(a) The CTF under the Ministry of Public Security shall assess and certify satisfaction of cybersecurity conditions of information systems critical for national security, except in the cases prescribed in sub-clauses (b) and (c) below; (b) The CTF under the Ministry of National Defence shall assess and certify satisfaction of cybersecurity conditions of military information systems; (c) The Government Cipher Committee shall assess and certify satisfaction of cybersecurity conditions of cipher information systems under such Committee. 4. Information systems critical for national security shall be commissioned for operation and use after they have been certified as satisfying cybersecurity conditions. 5. The Government shall provide detailed regulations for implementation of clause 2 above. Article 13 Inspections [audit] of cybersecurity of information systems critical for national security 1. An inspection [audit] of cybersecurity means the activity of identifying the actual cybersecurity status of the information system and of its infrastructure or of information stored, processed and transmitted on it, aimed at preventing, detecting and dealing with any cybersecurity threat and proposing plans and measures to ensure normal operation of such system. 2. An audit of cybersecurity of an information system critical for national security shall be conducted in the following cases: (a) When introducing e-facilities and network information security services for use in the information system; (b) When there is a change in the current status of the information system; (c) An annual inspection shall be conducted; (d) A one-off inspection shall be conducted when there is a cybersecurity incident [breakdown] or an infringement of network security; or on request made by [a State administrative agency] for cybersecurity; or on expiry of the deadline for remedying any weaknesses or security vulnerabilities on the recommendation of a CTF. 3. Items subject to an inspection of cybersecurity of an information system critical for national security comprise: (a) Hardware and software systems and digital devices used in the information system; (b) Regulations and measures on protecting network security; (c) Information which is stored, processed and transmitted on the information system; (d) Plans of the system administrator to respond to and remedy any cybersecurity incident; (dd) Measures for protecting State secrets and for preventing revelation or loss of State secrets via technical channels; (e) Cybersecurity protective human resources. 4. The administrator of an information system critical for national security shall conduct cybersecurity inspections of the system within the managerial scope of such administrator in the cases prescribed in sub-clauses (a), (b) and (c) of clause 2 above; and shall provide written notice of the inspection results prior to October each year to the CTF under the Ministry of Public Security, or to such Task Force under the Ministry of National Defence in the case of a military information system.  Allens - Vietnam Laws Online Database on www.vietnamlaws.com 8

Select target paragraph3