Article 11 Evaluation of cybersecurity of information systems critical for national security 1. Evaluation of cybersecurity means the activity of reviewing and assessing cybersecurity contents/items in order to provide the basis for a decision on constructing or upgrading an information system. 2. Items subject to an evaluation of cybersecurity of an information system critical for national security comprise: (a) The pre-feasibility study report and design file for construction/building of the works of an investment project for construction of an information system prior to their approval; (b) The plan on upgrading an information system prior to its approval. 3. Items to be evaluated regarding cybersecurity of an information system critical for national security comprise: (a) Compliance with regulations and conditions for cybersecurity set out in the design; (b) Conformity with plans on protection, response to and remedying any incident and on deployment of human resources protecting cybersecurity. 4. Authority to evaluate cybersecurity of an information system critical for national security is regulated as follows: (a) The Cybersecurity Task Force [CTF] under the Ministry of Public Security shall evaluate cybersecurity of information systems critical for national security, except in the cases prescribed in sub-clauses (b) and (c) below; (b) The CTF under the Ministry of National Defence shall evaluate cybersecurity of military information systems; (c) The Government Cipher Committee shall evaluate cybersecurity of cipher information systems under the Government Cipher Committee. Article 12 Assessment of cybersecurity conditions of information systems critical for national security 1. Assessment of cybersecurity conditions means reviewing whether an information system satisfies cybersecurity conditions prior to its being commissioned for operation and use. 2. Information systems critical for national security must satisfy the following conditions regarding: (a) Regulations, procedures and plans on ensuring cybersecurity; personnel operating and administering the system; (b) Ensuring cybersecurity of equipment, hardware and software being system components; (c) Technical measures for supervising and protecting cybersecurity; protective measures for the automatic control and monitoring system, and for the internet of things, complex virtual reality system, cloud computing, large data system, fast data system and artificial intelligence system; (d) Measures ensuring physical security comprising special isolation, data leakage prevention, prevention of information collection, and access control. 3. Authority to assess cybersecurity conditions of an information system critical for national security is regulated as follows:  Allens - Vietnam Laws Online Database on www.vietnamlaws.com 7

Select target paragraph3