Circular No. 58/2015/TT-BQP stipulates coordination and response activities to computer network incidents in the Vietnam People's Army, applicable to relevant agencies, units, and individuals. These regulations guide the establishment of incident response networks, coordination organization, handling incident notifications, implementing incident responses, and determining responsibilities of parties involved.
적용 범위
Agencies, units, and individuals related to coordination and response activities to computer network incidents in the Vietnam People's Army.
핵심 사항
- The Directorate of Information Technology/General Staff Department is the coordinating body for computer network incident response activities, with the authority to mobilize other members of the response network to participate in preventing, handling, and resolving incidents.
- Members of the network have the responsibility to share information and experience, participate in incident response drill activities, and attend training courses on incident response activities.
- When encountering incidents that cannot be resolved independently, agencies and units must report the incident to one or more of the following network members: the coordinating body; the network member responsible for responding to incidents for that agency or unit (if applicable).
- The Directorate of Information Technology/General Staff Department is responsible for drafting, reporting to the General Staff Department Head for issuance or submission to competent authorities for issuance of regulatory documents guiding coordination and response activities to computer network incidents.
- Responsibilities of individuals participating in incident response include strictly adhering to established procedures and measures; promptly reporting unusual signs during resolution to authorized persons; not exploiting incident response activities to steal data or cause data leaks from the system.
🌐 이 문서의 사회적 영향
- Positive impact: Enhancing the ability to respond to computer network incidents in the military, protecting national defense information security.
- Negative impact: May incur financial and human resource costs to maintain management and incident response systems.
❓ 자주 묻는 질문
What responsibilities does the Directorate of Information Technology/General Staff Department have?
The Directorate of Information Technology/General Staff Department is the coordinating body for computer network incident response activities, with the authority to mobilize other members of the response network to participate in preventing, handling, and resolving incidents. Additionally, they are responsible for drafting, reporting to the General Staff Department Head for issuance or submission to competent authorities for issuance of regulatory documents guiding coordination and response activities to computer network incidents.
When encountering an incident, which entities must agencies and units report to?
When encountering incidents that cannot be resolved independently, agencies and units must report the incident to one or more of the following network members: the coordinating body; the network member responsible for responding to incidents for that agency or unit (if applicable).
What actions must agencies and units managing, operating, and using computer networks take when discovering incidents?
Agencies and units managing, operating, and using computer networks must apply technical measures to monitor the system, have plans to resolve incidents, and implement solutions to ensure information security. They must also provide information and actively cooperate with incident response network members in detecting, preventing, and handling incidents.
What responsibilities do individuals participating in incident response have?
Individuals participating in incident response must strictly adhere to established procedures and measures; promptly report unusual signs during resolution to authorized persons; not exploit incident response activities to steal data or cause data leaks from the system.
What responsibilities does the Directorate of Information Technology/General Staff Department have regarding training and drills?
The Directorate of Information Technology/General Staff Department is responsible for organizing training, instructing operations, and conducting drills for coordination and response activities to computer network incidents.
전문
CIRCULAR
Issued Article 24regulating coordination and emergency response activities for computer networks
withinArticle 24within the People's Army Vstrict N |||at s
__________________________
Pursuant to the Law on Legislative Documents of 2008;
Pursuant to the Law on Information Technology 2006;
Pursuant to the Law on Telecommunications 2009;
Pursuant to the Law on Cryptography 2011;
Pursuant to Decree No. 64/2007/NĐ-CP dated April 10, 2007 of the Government on the application of information technology in the activities of state agencies;
Pursuant to Decree No. 72/2013/NĐ-CP dated July 15, 2013 of the Government on management, provision, and use of Internet services and information on networks;
Pursuant to Decree No. 35/2013/NĐ-CP dated April 22, 2013 of the Government on the functions, tasks, powers, and organizational structure of the Ministry of National Defense;
Considering the proposal of the Chief of General Staff of the Vietnam People's Army;
The Minister of National Defense hereby decides.
Article 1. Issuing this Circular to regulate coordination and emergency response activities for computer networks within the Vietnam People's Army.
Article 2. This Circular takes effect from August 24, 2015.
Article 3. The Chief of General Staff, Commanders of agencies and units, and individuals related to the Vietnam People's Army are responsible for implementing this Circular./.
|
|
DEPUTY MINISTER |
REGULATIONS
COORDINATION AND EMERGENCY RESPONSE ACTIVITIES FOR COMPUTER NETWORKS
WITHIN THE VIETNAM PEOPLE'S ARMY
(Issued together with Circular No. 58/2015/TT-BQP dated July 8, 2015 of the Minister of National Defense)
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This regulation stipulates the emergency response network for computer networks within the Vietnam People's Army (QDNDVN); coordination and emergency response activities for computer networks within QDNDVN; responsibilities of agencies, units, and individuals related to coordination and emergency response activities for computer networks within QDNDVN.
Article 2. Applicability
This regulation applies to agencies, units, and individuals related to coordination and emergency response activities for computer networks within QDNDVN and those managing, operating, and utilizing computer networks within QDNDVN.
Article 3. Explanation of Terms
In this Regulation, the following terms shall be understood as follows:
1. Computer network within the Vietnam People's Army (referred to as computer network) is a general term referring to military computer networks and Internet networks used within the Vietnam People's Army.
2. Military computer network is a computer network designed specifically to serve management, command, operation, and control of weapons and technical equipment within QDNDVN; not connected to the Internet or other commercial networks. The military computer network includes internal computer networks of agencies and units; wide area computer networks within the Ministry of National Defense; military data transmission networks and resources on computer networks.
3. Internet network used within the Vietnam People's Army is a computer network within agencies and units that is connected to the Internet and applications, services provided by agencies and units on the Internet.
4. Computer network incident (referred to as incident) is an event that has occurred, is occurring, or has the potential to occur, causing information security breaches discovered through monitoring, evaluation, and analysis by relevant agencies, organizations, or individuals, or warned by experts, agencies, and units working in the field of information security.
5. Serious incident is an incident that could occur on a large scale, spread quickly; capable of destroying the computer network system within QDNDVN; requiring cooperation among many agencies and units within the Ministry of National Defense or at the national level to resolve.
6. Emergency response network for computer networks (referred to as network) is a collection of agencies, units, and organizations obligated to participate in emergency response activities for computer networks.
Article 7. Network members are agencies, units, and organizations participating in emergency response activities for computer networks.
Article 4. General Principles
Clause 1. Coordinate emergency response activities according to levels, regions, and within jurisdictional scope.
Clause 2. Organize emergency response activities for computer networks must follow the emergency response procedures based on the nature, severity, scope, and cause of the incident; ensuring speed, accuracy, timeliness, effectiveness, and information security.
Clause 3. Information exchanged and provided during coordination and handling incidents must be kept confidential according to the requirements of the agency or unit affected by the incident, except when the incident involves multiple parties and requires warning or notification.
Clause 4. The emergency response network for computer networks is part of the national emergency response network for computer networks directed and guided by the Ministry of Information and Communications.
Chapter II
EMERGENCY RESPONSE NETWORK FOR COMPUTER NETWORKS
Article 5. Computer Network Incident Response Network
1. Members of the computer network incident response network include:
a) The Information Technology Department of the General Staff Department;
b) The Military Security Protection Department of the Political General Department;
c) The Cryptographic Department of the General Staff Department;
d) The Telecommunications and Communication Corps;
e) The Military Telecommunications Group;
g) Information technology management agencies at various agencies and units;
h) The team participating in responding to incidents of critical national network infrastructure under the Ministry of National Defense.
2. Members of the network have the rights and obligations to share information, experience, participate in incident response exercise activities, and attend training courses on incident response activities.
Article 6. Coordination Agency for Computer Network Incident Response Activities.
1. The Information Technology Department of the General Staff Department is the coordination agency for the computer network incident response network (referred to as the coordination agency) with the functions:
a) Directing and guiding business operations related to coordination and incident response activities; having the authority to mobilize other members of the incident response network to participate in preventing, handling, and resolving incidents within the Ministry of National Defense;
b) Deciding on the form of coordination for incident response activities and being responsible for coordination requirements;
c) Exchanging information and cooperating in incident response with domestic and international computer incident response organizations and Internet service providers.
2. The Operations Duty Section of the Information Technology Department is the unit that receives information about incident response requests and implements orders to coordinate incident response activities throughout the military.
Article 7. Incident Response Point of Contact
1. The incident response point of contact is an individual or department authorized to represent the member of the network to communicate and exchange information with other members of the network during incident response activities.
2. Network members are responsible for organizing the incident response point of contact and reporting the incident response point of contact to the coordination agency.
3. The incident response point of contact is responsible for receiving coordination information, exchanging incident information with the coordination agency and the unit where the incident occurred.
4. Individuals serving as the incident response point of contact must have professional expertise and operational skills to carry out incident response activities and ensure continuous communication.
Chapter III
COMPUTER NETWORK INCIDENT RESPONSE AND COORDINATION
Article 8. Incident Reporting
1. Agencies and units encountering incidents that they cannot resolve themselves must report the incident to one or more of the following network members:
a) The coordination agency;
b) The network member responsible for responding to incidents for that agency or unit (if applicable);
2. When discovering serious incidents, agencies and units must immediately report them to the coordination agency.
3. The content of the incident report includes:
a) Information describing the incident;
b) Measures already taken or currently being implemented to address the incident;
c) Other information as required by the coordination agency;
d) Recommendations and proposals.
4. The coordination agency provides detailed guidance on incident reporting.
Article 9. Receiving and Processing Incident Reports
1. Network members receiving incident reports are responsible for:
a) Processing incident information and providing feedback within twelve hours to the agency, unit, or individual who submitted the report to confirm receipt of the incident report;
b) Handling the incident within their capacity and responsibility, and reporting the results of the incident handling to the coordination agency as prescribed;
c) Promptly reporting the incident to the coordination agency if it cannot be handled.
2. The coordination agency receiving incident reports is responsible for:
a) Issuing coordination requests to network members participating in incident response when necessary;
b) Mobilizing other resources, inviting experts to participate in incident response when necessary.
c) Reporting to the Chief of the General Staff Department to mobilize forces outside the military to participate in responding to computer network incidents in the Vietnam People's Army when necessary.
Article 10. Coordination
1. The coordinating agency shall be responsible for organizing coordination in accordance with the procedures and regulations on network computer incident response activities issued by competent authorities.
2. Network members shall be responsible for cooperating and participating in network computer incident response activities and national critical information systems as required by the coordinating agency.
3. Agencies and units experiencing incidents must coordinate with the coordinating agency and network members during the coordination and incident response process.
Article 11. Incident Response
1. Network members shall organize incident response in accordance with the procedures and regulations on incident response issued by competent authorities.
2. Network members shall accept coordination requests; closely cooperate with the unit where the incident occurred and other participating members to implement incident response activities in accordance with coordination requirements.
3. Network members shall regularly report the situation and results of their incident response tasks to the coordinating agency as prescribed.
4. Incident response work concludes when the incident is resolved and the system returns to normal operation.
5. After resolving the incident, network members participating in incident response shall have the responsibility to:
a) Review and determine the fundamental cause of the incident;
b) Organize rechecks and thoroughly resolve the incident;
c) Ensure the system operates normally before handing over the entire system to the managing agency or unit.
Article 12. Conclusion of Coordination and Incident Response
When concluding coordination and incident response activities, network members participating in incident response shall be responsible for summarizing the results of incident response activities; organizing lessons learned for incident response and resolution activities; reporting the results of implementation and recommendations (if any) to the coordinating agency.
Chapter IV
RESPONSIBILITIES OF AGENCIES, UNITS, AND INDIVIDUALS
Article 13. Directorate of Information Technology/General Staff Department
1. Take the lead in drafting and reporting to the General Staff Department's head for issuance or submission to competent authorities for issuance of regulatory documents and guidelines on coordination and incident response activities for network computers.
2. Receive and process incident information; take the lead in organizing coordination for network computer incident response activities.
3. Develop and deploy technical systems to support monitoring and detecting incidents; organize coordination and incident response activities; build centralized management and command databases for coordination and incident response activities.
4. Aggregate and publish to network members information on notifications, warnings, and solutions to address vulnerabilities and security weaknesses; threats to network computer safety.
5. Organize training, guide operations, and conduct drills for coordination and incident response activities for network computers.
6. Manage the operation of the National Critical Network Infrastructure Incident Response Team of the Ministry of Defense; mobilize forces within the network to be ready to participate in protecting national critical information systems.
7. Coordinate with agencies and units managing and operating national critical information systems; agencies and units, organizations outside the military involved in incident response to develop cooperation mechanisms and incident response procedures.
8. Coordinate with the Finance Directorate/Ministry of Defense and related agencies and units to study and allocate funding to ensure coordination and incident response activities for network computers.
9. Represent the Ministry of Defense to organize forces to participate in incident response activities outside the military when requested; participate in international cooperation on coordination and incident response.
Article 14. The Military Computer Network Security Bureau/General Political Department
1. Coordinate with the Information Technology Bureau/Business Administration and Trade Ministry and relevant agencies in activities to respond to computer network incidents and critical national information systems.
2. Investigate and verify organizations and individuals responsible for compromising information security or exploiting emergency response activities to steal data or leak information.
Article 15. The Cryptographic Bureau/Military General Staff
1. Develop plans and organize responses to incidents involving computer network security systems.
2. Coordinate with the Information Technology Bureau/Business Administration and Trade Ministry in activities to respond to computer network incidents and critical national information systems related to security systems and equipment.
Article 16. Telecommunications Forces
1. Develop plans and organize responses to incidents involving data transmission network infrastructure.
2. Coordinate with network members in providing information and technical support for resolving incidents related to data transmission networks.
3. Coordinate with the Information Technology Bureau/Business Administration and Trade Ministry in activities to respond to computer network incidents and critical national information systems.
4. Ensure communication services for coordination and response activities to computer network incidents when requested.
Article 17. Military Telecommunications Group
1. Organize the implementation of responses to incidents for products, services, and Internet network infrastructure provided by the Military Telecommunications Group to agencies and units.
2. Participate in activities to respond to computer network incidents and critical national information systems according to the coordination of the Coordination Agency.
3. Provide information and technical support for resolving incidents related to Internet network infrastructure and services of the Military Telecommunications Group.
4. Implement activities to respond to incidents on the Vietnam Internet network as prescribed by the Ministry of Information and Communications.
Article 18. Agencies and Units throughout the Military
1. Information technology management agencies:
a) Guide the implementation of incident response activities within their scope of responsibility;
b) Promptly mobilize local information technology forces and implement solutions to resolve incidents;
c) Report to the coordination agency to receive guidance and support from specialized forces;
d) Provide full information and closely coordinate with the coordination agency and network members participating in incident resolution;
e) Determine the cause, organize lessons learned, and implement measures to ensure that incidents do not recur;
2. Agencies and units managing, operating, and using computer networks:
a) Apply technical measures to monitor systems, have incident response plans, and implement information security assurance measures;
b) Provide information and actively coordinate with network members in incident detection, prevention, and handling activities.
Article 19. Responsibilities of Individuals
1. Individuals participating in incident response shall be responsible for:
a) Strictly adhere to established procedures and measures;
b) Timely report to authorized persons about unusual signs during the resolution process;
c) Not exploit incident response activities to steal data or cause data leaks from the system.
2. Individuals managing, operating, and utilizing computer networks shall be responsible for:
a) Timely report to information technology management agencies about unusual signs and incidents occurring;
b) Proactively provide information and actively coordinate in incident response activities.
Chapter V
IMPLEMENTATION
Article 20. Guidance and Inspection
The Directorate of Information Technology under the General Staff Department shall take the lead and coordinate with relevant agencies to provide guidance and inspect the implementation by agencies, units, and individuals within the Military; promptly identify and coordinate with relevant agencies to handle cases of violation of this Regulation.
Article 21. Organization of Implementation
1. Commanders of agencies and units within the scope of their functions, duties, and authorities shall be responsible for disseminating, guiding, implementing, inspecting, supervising, and urging the implementation of this Regulation.
2. In the course of implementing this Regulation, if any difficulties or inconsistencies arise, agencies and units shall report to the General Staff Department (through the Directorate of Information Technology) for consolidation and reporting to the Head of the Ministry of National Defense for amendment and supplementation./.
DEPUTY MINISTER
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.