(e) Other acts of using cyberspace, IT or e-facilities to breach the law on national security, social order and safety. 2. Cybersecurity Task Forces are responsible to prevent and combat conduct being the use of cyberspace, IT, or e-facilities to breach the law on national security, social order and safety. Article 19 Prevention of and combating cyberattacks 1. Acts constituting a cyberattack and cyberattack-related acts comprise: (a) Distributing informatics programs which cause harm to a telecom network, the Internet, a computer network, information system, information processing and control system, database or e-facility; (b) Hindering, disordering, paralyzing, interrupting or stopping the operation of, and/or illegally preventing the transmission of data by a telecom network, the Internet, a computer network, information system, information processing and control system, database or e-facility; (c) Infiltrating, harming or appropriating data stored or transmitted on a telecom network, the Internet, a computer network, information systems, information processing and control systems, database or efacility; (d) Infiltrating, creating or exploiting security vulnerabilities or weaknesses and system services in order to appropriate information and/or to earn illicit profit; (dd) Producing, purchasing and selling, exchanging or donating tools, devices [equipment] and software with the function of attacking a telecom network, the Internet, a computer network, information system, information processing and control system, database or e-facility in order to use such objects [tools, devices and software] for illegal purposes; (e) Performing other acts which affect the normal operation of any telecom network, the Internet, computer network, information system, information processing and control system, database or efacility. 2. Information system administrators are responsible to apply technical measures to prevent and avoid the acts prescribed in sub-clauses (a), (b), (c), (d) and (e) of clause 1 above with respect to information systems within their managerial scope. 3. When a cyberattack occurs and infringes or threatens to infringe national sovereignty, interests and security and/or causes serious harm to social order and safety, the Cybersecurity Task Force shall preside over coordination with information system administrators and relevant organizations and individuals to apply measures to determine the origin of the cyberattack and collect evidence; and shall require enterprises providing services on telecom networks, the Internet and other added value services on cyberspace [cyberspace service providers] to block and filter information in order to prevent and eliminate acts of cyberattack, and shall promptly provide complete relevant information and data. 4. The responsibility to prevent and combat cyberattack is regulated as follows: (a) The Ministry of Public Security shall preside over coordination with relevant Ministries and line ministries to prevent, detect and deal with the acts prescribed in clause 1 of this article which infringe or threaten to infringe national sovereignty, interests and security or cause serious harm to social order and safety throughout the entire country, except in the cases prescribed in sub-clauses (b) and (c) below; (b) The Ministry of National Defence shall preside over coordination with relevant Ministries and line ministries to prevent, detect and deal with the acts prescribed in clause 1 of this article with respect to military information systems;  Allens - Vietnam Laws Online Database on www.vietnamlaws.com 14

Select target paragraph3