The Law on Cyber Security stipulates regulations concerning information protection activities on networks, state management, and human resource development in this field. The Law applies to both Vietnam and foreign organizations/persons participating in cyber security activities in Vietnam.
适用范围
Vietnamese agencies, organizations, individuals; foreign organizations, individuals participating or related to cyber security activities in Vietnam.
要点
- Agencies, organizations, individuals must protect information on networks and may not infringe upon others' information security (Article 4).
- Classify information according to its level of confidentiality and apply appropriate protective measures (Article 9).
- Information senders must comply with regulations regarding origin, content, and may not send illegal commercial information (Article 10).
- Telecommunications enterprises have the responsibility to manage, prevent, and handle malicious software (Article 11).
- State agencies are responsible for protecting national cyber security and organizing emergency response (Article 14).
🌐 本文件的社会影响
- Create a secure environment for business operations and transactions on networks, reducing the risk of cyber attacks.
- Require organizations/individuals to comply with regulations on personal information protection, enhancing citizens' privacy rights.
- Develop human resources in the field of cyber security, improving awareness and skills among citizens.
❓ 常见问题
Which agency is responsible for protecting national cyber security?
The Ministry of Information and Communications is primarily responsible for coordinating emergency response work to ensure national cyber security (Article 14).
What requirements must information senders comply with when sending information on networks?
Do not forge the source, comply with legal regulations, and may not send commercial information to recipients' electronic addresses without their consent (Article 10).
What responsibilities do telecommunications enterprises have in protecting cyber security?
Must take measures to block and handle when notified of violations in sending information and provide technical conditions for state agencies to perform management tasks (Article 10).
What basis is there for businesses operating civil cryptography products and services?
Must have a Business License and meet conditions regarding staff, equipment, and technical plans (Article 31).
What regulations must businesses operating cyber security products and services comply with?
Must have a Business License, manage technical solution files and documents, and submit periodic reports (Article 46).
全文
LAW
INFORMATION SECURITY ON NETWORKS
______________
On the basis of the Constitution of the Socialist Republic of Vietnam;
The National Assembly enacts the Law on Information Security on Networks.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Law stipulates activities related to information security on networks, rights and responsibilities of agencies, organizations, and individuals in ensuring information security on networks; civil cryptography; technical standards and specifications for information security on networks; business operations in the field of information security on networks; human resource development for information security on networks; state management over information security on networks.
Article 2. Applicability
This Law applies to agencies, organizations, and individuals of Vietnam, and foreign organizations and individuals directly participating or being related to activities concerning information security on networks in Vietnam.
Article 3. Explanation of Terms
In this Law, the following terms shall be understood as follows:
1. Information security on networks is the protection of information and information systems on networks from unauthorized access, use, disclosure, disruption, modification, or destruction to ensure the integrity, confidentiality, and availability of information.
2. Network is the environment in which information is provided, transmitted, collected, processed, stored, and exchanged through telecommunications networks and computer networks.
3. Information system is a set of hardware, software, and databases established to serve the purpose of creating, providing, transmitting, collecting, processing, storing, and exchanging information on networks.
4. National important information system is an information system whose destruction would cause particularly serious harm to national defense and security.
5. Manager of information system is the agency, organization, or individual with direct authority to manage the information system.
6. Violation of information security on networks is the act of unauthorized access, use, disclosure, disruption, modification, or destruction of information or information systems.
7. Information security incident is the situation where information or information systems are harmed, affecting their integrity, confidentiality, or availability.
8. Information security risk is subjective or objective factors that can affect the state of information security on networks.
9. Information security risk assessment is the process of identifying, analyzing, and estimating the level of damage and threats to information or information systems.
10. Information security risk management is the process of implementing measures to mitigate information security risks.
11. Malicious software is software capable of causing abnormal operation of part or all of an information system or performing unauthorized copying, modification, or deletion of information stored in the information system.
12. Malicious software filtering system is a set of hardware and software connected to the network to detect, prevent, filter, and statistically analyze malicious software.
13. Electronic address is an address used to send and receive information on networks including email addresses, phone numbers, Internet addresses, and similar forms.
14. Information conflict is the situation where two or more domestic and foreign organizations use technological and informational methods to harm information or information systems on networks.
15. Personal information is information associated with the identification of a specific person.
16. Subject of personal information is the person identified from such personal information.
17. Processing of personal information is the execution of one or several actions to collect, compile, use, store, provide, share, disseminate personal information on networks for commercial purposes.
18. Civil cryptography is cryptographic techniques and products used to secure or authenticate information not within the scope of state secrets.
19. Network information security product is hardware or software with functions to protect information and information systems.
20. Network information security service is a service to protect information and information systems.
Article 4. Principles for Ensuring Cybersecurity
1. Agencies, organizations, and individuals have the responsibility to ensure cybersecurity. Cybersecurity activities of agencies, organizations, and individuals must comply with the provisions of the law, ensuring national defense, national security, state secrets, maintaining political stability, public order, social safety, and promoting economic and social development.
2. Organizations and individuals may not infringe upon the cybersecurity of other organizations and individuals.
3. Handling cybersecurity incidents must protect the rights and legitimate interests of organizations and individuals, without violating personal privacy, individual secrets, family secrets of individuals, and organizational private information.
4. Cybersecurity activities must be carried out continuously, promptly, and effectively.
Article 5. State Policy on Cybersecurity
1. Promote training, developing human resources, and building infrastructure and technical cybersecurity measures to meet requirements for political stability, economic and social development, ensuring national defense, national security, public order, and social safety.
2. Encourage research, development, and application of technical and technological measures, support export, and expand markets for cybersecurity products and services produced and provided by domestic organizations and individuals; create conditions for importing modern products and technologies that domestic organizations and individuals do not yet have the capacity to produce and provide.
3. Ensure a fair competitive environment in the business of cybersecurity products and services; encourage and create conditions for organizations and individuals to participate in investment, research, development, and provision of cybersecurity products and services.
4. The State allocates funds to ensure cybersecurity for state agencies and for critical national information systems.
Article 6. International Cooperation on Cybersecurity
1. International cooperation on cybersecurity must adhere to the following principles:
a) Respect for independence, sovereignty, and territorial integrity of states, non-interference in internal affairs, equality, and mutual benefit;
b) Compliance with Vietnamese law and international treaties to which the Socialist Republic of Vietnam is a party.
2. Contents of international cooperation on cybersecurity include:
a) International cooperation in training, research, and application of science, technology, and engineering related to cybersecurity;
b) International cooperation in preventing and combating illegal acts concerning cybersecurity; investigation and handling of cybersecurity incidents, and prevention of terrorist activities using networks;
c) Other international cooperative activities related to cybersecurity.
Article 7. Prohibited acts
1. Preventing the transmission of information on networks, unauthorized access, causing harm, deleting, changing, copying, and distorting information on networks illegally.
2. Illegally affecting or hindering the normal operation of information systems or users' ability to access such systems.
3. Illegally attacking and rendering ineffective cybersecurity measures of information systems; illegally attacking and taking control of, or destroying information systems.
4. Spreading spam, malicious software, establishing fake information systems, and committing fraud.
5. Illegally collecting, using, disseminating, and trading personal information of others; exploiting vulnerabilities and weaknesses of information systems to collect and exploit personal information.
6. Illegally accessing cryptographic secrets and legally encrypted information of agencies, organizations, and individuals; disclosing information about civilian cryptographic products, information about customers legally using civilian cryptographic products; using and trading civilian cryptographic products of unknown origin.
Article 8. Handling Violations of Laws on Information Security
Any person who commits acts violating the provisions of this Law shall be subject to disciplinary action, administrative sanctions, or criminal prosecution depending on the nature and severity of the violation; if damage is caused, compensation must be provided according to the law.
Chapter II
INFORMATION SECURITY SAFEGUARD
Section 1
INFORMATION PROTECTION
Article 9. Classification of Information
1. Agencies and organizations owning information classify information based on its confidential attributes to implement appropriate protective measures.
2. Information within the scope of state secrets is classified and protected in accordance with the laws on protecting state secrets.
Agencies and organizations using classified and unclassified information in their activities must establish regulations and procedures for handling such information; determine the content and methods of permitted access to classified information.
Article 10. Management of Information Transmission
1. The transmission of information over networks must meet the following requirements:
a) Not to forge the source of transmitted information;
b) To comply with the provisions of this Law and other relevant laws.
2. Organizations and individuals may not send commercial information to the electronic address of the recipient without the recipient's consent or after the recipient has refused, except when the recipient is legally obligated to receive such information.
3. Telecommunications enterprises, telecommunications application service providers, and information technology service providers transmitting information have the following responsibilities:
a) To comply with the laws on storing information, protecting personal data, and private information of organizations and individuals;
b) To apply preventive measures and handle violations upon receiving notifications from organizations or individuals regarding illegal information transmission;
c) To provide means for recipients to refuse receipt of information;
d) To provide technical and operational conditions necessary for competent state agencies to perform management tasks and ensure network information security when requested.
Article 11. Prevention, Detection, Blocking, and Handling Malicious Software
1. Agencies, organizations, and individuals are responsible for implementing prevention and blocking of malicious software according to the guidance and requirements of competent state agencies.
2. Managers of critical national information systems deploy technical and operational systems to prevent, detect, block, and promptly handle malicious software.
3. Email service providers, information transmission, and storage service providers must have systems to filter out malicious software during the sending, receiving, and storing of information on their systems and report to competent state agencies as prescribed by law.
4. Internet service providers must take measures to manage, prevent, detect, block the spread of malicious software, and handle it according to the requirements of competent state agencies.
5. The Ministry of Information and Communications takes the lead, coordinating with the Ministry of National Defense, the Ministry of Public Security, and related ministries and sectors to organize the prevention, detection, blocking, and handling of malicious software that affects national defense and security.
Article 12. Ensuring the Safety of Telecommunications Resources
1. Organizations, individuals using telecommunications resources shall have the following responsibilities:
a) Implement management and technical measures to prevent information security incidents originating from their frequencies, numbers, domain names, and Internet addresses;
b) Cooperate and provide relevant information on the safety of telecommunications resources upon request of competent state agencies.
2. Internet service providers shall have the responsibility to manage and cooperate to prevent information security incidents originating from Internet resources and their customers; provide complete information as required by competent state agencies; connect and route to ensure the safe and stable operation of the national domain name server system of Vietnam.
3. The Ministry of Information and Communications shall be responsible for ensuring the safety of the national domain name server system.
Article 13. Emergency Response to Information Security Incidents
1. Emergency response to information security incidents is an activity aimed at handling and rectifying incidents causing information security breaches.
2. Emergency response to information security incidents must comply with the following principles:
a) Timely, swift, accurate, synchronized, and effective;
b) Compliance with legal regulations on coordinating emergency response to information security incidents;
c) Cooperation between domestic and foreign agencies, organizations, and enterprises.
3. Ministries, ministerial-level agencies, government-affiliated agencies, provincial People's Committees, telecommunications enterprises, and managers of important national information systems must establish or designate specialized units for emergency response to information security incidents.
4. The Ministry of Information and Communications shall be responsible for coordinating emergency response to information security incidents nationwide; detailing regulations on coordinating emergency response to information security incidents.
Article 14. Urgent Measures to Ensure National Information Security
1. Urgent measures to ensure national information security are emergency response activities conducted during disaster situations or upon request of competent state agencies to ensure national information security.
2. Urgent measures to ensure national information security must comply with the following principles:
a) Organized implementation according to levels;
b) On-site implementation, swift, strict, and closely coordinated;
c) Application of technical measures to ensure effectiveness and feasibility.
3. The system of urgent measures to ensure national information security includes:
a) Urgent measures to ensure national information security;
b) Urgent measures to ensure information security of state agencies, political organizations, and socio-political organizations;
c) Urgent measures to ensure information security of localities;
d) Urgent measures to ensure information security of telecommunications enterprises.
4. Responsibilities for ensuring national information security are stipulated as follows:
a) The Prime Minister decides on the system of urgent measures to ensure national information security;
b) The Ministry of Information and Communications shall be responsible for coordinating urgent measures to ensure national information security;
c) Ministries, sectors, People's Committees at all levels, and related agencies and organizations within their scope of duties and powers shall be responsible for cooperating and directing urgent measures to ensure national information security;
d) Telecommunications enterprises shall be responsible for implementing urgent measures, cooperating with the Ministry of Information and Communications, ministries, sectors, and People's Committees at all levels to ensure national information security.
Article 15. Responsibilities of agencies, organizations, and individuals in ensuring cybersecurity
1. Agencies, organizations, and individuals participating in cybersecurity activities shall cooperate with competent state agencies and other organizations and individuals to ensure cybersecurity.
2. Agencies, organizations, and individuals using services on networks shall promptly notify service providers or dedicated incident response units upon discovering acts of sabotage or cybersecurity incidents.
Section 2
PROTECTION OF PERSONAL INFORMATION
Article 16. Principles for protecting personal information on networks
1. Individuals shall protect their own personal information and comply with legal provisions regarding the provision of personal information when using network services.
2. Agencies, organizations, and individuals processing personal information shall be responsible for ensuring the security of personal information they handle.
3. Organizations and individuals processing personal information must establish and publicly disclose measures for handling and protecting personal information.
4. The protection of personal information shall be carried out in accordance with this Law and other relevant legal provisions.
5. Processing personal information for purposes of national defense, national security, public order, social safety, or not for commercial purposes shall be conducted in accordance with other relevant legal provisions.
Article 17. Collection and use of personal information
1. Organizations and individuals processing personal information shall have the following responsibilities:
a) Collect personal information only after obtaining the consent of the subject concerning the scope and purpose of collecting and using such information;
b) Only use collected personal information for purposes other than the original purpose after obtaining the consent of the subject;
c) Shall not provide, share, or disseminate personal information they have collected, accessed, or controlled to third parties without the consent of the subject or at the request of a competent state agency.
2. State agencies shall be responsible for securing and storing personal information they collect.
3. Personal information subjects have the right to request organizations and individuals processing personal information to provide them with their personal information that has been collected and stored.
Article 18. Updating, modifying, and deleting personal information
1. Personal information subjects have the right to request organizations and individuals processing personal information to update, modify, delete their personal information that has been collected and stored or cease providing it to third parties.
2. Upon receiving requests from personal information subjects to update, modify, delete personal information or to stop providing it to third parties, organizations and individuals processing personal information shall undertake the following responsibilities:
a) Fulfill the request and inform the personal information subject or provide them with access rights to update, modify, or delete their personal information themselves;
b) Apply appropriate measures to protect personal information and inform the personal information subject if the request cannot be fulfilled due to technical or other factors.
3. Organizations and individuals processing personal information must delete stored personal information once its intended use is completed or the storage period has expired and inform the personal information subject, except where otherwise provided by law.
Article 19. Ensuring Personal Data Security on Networks
1. Organizations and individuals processing personal data must apply appropriate management and technical measures to protect personal data they collect and store; comply with technical standards and norms for ensuring network security.
2. When a network security incident occurs or there is a risk of such an occurrence, organizations and individuals processing personal data need to take remedial and preventive measures as soon as possible.
Article 20. Responsibilities of State Management Agencies in Protecting Personal Data on Networks
1. Establish online channels to receive complaints and reflections from organizations and individuals related to ensuring personal data security on networks.
2. Conduct regular annual inspections and audits of organizations and individuals processing personal data; conduct surprise inspections when necessary.
Section 3
PROTECTING INFORMATION SYSTEMS
Article 21. Classification of Information System Security Levels
1. Classifying information system security levels involves determining the security level of information systems on an ascending scale from 1 to 5 to apply management and technical measures suitable for protecting information systems according to each level.
2. Information systems are classified according to security levels as follows:
a) Level 1 is the level where destruction would harm the legitimate rights and interests of organizations and individuals but not public interest, social order, safety, national defense, and national security.
b) Level 2 is the level where destruction would seriously harm the legitimate rights and interests of organizations and individuals or public interest but not social order, safety, national defense, and national security.
c) Level 3 is the level where destruction would seriously harm production, public interest, and social order or national defense and national security.
d) Level 4 is the level where destruction would cause particularly serious harm to public interest and social order or seriously harm national defense and national security.
đ) Level 5 is the level where destruction would cause particularly serious harm to national defense and national security.
3. The Government shall provide detailed regulations on criteria, authority, procedures, and processes for determining information system security levels and responsibilities for ensuring information system security at each level.
Article 22. Tasks for Protecting Information Systems
1. Determine the security level of information systems.
2. Assess and manage risks to information system security.
3. Supervise, monitor, and inspect information system protection work.
4. Organize the implementation of information system protection measures.
5. Implement reporting procedures as prescribed.
6. Organize publicity and raise awareness about network security.
Article 23. Measures for Protecting Information Systems
1. Issue regulations on ensuring network security in the design, construction, management, operation, use, upgrading, and decommissioning of information systems.
2. Apply management and technical measures according to technical standards and norms for network security to prevent and address network security threats and incidents.
3. Inspect and supervise compliance with regulations and evaluate the effectiveness of applied management and technical measures.
4. Monitor information system security.
Article 24. Supervision of Information System Security
1. Supervision of information system security is an activity selecting supervised objects, collecting, analyzing the status of information of the supervised objects to determine factors affecting information system security; reporting and warning about actions that violate network security or actions that may cause information security incidents for information systems; conducting analysis of critical factors affecting the status of network security; proposing changes to technical measures.
2. The objects of supervision of information system security include firewalls, access control, main communication lines, important servers, important devices, or important terminal devices.
3. Telecommunications enterprises, information technology service providers, and network security service providers have the responsibility to cooperate with the managers of information systems in supervising information system security according to the requirements of competent state agencies.
Article 25. Responsibilities of Information System Managers
1. Information system managers are responsible for implementing protection of information systems as prescribed in Articles 22, 23, and 24 of this Law.
2. Information system managers using state budget funds to fulfill the responsibilities prescribed in Clause 1 of this Article shall also be responsible for the following:
a) Having a plan to ensure network security that has been reviewed by a competent state agency when establishing, expanding, or upgrading information systems;
b) Designating individuals or departments responsible for network security.
Article 26. National Important Information Systems
1. When establishing, expanding, and upgrading national important information systems, it is necessary to conduct a security assessment before operation and exploitation.
2. The Ministry of Information and Communications shall take the lead and coordinate with the Ministry of Defense, the Ministry of Public Security, and relevant ministries and sectors to build a list of national important information systems to submit for approval by the Prime Minister. for promulgation by the Prime Minister.
Article 27. Responsibilities for Ensuring Network Security for National Important Information Systems
1. National important information system managers shall be responsible for the following:
a) Implementing the provisions of Clause 2 of Article 25 of this Law;
b) Regularly assessing network security risks. Risk assessments must be conducted by specialized organizations designated by competent state agencies;
c) Implementing preventive measures for information systems;
d) Developing plans to protect, developing and rehearsing protection plans for national important information systems.
2. The Ministry of Information and Communications shall be responsible for the following:
a) Taking the lead and coordinating with national important information system managers, the Ministry of Public Security, and relevant ministries and sectors to guide, urge, inspect, and supervise the work of protecting network security for national important information systems, except for systems specified in Clauses 3 and 4 of this Article;
b) Requesting telecommunications enterprises, information technology service providers, and network security service providers to participate in consulting, providing technical support, and responding to network security incidents for national important information systems.
3. The Ministry of Public Security shall take the lead in guiding, urging, inspecting, and supervising the work of protecting network security for national important information systems under its management; coordinating with the Ministry of Information and Communications, national important information system managers, relevant ministries and sectors, and People's Committees at all levels in protecting other national important information systems when requested by competent state agencies.
4. The Ministry of Defense shall take the lead in guiding, urging, inspecting, and supervising the work of protecting network security for national important information systems under its management.
5. The Government Cryptographic Office shall take the lead in organizing the implementation of cryptographic solutions to protect information in national important information systems of state agencies, political organizations, and political-social organizations; coordinating with national important information system managers in monitoring network security in accordance with the law.
Section 4
PREVENTING INFORMATION CONFLICTS ON THE NETWORK
Article 28. Responsibilities of organizations and individuals in preventing information conflicts on the internet
1. Within their duties and powers, organizations and individuals shall have the following responsibilities:
a) Prevent destructive information originating from their own information systems; cooperate to identify sources, repel, and mitigate consequences of cyber attacks carried out through domestic and foreign organizations' and individuals' information systems;
b) Prevent actions by domestic and foreign organizations and individuals with the purpose of destroying the integrity of the network;
c) Eliminate the organization's implementation of unlawful activities on the internet that seriously affect national defense, national security, public order, and social safety of domestic and foreign organizations and individuals.
2. The Government shall provide detailed regulations on preventing information conflicts on the internet.
Article 29. Prevention of activities using the internet for terrorism
1. Measures to prevent activities using the internet for terrorism include:
a) Disabling Internet sources used to commit terrorist acts;
b) Preventing the establishment and expansion of information exchanges about signals, factors, methods, and ways of using the Internet to commit terrorist acts, about targets and activities of terrorist organizations on the internet;
c) Exchanging experiences and practices in controlling Internet sources, finding and monitoring the content of websites with terrorist purposes.
2. The Government shall provide detailed regulations on the responsibility for implementing and measures to prevent activities using the internet for terrorism as stipulated in Clause 1 of this Article.
Chapter III
CIVIL CRYPTOGRAPHY
Article 30. Civil cryptography products and services
1. Civil cryptography products are documents, technical and operational equipment for protecting information not within the scope of state secrets.
2. Civil cryptography services include information protection services using civil cryptography products; testing and evaluating civil cryptography products; consulting on security and network information safety using civil cryptography products.
Article 31. Business of civil cryptography products and services
1. Enterprises must have a License for Civil Cryptography Products and Services when conducting business in civil cryptography products and services listed in the List of Civil Cryptography Products and Services.
2. Enterprises shall be granted a License for Civil Cryptography Products and Services when meeting the following conditions:
a) Having a management and technical staff team meeting the professional requirements for security and information safety;
b) Having a system of equipment and infrastructure suitable for the scale of providing civil cryptography products and services;
c) Having a technical plan consistent with technical standards and specifications;
d) Having a security and network information safety plan during the management and provision of civil cryptography products and services;
e) Having a business plan appropriate to the situation.
3. Civil cryptography products must be tested and certified before being circulated in the market.
4. Enterprises granted a License for Civil Cryptography Products and Services must pay fees as prescribed by laws on fees and charges.
5. The Government shall issue the List of Civil Cryptography Products and Services and provide detailed regulations on this matter.
Article 32. Procedures and formalities for applying for a License for Civil Cryptography Products and Services
1. Enterprises applying for a License for Civil Cryptography Products and Services shall submit the application at the General Office for Official Communications.
2. The application for a License for Civil Cryptography Products and Services shall be prepared in two copies, including:
a) An application form for a License for Civil Cryptography Products and Services;
b) A copy of the Enterprise Registration Certificate or Investment Registration Certificate or other equivalent documents;
c) Copies of diplomas or certificates of expertise in security and cybersecurity of the management, operational, and technical teams;
d) A technical plan including documentation on the technical characteristics and parameters of the product; technical standards and specifications of the product; service standards and quality; technical measures and solutions; warranty and maintenance plans for the product;
e) A security and network information safety plan during the management and provision of civil cryptography products and services;
f) A business plan including the scope, target audience, quantity scale of products and services, customer service systems, and technical assurance.
3. Within thirty days from the date of receiving all documents, the General Office for Official Communications shall review and grant a License for Civil Cryptography Products and Services; if refusal, it must notify in writing and specify the reasons.
4. The License for Civil Cryptography Products and Services has a validity period of ten years.
Article 33. Amending, Supplementing, Reissuing, Extending, Temporarily Suspending, and Revoking Civil Cryptographic Product and Service Business Licenses
1. The amendment and supplementation of civil cryptographic product and service business licenses shall be carried out when a business entity has changed its name, legal representative, or added, supplemented civil cryptographic products and services after being granted a license.
The business entity is responsible for submitting the application dossier to amend and supplement the License at the Government General Office. The dossier shall be prepared in two copies, including:
a) Application form for amending and supplementing the License;
b) A copy of the Enterprise Registration Certificate or Investment Registration Certificate or other equivalent documents;
c) The Business License for Civil Cryptographic Products and Services that has been issued;
d) Technical plan, security plan, and network information security plan, business plan for additional civil cryptographic products and services as stipulated in Points d, đ, and e Clause 2 Article 32 of this Law in cases where the business entity requests to supplement civil cryptographic products and services, business sectors;
Within ten working days from the date of receiving all necessary documents, the Government General Office shall review, amend, supplement, and reissue the License to the business entity; if the issuance is refused, it must notify in writing and specify the reasons.
2. In case the civil cryptographic product and service business License is lost or damaged, the business entity shall submit an application for reissuing the License to the Government General Office, clearly stating the reason. Within five working days from the date of receipt of the application, the Government General Office shall examine and reissue the License to the business entity.
3. A business entity that does not violate the laws on conducting civil cryptographic product and service business may have its business License extended once for a period not exceeding one year.
The application dossier for extending the License must be submitted to the Government General Office no later than sixty days before the expiration date of the License. The dossier for extending the License shall be prepared in two copies, including:
a) Application form for extending the License;
b) The current valid Business License for Civil Cryptographic Products and Services;
c) Reports on the business activities of the enterprise in the last two years.
Within twenty days from the date of receiving all necessary documents, the Government General Office shall review and decide to extend and reissue the License to the business entity; if the issuance is refused, it must notify in writing and specify the reasons.
4. A business entity shall be temporarily suspended from conducting civil cryptographic product and service business for a period not exceeding six months in the following cases:
a) Providing products and services not in accordance with the contents recorded on the License;
b) Failing to meet any of the conditions stipulated in Clause 2 Article 31 of this Law;
c) Other cases as prescribed by law.
5. A business entity shall have its civil cryptographic product and service business License revoked in the following cases:
a) Not implementing the provision of services within one year from the date of issuance of the License without a valid reason;
b) The permit has expired;
c) Exceeding the suspension period without rectifying the reasons specified in Clause 4 of this Article.
Article 34. Exporting and Importing Civil Cryptographic Products
1. When exporting or importing civil cryptographic products listed in the Civil Cryptographic Product Export and Import List under the License, the business entity must have an export and import License for civil cryptographic products issued by the competent state agency.
2. A business entity shall be granted an export and import License for civil cryptographic products if it meets the following conditions:
a) Having a License for civil cryptographic product and service business;
b) Imported civil cryptographic products must be certified and declared compliant according to Article 39 of this Law;
c) The object and purpose of using civil cryptographic products do not harm national defense, national security, and public order and safety.
3. The application dossier for issuing an export and import License for civil cryptographic products includes:
a) Application form for issuing an export and import License for civil cryptographic products;
b) A copy of the business license for civil cryptographic products and services;
c) A copy of the conformity certification for imported civil cryptographic products.
4. Within ten working days from the date of receiving all necessary documents, the Government General Office shall review and issue the export and import License for civil cryptographic products to the business entity; if the issuance is refused, it must notify in writing and specify the reasons.
5. The Government shall promulgate the Civil Cryptographic Product Export and Import List under the License and provide detailed regulations on this matter.
Article 35. Responsibilities of Enterprises Engaging in Civil Cryptographic Products and Services Business
1. Managing files and documents related to technical solutions and technology of products.
2. Establishing, retaining, and safeguarding customer information, including names, types, quantities, and purposes of using civil cryptographic products and services.
3. Annually reporting to the Government’s Administrative Technical Department on business conditions, export, import of civil cryptographic products and services, and compiling customer information before December 31.
4. Implementing measures to ensure security and safety during transportation and storage of civil cryptographic products.
5. Refusing to provide civil cryptographic products and services when discovering organizations or individuals violating laws on the use of such products and services, or breaching commitments regarding their use as agreed with the enterprise.
6. Temporarily suspending or ceasing provision of civil cryptographic products and services to ensure national defense, security, public order, and social safety at the request of competent state agencies.
7. Cooperating and facilitating competent state agencies in implementing investigative measures upon request.
Article 36. Responsibilities of Organizations and Individuals Using Civil Cryptographic Products and Services
1. Adhering to management regulations for cryptographic keys, transfer, repair, maintenance, abandonment, and destruction of civil cryptographic products, as well as other relevant matters, as committed to the enterprise providing such products.
2. Providing necessary information related to cryptographic keys to competent state agencies upon request.
3. Cooperating and facilitating competent state agencies in implementing preventive measures against crimes involving theft of information and cryptographic keys, and illegal use of civil cryptographic products.
4. Organizations and individuals using civil cryptographic products not provided by enterprises licensed to engage in such product business must report to the Government’s Administrative Technical Department, except for diplomatic missions, consular offices of foreign countries, and representative offices of international intergovernmental organizations in Vietnam.
Chapter IV
INFORMATION SECURITY NETWORK TECHNICAL STANDARDS AND REGULATIONS
Article 37. Information Security Network Technical Standards and Regulations
1. Information security network standards include international standards, regional standards, foreign standards, national standards, and basic standards applicable to information systems, hardware, software, management, and operation of information security networks in Vietnam.
2. Information security network technical regulations include national technical regulations and local technical regulations applicable to information systems, hardware, software, management, and operation of information security networks established, issued, and applied in Vietnam.
Article 38. Management of Information Security Network Technical Standards and Regulations
1. Conformity certification for information security networks involves certifying that information systems, hardware, software, management, and operation of information security networks comply with information security network technical regulations.
2. Conformity declaration for information security networks involves announcing that information systems, hardware, software, management, and operation of information security networks comply with information security network technical regulations.
3. Standard conformity certification for information security networks involves certifying that information systems, hardware, software, management, and operation of information security networks comply with information security network standards.
4. Standard conformity declaration for information security networks involves announcing that information systems, hardware, software, management, and operation of information security networks comply with information security network standards.
5. The Ministry of Science and Technology shall take the lead and coordinate with relevant agencies to assess and announce national standards on information security according to the law on technical standards and regulations.
6. The Ministry of Information and Communications shall have the following responsibilities:
a) Drafting national standards on information security, except for national standards specified in Clause 7 of this Article;
b) Issuing national technical regulations on information security, except for national technical regulations specified in Clause 7 of this Article; and provisions on conformity assessment for information security;
c) Managing the quality of information security products and services, except for cryptographic products and services;
d) Registering, designating, and managing the activities of conformity certification organizations for information security, except for organizations certifying conformity for cryptographic products and services.
7. The Government’s Administrative Technical Department shall assist the Minister of National Defense in drafting national standards for cryptographic products and services, submitting them to competent state agencies for announcement and guidance on implementation; drafting and submitting to the Minister of National Defense for issuance of national technical regulations for cryptographic products and services; designating and managing the activities of conformity certification organizations for cryptographic products and services; and managing the quality of cryptographic products and services.
8. Provincial People's Committees shall draft, issue, and guide the implementation of local technical regulations on information security; manage the quality of information security products and services within their jurisdiction.
Article 39. Evaluation for conformity and compliance with information security standards
1. The evaluation for conformity and compliance with information security standards shall be carried out in the following cases:
a) Before organizations or individuals bring information security products to market circulation, they must conduct certification for compliance or declare compliance and use the compliance mark;
b) To serve state management activities on information security.
2. The evaluation for conformity and compliance with information security standards serving the national important information systems and state management activities on information security shall be conducted at conformity assessment organizations designated by the Minister of Information and Communications.
3. The evaluation for conformity and compliance with information security standards for civil cryptographic products and services shall be conducted at conformity assessment organizations designated by the Minister of National Defense.
4. The recognition of evaluation results for conformity and compliance with information security standards between Vietnam and other countries or territories, and between conformity assessment organizations in Vietnam and those in other countries or territories shall be carried out in accordance with the laws on technical standards and regulations.
Chapter V
BUSINESS IN THE FIELD OF INFORMATION SECURITY
Section 1
ISSUANCE OF BUSINESS LICENSE FOR INFORMATION SECURITY PRODUCTS AND SERVICES
Article 40. Business in the field of information security
1. Business in the field of information security is a business sector subject to conditions. Business in the field of information security includes business in information security products and business in information security services.
2. Enterprises engaged in business in information security products and services as stipulated in Article 41 of this Law must have a Business License for Information Security Products and Services issued by competent state agencies. The validity period of the Business License for Information Security Products and Services is ten years.
3. Business in information security products and services must comply with the provisions of this Law and other relevant laws.
Conditions for business, procedures for issuing Business Licenses for civil cryptographic products and services, export and import of civil cryptographic products, responsibilities of enterprises engaged in civil cryptographic products and services, and the use of such products and services shall be implemented in accordance with the provisions of Chapter III of this Law.
Conditions for business, procedures for issuing Business Licenses for electronic signature verification services shall be implemented in accordance with the laws on electronic transactions.
Article 41. Products and services in the field of information security
1. Information security services include:
a) Information security testing and evaluation services;
b) Information security services without using civil cryptography;
c) Civil cryptography services;
d) Electronic signature verification services;
đ) Information security consulting services;
e) Information security monitoring services;
g) Information security incident response services;
h) Data recovery services;
i) Cyber attack prevention and defense services;
k) Other information security services.
2. Information security products include:
a) Civil cryptography products;
b) Information security testing and evaluation products;
c) Information security monitoring products;
d) Intrusion prevention and defense products;
đ) Other information security products.
3. The Government shall provide detailed regulations on the list of information security products and services specified in point k Clause 1 and point đ Clause 2 of this Article.
Article 42. Conditions for Issuing a Business License for Network Security Products and Services
1. A business entity shall be issued a Business License for network security products and services, except for those specified in points a, b, c, d of Clause 1 and point a of Clause 2 of Article 41 of this Law, when it meets the following conditions:
a) In accordance with the national strategy, planning, and plan for network security development;
b) Possessing a system of equipment and physical facilities suitable to the scale of providing network security products and services;
c) Having a management and technical staff team meeting the professional requirements for network security;
d) Having a business plan that is appropriate.
2. A business entity shall be issued a Business License for network security testing and evaluation services when it meets the following conditions:
a) The conditions prescribed in Clause 1 of this Article;
b) Being a business entity established and legally operating within the territory of Vietnam, except for foreign-invested enterprises;
c) The legal representative, management, and technical staff being Vietnamese citizens residing permanently in Vietnam;
d) Possessing a technical plan that complies with technical standards and regulations;
đ) Possessing a customer information protection plan during service provision;
e) The management, operation, and technical staff having academic degrees or certificates in network security testing and evaluation.
3. A business entity shall be issued a Business License for non-cryptographic civil information security services when it meets the following conditions:
a) The conditions stipulated in points a, b, c, d, and đ of Clause 2 of this Article;
b) The management and technical staff having academic degrees or certificates in information security.
4. The Government shall provide detailed regulations on this matter.
Article 43. Application Documents for Issuing a Business License for Network Security Products and Services
1. A business entity applying for a Business License for network security products and services shall submit the application documents to the Ministry of Information and Communications.
2. The application documents for issuing a Business License for network security products and services shall be prepared in five copies, including:
a) An application form for a Business License for network security products and services, specifying the type of network security products and services to be operated;
b) A copy of the Enterprise Registration Certificate, Investment Registration Certificate, or other equivalent documents;
c) A description of the technical equipment system ensuring compliance with legal provisions;
d) A business plan including the scope and target customers for product and service provision, product and service standards and quality;
đ) Copies of academic degrees or certificates of the management, operation, and technical staff in network security.
3. In addition to the documents and materials specified in Clause 2 of this Article, the application documents for issuing a Business License for network security testing and evaluation services or non-cryptographic civil information security services must also include:
a) Criminal record sheets of the legal representative and management, operation, and technical staff;
b) A technical plan;
c) A customer information protection plan during service provision.
Article 44. Review of Application Documents and Issuance of a Business License for Network Security Products and Services
1. Within forty days from the date of receipt of all application documents, the Ministry of Information and Communications shall lead and coordinate with relevant ministries and sectors to review and issue a Business License for network security products and services, except for the products and services specified in point c, point d of Clause 1 and point a of Clause 2 of Article 41 of this Law; if the issuance is refused, a written notification with reasons must be provided.
2. The Business License for network security products and services shall contain the following main contents:
a) The name of the business entity, its trading name in Vietnamese and foreign languages (if applicable), and the address of its headquarters in Vietnam;
b) The name of the legal representative;
c) The license number, date of issuance, and expiration date of the license;
d) The network security products and services permitted to operate.
3. A business entity issued a Business License for network security products and services must pay fees as prescribed by laws on fees and charges.
Article 45. Amending, supplementing, extending, temporarily suspending, revoking, and reissuing Business Licenses for network information security products and services
1. The amendment and supplementation of Business Licenses for network information security products and services shall be carried out in cases where enterprises have changed their name, legal representative, or added, supplemented network information security products and services they provide after being granted such licenses.
Enterprises are responsible for submitting applications to amend and supplement the contents of the License to the Ministry of Information and Communications. The application consists of two sets, including a request to amend and supplement the License's content, a detailed report describing the proposed amendments and supplements, and other related documents.
Within ten working days from the date of receiving complete files, the Ministry of Information and Communications will review, amend, supplement, and reissue the License to the enterprise; if the issuance is refused, it must notify in writing and specify the reasons.
2. In cases where the Business License for network information security products and services is lost or damaged, the enterprise submits a request for reissuance of the License to the Ministry of Information and Communications, clearly stating the reason. Within five working days from the date of receipt of the request, the Ministry of Information and Communications will consider and reissue the License to the enterprise.
3. Enterprises that comply with the laws on operating network information security products and services may extend their Business Licenses once for a period not exceeding one year. Applications for license extension must be submitted to the Ministry of Information and Communications at least sixty days before the expiration date of the License. The application for license extension consists of two sets, including:
a) Application form for extending the License;
b) The currently valid Business License for network information security products and services;
c) A report on the enterprise's activities in the last two years. Within twenty days from the date of receiving complete files, the Ministry of Information and Communications will review, decide on the extension, and reissue the License to the enterprise; if the issuance is refused, it must notify in writing and specify the reasons.
4. Enterprises will be temporarily suspended from operating network information security products and services for a period not exceeding six months in the following cases:
a) Providing services inconsistent with the content recorded on the License;
b) Failing to meet any of the conditions stipulated in Article 42 of this Law;
c) Other cases as prescribed by law.
5. Enterprises will have their Business Licenses for network information security products and services revoked in the following cases:
a) Not implementing the provision of services within one year from the date of issuance of the License without a valid reason;
b) The permit has expired;
c) Exceeding the suspension period without rectifying the reasons specified in Clause 4 of this Article.
Article 46. Responsibilities of enterprises operating network information security products and services
1. Managing files and documents related to technical solutions and technology of products.
2. Establishing, retaining, and securing customer information.
3. Annually reporting to the Ministry of Information and Communications on business operations, export, and import of network information security products and services before December 31.
4. Refusing to provide network information security products and services when discovering organizations or individuals violating laws on using such products and services, or breaching commitments agreed upon regarding the use of products and services provided by the enterprise.
5. Temporarily suspending or ceasing to provide network information security products and services to ensure national defense, security, public order, and social safety as required by competent state agencies.
6. Cooperating and facilitating competent state agencies in implementing investigative measures when requested.
Section 2
MANAGEMENT OF IMPORTATION OF NETWORK INFORMATION SECURITY PRODUCTS
Article 47. Principles for Managing Importation of Cybersecurity Products
1. The management of importation of cybersecurity products shall be carried out in accordance with the provisions of this Law and other relevant laws.
2. The importation of cybersecurity products by agencies, organizations, and individuals enjoying preferential treatment and diplomatic immunity shall be implemented in accordance with the laws on customs, preferential treatment, and immunities granted to foreign diplomatic missions, consular offices, and intergovernmental international organization representative offices in Vietnam.
3. In cases where Vietnam has not established technical standards for imported cybersecurity products, international agreements and treaties to which the Socialist Republic of Vietnam is a member shall apply.
Article 48. Imported Products under Permit in the Field of Cybersecurity
1. When importing cybersecurity products listed in the Import Permit Product List for Cybersecurity Products prescribed by the Government, enterprises must hold an Import Permit for Cybersecurity Products issued by the competent state authority.
2. Organizations and enterprises importing cybersecurity products must conduct conformity assessment and declaration before importation in accordance with Article 39 of this Law.
3. Organizations and enterprises shall be granted an Import Permit for Cybersecurity Products if they meet the following conditions:
a) Possessing a Business License for Cybersecurity Products;
b) Cybersecurity products must undergo conformity assessment and declaration in accordance with Article 39 of this Law;
c) The use of cybersecurity products does not harm national defense, national security, and public order and social safety.
4. The Ministry of Information and Communications shall detail the procedures, formalities, and documentation for issuing an Import Permit for Cybersecurity Products under permit.
Chapter VI
DEVELOPMENT OF CYBERSECURITY HUMAN RESOURCES
Article 49. Training and Professional Development in Cybersecurity
1. System administrators have the responsibility to train and enhance knowledge and skills for managers and technicians in cybersecurity.
2. Full-time cybersecurity staff shall be assigned and provided working conditions suitable to their expertise and prioritized for professional development in cybersecurity.
3. The State encourages organizations and individuals to invest, form joint ventures, or collaborate with other organizations to build higher education institutions and vocational training centers aimed at training human resources in the field of cybersecurity.
4. The Ministry of Home Affairs, in collaboration with the Ministry of Information and Communications and related ministries and sectors, shall develop plans and implement training and enhancement of knowledge and skills in cybersecurity for civil servants and public officials.
Article 50. Certificates and Diplomas in Cybersecurity Education
1. Higher education institutions and vocational training centers within their scope of duties and powers issue certificates and diplomas in cybersecurity education.
2. The Ministry of Education and Training, in collaboration with the Ministry of Information and Communications and related ministries and sectors, shall recognize university degrees in cybersecurity awarded by foreign organizations.
3. The Ministry of Labor, Invalids, and Social Affairs, in collaboration with the Ministry of Information and Communications and related ministries and sectors, shall recognize vocational certificates and diplomas in cybersecurity awarded by foreign organizations.
Chapter VII
STATE MANAGEMENT OF CYBERSECURITY
Article 51. Contents of State Management on Cybersecurity
1. Develop strategies, planning, plans, and policies in the field of cybersecurity; build and direct the implementation of the national program on cybersecurity.
2. Issue and organize the implementation of normative legal documents on cybersecurity; build and announce national standards, issue technical regulations on cybersecurity.
3. Manage state affairs regarding civil cryptography.
4. Manage the work of evaluating, announcing conformity and compliance with standards on cybersecurity.
5. Manage the work of monitoring the security of information systems.
6. Review cybersecurity in design project files for information systems.
7. Propagate and disseminate laws on cybersecurity.
8. Manage business activities related to cybersecurity products and services.
9. Organize research, application of science and technology on cybersecurity; develop cybersecurity human resources; train specialized staff on cybersecurity.
10. Inspect, audit, resolve complaints and denunciations, and handle violations of laws on cybersecurity.
11. International cooperation on cybersecurity.
Article 52. Responsibilities of State Management on Cybersecurity
1. The Government uniformly manages state affairs on cybersecurity.
2. The Ministry of Information and Communications is responsible before the Government for managing state affairs on cybersecurity, with the following tasks and powers:
a) Issue or draft, submit to competent authorities for issuance normative legal documents, strategies, planning, plans, national standards, national technical regulations on cybersecurity;
b) Review cybersecurity in design project files for information systems;
c) Manage the work of monitoring the security of information systems nationwide, except for systems specified in point c Clause 3 and point b Clause 5 of this Article;
d) Manage the work of evaluating cybersecurity;
đ) Issue licenses for the sale of cybersecurity products and services, import licenses for cybersecurity products, except for civilian cryptography products and services;
e) Research and apply science and technology on cybersecurity; train and develop human resources;
g) Manage and implement international cooperation on cybersecurity;
h) Inspect, audit, resolve complaints and denunciations, and handle violations of laws on cybersecurity;
i) Take the lead and coordinate with ministries, sectors, provincial People's Committees, and related enterprises in ensuring cybersecurity;
k) Organize the dissemination and popularization of laws on cybersecurity;
l) Report annually to the Government on cybersecurity activities.
3. The Ministry of National Defense has the following tasks and powers:
a) Issue or draft, submit to competent authorities for issuance normative legal documents, strategies, planning, plans, national standards, national technical regulations on cybersecurity within its management domain;
b) Inspect, audit, resolve complaints and denunciations, and handle violations of laws in cybersecurity activities within its management domain;
c) Implement the management of the work of monitoring the security of information systems within the Ministry of National Defense.
4. The Government Cryptographic Office assists the Minister of National Defense in managing state affairs on civilian cryptography, with the following tasks:
a) Draft, submit to competent authorities for issuance normative legal documents on civilian cryptography management;
b) Take the lead and coordinate with relevant ministries and sectors to draft, submit to competent state authorities for issuance national standards, national technical regulations for civilian cryptography products and services;
c) Manage the business operations and use of civilian cryptography; manage the quality of civilian cryptography products and services; manage the work of evaluating and announcing conformity and compliance with standards for civilian cryptography products and services;
d) Draft, submit to competent authorities for issuance lists of civilian cryptography products and services and lists of exportable and importable civilian cryptography products under license;
đ) Issue licenses for the sale of civilian cryptography products and services, export and import licenses for civilian cryptography products;
e) Inspect, audit, resolve complaints and denunciations, and handle violations of laws in civilian cryptography business operations and use;
g) International cooperation on civilian cryptography.
5. The Ministry of Public Security has the following tasks and powers:
a) Take the lead and coordinate with relevant ministries and sectors to draft and submit to competent authorities for issuance or issuance according to authority and guidance on the implementation of normative legal documents on protecting state secrets, preventing and combating cybercrime, exploiting networks to infringe upon national security, public order, and social safety;
b) Implement the management of the work of monitoring the security of information systems within the Ministry of Public Security;
c) Organize, direct, and implement the work of preventing and combating crime, organizing investigations of cybercrimes and other illegal acts in the field of cybersecurity;
d) Coordinate with the Ministry of Information and Communications and relevant ministries and sectors to inspect, audit cybersecurity, and handle violations of laws on cybersecurity according to authority.
6. The Ministry of Home Affairs is responsible for organizing training and upgrading knowledge and skills in cybersecurity for cadres, civil servants, and public officials.
7. The Ministry of Education and Training is responsible for organizing training and disseminating knowledge about cybersecurity in higher education institutions.
8. The Ministry of Labor, Invalids, and Social Affairs is responsible for organizing training, upgrading, and disseminating knowledge about cybersecurity in vocational education institutions.
9. The Ministry of Finance is responsible for guiding and allocating funds to implement tasks to ensure cybersecurity according to the provisions of the law.
10. Ministries and agencies at the level of ministries within their scope of tasks and powers are responsible for managing cybersecurity in their sectors and cooperate with the Ministry of Information and Communications to implement state management on cybersecurity.
11. Provincial People's Committees within their scope of tasks and powers implement state management on cybersecurity locally.
Chapter VIII
IMPLEMENTING PROVISIONS
Article 53. Effective Date
This Law takes effect from July 1, 2016.
Article 54. Detailed provisions
The Government and competent state agencies shall provide detailed regulations for the Articles and Clauses assigned in this Law.
_______________________________________________________________
This Law has been adopted by the National Assembly of the Socialist Republic of Vietnam, the XIIIth term, the session number 10 on the date 19 the 11 year 2015.
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。