Decision No. 864/2003/QĐ-NHNN amends and supplements certain articles of the Regulation on Management and Use of Information Technology Systems in the Banking Industry issued together with Decision No. 14/2000/QĐ-NHNN. This document stipulates the management and use of equipment, software, computer networks, databases, application programs, as well as information security in the banking industry.
适用范围
State-owned credit institutions, units under the State Bank, provincial/municipal branches of the State Bank, and individuals using information technology systems in the banking industry.
要点
- Banks and related units must strictly manage the use of software copyright.
- The Banking Information Technology Department is responsible for researching, issuing, and managing standards for hardware equipment, software development in the banking industry.
- When upgrading and renovating information technology systems, technical criteria consistency must be ensured.
- Network users may only use limited business operations that have been permitted; they must manage access key security and bear responsibility for their access keys.
- Databases must be organized scientifically, capable of backup and data recovery.
🌐 本文件的社会影响
- Positive impact: Enhance information security, improve the efficiency of management and use of information technology systems in the banking industry.
- Negative impact: May cause difficulties in using devices and software not specifically defined.
❓ 常见问题
What should units do when managing software copyright?
Strictly manage the use of software copyright including: Operating system software, security software, application software, network management software, and communication software.
What responsibilities does the Banking Information Technology Department have?
Research, issue, and manage standards for hardware equipment, software development in the banking industry to ensure consistency.
How should network users store access keys?
Network administrator passwords must be stored according to confidential document protection regulations. Users granted network access rights are responsible for managing access key security and bear responsibility for their network access keys.
What requirements must databases meet?
They must be organized scientifically, allowing software systems to easily update information, aggregate, select, process, transmit quickly and accurately. At the same time, data stored on networks must include elements to accurately identify the person and time of creation or modification of the data.
What should banks do when upgrading information technology systems?
When upgrading, ensure technical criteria consistency, aligning with the actual development of the information technology industry.
全文
Pursuant to …;
Regarding the amendment and supplementation of certain articles of the Regulation on the management and use of information technology systems in the banking industry issued together with Decision No. 14/2000/QĐ-NHNN16
dated January 7, 2000
_____________________________
DATE 07 MONTH 01 YEAR 2000
Pursuant to the Law on the State Bank of Vietnam and the Law on Credit Organizations dated December 12, 1997;
Pursuant to Decree No. 86/2002/NĐ-CP dated November 5, 2002 of the Government stipulating the functions, tasks, powers, and organizational structure of Ministries and ministerial-level agencies;
At the proposal of the Director of the Banking Information Technology Department,
DECISION:
Article 1. Amends and supplements certain articles of the Regulation on the management and use of information technology systems in the banking industry issued together with Decision No. 14/2000/QĐ-NHNN16 dated January 7, 2000 of the Governor of the State Bank of Vietnam as follows:
1. Amends Clause 5, Clause 7, Article 3 as follows:
“5. Special equipment includes printers, scanners (Scanner), automatic teller machines (ATM), card readers, data encryption devices (Encryptor), data protection and intrusion prevention devices (Firewall), uninterruptible power supplies (UPS), voltage stabilizers.
7. Network equipment includes: network interface cards (NIC, Transceiver), hubs (Hub, Switching Hubs), repeaters, bridges, routers, packet switches (X25), frame relay switches, ATM switches, modems (MODEM), connectors or conversion devices, network cables.”
2. Adds Clause 3, Clause 4 to Article 4 as follows:
“3- Strictly manage the use of software copyright including: operating system software, security software, application software, network management software, communication software.
4- The Banking Information Technology Department is responsible for researching, issuing, and managing hardware standards and software development in the banking industry to ensure uniformity as stipulated in Clause 2, Article 4.”
3. Adds Clause 5 to Article 5 as follows:
“5. Upgrading and improving information technology systems in the banking industry must ensure technical criteria consistency and be suitable for the actual development of the information technology industry.”
4. Amends Clause 4, adds Clause 5, Clause 6 to Article 11 as follows:
“4- Units and individuals granted access rights to the banking computer network to perform specific tasks may only use the network within the scope of the permitted tasks; they shall not use the network for other purposes without authorization, nor access unauthorized addresses on the network.
5- Network administrator passwords must be stored according to the confidentiality document protection regulations. Users granted network access rights are responsible for managing and securing their access passwords and bear responsibility for these network access passwords.
6- For each information network system, internal rules must be established to specifically regulate safe and secure information usage on the network, ensuring the safety of the information network system. In emergency situations, network administrators have the right to temporarily suspend or limit resource exploitation access.”
5. Amends Clause 4, adds Clause 5, Clause 6 to Article 13 as follows:
“4- Databases must be organized scientifically to facilitate quick and accurate information updates, aggregation, selection, processing, and transmission by the software system.
5- Data stored on the computer network must include elements to accurately identify the person and time of creation or last modification of the data, as well as the person and time of data control.
6- The selection of databases must be based on business requirements, industry trends, unit development, global trends, and consider the interconnection of database systems based on software program systems and data backup and recovery capabilities.”
6. Adds Clause 7, Clause 8, Clause 9, Clause 10 to Article 14 as follows:
“7. Application programs running on the computer network must be designed to allow hierarchical management and user permissions. Application software must meet service quality criteria.
8. Application programs must be secured and meet system security requirements, and databases must have encryption keys. Business application software must have usage licenses in the banking industry.
9. Each application program running on the computer network must have backup and data recovery functions.
10. Related business software in units (treasury, payment, supervision, inspection...) must be able to connect and use a unified input information for regular data verification to ensure asset safety.”
7. Amends Clause 5 of Article 15 as follows:
“5- Users may only use computers for assigned work and shall not use them for personal matters that could affect the information technology system of the unit.”
8. Amends Article 21 as follows:
“For information and data classified as state secrets, the provisions of the law on confidentiality must be followed.”
9. Adds Clause 5, Clause 6 to Article 22 as follows:
“5. To protect data, when applying cryptographic techniques in the banking industry, national and international standards must be met.
6. Hardware and software security devices must be continuously updated and adapted to the actual conditions in Vietnam and meet international standards.”
Article 2. This Decision takes effect 15 days from the date of publication in the Official Gazette.
Article 3. The Head of the Office of the State Bank of Vietnam, the Director of the Banking Information Technology Department, the Heads of units under the State Bank of Vietnam, the Governors of the State Bank of Vietnam branches in provinces and centrally-administered cities, the Chairmen of the Boards of Directors, General Managers (Directors) of state credit organizations are responsible for implementing this Decision./.
关系图
点击文件即可打开。红色边框=改变效力的关系。
译本
本文件提供以下语言版本: