Article 15
Responding to and remedying any cybersecurity incident on an information system critical for
national security
1.
Activities being response and remedying a cybersecurity incident on an information system critical for
national security comprise:
(a)
Detecting and identifying the cybersecurity incident;
(b)
Protecting the site and collating evidence;
(c)
Blockading and restricting the scope of the incident which has occurred, and mitigating loss and
damage caused by it;
(d)
Determining the objectives, objects and scope of the response;
(dd)
Verifying, analysing, assessing and classifying such cybersecurity incident;
(e)
Implementing plans on responding to and remedying the incident;
(g)
Determining the cause of the incident and tracing its origin;
(h)
Investigating and dealing with the incident in accordance with law.
2.
The administrator of an information system critical for national security shall formulate a plan on
addressing/responding to and remedying any cybersecurity incident on the system within the
managerial scope of such administrator; and shall deploy such plan on occurrence of a cybersecurity
incident and promptly report same to the competent CTF.
3.
Coordination of the response and remedying any cybersecurity incident on an information system
critical for national security is regulated as follows:
(a)
The CTF under the Ministry of Public Security shall preside over coordination of activities of
responding to and remedying any cybersecurity incident on an information system critical for national
security, except in the cases prescribed in sub-clauses (b) and (c) below; shall participate in
responding to and remedying a cybersecurity incident on an information system critical for national
security when requested; and shall notify the system administrator on detection of a cyberattack or
cybersecurity incident;
(b)
The CTF under the Ministry of National Defence shall preside over coordination of activities
responding to and remedying any cybersecurity incident occurring on a military information system;
(c)
The Government Cipher Committee shall preside over coordination of activities of responding to and
remedying any cybersecurity incident on a cipher information system under such Committee.
4.
Agencies, organizations and individuals are responsible to participate in responding to and
remedying any cybersecurity incident occurring on an information system critical for national security
on request made by the force in charge of coordinating such response.
Allens - Vietnam Laws Online Database on www.vietnamlaws.com
10