5.
One-off inspections of cybersecurity of an information system critical for national security are
regulated as follows:
(a)
Prior to the time for conducting an inspection, the CTF is responsible to provide at least twelve
(12) hours advance written notice to the system administrator in the case of a cybersecurity incident
or violation of cybersecurity, and at least 72 hours advance written notice in the case of a request [for
inspection] made by a State administrative agency for cybersecurity or on expiry of the deadline for
remedying any weaknesses or security vulnerabilities on the recommendation of a CTF;
(b)
Within thirty (30) days after the day of ending an inspection, the CTF shall notify the inspection
results and provide its requirements to the system administrator if any weaknesses or security
vulnerabilities have been detected; and shall guide or participate in remedying [such defects] in the
case where a proposal was made by the system administrator;
(c)
The CTF under the Ministry of Public Security shall conduct one-off inspections of cybersecurity of
information systems critical for national security, except for military information systems managed by
the Ministry of National Defence, and except for cipher information systems under the Government
Cipher Committee and cipher products which such Committee provides in order to protect
information classified as State secret.
The CTF under the Ministry of National Defence shall conduct one-off inspections of cybersecurity of
military information systems.
The Government Cipher Committee shall conduct one-off inspections of cybersecurity of cipher
information systems managed by such Committee and of cipher products which such Committee
provides in order to protect information classified as State secret;
(d)
The administrator of an information system critical for national security is responsible to co-ordinate
with the CTF to conduct the one-off inspection of cybersecurity.
6.
The results of an inspection of cybersecurity must be kept confidential in accordance with law.
Article 14
Supervision of cybersecurity of information systems critical for national security
1.
Supervision of cybersecurity means activities of collecting and analysing the current status so as to
identify cybersecurity threats, cybersecurity incidents, any weaknesses or security vulnerabilities,
malicious codes and malicious hardware in order to provide warnings thereof and remedy and deal
with [such issues].
2.
The administrator of an information system critical for national security shall preside over
co-ordination with the competent CTF to regularly supervise cybersecurity of the system within the
managerial scope of such administrator; and to formulate mechanisms for automatic warnings and
receipt of such warnings of any cybersecurity threats, cybersecurity incidents, weaknesses or
security vulnerabilities, malicious codes or malicious hardware in order to provide plans on
emergency response and remedy.
3.
The CTF shall supervise cybersecurity of information systems critical for national security within its
managerial scope; and shall provide warnings and co-ordinate with the system administrator to
remedy and deal with any cybersecurity threat, cybersecurity incident, weakness or security
vulnerability, malicious code or malicious hardware in respect of the information system critical for
national security.
Allens - Vietnam Laws Online Database on www.vietnamlaws.com
9