What are regulations on inspection of cybersecurity of national security information systems in Vietnam?

Hello Lawnet. My name is Dinh Toan. Currently, I'm learning regulations related to protection of national security and public order in cyberspace. I found that the National Assembly had issued the Cybersecurity Law. I have some questions in order to serve my learning needs. According to latest regulations, what are regulations on inspection of cybersecurity of national security information systems in Vietnam? Thank you!

What are regulations on inspection of cybersecurity of national security information systems in Vietnam? - image from internet

Pursuant to Article 13 of the Cybersecurity Law in 2018 (effective from 01/01/2019) stipulating inspection of cybersecurity of national security information systems in Vietnam:

1. Inspection of cybersecurity means determination of cybersecurity status of an information system, information system infrastructure or information stored, processed or transmitted within the information system in order to prevent, discover and handle cybersecurity threats; implement plans and measures for ensuring normal operation of the information system.

2. A national security information system shall undergo cybersecurity inspection in the following cases:

a) An or network information security service or electronic device is put into use in the information system;

b) There are changes to status of the information system;

c) Annual inspection;

d) Ad hoc inspection in case of cybersecurity incidents or cybersecurity violations; at the request of a cybersecurity authority; expiration of the deadline for remediating vulnerabilities recommended by a professional cybersecurity force.

3. Cybersecurity inspection shall be carried out for:

a) Hardware systems, software systems, digital devices in information systems;

b) Cybersecurity regulations and measures;

c) Information stored, processed and transmitted within the information system;

d) Cybersecurity incident response and remediation plans of the information system admin;

dd) Measures for protection of state secrets; prevention of leak of state secrets through technical channels;

e) Cybersecurity protection.

4. The administrator of a national security information system shall carry out cybersecurity inspection in the cases mentioned in Point a through c Clause 2 of this Article and send the annual inspection report to the professional cybersecurity force of the Ministry of Public Security (or the Ministry of National Defense for military information systems) before October.

5. Ad hoc inspection of cybersecurity:

a) The cybersecurity force shall send a written notification to the system’s administrator at least 12 hours before the inspection in case of a cybersecurity incident or cybersecurity violation; at least 72 hours if the inspection is meant to serve state management of cybersecurity or the deadline for remediation of vulnerabilities has expired;

b) Within 30 days from the end of the inspection, the cybersecurity force shall send a notification and requests to the administrator in case weaknesses or vulnerabilities are found; provide instructions if requested by the admin;

c) The cybersecurity force of the Ministry of Public Security shall carry out ad hoc inspection of national security information systems other than those under the management of the Ministry of National Defense, cryptography systems of VGCA and cryptography products provided by VGCA for protection of state-secret information.

The professional cybersecurity force of the Ministry of National Defense shall carry out ad hoc cybersecurity inspection of military information systems.

VGCA shall carry out ad hoc cybersecurity inspection of its cryptography systems and cryptography products it provides for protection of state-secret information.

d) Administrators of national security information systems shall cooperate with professional cybersecurity forces in the ad hoc cybersecurity inspections.

6. The cybersecurity inspection results shall be kept confidential as prescribed by law.

Above are regulations on inspection of cybersecurity of national security information systems in Vietnam. Please refer to the Cybersecurity Law in 2018 for more details.

Best regards!

Related Posts
LawNet
Vietnam: Top 20+ wishes for International Women's Day March 8 for teachers in 2025
LawNet
What is the best speech for the 115th Anniversary of March 8 in 2025?
LawNet
Vietnam: What are some meaningful wishes for mothers on the International Women's Day, March 8, 2025?
LawNet
When does the Da Nang International Fireworks Festival 2025 (DIFF 2025) occur?
LawNet
What is March 8? What is the lunar calendar date of March 8, 2025?
LawNet
What is the template of the Fire Prevention and Fighting Regulations in 2025 in Vietnam?
LawNet
Gregorian calendar for March 2025
LawNet
What is the date of Hung Kings Commemoration Day in 2025 in Vietnam? What are regulations on organizations of the Hung Kings Commemoration Day in Vietnam?
LawNet
What are details of the Catholic calendar for 2025?
LawNet
What are wishes for Valentine's Day for boyfriend in Vietnamese?
Lượt xem: 0
Latest Post

Đơn vị chủ quản: Công ty THƯ VIỆN PHÁP LUẬT.
Chịu trách nhiệm chính: Ông Bùi Tường Vũ - Số điện thoại liên hệ: 028 3935 2079
P.702A , Centre Point, 106 Nguyễn Văn Trỗi, P.8, Q. Phú Nhuận, TP. HCM;