3.
The Ministry of Public Security shall preside over coordination with relevant Ministries and line
ministries in fighting to protect cybersecurity.
CHAPTER 4
Cybersecurity Protective Activities
Article 23
Implementation of cybersecurity protective activities in State agencies and political
organizations at the central and local levels
1.
Contents of implementation of cybersecurity protective activities comprise:
(a)
Formulating and completing rules and regulations on use of local area networks and Internetconnected computer networks; plans for ensuring cybersecurity of information systems; and plans for
responding to and remedying cybersecurity incidents;
(b)
Applying and implementing plans, measures and technology to protect cybersecurity of information
systems and of information and data archived, drafted and transmitted on information systems within
the scope of their managerial authority [managed by such State agencies and political organizations];
(c)
Organizing retraining on cybersecurity knowledge for cadres [senior officials], other officials and
employees; increasing the capability of Cybersecurity Task Forces [CTF] to protect cybersecurity;
(d)
Protecting cybersecurity in the following activities: providing public services in cyberspace; providing
information to, exchanging information with and collecting information from agencies, organizations
and individuals; sharing information internally and with other agencies or during other activities in
accordance with Government regulations;
(dd)
Conducting investment in and building physical infrastructure in conformity with conditions for
ensuring implementation of cybersecurity protective activities for information systems;
(e)
Inspecting cybersecurity of information systems; preventing and combating breaches of the law on
cybersecurity; responding to and remedying cybersecurity incidents.
2.
Heads of agencies and organizations are responsible to carry out cybersecurity protective activities
[for networks] within the scope of their managerial authority.
Article 24
Inspection [audit] of cybersecurity of information systems of agencies and organizations not on
the list of information systems critical for national security
1.
Cybersecurity of information systems of agencies and organizations not on the list of information
systems critical for national security shall be inspected in the following cases:
(a)
When there is a breach of the law on cybersecurity infringing national security or materially affecting
social order and safety;
(b)
When there is a request from the information system administrator.
2.
Items subject to cybersecurity inspection comprise:
(a)
Hardware and software systems and digital devices used in the information system;
(b)
Information stored, processed and transmitted on the information system;
(c)
Measures for protecting State secrets, and for preventing and combating revelation and loss of State
secrets via technical channels.
Allens - Vietnam Laws Online Database on www.vietnamlaws.com
17