(a)
The CTF under the Ministry of Public Security shall assess and certify satisfaction of cybersecurity
conditions of information systems critical for national security, except in the cases prescribed in
sub-clauses (b) and (c) below;
(b)
The CTF under the Ministry of National Defence shall assess and certify satisfaction of cybersecurity
conditions of military information systems;
(c)
The Government Cipher Committee shall assess and certify satisfaction of cybersecurity conditions
of cipher information systems under such Committee.
4.
Information systems critical for national security shall be commissioned for operation and use after
they have been certified as satisfying cybersecurity conditions.
5.
The Government shall provide detailed regulations for implementation of clause 2 above.
Article 13
Inspections [audit] of cybersecurity of information systems critical for national security
1.
An inspection [audit] of cybersecurity means the activity of identifying the actual cybersecurity status
of the information system and of its infrastructure or of information stored, processed and transmitted
on it, aimed at preventing, detecting and dealing with any cybersecurity threat and proposing plans
and measures to ensure normal operation of such system.
2.
An audit of cybersecurity of an information system critical for national security shall be conducted in
the following cases:
(a)
When introducing e-facilities and network information security services for use in the information
system;
(b)
When there is a change in the current status of the information system;
(c)
An annual inspection shall be conducted;
(d)
A one-off inspection shall be conducted when there is a cybersecurity incident [breakdown] or an
infringement of network security; or on request made by [a State administrative agency] for
cybersecurity; or on expiry of the deadline for remedying any weaknesses or security vulnerabilities
on the recommendation of a CTF.
3.
Items subject to an inspection of cybersecurity of an information system critical for national security
comprise:
(a)
Hardware and software systems and digital devices used in the information system;
(b)
Regulations and measures on protecting network security;
(c)
Information which is stored, processed and transmitted on the information system;
(d)
Plans of the system administrator to respond to and remedy any cybersecurity incident;
(dd)
Measures for protecting State secrets and for preventing revelation or loss of State secrets via
technical channels;
(e)
Cybersecurity protective human resources.
4.
The administrator of an information system critical for national security shall conduct cybersecurity
inspections of the system within the managerial scope of such administrator in the cases prescribed
in sub-clauses (a), (b) and (c) of clause 2 above; and shall provide written notice of the inspection
results prior to October each year to the CTF under the Ministry of Public Security, or to such Task
Force under the Ministry of National Defence in the case of a military information system.
Allens - Vietnam Laws Online Database on www.vietnamlaws.com
8