What are regulations on order and procedures for cybersecurity supervision in Vietnam?

What are regulations on order and procedures for cybersecurity supervision in Vietnam? What are regulations on order and procedures for cybersecurity testing in Vietnam? What are regulations on order and procedures for responding to and remedying cybersecurity incidents of major national security information systems in Vietnam?

Thank you!

What are regulations on order and procedures for cybersecurity supervision in Vietnam?

Pursuant to Article 15 of the Decree 53/2022/NĐ-CP stipulating order and procedures for cybersecurity supervision in Vietnam as follows:

1. The Department of Cyber Security and Hi-tech Crime Prevention of the Ministry of Public Security of Vietnam and the Cyber Command of the Ministry of National Defense of Vietnam shall conduct the supervision of cybersecurity of the national cyberspace and national major security information systems according to their functions and assigned tasks. The Cipher Department of the Government of Vietnam shall conduct the supervision of cybersecurity of cipher information systems of the Cipher Department of the Government of Vietnam according to its functions and assigned tasks.

2. Order of the supervision of cybersecurity of cybersecurity protection forces:

a) Send written notifications to governing bodies of information systems to request the implementation of cybersecurity supervision measures which specify the reason, time, content, and the implementation scope of cybersecurity supervision;

b) Implement cybersecurity supervision measures;

c) Make periodic statistics and reports on cybersecurity supervision results.

3. Governing bodies of major national security information systems shall:

a) Develop and implement cybersecurity supervision systems and cooperate with cybersecurity protection forces in implementing cybersecurity supervision activities for information systems under their management;

b) Arrange premises and technical conditions and establish and connect systems and supervision devices of cybersecurity protection forces to information systems under their management for cybersecurity supervision;

c) Provide and update information on information systems under their management, technical plans for the implementation of supervision systems for cybersecurity protection forces periodically or irregularly at the request of competent cybersecurity protection forces;

d) Notify cybersecurity protection forces of their supervision activities once every 3 months;

dd) Protect the confidentiality of relevant information in the process of cooperating with cybersecurity protection forces.

4. Telecommunications enterprises and enterprises that provide services of information technology, telecommunications, and the internet shall cooperate with cybersecurity protection forces in conducting cybersecurity supervision according to their entitlements for cybersecurity protection.

5. Cybersecurity supervision results shall be protected as prescribed by law.'

What are regulations on order and procedures for cybersecurity testing in Vietnam?

Pursuant to Article 16 of the Decree 53/2022/NĐ-CP stipulating order and procedures for cybersecurity testing in Vietnam as follows:

1. Cybersecurity protection forces shall conduct cybersecurity testing for information systems according to regulations prescribed in Clause 5 Article 13 and Clause 1 Article 24 of the Law on Cybersecurity. Cybersecurity testing contents include the inspection of compliance with regulations of laws on cybersecurity assurance and protection of state confidentiality in cyberspace; inspection and assessment of the efficiency of plans and measures to ensure cybersecurity and plans for responding to and remedying cybersecurity incidents; inspection and assessment of detection of vulnerabilities, security weaknesses, and malicious codes and system intrusion test attacks; other testing and assessments prescribed by governing bodies.

2. Order and procedures for cybersecurity testing of cybersecurity protection forces:

a) Notify cybersecurity testing plans as per regulation;

b) Establish Testing Teams according to functions and assigned tasks;

c) Conduct cybersecurity testing and strictly cooperate with governing bodies of information systems during the testing process;

d) Make records of cybersecurity testing processes and results and preserve them as prescribed by law;

dd) Notify cybersecurity testing results within 3 working days from the completion date of the testing.

3. In case it is necessary to keep the current state of information systems to investigate and handle law violations, detect security weaknesses and vulnerabilities, provide guidelines, or participate in remedial activities as requested by governing bodies of information systems, cybersecurity protection forces shall request governing bodies of information systems to suspend cybersecurity testing in writing. The mentioned documents shall specify the reason, purpose, and time of the temporary suspension of cybersecurity testing.

What are regulations on order and procedures for responding to and remedying cybersecurity incidents of major national security information systems in Vietnam?

Pursuant to Article 17 of the Decree 53/2022/NĐ-CP stipulating order and procedures for responding to and remedying cybersecurity incidents of major national security information systems in Vietnam as follows:

1. Regarding major national security information systems, when facing cybersecurity incidents, shall comply with the following order and procedures for response and remedy as follows:

a) Cybersecurity protection forces shall provide written notifications and guidelines on temporary measures to prevent and handle cyber-attacks and remedy consequences of cyber-attacks and cybersecurity incidents for governing bodies of major national security information systems.

In case of emergencies, provide notifications by phone or other forms before providing written notifications;

b) Governing bodies of major national security information systems shall implement measures according to guidelines and implement other suitable measures to prevent, handle, and remedy consequences right after receiving notifications, excluding cases prescribed in Point c of this Clause.

In case of inability to handle, timely notify cybersecurity protection forces for coordination and response to cybersecurity incidents;

c) In case it is necessary to immediately respond to and prevent consequences that threaten national security, cybersecurity protection forces shall decide on the direct coordination and remedial response to cybersecurity incidents.

2. Coordination and remedial response to cybersecurity incidents of cybersecurity protection forces:

a) Assess and decide on schemes for response and remedy for cybersecurity incidents;

b) Operate the response and remedy for cybersecurity incidents;

c) Preside over the receipt, collection, handling, and sharing of information on response and remedy for cybersecurity incidents;

d) Mobilize and cooperate with organizations and individuals inside and outside of Vietnam related to the participation in responding to and remedying cybersecurity incidents in necessary cases;

dd) Appoint focal agencies to cooperate with relevant agencies of other countries or international organizations in responding to and handling international incidents based on international agreements or treaties that Vietnam is a signatory;

e) Inspect, supervise, and urge the implementation of units related to the response and remedy for cybersecurity incidents;

g) Make records of the process of responding to cybersecurity incidents.

3. Organizations and individuals participating in responding to and remedying cybersecurity incidents shall implement measures, responses, and remedies for incidents according to the coordination of cybersecurity protection forces.

4. In case of the protection of national security and social order and safety, telecommunications enterprises and enterprises that provide Internet services shall arrange premises, connectors, and necessary technical measures for the Department of Cyber Security and Hi-tech Crime Prevention of the Ministry of Public Security of Vietnam to carry out their tasks and ensure cybersecurity. Telecommunications enterprises and enterprises that provide Internet services shall cooperate with the Department of Cyber Security and Hi-tech Crime Prevention of the Ministry of Public Security of Vietnam in implementing the specific order and procedures.

Best regards!

Related Posts
LawNet
Is a 13-year-old orphan in Vietnam entitled to the monthly social allowance?
LawNet
What date is Lunar New Year's Eve 2025 according to Gregorian Calendar? Are foreign employees in Vietnam entitled to days off on Lunar New Year's Eve 2025?
LawNet
Is it required to include the résumé in the dossier for admission to social welfare institutions in Vietnam?
LawNet
Vietnam: Are higher-level delegates required to give a speech at the anniversary celebration of the traditional day?
LawNet
A fine up to VND 2.000.000 shall be imposed for throwing shrimp paste to smear houses of others in Vietnam
LawNet
Does the district-level police authority in Vietnam have the power to inspect the operations of gaming centers?
LawNet
Application for social benefits of elderly people in Vietnam
LawNet
Vietnam: What are the regulations on the forms of converting other types of informational resources?
LawNet
Does maternity leave be calculated as period of social insurance premium payment in Vietnam?
LawNet
Is it possible to issue 02 copies of marital status certificate in Vietnam?
Lượt xem: 0
Latest Post

Đơn vị chủ quản: Công ty THƯ VIỆN PHÁP LUẬT.
Chịu trách nhiệm chính: Ông Bùi Tường Vũ - Số điện thoại liên hệ: 028 3935 2079
P.702A , Centre Point, 106 Nguyễn Văn Trỗi, P.8, Q. Phú Nhuận, TP. HCM;