3.
An information system administrator is responsible to notify the CTF under the Ministry of Public
Security upon discovery of any breach of the law on cybersecurity on an information system within
the scope of his/her managerial authority.
4.
The CTF under the Ministry of Public Security shall conduct inspections of cybersecurity of
information systems of agencies and organizations in the cases prescribed in clause 1 of this article.
5.
The CTF shall provide [advance] written notice to the information system administrator at least twelve
(12) hours prior to the time of conducting an inspection.
The CTF shall, within thirty (30) days after the end date of an inspection or audit, notify the inspection
results and provide requirements to the information system administrator if any security weakness or
vulnerabilities are discovered; and shall provide guidelines for or participate in remedying [such
weakness or vulnerabilities] pursuant to a request from the information system administrator.
6.
Results of cybersecurity inspection shall be kept confidential in accordance with law.
7.
The Government shall stipulate the sequence and procedures for cybersecurity inspections
prescribed in this article.
Article 25
Protection of cybersecurity of national cyberspace infrastructure and international network
gateways
1.
The protection of cybersecurity of the national cyberspace infrastructure and international network
gateways must closely combine requirements on cybersecurity protection with requirements on
socio-economic construction and development; international network gateways are encouraged to be
located within the territory of Vietnam; and organizations and individuals are encouraged to
participate in investment in building national cyberspace infrastructure.
2.
Agencies, organizations and individuals managing and operating national cyberspace infrastructure
and international network gateways have the following responsibilities:
(a)
To protect cybersecurity within the scope of their managerial authority; to be subject to management,
investigation and inspection by, and to comply with requirements on cybersecurity protection of
competent State agencies;
(b)
To facilitate and implement necessary technical measures and professional activities when
requested in order for competent State agencies to perform cybersecurity protective tasks.
Article 26
Guarantees relating to information security in cyberspace
1.
Websites, portals [and] specialized pages on social networks of agencies, organizations and
individuals must not provide, upload or transmit any information with the contents prescribed in
clauses 1 to 5 of article 16 of this Law and other information containing contents infringing national
security.
2.
Any domestic or foreign enterprise which provides services on telecom networks and on the Internet
and other value added services in cyberspace in Vietnam [cyberspace service provider] has the
following responsibilities:
(a)
To authenticate information when a user registers a digital account; to maintain confidentiality of
information and accounts of users; to provide user information to the Cybersecurity Task Force under
the Ministry of Public Security when so requested in writing in order to serve investigation of and
dealing with breaches of the law on cybersecurity;
(b)
To prevent the sharing of information and to delete information with the contents prescribed in
clauses 1 to 5 inclusive of article 16 of this Law on services or information systems directly managed
Allens - Vietnam Laws Online Database on www.vietnamlaws.com
18