Decision No. 71/2004/QĐ-BCA stipulates regulations on ensuring safety and security in the management, provision, and use of Internet services in Vietnam. These regulations apply to enterprises, units providing Internet services, Internet agents, and Internet service users. Notably, it requires enterprises to have technical equipment, establish operational rules, and cooperate with public security agencies to detect and prevent acts that infringe upon national security and social order and safety.
적용 범위
Internet service providers (IXP, ISP, OSP, ICP), Internet agents, and Internet service users in Vietnam.
핵심 사항
- Internet service providers must have technical equipment, establish operational rules, and cooperate with public security agencies to detect and prevent acts that infringe upon national security and social order and safety.
- Internet users must be responsible for the content they post and transmit on the Internet, report information harmful to national security, social order, and public safety.
- Violations of information safety and security regulations will be subject to fines ranging from VND 200,000 to VND 50,000,000 depending on the severity of the violation.
- The National Security Agency - Ministry of Public Security is the state administrative agency responsible for ensuring security in Internet activities, having the authority to inspect, control, and monitor information on the Internet.
- Internet service providers must report to the National Security Agency about network connection diagrams and measures to ensure safety and security before being permitted to provide services.
🌐 이 문서의 사회적 영향
- Positive impact: Helps prevent acts that infringe upon national security and social order and safety through the Internet.
- Negative impact: May impose a financial burden on enterprises when they need to invest in technical equipment to ensure safety and security.
- Internet service users have a higher responsibility in managing content information and reporting violations.
❓ 자주 묻는 질문
What must Internet service providers do to ensure safety and security?
Enterprises must have technical equipment, establish operational rules, cooperate with public security agencies, and report to the National Security Agency about measures to ensure safety and security before being permitted to provide services.
What responsibilities do Internet users have?
Users must be responsible for the content they post and transmit on the Internet. They need to report information harmful to national security, social order, and public safety.
How will violations of information safety and security regulations be punished?
Violations will be subject to fines ranging from VND 200,000 to VND 50,000,000 depending on the severity of the violation.
What responsibilities does the National Security Agency have?
The National Security Agency is the state administrative agency responsible for ensuring security in Internet activities, having the authority to inspect, control, and monitor information on the Internet and guide enterprises in implementing preventive, detection, and prevention work against acts that infringe upon national security.
What must Internet service providers report to the National Security Agency?
Enterprises must report network connection diagrams, plans, measures, and technical equipment to ensure safety and security in Internet activities before being permitted to provide services.
전문
|
MINISTRY OF PUBLIC SECURITY |
SOCIALIST REPUBLIC OF VIETNAM |
|
Number: 71/2004/QĐ-BCA |
Hanoi, January 29, 2004 |
DECISION OF THE MINISTER OF PUBLIC SECURITY
Regarding the issuance of regulations on ensuring safety and security in the management, provision, and use of Internet services in Vietnam
in accordance with
MINISTER OF PUBLIC SECURITY
Decree No. 136/2003/ND-CP dated November 14, 2003, of the Government stipulating the functions, tasks, powers, and organizational structure of the Ministry of Public Security;
Decree No. 55/2001/ND-CP dated August 23, 2001, of the Government on the management, provision, and use of Internet services;
At the proposal of the Director of the General Department of Security,
DECISION:
Article 1. This Decision promulgates "Regulations on Ensuring Safety and Security in the Management, Provision, and Use of Internet Services in Vietnam."
Article 2. This Decision shall take effect fifteen days from the date of publication in the Official Gazette and shall replace Decision No. 848/1997/QĐ-BNV (A11) dated October 23, 1997, of the Minister of Home Affairs (now the Ministry of Public Security) promulgating Regulations on Measures and Equipment for Ensuring National Security in Internet Activities in Vietnam.
Article 3Relevant units under the Ministry of Public Security, organizations, units, enterprises providing Internet services, Internet agents, and users of Internet services in Vietnam are responsible for implementing this Decision.
|
THE MINISTER |
REGULATIONS
ON ENSURING SAFETY AND SECURITY IN THE MANAGEMENT, PROVISION, AND USE OF INTERNET SERVICES IN VIETNAM
(Issued together with Decision No. 71/2004/QĐ-BCA (A11) dated January 29, 2004, of the Minister of Public Security)
PART I
GENERAL PROVISIONS
Article 1.These regulations apply to entities such as enterprises, units providing Internet services (Internet Exchange Point - IXP, Internet Service Provider - ISP, Internet Operating Service Provider - OSP, Internet Content Provider - ICP, Dedicated Internet Service Provider - ISP dedicated), Internet agents (agents providing access and application Internet services), and individuals using Internet services in Vietnam.
Article 2.Ensuring safety and security in Internet activities in Vietnam includes protecting systems, equipment, information, and data in databases and networks of participants in Internet activities to ensure stable operation; ensuring that information transmitted over the Internet is uninterrupted, intact, fast, and timely; proactively preventing, detecting, and blocking acts of exploiting Internet services to infringe upon national security and social order and safety.
Article 3Ensuring safety and security in Internet activities is the responsibility of agencies, organizations, and individuals. The Ministry of Public Security is the state administrative agency responsible for ensuring security in Internet activities, having the authority to inspect, supervise, and monitor information on the Internet according to the provisions of the law.
Article 4Every organization, enterprise, and individual participating in Internet activities in Vietnam must be responsible for the contents of information they store and transmit over the Internet; be subject to management, inspection, supervision, and implementation of requirements to ensure safety and security in Internet activities as stipulated in these regulations and other relevant laws.
Article 5.Strictly prohibited are the following acts:
1. Exploiting the Internet to engage in activities that infringe upon national security, social order and safety, violate Vietnamese customs and traditions, cultural identity, and the legitimate rights and interests of organizations and citizens, as well as conducting criminal activities through any form or means.
2. Storing on computers connected to the Internet information, documents, and data classified as state secrets.
3. Using cryptographic methods contrary to the provisions of the law on official seals.
4. Accessing foreign Internet service providers directly via international telephone calls; using or instructing others to use tools to access websites banned by competent state authorities; sending, spreading, disseminating computer viruses, software programs with features to steal information and destroy computer data onto the Internet; disrupting, hindering the provision and use of Internet services; establishing websites and forums on the Internet with content guiding, enticing, and inciting others to commit such acts.
5. Exploiting positions and powers in state administration regarding information security to obstruct the lawful activities of Internet service participants; infringing upon the legitimate rights and interests of agencies, organizations, and citizens.
PART II
SPECIFIC PROVISIONS
Article 6.Internet service enterprises have the responsibility to:
1. Equip with technical facilities commensurate with the scale of their operations to manage, inspect, and supervise to ensure safety for their systems, and block information prohibited by law from being stored and transmitted over the Internet through their managed systems.
2. Develop operational, exploitation, and usage guidelines for Internet services provided by the enterprise. Organize propaganda, guidance, and inspections of the implementation of these guidelines for enterprises using services (for ICPs, these are members providing content on the Internet), Internet agents, Internet service users, and employees within the enterprise.
3. Cooperate with functional units of the Ministry of Public Security and competent state agencies to detect, prevent, and handle acts of exploiting the Internet to engage in activities that infringe upon national security and social order and safety.
4. Immediately cease providing Internet services to entities that exploit the Internet to engage in activities against the Socialist Republic of Vietnam, causing harm to national security.
5. Provide premises, network access points, and necessary technical conditions for functional units of the Ministry of Public Security to carry out tasks related to national security protection in Internet activities.
6. Only provide public services after obtaining written permission from the Ministry of Posts and Telecommunications based on the report of the inter-ministerial inspection team according to Circular No. 04/2001/TT-TCBD dated November 20, 2001, of the General Post Office (now the Ministry of Posts and Telecommunications) guiding the implementation of Decree No. 55/2001/ND-CP dated August 23, 2001, of the Government on the management, provision, and use of Internet services (hereinafter referred to as Decree No. 55) regarding the results of actual network, equipment inspections, and measures to ensure the safety and security of Internet activities by the enterprise.
Article 7.
Organizations, enterprises providing Internet access services (ISP), Internet application services (OSP), units providing Internet information services (ICP), dedicated Internet access services (dedicated ISP) shall be responsible for:
1. Having a firewall system (Firewall) commensurate with the scale of each enterprise's operations to ensure detection and prevention of prohibited information as stipulated in Decree No. 55, as well as protecting the safety of equipment, information, and data of the enterprise or unit.
2. Information transmitted into and through the Internet must be retained on the server of the enterprise or unit for a period of 15 days, the retention period being calculated from the time the information arrives at or departs from the server.
3. Organizing training sessions for Internet agent employees to thoroughly understand the State regulations on information security and technical solutions suitable for agents to effectively guide customers in using services for legitimate purposes, promptly detecting and preventing customers who violate the provisions of Decree No. 55.
4. Internet access service providers (ISP and dedicated ISP) must cooperate with each other to prevent the misuse of their systems, networks, and services to cause disruption, destruction, and obstruction of Internet service provision and usage.
Article 8.Internet agents shall be responsible for:
1. Adhering to legal regulations concerning Internet information security. Establishing and publicly posting internal rules for Internet use at exploitation points.
2. Information related to service users must be retained on the agent's server for a period of 30 days, the retention period being calculated from the time the information arrives at or departs from the server.
3. Maintaining a detailed registration book of customer service usage that includes full details such as name, address, identity card number or passport number, and usage time. Must have measures to block access to websites with harmful content on the Internet and install software programs to manage customer information in real-time.
4. Assigning technical staff to manage and guide customers to use services for legitimate purposes, promptly detecting and preventing customers who violate legal regulations regarding the Internet.
5. Providing complete technical configuration data, network connection diagrams, and information traffic within the managed agency area truthfully, accurately, and comprehensively when requested by competent state management agencies.
6. Cooperating with public security agencies and other competent state agencies to implement requirements for ensuring information security and safety.
Article 9.Internet users shall be responsible for:
1. Being legally accountable for the contents of information they post and transmit on the Internet.
2. When receiving information that harms national security, social order, public safety, violates customs, and cultural traditions of Vietnam, they must not print, copy, distribute it, and immediately report it to the nearest public security agency for handling.
3. Protecting passwords, encryption keys, personal information content, and safeguarding their own Internet equipment systems.
Article 10.Agencies, organizations, and individuals participating in Internet activities shall be responsible for implementing the following reporting and information dissemination systems:
1. After obtaining permission to provide Internet services, enterprises and units must report to the General Bureau of Security - Ministry of Public Security the network connection diagram, plans, measures, and equipment to ensure security and safety during Internet activities, a list of key personnel and employees of the enterprise or unit, and the resumes of network administrators, system managers, and network operation staff, no later than 15 days before the inter-ministerial inspection team conducts an actual inspection, according to Circular No. 04/2001/TT-TCB dated November 20, 2001, issued by the General Post Office (now the Ministry of Posts and Telecommunications).
2. Every six months, Internet service providers must report to the General Bureau of Security - Ministry of Public Security on the results of implementing security and safety measures in Internet service provision and usage, changes and additions to network structure, lists of Internet agents, and Internet service subscribers; statistics on information providers and types of electronic news on the Internet according to a unified model, and organize strict monitoring and management.
3. Promptly reporting to public security agencies about activities violating information security, attacking and destroying equipment systems, obstructing Internet service provision, and other illegal acts; closely cooperating with public security agencies during the verification process to clarify the content of violations, and providing necessary information and documents related to the case upon request.
Article 11.
The Ministry of Public Security assigns the General Bureau of Security as the permanent body assisting the leadership of the Ministry of Public Security in directing and organizing work to ensure security and safety in Internet activities, and shall be responsible for:
1. Implementing and deploying operational measures to inspect, control, and monitor information on the Internet as prescribed by law.
2. Guiding agencies, organizations, and individuals participating in Internet activities to implement preventive measures, detect, and prevent activities exploiting Internet services to harm national security and social order and public safety.
3. Guiding provincial and centrally-administered city police forces to organize and implement work to ensure security and safety in Internet activities in their respective localities.
Article 12.
The General Bureau of Security directs functional bureaus and local police forces:
1. Conducting inspections every six months on the implementation of measures to ensure information security in Internet activities by service providers as stipulated in this Regulation.
2. Cooperating with specialized postal and telecommunications inspectors and information technology inspectors, and cultural and information inspectors to conduct inspections, investigations, and handle violations in Internet activities according to legal provisions.
Article 13.
Agencies, organizations, and individuals violating regulations on information security and safety in managing, providing, and using Internet services shall be subject to penalties according to the provisions of Articles 41 and 45 of Decree No. 55, depending on the nature and severity of the violation. Specifically as follows:
1. A fine of VND 200,000 to VND 1,000,000 for any of the following violations:
a) Using another person's password, encryption key, or personal information to access and use Internet services without authorization;
b) Using software tools to access and use Internet services without authorization.
2. A fine of VND 1,000,000 to VND 5,000,000 for any of the following violations:
a) Violating state regulations on encoding and decoding information on the Internet when using Internet services;
b) Violating state regulations on information security and safety on the Internet when using Internet services.
3. A fine of from VND 10,000,000 to VND 20,000,000 shall be imposed for any of the following violations:
a) Violating state regulations on encoding and decoding information on the Internet when providing Internet services;
b) Violating state regulations on information security and safety on the Internet when providing Internet services;
c) Using the Internet with the intent to threaten, harass, or defame others without reaching the level of criminal prosecution;
d) Posting or exploiting the Internet to disseminate pornographic information or other content that contravenes legal provisions on Internet content without reaching the level of criminal prosecution;
đ) Stealing passwords, encryption keys, or personal information of organizations or individuals and disseminating them to others for use;
e) Violating regulations on operating, exploiting, and using computers causing disruptions, blocking, or altering, destroying data on the Internet without reaching the level of criminal prosecution.
4. A fine of VND 20,000,000 to VND 50,000,000 for creating and intentionally spreading computer viruses on the Internet without reaching the level of criminal prosecution.
5. In addition to administrative penalties, depending on the nature and severity of the violation, organizations and individuals may also be subject to supplementary penalties or measures to rectify the consequences as follows:
a) Temporarily suspending or stopping the provision and use of Internet services for violations under points a, b, c, and d of Clause 1, points a and b of Clause 2, points a and b of Clause 3, and Clause 4 of Article 13 of this Regulation.
b) Compelling restoration to the original condition altered due to administrative violations for violations under point e of Clause 3 and Clause 4 of Article 13 of this Regulation.
6. Acts exploiting the Internet to oppose the Socialist Republic of Vietnam and disrupt public order, and other serious violations indicating criminal offenses will be prosecuted criminally according to the provisions of the law.
CHAPTER III
IMPLEMENTING PROVISIONS
Article 14. Based on this Regulation, organizations and enterprises providing Internet services in Vietnam shall establish internal management regulations for the Internet, manage users, manage information content, and technical measures for monitoring and ensuring information security and safety in Internet activities.
Article 15.
1. The General Security Department of the Ministry of Public Security shall direct relevant units to cooperate with competent agencies of the Ministry of Posts and Telecommunications, the Ministry of Culture and Information, and related ministries, sectors, and localities to examine technical solutions to ensure the security and safety of Internet operations of organizations, units, and enterprises providing Internet services from the time of licensing and periodically inspect the organization and implementation of this Regulation.
2. Agencies, organizations, and individuals encountering difficulties during the implementation of this Regulation should report to the Ministry of Public Security (through the General Security Department) for timely guidance and resolution./.
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.
번역본
이 문서는 다음 언어로 제공됩니다: