAL TO NATIONAL SECURITY

Article 8. Conditions for regulations, procedures, and plans to ensure cyber security for information systems crucial to national security

1. Based on provisions for cyber security protection, state secrets protection, job-related secrets protection, technical standards and specifications for information security, and other relevant technical standards, the management subject of information systems crucial to national security shall establish regulations, procedures, and plans to protect cyber security for such information systems under their management.

2. The contents of regulations, procedures, and plans for protecting cyber security must clearly define the information systems and important information that need priority protection; management processes, technical and operational procedures in using and protecting cyber security for data and technical infrastructure; conditions regarding personnel engaged in network administration, system operation, ensuring cyber security and information security, and activities related to drafting, storing, and transmitting state secrets through the information system; responsibilities of each department and individual in management, operation, and use; sanctions for violations.

Article 9. Conditions for personnel operating, managing systems, and protecting cyber security

1. There must be a department responsible for system operation, management, and cyber security protection.

2. Personnel responsible for system operation, management, and cyber security protection must have expertise in cyber security, information security, and information technology; they must commit to maintaining confidentiality related to information systems crucial to national security during employment and after leaving the job.

3. There must be an independent mechanism for professional operations among departments responsible for system operation, management, and cyber security protection for information systems crucial to national security.

Article 10. Conditions for ensuring cyber security for equipment, hardware, and software components of the system

1. Hardware components of the system must undergo cyber security testing to identify vulnerabilities, security gaps, malware, transmitters, harmful hardware, and ensure compatibility with other components within the information system crucial to national security. Management devices must be installed with clean operating systems and software, equipped with firewall layers for protection. Information systems processing state secrets must not be connected to the Internet.

2. Products warned or reported by specialized forces responsible for cyber security and information security about potential threats to cyber security must not be put into use or must be addressed with measures to fix vulnerabilities, security gaps, malware, and harmful hardware before being put into use.

3. Data and information in digital form processed and stored through information systems classified as state secrets must be encrypted or protected according to legal provisions on state secret protection during creation, exchange, and storage on the Internet.

4. Information and communication technology devices, communication means, carriers of information, and equipment serving the operation of the information system must be managed, destroyed, and repaired according to legal provisions on state secret protection and operational regulations of the information system's management subject.

5. System software, utility software, middleware, databases, application programs, source code, and development tools must be regularly reviewed and updated with patches.

6. Mobile devices and information storage-capable devices when connecting to the internal network of information systems crucial to national security must be inspected and controlled to ensure safety and can only be used within the information systems crucial to national security.

7. Equipment and means of information storage when connecting, transporting, and storing must:

a) Undergo security checks before connecting to information systems crucial to national security;

b) Control the connection and disconnection of devices belonging to information systems crucial to national security;

c) Implement safety measures during transportation and storage and protective measures for information classified as state secrets stored therein.

Article 11. Technical conditions for monitoring and ensuring national security information system safety

1. The operational environment of national security critical information systems must meet the following requirements:

a) Isolation from development, testing, and trial environments;

b) Implementation of solutions to ensure information security;

c) No installation of application development tools and means;

d) Removal or deactivation of unused or unnecessary features and utility software on the information system.

2. Data of national security critical information systems must have an appropriate automatic backup plan to external storage media at a frequency matching data changes and ensure that newly generated data is backed up within 24 hours. Backup data must be tested and ensured to be recoverable every six months.

3. Network systems must meet the following requirements:

a) Segmentation into different network zones based on user type and purpose, at minimum: a separate network zone for system information servers; an intermediate network zone (DMZ) for providing services on the Internet; a separate network zone for wireless network services; a separate network zone for database servers;

b) Equipment and software to control connections and access to important network zones;

c) Solutions to detect and block promptly untrusted connections and unauthorized intrusions;

d) Plans to respond to denial-of-service attacks and other forms of attack suitable to the scale and nature of national security critical information systems.

4. Measures and solutions to detect and identify technical vulnerabilities and illegal connections, devices, and software installed in the network in a timely manner.

5. Recording and storing logs of system activities, user actions, errors, and information security incidents for a minimum of three months in a centralized form and backing up at least once a year.

6. Access control for users and user groups using equipment and tools:

a) Registration, issuance, renewal, and revocation of access rights for devices and users;

b) Each system access account must be assigned to a single user; in cases where shared accounts are used to access national security critical information systems, they must be approved by authorized authorities and individual responsibilities must be determined at each point of use;

c) Limitation and control of administrative account accesses: (i) Establish a mechanism to control the creation of administrative accounts to ensure that no account can be used without authorized approval; (ii) There must be measures to monitor the use of administrative accounts; (iii) Use of administrative accounts must be limited to ensure only one administrative access session exists, automatically logging out after a set period of inactivity;

d) Management and issuance of secret key access codes for information systems;

đ) Review, inspection, and re-evaluation of user access rights;

e) Security requirements for devices and tools used for access.

Article 12. Physical security conditions

1. Important information systems for national security shall be located and installed at safe sites and protected to minimize risks from environmental threats and unauthorized intrusions.

2. Important information systems for national security shall be guaranteed power supply and support systems when the main power source is interrupted; measures against overload or voltage drop, lightning surge protection; grounding system; backup generator system and uninterruptible power supply system to ensure continuous operation of equipment.

3. Important information systems for national security shall have plans and measures to protect against the collection of information by unmanned aerial vehicles.

4. The data centers of important information systems for national security shall be controlled 24/7.

Chapter III

PROCEDURES FOR APPLYING CERTAIN SECURITY MEASURES

Article 13. Procedures and formalities for cybersecurity assessment of important information systems for national security

1. Cybersecurity assessment of information systems listed in the Catalogue of important information systems for national security shall be conducted by specialized forces responsible for cybersecurity in accordance with regulations.

2. Procedures for conducting cybersecurity assessment of important information systems for national security

a) The management body of important information systems for national security shall submit the application dossier for cybersecurity assessment to the competent specialized force responsible for cybersecurity;

b) The specialized force responsible for cybersecurity shall accept, examine, guide the completion of the cybersecurity assessment application dossier and issue a receipt immediately upon receiving a complete and valid dossier within three working days;

c) The specialized force responsible for cybersecurity shall conduct the cybersecurity assessment according to the contents stipulated in Clause 3, Article 11 of the Cybersecurity Law and notify the results within thirty days from the date of issuing the receipt for the application dossier to the management body of important information systems for national security.

3. Application dossier for cybersecurity assessment of important information systems for national security includes:

a) Request for cybersecurity assessment (Form No. 06 Appendix);

b) Preliminary feasibility study report, design construction project dossier before approval;

c) Upgrade plan for important information systems for national security before approval in cases of upgrading such systems.

4. In cases where it is necessary to determine the conformity between the current status of important information systems for national security and the application dossier for cybersecurity assessment, the specialized force responsible for cybersecurity shall conduct surveys and evaluations of the actual status of important information systems for national security to compare with the application dossier for cybersecurity assessment. Such surveys and evaluations shall ensure that they do not affect the normal operations of the management body as well as important information systems for national security. The time for conducting surveys and evaluations shall not exceed seven working days.

5. The results of cybersecurity assessments shall be protected in accordance with the provisions of the law.

Article 14. Procedures and formalities for assessing cybersecurity conditions of important information systems for national security

1. Assessment of cybersecurity conditions of information systems listed in the Catalogue of important information systems for national security shall be conducted by specialized forces responsible for cybersecurity in accordance with regulations.

2. Procedures for assessing cybersecurity conditions of important information systems for national security:

a) The management body of important information systems for national security shall submit the application dossier for cybersecurity condition assessment to the competent specialized force responsible for cybersecurity for assessing cybersecurity conditions in accordance with Clause 3, Article 12 of the Cybersecurity Law;

b) The specialized force responsible for cybersecurity shall accept, examine, guide the completion of the application dossier for cybersecurity condition assessment and issue a receipt immediately upon receiving a complete and valid dossier;

c) After receiving a complete and valid dossier, the specialized force responsible for cybersecurity shall conduct the cybersecurity condition assessment and notify the results within thirty days from the date of issuing the receipt for the complete and valid dossier of the management body of important information systems for national security;

d) In cases where cybersecurity conditions are met, the head of the agency assessing cybersecurity conditions shall issue a Certificate of Meeting Cybersecurity Conditions for important information systems for national security within three working days from the end of the cybersecurity condition assessment.

3. Application dossier for certification of meeting cybersecurity conditions for important information systems for national security includes:

a) Request for certification of cybersecurity conditions (Form No. 07 Appendix);

b) Preliminary feasibility study report, design construction project dossier before approval;

c) Dossier of solutions ensuring cybersecurity for important information systems for national security.

4. In cases where cybersecurity conditions are not met, the specialized force responsible for cybersecurity shall require the management body of important information systems for national security to supplement and upgrade important information systems for national security to meet the conditions.

Article 15. Procedures and formalities for cybersecurity supervision

1. The Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security and the Cyber Command under the Ministry of National Defense shall be responsible for conducting cybersecurity supervision over the national cyberspace and important information systems concerning national security according to their assigned functions and tasks. The Government Cryptographic Office shall conduct cybersecurity supervision over cryptographic information systems under its jurisdiction according to its assigned functions and tasks.

2. Procedures for cybersecurity supervision by specialized forces protecting cybersecurity:

a) Sending a written notice requesting the implementation of cybersecurity supervision measures to the management authority of the information system; specifying the reasons, time, content, and scope of the cybersecurity supervision in the notice.

b) Implementing cybersecurity supervision measures.

c) Regularly compiling statistics and reporting the results of cybersecurity supervision.

3. Responsibilities of the management authority of important information systems concerning national security:

a) Establishing and implementing a cybersecurity supervision system, coordinating with specialized forces protecting cybersecurity to carry out cybersecurity supervision activities over information systems under their management authority.

b) Arranging premises, technical conditions, setting up, and connecting the specialized force's cybersecurity supervision system and equipment into the information system they manage to facilitate cybersecurity supervision.

c) Providing and updating information about information systems under their management authority, technical plans for establishing the cybersecurity supervision system for the specialized force protecting cybersecurity on a regular basis or at any time when requested by the authorized specialized force protecting cybersecurity.

d) Notifying the specialized force protecting cybersecurity about the management authority's cybersecurity supervision activities every three months.

đ) Securing related information during cooperation with the specialized force protecting cybersecurity.

4. Telecommunications enterprises, information technology service providers, telecommunications, and internet service providers shall cooperate with specialized forces protecting cybersecurity in cybersecurity supervision according to their authority to protect cybersecurity.

5. The results of cybersecurity supervision shall be kept confidential in accordance with the provisions of the law.

Article 16. Procedures and formalities for cybersecurity inspection

1. Specialized forces protecting cybersecurity shall conduct cybersecurity inspections on information systems as stipulated in Clause 5, Article 13 and Clause 1, Article 24 of the Cybersecurity Law. The content of cybersecurity inspections includes: inspecting compliance with legal provisions on ensuring cybersecurity and safeguarding state secrets in cyberspace; evaluating the effectiveness of cybersecurity assurance plans and measures, response and remediation plans for cybersecurity incidents; detecting vulnerabilities, weaknesses, malware, and penetration testing attacks on the system; other inspections as specified by the management authority of the information system.

2. Procedures and formalities for cybersecurity inspections by specialized forces protecting cybersecurity:

a) Announcing the inspection plan according to regulations.

b) Forming an Inspection Team according to their assigned functions and tasks.

c) Conducting cybersecurity inspections, closely coordinating with the management authority of the information system during the inspection process.

d) Preparing a record of the inspection process and results and preserving it in accordance with the law.

đ) Notifying the inspection results within three working days from the completion of the inspection.

3. In cases where it is necessary to maintain the current status of the information system to serve investigations, handling violations of the law, discovering weaknesses and vulnerabilities; guiding or participating in remediation upon request of the management authority of the information system, the specialized force protecting cybersecurity may send a written request to the management authority of the information system to temporarily halt cybersecurity inspections. The content of the document must clearly specify the reasons, purpose, and duration of the temporary suspension of cybersecurity inspections.

Article 17. Procedures and formalities for responding to and rectifying cybersecurity incidents concerning important information systems for national security

1. For important information systems for national security encountering cybersecurity incidents, the procedures and formalities for responding to and rectifying such incidents shall be carried out as follows:

a) The specialized force responsible for protecting cybersecurity shall notify in writing and guide temporary measures to prevent, handle cyber attacks, and mitigate consequences caused by cyber attacks and cybersecurity incidents for the management authority of important information systems for national security. In urgent cases, notification may be made by telephone or other means before written notification;

b) The management authority of important information systems for national security shall be responsible for implementing measures according to guidance and other appropriate measures to prevent, handle, and mitigate consequences immediately upon receiving notification, except as provided in point c of this clause. If beyond its capacity to handle, it shall promptly notify the specialized force responsible for protecting cybersecurity to coordinate and respond to rectify cybersecurity incidents;

c) In cases where immediate response is necessary to prevent potential harmful consequences to national security, the specialized force responsible for protecting cybersecurity shall directly decide to coordinate and respond to rectify cybersecurity incidents.

2. Coordination and response to rectify cybersecurity incidents by the specialized force responsible for protecting cybersecurity:

a) Assess and decide on the response plan to rectify cybersecurity incidents;

b) Direct the work of responding to and rectifying cybersecurity incidents;

c) Take the lead in receiving, collecting, processing, and exchanging information related to responding to and rectifying cybersecurity incidents;

d) Mobilize and coordinate with domestic and foreign organizations and individuals relevant to participate in responding to and rectifying cybersecurity incidents when necessary;

đ) Designate the focal unit to coordinate with functional units of other countries or international organizations in cross-border incident response activities based on international agreements or treaties to which Vietnam is a party;

e) Inspect, supervise, and urge related units to implement response and rectification of cybersecurity incidents;

g) Record the process of responding to cybersecurity incidents.

3. Organizations and individuals participating in responding to and rectifying cybersecurity incidents shall be responsible for implementing measures and activities for response and rectification according to the coordination of the specialized force responsible for protecting cybersecurity.

4. In cases involving national security, social order, and public safety, telecommunications enterprises and Internet service providers shall arrange premises, connection ports, and necessary technical measures for the Cybersecurity Bureau and High-Tech Crime Prevention Department under the Ministry of Public Security to perform their tasks of ensuring cybersecurity. Specific procedures shall be coordinated between telecommunications enterprises, Internet service providers, and the Cybersecurity Bureau and High-Tech Crime Prevention Department under the Ministry of Public Security.

Article 18. Procedures for Implementing Cryptographic Measures to Protect Network Information

1. The specialized force responsible for protecting cybersecurity shall use cryptographic encoding measures of official seals to protect network information when transmitting information and documents containing state secrets in cyberspace. Encoding measures must meet requirements stipulated by laws on official seals, protection of state secrets, and cybersecurity.

2. In cases deemed necessary for reasons of national security, social order, and public safety, and to protect the legitimate rights and interests of agencies, organizations, and individuals, the specialized force responsible for protecting cybersecurity shall send a written request to relevant agencies, organizations, and individuals to encrypt information not within the scope of state secrets before storing or transmitting on the Internet. The content of the document must clearly state the reason for the request and the information to be encrypted.

Article 19. Procedures and formalities for implementing measures to remove illegal information or false information on cyberspace that infringe upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals

1. Cases for applying measures:

a) When information on cyberspace is determined by competent authorities to contain content that infringes upon national security, disseminates propaganda against the Socialist Republic of Vietnam; incites riots, disrupts public security, and disturbs public order as prescribed by law;

b) When there is legal basis to determine that information on cyberspace contains content that humiliates, slanders; infringes upon economic management order; fabricates false information causing public panic, resulting in serious damage to economic and social activities to the extent that removal of such information is required;

c) Other information on cyberspace containing content as stipulated at point c, point e, clause 1 of Article 8 of the Cybersecurity Law according to the provisions of law.

2. The Director of the Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security, the Heads of competent authorities of the Ministry of Information and Communications:

a) Decide to apply measures to remove illegal information or false information on cyberspace that infringes upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals as prescribed in clause 1 of this Article;

b) Send documents requesting enterprises providing telecommunications services, Internet services, value-added services on cyberspace, and system administrators to remove illegal information or false information on cyberspace that infringes upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals as prescribed in clause 1 of this Article;

c) Inspect the implementation of measures by related subjects who are requested;

d) Exchange and share information about the implementation of these measures, except for cases involving state secrets or operational requirements of the Ministry of Public Security.

3. Special forces responsible for cyber security under the Ministry of National Defense decide to apply measures to remove illegal information or false information on cyberspace that infringes upon national security and military security as prescribed in clause 1 of this Article for military information systems.

Article 20. Procedures and formalities for implementing measures to collect electronic data related to activities infringing upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals on cyberspace

1. Electronic data is information in the form of symbols, writing, numerals, images, sounds, or similar forms.

2. The Director of the Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security decides to implement measures to collect electronic data to serve investigations and handling of acts infringing upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals on cyberspace.

3. Collection of electronic data related to activities infringing upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals on cyberspace shall be carried out in accordance with the law, while ensuring the following requirements:

a) Maintaining the original condition of digital devices and electronic data;

b) The process of duplicating electronic data must be conducted according to established procedures using recognized equipment and software that can be verified, ensuring the integrity of the electronic data stored in the device;

c) The process of recovering and searching for electronic data must be recorded in minutes, photographs, videos, and if necessary, may be repeated to achieve similar results to present in court;

d) Persons collecting electronic data must be specialized staff assigned to perform the task of collecting electronic data.

4. Principles for duplicating and restoring electronic data related to activities infringing upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals on cyberspace:

a) In cases where electronic data is considered to have evidentiary value for criminal offenses and requires duplication or restoration, the person duplicating or restoring must have the authority to do so and must obtain approval from the competent authority as prescribed by law;

b) Minutes must be made for activities of duplicating and restoring electronic evidence, and if necessary, an independent third party may be invited to participate, witness, and confirm the process.

5. Seizure of storage, transmission, and processing means of electronic data related to activities infringing upon national security, public order and safety, and the legitimate rights and interests of agencies, organizations, and individuals on cyberspace shall be carried out in accordance with the law.

6. Special forces responsible for cyber security under the Ministry of National Defense decide to apply measures to collect electronic data to serve investigations of violations and crimes causing loss of information security, infringing upon national security and military security on cyberspace.

Article 21. Procedures and formalities for implementing measures to suspend, temporarily suspend, or request cessation of operation of information systems, and reclaim domain names

1. Cases of application:

a) There are documents proving that the operation of the information system violates laws on national security and cybersecurity;

b) The information system is being used for purposes of infringing upon national security and social order and safety.

2. The Minister of Public Security shall directly decide on suspending, temporarily suspending, or requesting cessation of operation of the information system, temporarily suspending, or reclaiming domain names with activities violating cybersecurity laws.

3. The Director of the Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security shall be responsible for implementing decisions to suspend, temporarily suspend, or request cessation of operation of the information system, temporarily suspend, or reclaim domain names.

4. Procedures and formalities for implementing measures:

a) Report on the application of measures to suspend, temporarily suspend, or request cessation of operation of the information system, temporarily suspend, or reclaim domain names;

b) Decision to suspend, temporarily suspend, or request cessation of operation of the information system, temporarily suspend, or reclaim domain names;

c) Send a document requesting relevant agencies, organizations, or individuals to implement suspension, temporary suspension, or cessation of operation of the information system, or send it to the Vietnam Internet Center to request temporary suspension or reclamation of domain names according to procedures and formalities prescribed by law; the document must clearly state the reasons, time, content, and recommendations;

d) In urgent cases where immediate action is necessary to prevent harmful effects on national security or to prevent potential consequences, the Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security may directly request or send a document via fax or email to request agencies, organizations, or individuals to suspend, temporarily suspend, or cease operation of the information system; within the latest 24 hours from the time of the request, the Cybersecurity and High-Tech Crime Prevention Department under the Ministry of Public Security must send a document requesting suspension, temporary suspension, or cessation of operation of the information system. If the decision is not made in writing within this period, the information system will continue to operate. Depending on the nature, severity, and consequences caused by the delay in sending the document, the officials involved and related persons must bear responsibility according to the law;

e) Suspension, temporary suspension, or cessation of operation of the information system must be recorded in a protocol. The protocol must clearly record the time, place, basis, and be made in two copies. The competent authority retains one copy, and the agency, organization, or individual owning or managing the information system retains one copy;

f) In cases specified in Clause 1 of this Article, the competent authority sends a document requesting the Vietnam Internet Center to temporarily suspend or reclaim domain names according to procedures and formalities prescribed by law.

5. If suspension, temporary suspension, or cessation of operation of the information system is carried out without the grounds stipulated in Clause 2 of this Article, the head or deputy head of the competent authority and related officials must bear legal responsibility, and if damage is caused to relevant agencies, organizations, or individuals, compensation must be provided according to the law.

Article 22. Responsibilities of agencies, organizations, and individuals in implementing measures to protect cybersecurity

1. Specialized forces responsible for protecting cybersecurity shall be responsible for guiding specific agencies, organizations, and individuals related to the implementation of regulations on procedures and formalities for applying certain cybersecurity protection measures.

2. Agencies, organizations, and individuals within their scope of responsibility and authority shall promptly coordinate and support specialized forces responsible for protecting cybersecurity in implementing regulations on procedures and formalities for applying certain cybersecurity protection measures.

3. In cases where enterprises providing cross-border services are announced by competent authorities to have violated Vietnamese laws, Vietnamese organizations and enterprises shall be responsible for coordinating with competent authorities to prevent, stop, and handle violations of law by enterprises providing cross-border services.

4. Any acts of exploiting or misusing cybersecurity protection measures to violate the law shall be subject to handling according to the provisions of the law depending on the nature and degree of violation; in cases causing damage to the legitimate rights and interests of organizations and individuals, compensation must be provided according to the provisions of the law.

5. For information systems not included in the List of Important Information Systems for National Security, the Ministry of Public Security, the Ministry of Defense, and the Ministry of Information and Communications shall cooperate synchronously to protect cybersecurity and ensure information security according to their assigned functions and tasks:

a) The Ministry of Information and Communications shall be the lead agency for civilian activities, except for cases stipulated in points b and c of this clause;

b) The Ministry of Public Security shall be the lead agency for national security protection activities, social order and safety protection, cybersecurity protection, prevention and combating cybercrime, cyber terrorism, and cyber espionage;

c) The Ministry of Defense shall be the lead agency for national defense activities in cyberspace.

Chapter IV

IMPLEMENTATION OF CERTAIN CYBERSECURITY PROTECTION ACTIVITIES IN STATE AGENCIES AND CENTRAL AND LOCAL POLITICAL ORGANIZATIONS

Article 23. Construction and improvement of regulations on the use of computer networks by state agencies and central and local political organizations

1. State agencies and central and local political organizations must establish regulations on the use, management, and ensuring cybersecurity for internal computer networks and computer networks connected to the Internet under their management. The contents of regulations on ensuring safety and cybersecurity shall be based on regulations on cybersecurity protection, state secrets protection, technical standards and specifications for information security, and other relevant technical standards.

2. Regulations on the use and ensuring cybersecurity for computer networks of state agencies and central and local political organizations must include the following basic contents:

a) Clearly identify the information systems and important information that need priority cybersecurity protection;

b) Clearly define prohibitions and principles for managing, using, and ensuring cybersecurity for internal computer networks storing and transmitting state secrets, which must be physically separated from computer networks and electronic devices connected to the Internet, and in other cases, must comply with legal provisions on state secrets protection;

c) Management processes, operational procedures, and technical requirements for operating, using, and ensuring cybersecurity for data and technical infrastructure, including meeting basic requirements for ensuring the safety of information systems;

d) Conditions for personnel engaged in network administration, system operation, cybersecurity assurance, and information security, and those involved in drafting, storing, and transmitting state secrets through computer networks;

đ) Clearly define the responsibilities of each department, staff members in managing, using, and ensuring cybersecurity and information security;

e) Sanctions for violations of regulations on ensuring cybersecurity.

Article 24. Construction and Improvement of Cybersecurity Assurance Plans for Information Systems of State Agencies and Political Organizations at Central and Local Levels

1. The heads of state agencies and political organizations at central and local levels shall be responsible for issuing cybersecurity assurance plans for information systems under their management, ensuring synchronization, uniformity, concentration, resource sharing to optimize performance, and avoiding duplicate investments.

2. A cybersecurity assurance plan for information systems includes:

a) Provisions on cybersecurity in the design and construction of information systems, meeting basic requirements such as management, technical, and operational needs;

b) Cybersecurity assessment;

c) Cybersecurity inspection and evaluation;

d) Cybersecurity monitoring;

đ) Prevention, response, and recovery from cyber incidents and dangerous situations;

e) Risk management;

g) Termination of operation, exploitation, repair, liquidation, and cancellation.

Article 25. Emergency Response and Recovery Plans for Cybersecurity Incidents of State Agencies and Political Organizations at Central and Local Levels

1. An emergency response and recovery plan for cybersecurity incidents includes:

a) A plan to prevent and handle information containing propaganda against the Socialist Republic of Vietnam; incitement to cause riots, disrupt public security, disturb public order; defamation and slander; violation of economic management order posted on information systems;

b) A plan to prevent and combat cyber espionage; protect information classified as state secrets, work-related secrets, business secrets, personal secrets, family secrets, and private life on information systems;

c) A plan to prevent and combat illegal activities using cyberspace, information technology, and electronic devices that violate laws on national security, public order, and social safety;

d) A plan to prevent and combat cyber attacks;

đ) A plan to prevent and combat cyber terrorism;

e) A plan to prevent and handle dangerous cybersecurity situations.

2. Contents of the emergency response and recovery plan for cybersecurity incidents

a) General provisions;

b) Evaluation of cybersecurity risks and incidents;

c) Response and recovery plans for specific situations;

d) Tasks and responsibilities of agencies in organizing, coordinating, handling, responding, and recovering from incidents;

đ) Training, drills, prevention of incidents, monitoring and detection, ensuring conditions for readiness to respond and recover from incidents;

e) Measures to ensure the organization and implementation of the plan, budget, and execution.

Chapter V

DATA STORAGE AND ESTABLISHMENT OF BRANCHES OR REPRESENTATIVE OFFICES IN VIETNAM

Article 26. Data Storage and Establishment of Branches or Representative Offices in Vietnam

1. Data to be stored in Vietnam:

a) Personal data of users of services in Vietnam;

b) Data created by users of services in Vietnam: Service account name, service usage time, credit card information, email address, most recent login and logout IP address, phone number registered with the account or data;

c) Data about relationships of users of services in Vietnam: friends, groups connected to or interacted with by the user.

2. Domestic enterprises must store data specified in Clause 1 of this Article in Vietnam.

3. Data storage and establishment of branches or representative offices in Vietnam by foreign enterprises:

a) Foreign enterprises conducting business in Vietnam in the following fields: Telecommunication services; cloud storage and data sharing services; provision of national or international domain names for service users in Vietnam; e-commerce; online payment; payment intermediaries; network-based transportation connection services; social networks and social media; online games; other information provision, management, or operation services on the internet in the form of messages, voice calls, video calls, emails, and online chats must store data specified in Clause 1 of this Article and establish branches or representative offices in Vietnam if the services provided by the enterprise are used to commit cybercrime violations reported and required to cooperate, prevent, investigate, and handle by the Cybersecurity Bureau and High-Tech Crime Prevention Department under the Ministry of Public Security through written notification but not complied with, not fully complied with, obstructed, rendered ineffective, or nullified the cybersecurity protection measures implemented by specialized cybersecurity forces;

b) In cases of force majeure where compliance with cybersecurity laws by foreign enterprises cannot be carried out, the foreign enterprise must notify the Cybersecurity Bureau and High-Tech Crime Prevention Department under the Ministry of Public Security within three working days for verification of the authenticity of the force majeure situation. In this case, the enterprise has thirty working days to find solutions to remedy the situation.

4. If the data collected, analyzed, processed by the enterprise is incomplete as stipulated in Clause 1 of this Article, the enterprise shall cooperate with the Cybersecurity Bureau and High-Tech Crime Prevention Department under the Ministry of Public Security to confirm and store the types of data currently being collected, analyzed, and processed. If the enterprise supplements the collection, analysis, and processing of data as stipulated in Clause 1 of this Article, the enterprise shall be responsible for cooperating with the Cybersecurity Bureau and High-Tech Crime Prevention Department under the Ministry of Public Security to supplement the list of data to be stored in Vietnam.

5. The method of storing data in Vietnam is decided by the enterprise.

6. Procedures and formalities for requesting data storage and establishment of branches or representative offices of foreign enterprises in Vietnam:

a) The Minister of Public Security issues a decision requiring data storage and establishment of branches or representative offices in Vietnam;

b) The Cyber Security Agency under the Ministry of Public Security shall notify, guide, monitor, supervise, urge enterprises to fulfill the requirements for data storage, establish branches or representative offices in Vietnam; and at the same time, report to relevant agencies to perform state management functions within their jurisdiction.

c) Within twelve months from the date the Minister of Public Security issues the decision, enterprises specified in point a, Clause 3, Article 26 of this Decree must complete data storage, establish branches or representative offices in Vietnam.

7. The procedures and formalities for establishing branches or representative offices in Vietnam shall be carried out in accordance with the provisions of laws on business, trade, enterprises, and other related regulations.

8. Enterprises that fail to comply with the provisions of this Article shall be subject to handling according to the law depending on the nature and degree of violation.

Article 27. Time for Data Storage and Establishment of Branches or Representative Offices in Vietnam

1. The period for data storage as prescribed in Article 26 of this Decree starts from when the enterprise receives the data storage request until the end of the request. The minimum storage period is twenty-four months.

2. The period for establishing branches or representative offices in Vietnam as prescribed in Article 26 of this Decree starts from when the enterprise receives the request to establish branches or representative offices in Vietnam until the enterprise ceases operations in Vietnam or the specified service is no longer provided in Vietnam.

3. System logs for serving investigations and handling violations of cybersecurity laws as stipulated in point b, Clause 2, Article 26 of the Cybersecurity Law shall be stored for a minimum of twelve months.

Chapter VI

IMPLEMENTING PROVISIONS

Article 28. Funding Assurance

1. Funding for ensuring cybersecurity in the activities of central and local state agencies and political organizations shall be guaranteed by the state budget.

2. Funding for cybersecurity using public investment capital shall be implemented in accordance with the Public Investment Law. For public investment projects for new construction, expansion, or upgrading information systems, the investment funding shall be allocated within the corresponding project's investment capital.

3. Funding for assessing, supervising, inspecting, and evaluating cybersecurity conditions; implementing cybersecurity assurance plans of central and local state agencies and political organizations shall be balanced and allocated in the annual budget estimates of those agencies and organizations according to the分级任务袯:

4. The Ministry of Finance shall provide guidance on budgetary funding for cybersecurity protection work, and manage and use regular funding for cybersecurity assurance work of state agencies and organizations.

5. Based on assigned tasks, state agencies and organizations shall prepare budgets, manage, use, and settle accounts for funding to implement cybersecurity assurance tasks in accordance with the State Budget Law.

Article 29. Effective Date

This Decree takes effect from October 1, 2022.

Article 30. Responsibility for Implementation

1. The Minister of Public Security shall urge, inspect, and guide the implementation of this Decree. During the implementation process, if there are difficulties, ministries, sectors, and localities shall exchange with the Ministry of Public Security to compile and report to the Government for consideration and adjustment.

2. The Ministers, Heads of Ministries equivalent to ministries, Heads of government agencies, Chairmen of provincial and municipal People's Committees directly under the Central Government shall be responsible for enforcing this Decree.

PRIME MINISTER
KT. PRIME MINISTER 
DEPUTY PRIME MINISTER
Vu Duc Dam

The original file of this document is being updated. Please read the full text and check back later.

Relations map

↑ Basis & documents that affect this document
Based on 17
76/2015/QH13 Luật Tổ chức Chính phủ số 76/2015/QH13 Expired 32/2004/QH11 Luật An ninh Quốc gia số 32/2004/QH11 In effect 24/2018/QH14 Luật An ninh mạng số 24/2018/QH14 In effect 86/2015/QH13 Luật An toàn thông tin mạng số 86/2015/QH13 In effect 162/2025/QĐ-UBND Quyết định số 162/2025/QĐ-UBND Ban hành Quy chế quản lý, vận hành và sử dụng Hệ thống thư điện tử công vụ trong các cơ quan hành chính nhà nước tỉnh Ninh Bình In effect 161/2025/QĐ-UBND Quyết định số 161/2025/QĐ-UBND Ban hành Quy chế quản lý, vận hành và sử dụng Hệ thống quản lý văn bản và điều hành trong các cơ quan hành chính nhà nước trên địa bàn tỉnh Ninh Bình In effect 85/2025/QĐ-UBND Quyết định số 85/2025/QĐ-UBND Về việc ban hành Quy chế quản lý, khai thác, sử dụng hạ tầng Trung tâm Dữ liệu và cơ sở dữ liệu thành phố Hà Nội In effect 46/2025/TT-NHNN Thông tư số 46/2025/TT-NHNN quy định quản lý sử dụng mạng máy tính của Ngân hàng Nhà nước Việt Nam In effect 26/2026/QĐ-UBND Quyết định số 26/2026/QĐ-UBND Ban hành Quy chế quản lý, khai thác và vận hành Trung tâm dữ liệu thành phố Cần Thơ In effect 29/2026/QĐ-UBND Quyết định số 29/2026/QĐ-UBND Ban hành định mức kinh tế - kỹ thuật giám sát đảm bảo an toàn thông tin đối với hệ thống hạ tầng kỹ thuật dịch vụ công nghệ thông tin phục vụ công tác quản lý nhà nước lĩnh vực tài nguyên, môi trường In effect 02/2026/QĐ-UBND Quyết định số 02/2026/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin, an ninh mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Gia Lai In effect 132/2025/QĐ-UBND Quyết định số 132/2025/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Phú Thọ In effect 40/2025/QĐ-UBND Quyết định số 40/2025/QĐ-UBND Ban hành Quy chế bảo đảm an ninh mạng, an toàn thông tin trên địa bàn tỉnh Bắc Ninh In effect 38/2024/QĐ-UBND Quyết định số 38/2024/QĐ-UBND Ban hành Quy chế Quản lý, vận hành và khai thác Trung tâm Tích hợp dữ liệu tỉnh Hòa Bình In effect 48/2024/QĐ-UBND Quyết định số 48/2024/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng tỉnh Ninh Bình In effect 47/2023/QĐ-UBND Quyết định số 47/2023/QĐ-UBND Ban hành Quy chế đảm bảo an toàn, an ninh thông tin trên môi trường mạng trong hoạt động của các cơ quan nhà nước trên địa bàn tỉnh Bến Tre In effect 48/2024/QĐ-UBND Quyết định số 48/2024/QĐ-UBND Ban hành Quy chế bảo đảm an toàn thông tin mạng trong hoạt động ứng dụng công nghệ thông tin của các cơ quan nhà nước trên địa bàn tỉnh Hậu Giang Expired
53/2022/NĐ-CP
Decree No. 53/2022/NĐ-CP detailing certain provisions of the Cybersecurity Law
In effect
↓ Documents affected by this document
Related 9
47/2023/QĐ-UBND Quyết định số 47/2023/QĐ-UBND Ban hành Điều lệ tổ chức và hoạt động của Quỹ Bảo lãnh tín dụng cho doanh nghiệp nhỏ và vừa tỉnh Vĩnh Phúc In effect 29/2026/QĐ-UBND Quyết định số 29/2026/QĐ-UBND Ban hành quy định khu vực, địa điểm đổ thải, nhận chìm ở biển đối với vật chất nạo vét từ hệ thống giao thông đường thủy nội địa và đường biển; tuyến đường, thời gian vận chuyển chất thải rắn công nghiệp thông thường phải xử lý và chất thải nguy hại trên địa bàn tỉnh Đồng Tháp In effect 36/2023/QĐ-UBND Quyết định số 36/2023/QĐ-UBND Phân cấp thẩm quyền cho các sở, ban, ngành, đoàn thể cấp tỉnh và UBND các huyện, thành phố ban hành tiêu chuẩn, định mức sử dụng máy móc, thiết bị chuyên dùng của các đơn vị thuộc phạm vi quản lý Expired 132/2025/QĐ-UBND Quyết định số 132/2025/QĐ-UBND Về việc ban hành quy định về bồi thường, hỗ trợ, tái định cư khi nhà nước thu hồi đất trên địa bàn tỉnh Thanh Hóa In effect 48/2024/QĐ-UBND Quyết định số 48/2024/QĐ-UBND Ban hành Bảng giá tính thuế tài nguyên trên địa bàn tỉnh Bà Rịa – Vũng Tàu năm 2025 Expired 40/2025/QĐ-UBND Quyết định số 40/2025/QĐ-UBND Quy định tỷ lệ (mức) khoán chi phí quản lý, xử lý tài sản là tang vật, phương tiện vi phạm hành chính bị tịch thu được xác lập quyền sở hữu toàn dân trên địa bàn tỉnh Lâm Đồng In effect 38/2024/QĐ-UBND Quyết định số 38/2024/QĐ-UBND Quy chế phối hợp cung cấp thông tin về nhà ở trên địa bàn tỉnh Bạc Liêu In effect

Click a document to open. A red border = a relation that changes validity.