4.
To co-ordinate with the Ministry of Public Security to organize drills to prevent and combat
cyberattacks; to carry out drills to respond to and remedy cybersecurity incidents within any
information system critical for national security; and to commence implementation of cybersecurity
protective work.
5.
To conduct inspections and investigations, resolve complaints and denunciations, and deal with
breaches of the law on cybersecurity within its managerial scope.
Article 38
Responsibilities of the Ministry of Information and Communications
1.
To co-ordinate with the Ministry of Public Security and the Ministry of National Defence in protecting
cybersecurity.
2.
To co-ordinate with relevant agencies to disseminate [educate about the dangers of] and to counter
information which opposes the Socialist Republic of Vietnam as prescribed in article 16.1 of this Law.
3.
To request cyberspace service providers and information system administrators to remove
information in breach of the law on cybersecurity from the services and information systems directly
managed by enterprises, agencies or organizations.
Article 39
Responsibilities of the Government Cipher Department
1.
To consult with and propose that the Ministry of National Defence promulgate or submit to the
competent agency to promulgate and organize implementation of legal instruments, programs and
plans on cryptography in order protect cybersecurity within the managerial scope of such
Department.
2.
To protect cybersecurity of the cipher information system of the Government Cipher Department and
cryptographic products provided by such Department in accordance with this Law.
3.
To uniformly manage science and technology research on cryptography; and to produce, use and
provide cryptographic products in order to protect information stored or exchanged in cyberspace
which is State secret.
Article 40
Responsibilities of ministries, branches and provincial people's committees
Ministries, branches and provincial people's committees shall, depending on their respective duties and
powers, protect cybersecurity of information and information systems within their managerial scope; and
shall co-ordinate with the Ministry of Public Security to exercise State administration of cybersecurity of
such ministries, branches and localities.
Article 41
Responsibilities of service providers in cyberspace
1.
A cyberspace service provider4 in Vietnam has the following responsibilities:
(a)
To give warnings of the possibility of a loss of cybersecurity during use of the services in cyberspace
provided by such enterprise and to provide guidelines on preventive measures;
(b)
To formulate plans and solutions to quickly respond to cybersecurity incidents, and to immediately
deal with any security weaknesses or vulnerabilities, malicious codes, cyberattacks, cyber
intrusions/infringements or other security risks; and when a cybersecurity incident occurs, to
immediately implement appropriate emergency plans and response measures, and at the same time
provide a report thereon to the CTF in accordance with this Law;
(c)
To apply technical solutions and other necessary measures to ensure security during the process of
collecting information and to prevent the risk of revelation, damage to or loss of data; and in the case
4
Allens footnote: The literal translation is "An enterprise providing services in cyberspace".
Allens - Vietnam Laws Online Database on www.vietnamlaws.com
23