|
MINISTRY OF INFORMATION AND COMMUNICATIONS OF VIETNAM
-------
|
SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------
|
|
No. 12/2022/TT-BTTTT
|
Hanoi August 12, 2022
|
CIRCULAR
ELABORATION AND GUIDELINES ON DECREE NO. 85/2016/ND-CP DATED
JULY 1, 2016 OF THE GOVERNMENT OF VIETNAM ON LEVEL-BASED INFORMATION SYSTEM
SECURITY
Pursuant to the Law on
Cyber Information Security dated November 19, 2015;
Pursuant to Decree No.
85/2016/ND-CP dated July 1, 2016 of the Government of Vietnam on level-based
information system security;
Pursuant to Decree No.
48/2022/ND-CP dated July 26, 2022 of the Government of Vietnam on functions,
tasks, entitlements, and organizational structure of the Ministry of
Information and Communications of Vietnam;
At the request of the
Authority of Information Security;
The Minister of
Information and Communications of Vietnam hereby promulgates the Circular on
elaboration and guidelines on Decree No. 85/2016/ND-CP dated July 1, 2016 on
level-based information system security.
Chapter
I
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Article
1. Scope
This Circular provides
for the elaboration and guidelines on level-based information system security,
including: identification of information systems and description of their
security classification levels; security requirements for level-based
information systems; information security inspection and assessment;
reports.
Article
2. Regulated entities
The regulated entities of
this Circular shall comply with Article 2 of Decree No. 85/2016/ND-CP dated
July 1, 2016 of the Government of Vietnam on level-based information system
security (hereinafter referred to as “Decree No. 85/2016/ND-CP”).
Article
3. Interpretation of terms
For the purpose of this
Circular, the following terms shall be construed as follows:
1. Hot standby refers
to the devices’ capability to take over functions in the event of a failure
without interrupting the system's operation.
2. Core/critical
network devices refer to devices in the system whose unplanned shutdown
will disrupt the entire information system’s operation. The components of the
core network devices are identified by the information system’s classification
levels, including at least: core switches or equivalents, core firewalls, web
application firewalls, centralized storage systems, and database
firewalls.
Article
4. Information system owners
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
a) Ministry, ministerial
agency, or governmental agency;
b) People’s Committee of
the province/centrally affiliated city;
c) Competent authority
that decides on investment in the information system development,
establishment, upgrade, or expansion. Ministries, ministerial agencies,
governmental agencies, and People’s Committees of provinces/centrally
affiliated cities shall designate the owners according to this Clause, ensuring
that the designated agencies/organizations have sufficient capacity to fully
implement Article 20 of Decree No. 85/2016/ND-CP.
2. For other enterprises
and organizations (that are not entities mentioned in Clause 1), the
information system owner shall be the competent authority that decides on the
information system development, establishment, upgrade, or expansion.
3. If necessary, the
information system owner may authorize an affiliate with sufficient capacity to
act on its behalf to carry out the responsibilities prescribed in Clause 2
Article 20 of Decree No. 85/2016/ND-CP.
The authorization must be
made in writing, specifying the system’s scope, the authorized organization’s
responsibilities, and the authorization duration.
Article
5. Information system operating units
1. An information system
operating unit is an agency/organization assigned by the information system
owner to operate the information system.
2. Where the information
system includes multiple subsystems or is distributed and has more than one
operating unit, the information system owner shall designate a unit to take
charge of the rights and obligations of information system operating units as
prescribed by the law.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
a) If the service
provider has not been identified according to the law, the unit in charge of
hiring the service shall act as the operating unit;
b) If the service
provider has been identified according to the law, the operating unit shall be
the service provider;
c) If the service
provision contract expires and the information system established through
outsourcing continues to operate, the operating unit shall be the unit in
charge of hiring the service.
Article
6. Appraisal of proposal dossiers on classification levels in cases where
specialized information security units are assigned to manage information and
operate information systems by information system owners
Where a specialized information
security unit is assigned by an information system owner to manage and operate
the information system, the appraisal of any proposal dossier on classification
levels shall be carried out according to one of the following plans:
1. The specialized
information security unit shall request the information system owner to assign
an affiliate with sufficient capacity to take charge and organize the
appraisal.
2. The specialized
information security unit shall request the information system owner to establish
an independent appraisal council to appraise the proposal dossier on
classification levels.
Chapter
II
IDENTIFICATION
OF INFOMRAITON SYSTEMS AND DESCRIPTION OF THEIR SECURITY CLASSIFICATION LEVELS
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1. The identification of
an information system for classification shall be based on the principles
prescribed in Clause 1 Article 5 of Decree No. 85/2016/ND-CP.
2. Internal information
systems are systems used solely for the internal management and operation of
agencies/organizations.
3. Information systems
serving people and enterprises are systems directly providing or supporting the
provision of online services, including online public services and other online
services concerning telecommunications, information technology, trade, finance,
banking, health, education, and other specialized fields.
4. Information
infrastructure systems consist of equipment and transmission lines that serve
multiple agencies/organizations, such as wide area networks, databases, data
centers, and cloud computing platforms; electronic authentication, electronic
certification, and digital signatures; and interconnection frameworks for
information systems.
5. Industrial control
information systems are systems used to supervise, collect data, manage, and
control key items that ensure the normal operation of construction facilities.
6. Other information
systems are information systems that do not fall under the categories specified
in Clauses 2, 3, 4, and 5 of this Article. They are used to directly serve or
support specific professional/business/manufacturing operations of
agencies/organizations in specialized fields.
7. Quarterly (on the
first day of each quarter), the Authority of Information Security – Ministry of
Information and Communications of Vietnam shall update and supplement the list
of information systems according to Clauses 2, 3, 4, 5, and 6 of this Article
and announce it on the Ministry of Information and Communications of Vietnam's
web portal.
Article
8. Description of information systems’ security classification levels
1. For any newly
developed, expanded, or upgraded information system, depending on the
investment form, the technical plan in the technical-economic report (in case
the investment project applies the 1-step design method), the base design
within the feasibility research report (in case the investment project applies
the 2-step design method), the plan for outsourced IT services (in case of
outsourced IT services), or the detailed outline and estimate (in case of
investment in IT applications without requirements for a formal project) must
meet the requirements of the plan for level-based information system security
as proposed and explained in the proposal dossier on classification levels.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
a) General description of
the information system;
b) Description of the
proposed classification levels;
c) Description of the
plan for information security.
3. General description of
the information system includes:
a) Information on the
owner of the information system, including: name, functions, tasks,
entitlements, representative, position, address, and contact information
(including phone number and email address);
b) Information on the
operating unit of the information system, including: name, functions, tasks,
entitlements, representative, position, address, and contact information
(including phone number and email);
c) Description of the
information system’s scale and scope, specifying the system’s scale, scope, and
target users;
d) Description of the
system’s architecture, either current (for a currently operating system) or
expected (for a new, upgraded, or expanded system). The description includes
the logical and physical models of the system, a list of core network devices
and devices in the system (including name/type, implementation location, and
purposes), a list of applications/services provided by the system (including
service names, servers/implementation locations/operating systems of servers,
and service purposes), and planning for network zones and IP addresses in the
system (including network zones, internal IP addresses (Private IP), and public
IP addresses (Public IP)).
4. Description of the
proposed classification levels includes:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
b) Detailed description
of information systems, specifying the processed information types, information
system types, and grounds to propose the classification levels for each
information system.
5. Description of the
proposed classification levels for information systems classified at level 4 or
level 5, in addition to the contents specified in Clause 3 of this Article,
must clarify the following contents:
a) Identification of
other related or connected information systems or those that impact the normal
operation of information systems with proposed classification levels;
b) Description of
potential cyberattacks and their impact on the information systems with
proposed classification levels;
c) Assessment of the
scope and level of impact on public interests, social order and safety, or
national defense and security upon cyberattacks causing loss of information
security or disruption of the operation of the information systems with
proposed classification levels;
d) Description of the
requirement for 24/7 uninterrupted operation and justification for not
accepting unplanned downtime for information systems according to Clauses 2 and
3 Article 10 of Decree No. 85/2016/ND-CP.
6. Description of
the plan for information security includes:
a) Description of how the
plan’s proposed classification levels meet the corresponding management
requirements;
b) Description of how the
plan’s proposed classification levels meet the corresponding technical
requirements;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
REQUIREMENTS
FOR LEVEL-BASED INFORMATION SYSTEM SECURITY
Article
9. General requirements
1. The assurance of
level-based information system security shall comply with the basic
requirements specified in this Circular and National Technical Standard TCVN
11930:2017 on Information technology – Security techniques – Basic requirements
for securing information system according to security levels.
2. The basic requirements
for each classification level in this Circular are the minimum requirements for
ensuring information system security. These include basic management and
technical requirements, excluding physical security requirements.
3. Basic management
requirements include:
a) Establishment of
information security policies;
b) Assurance of
information security;
c) Assurance of personnel
sources;
d) Management of system
design and development;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
e) Plans to manage
information security risks;
g) Plans for
decommissioning, utilization, liquidation, and termination of the information
systems.
4. Basic technical requirements
include:
a) Network security
assurance;
b) Server security
assurance;
c) Application security
assurance;
d) Data security
assurance.
5. The development of
plans for information security meeting the basic requirements by each
classification level shall comply with the principles prescribed in Clause 2
Article 4 of Decree No. 85/2016/ND-CP, specifically:
a) For information
systems of levels 1, 2, and 3: the information security plan must consider the
possibility of shared use among information systems regarding solutions to
resource protection and sharing to optimize efficiency and prevent redundant,
overlapping, and wasteful investments;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
6. Newly developed,
expanded, or upgraded information systems must fully implement information
security plans approved in the proposal dossiers on classification levels and
meet the security requirements prescribed in Articles 9 and 10 of this Circular
before being put into operation.
7. Regulations on
information system security must be developed according to the security
requirements for management by security classification levels of the respective
information systems. The mentioned regulations must be approved and issued by
competent authorities before the proposal dossiers on classification levels are
approved.
8. Information security
requirements for newly developed, expanded, or upgraded internal software:
a) The internal software
must comply with the Security Software Development Framework;
b) The internal software
must meet the basic security requirements applicable to internal software.
9. Where level-3
information systems are implemented in the form of outsourced IT services at
data centers or via cloud computing platforms, the system design must meet the
following requirements:
a) The level-3
information systems must be logically separated and independent from other
systems, with adopted access management measures among the systems;
b) Network zones within
the systems must be logically separated and independent, with adopted access control
measures among the zones;
c) Storage partitions
must be logically separated and independent.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
a) The level-4/5
information systems must be physically separated and independent from other
systems, with adopted access management measures among the systems;
b) Network zones within
the systems must be logically separated and independent, with adopted access
control measures among the zones;
c) Storage partitions
must be physically separated and independent;
d) Core network devices
must be physically separated and independent.
Article
10. Plans for information security by each classification level
1. Information security
plans for level-1 information systems must meet the requirements specified in
Appendix I enclosed with this Circular.
2. Information security
plans for level-2 information systems must meet the requirements specified in
Appendix II enclosed with this Circular.
3. Information security
plans for level-3 information systems must meet the requirements specified in
Appendix III enclosed with this Circular.
4. Information security
plans for level-4 information systems must meet the requirements specified in
Appendix IV enclosed with this Circular.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Chapter
IV
INFORMATION
SECURITY INSPECTION AND ASSESSMENT
Article
11. General regulations on inspection and assessment
1. Content:
a) Compliance with the
law on level-based information system security;
b) Effectiveness of
information security measures according to approved information security plans;
c) Malware,
vulnerabilities, weaknesses, and penetration tests on the information systems.
2. Frequency:
a) Periodic inspection
and assessment according to Point c Clause 2 Article 20 of Decree No. 85/2016/ND-CP;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
3. Forms of inspection
and assessment to detect malware, vulnerabilities, and weaknesses and perform
penetration tests on the information systems include the following 3 forms:
a) Black box
inspection/assessment;
b) Gray box
inspection/assessment;
c) White box
inspection/assessment.
Article
12. Content of information security inspection and assessment
1. The content of the inspection/assessment
of compliance with the law on level-based information system security includes:
a) Inspecting/assessing
an information system owner’s compliance according to Article 20 of Decree No.
85/2016/ND-CP, including: establishing/designating specialized
units/departments for information security of the information security owner
according to Clause 1 Article 20 of Decree No. 85/2016/ND-CP; formulating
proposal dossiers on classification levels and appraising/approving such
dossiers under regulations for information systems under the owner’s
management; implementing plans for information security according to the
approved plans in the proposal dossiers on classification levels for
information systems under the management of the owner; inspecting/assessing
information security and information security risk management within the owner
according to Point c Clause 2 Article 20 of Decree No. 85/2016/ND-CP;
implementing short-term training, dissemination, universalization, improvement
of awareness, and information security drills according to Point d Clause 2
Article 20 of Decree No. 85/2016/ND-CP;
b) Inspecting/assessing
compliance of a specialized unit for information safety of an information
system owner according to Article 21 of Decree No. 85/2016/ND-CP, including:
counseling, implementing, urging, inspecting, and assessing information
security assurance; appraising, approving, or providing professional opinions
on proposal dossiers on classification levels according to the prescribed
jurisdiction;
c) Inspecting/assessing
an operating unit’s compliance according to Article 22 of Decree No.
85/2016/ND-CP;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2. The content of the
inspection/assessment of the effectiveness of information security measures
according to approved information security plans includes:
a) Inspecting the
adequacy and appropriateness of the regulations on information security
according to the approved information security plans concerning management;
b) Assessing compliance
with regulations and procedures in the regulations on information security
during the operation, utilization, termination, or decommissioning of the
information systems;
c) Assessing the system
design according to the approved information security plans;
d) Assessing the system
establishment and configuration according to the approved information security
plans;
dd) Inspecting the
configuration and security enhancement for system devices, operating systems,
applications, databases, and other relevant components of the systems under the
Ministry of Information and Communications of Vietnam's guidelines.
3. The content of the
inspection/assessment for the detection of malware, vulnerabilities, and
weaknesses and performance of penetration tests on the information systems
includes:
a) Scanning and detecting
malware, vulnerabilities, and weaknesses of the systems and performing test
penetrations for system devices, operating systems, applications, databases,
and other relevant components of the systems;
b) Assessing the security
of source codes for internal software;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Chapter
V
REPORTS
Article
13. General regulations on reports
1. Submission and receipt
methods:
a) Via the document
management and administration system;
b) Via the reporting
software system implemented by the Ministry of Information and Communications
of Vietnam;
c) Via the email system;
d) Other methods
prescribed by the law.
2. Frequency:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
b) Ad hoc upon requests
from competent authorities.
3. Data finalization
period for annual reports:
From December 15 of the
year before the reporting period until December 14 of the reporting period.
4. Deadline for
submitting annual reports:
a) Specialized units for information
security and information system operating units shall submit reports to the
information system owners before December 20 every year;
b) The information system
owners shall submit reports to the Ministry of Information and Communications
of Vietnam before December 25 every year.
Article
14. Report contents
1. General information on
the information system owner, specialized units for information security, and
operating units of each information system under the management of such owner,
including: names of the mentioned entities; functions, tasks, and entitlements;
representatives, positions; addresses; contact information (including phone
numbers and email addresses).
2. List of information
systems under the management of the owner, including: system names, operating
units, and proposed classification levels.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
4. List of information
systems that have fully, partially, or not yet implemented security measures
that meet the security requirements according to the approved plans for
level-based information security.
5. List of information
systems with regulations on information security according to regulations.
6. List of information
systems complying with the regulations and procedures in the regulations on
information security during the operation, utilization, termination, or
decommissioning of the information systems.
7. List of information
systems that have undergone inspection/assessment as per regulation.
8. Assessment of the
implementation of information security measures according to the approved plans
for information security in the proposal dossiers on classification levels by
each criterion and requirement.
9. Information on the
decision to approve the proposal dossiers on classification levels and approved
plans for information security in such dossiers by each criterion and
requirement (fully met/not fully met; plans or roadmaps for fulfilling unmet
criteria and requirements).
10. Information on the
promulgation decision and the regulations on information security.
11. Other information
according to competent authorities’ requests.
Chapter
VI
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Article
15. Time for approval of proposal dossiers on classification levels when newly
developing, expanding, or upgrading information systems
Proposal dossiers on
classification levels of information security are encouraged to be approved
before competent authorities approve the respective technical-economic reports,
base designs of the feasibility research reports, plans for outsourced IT
services, or detailed outline and estimate.
Article
16. Transitional provisions
1. For information
systems already in operation with classification levels approved before the
effective date of this Circular, the information system owners shall review the
approved proposal dossiers on classification levels and plans for information
security. The review, revision, and re-approval of proposal dossiers on
classification levels and plans for information security (if necessary) must be
completed before June 2023.
2. For information
systems already in operation but not yet have their proposal dossiers on
classification levels approved, the development, appraisal, and approval of
proposal dossiers on classification levels and implementation of plans for
information security according to the approved plans in the proposal dossiers
on classification levels must meet the requirements prescribed in Circular No.
03/2017/TT-BTTTT dated April 25, 2017 of the Ministry of Information and
Communications of Vietnam and align with this Circular, ensuring that once this
Circular takes effect, the processes of developing, appraising, and approving
the proposal dossiers on classification levels will not need to be repeated.
Article
17. Entry into force and implementation responsibilities
1. This Circular comes
into force as of October 1, 2022 and replaces Circular No. 03/2017/TT-BTTTT
dated April 24, 2017 of the Ministry of Information and Communications of
Vietnam.
2. Any difficulty arising
during the implementation of this Circular shall be promptly reported to the
Ministry of Information and Communications (Authority of Information Security)
for cooperation in handling./.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
MINISTER
Nguyen Manh Hung
APPENDIX I
BASIC REQUIREMENTS FOR
INFORMATION SYSTEM SECURITY FOR LEVEL-1 INFORMATION SYSTEMS
(Enclosed with Circular No. 12/2022/TT-BTTTT dated August 12, 2022 of the Minister
of Information and Communications of Vietnam)
I.
MANAGEMENT REQUIREMENTS
NO.
Requirement
TCVN 11930:2017
1.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 5.1.1
1.1.1
Information security
policies
Section 5.1.1.1
1.1.2
Development and
announcement
Section 5.1.1.2
1.1.3
Review and revision
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.2
Assurance of
information security
Section 5.1.2
1.2.1
Specialized units for
information security
Section 5.1.2.1
1.2.2
Cooperation with
competent agencies/organizations
Section 5.1.2.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Assurance of
personnel sources
Section 5.1.3
1.3.1
Recruitment
Section 5.1.3.1
1.3.2
During employment
Section 5.1.3.2
1.3.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 5.1.3.3
1.4
Management of system
design and development
Section 5.1.4
1.4.1
Information system
security design
Section 5.1.4.1
1.4.2
System testing and
acceptance
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.5
Management of system
operation
Section 5.1.5
1.5.1
Network security
management
Section 5.1.5.1
1.5.2
Server and application
security management
Section 5.1.5.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Data security
management
Section 5.1.5.3
1.6
Plan to manage
information security risks
1.7
Plan for
decommissioning, utilization, liquidation, and termination
II.
TECHNICAL REQUIREMENTS
1. System design
requirements
a) The design of network
zones in the system must be based on functionality, with at least the following
zones:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
ii. Perimeter network
zone;
iii. DMZ zone
(demilitarized zone).
b) Design plan must
ensure the following:
i. Safe access management
and remote system administration using virtual private networks or equivalents;
ii. Access management
among network zones, intrusion prevention, and use of firewalls integrated with
intrusion prevention features or equivalents;
iii. Anti-malware for
servers and workstations using anti-malware products or equivalents.
2. System
establishment and configuration requirements
NO.
Requirement
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1
Network security
assurance
Section 5.2.1
1.1.1
External access control
Section 5.2.1.2
1.1.2
System logs
Section 5.2.1.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Intrusion prevention
Section 5.2.1.4
1.1.4
System device
protection
Section 5.2.1.5
1.2
Server security
assurance
Section 5.2.2
1.2.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 5.2.2.1
1.2.2
Access control
Section 5.2.2.2
1.2.3
System logs
Section 5.2.2.3
1.2.4
Intrusion prevention
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.2.5
Anti-malware
Section 5.2.2.5
1.3
Application security
assurance
Section 5.2.3
1.3.1
Authentication
Section 5.2.3.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Access control
Section 5.2.3.2
1.3.3
System logs
Section 5.2.3.3
1.4
Data security
assurance
Section 5.2.4
1.4.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 5.2.4.1
APPENDIX II
BASIC REQUIREMENTS FOR
INFORMATION SYSTEM SECURITY FOR LEVEL-2 INFORMATION SYSTEMS
(Enclosed with Circular No. 12/2022/TT-BTTTT dated August 12, 2022 of the
Minister of Information and Communications of Vietnam)
I. MANAGEMENT
REQUIREMENTS
NO.
Requirement
TCVN 11930:2017
1.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 6.1.1
1.1.1
Information security
policies
Section 6.1.1.1
1.1.2
Development and
announcement
Section 6.1.1.2
1.1.3
Review and revision
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.2
Assurance of information
security
Section 6.1.2
1.2.1
Specialized units for
information security
Section 6.1.2.1
1.2.2
Cooperation with
competent agencies/organizations
Section 6.1.2.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Assurance of
personnel sources
Section 6.1.3
1.3.1
Recruitment
Section 6.1.3.1
1.3.2
During employment
Section 6.1.3.2
1.3.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 6.1.3.3
1.4
Management of system
design and development
Section 6.1.4
1.4.1
Information system
security design
Section 6.1.4.1
1.4.2
Contracting software development
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.4.3
System testing and
acceptance
Section 6.1.4.3
1.5
Management of system
operation
Section 6.1.5
1.5.1
Network security
management
Section 6.1.5.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Server and application
security management
Section 6.1.5.2
1.5.3
Data security
management
Section 6.1.5.3
1.5.4
Information security
incident management
Section 6.1.5.4
1.5.5
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 6.1.5.5
1.6
Plan to manage
information security risks
1.7
Plan for decommissioning,
utilization, liquidation, and termination
II. TECHNICAL
REQUIREMENTS
1. System design
requirements
a) The design of network
zones in the system must be based on functionality, with at least the following
zones:
i. Internal network zones;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
iii. DMZ zone
(demilitarized zone).
iv. Internal server zone;
v. Wireless network zone
(if any) separated and independent from other network zones.
b) Design plan must
ensure the following:
i. Safe access management
and remote system administration using virtual private networks or equivalents;
ii. Access management
among network zones, intrusion prevention, and use of firewalls integrated with
intrusion prevention features or equivalents;
iii. Anti-malware for
servers and workstations using anti-malware products or equivalents;
iv. Cyberattack
prevention for web applications; use of a Web Application Firewall (WAF) for
information system s prescribed in Clause 2 Article 8 of Decree No.
85/2016/ND-CP;
v. Assurance of
information security for email systems, applicable to systems with email
functionality;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2. System
establishment and configuration requirements
NO.
Requirement
TCVN 11930:2017
1.1
Network security
assurance
Section 6.2.1
1.1.1
External access control
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1.2
Internal access control
Section 6.2.1.3
1.1.3
System logs
Section 6.2.1.4
1.1.4
Intrusion prevention
Section 6.2.1.5
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
System device
protection
Section 6.2.1.6
1.2
Server security
assurance
Section 6.2.2
1.2.1
Authentication
Section 6.2.2.1
1.2.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 6.2.2.2
1.2.3
System logs
Section 6.2.2.3
1.2.4
Intrusion prevention
Section 6.2.2.4
1.2.5
Anti-malware
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.2.6
Server handling upon
handover
Section 6.2.2.6
1.3
Application security
assurance
Section 6.2.3
1.3.1
Authentication
Section 6.2.3.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Access control
Section 6.2.3.2
1.3.3
System logs
Section 6.2.3.3
1.3.4
Application and source
code security
Section 6.2.3.4
1.4
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 6.2.4
1.4.1
Data confidentiality
Section 6.2.4.1
1.4.2
Backup and recovery
Section 6.2.4.2
APPENDIX III
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
I. MANAGEMENT
REQUIREMENTS
NO.
Requirement
TCVN 11930:2017
1.1
Establishment of
information security policies
Section 7.1.1
1.1.1
Information security
policies
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1.2
Development and
announcement
Section 7.1.1.2
1.1.3
Review and revision
Section 7.1.1.3
1.2
Assurance of
information security
Section 7.1.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Specialized units for
information security
Section 7.1.2.1
1.2.2
Cooperation with
competent agencies/organizations
Section 7.1.2.2
1.3
Assurance of
personnel sources
Section 7.1.3
1.3.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 7.1.3.1
1.3.2
During employment
Section 7.1.3.2
1.3.3
Termination or job
transfer
Section 7.1.3.3
1.4
Management of system
design and development
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.4.1
Information system
security design
Section 7.1.4.1
1.4.2
Contracting software
development
Section 7.1.4.2
1.4.3
System testing and
acceptance
Section 7.1.4.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Management of system
operation
Section 7.1.5
1.5.1
Network security
management
Section 7.1.5.1
1.5.2
Server and application
security management
Section 7.1.5.2
1.5.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 7.1.5.3
1.5.4
Endpoint device
security management
Section 7.1.5.4
1.5.5
Anti-malware management
Section 7.1.5.5
1.5.6
Information system
security supervision management
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.5.7
Information security
weakness management
Section 7.1.5.7
1.5.8
Information security
incident management
Section 7.1.5.8
1.5.9
End-user security
management
Section 7.1.5.9
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Plan to manage
information security risks
1.7
Plan for
decommissioning, utilization, liquidation, and termination
II. TECHNICAL
REQUIREMENTS
1. System design
requirements
a) The design of network
zones in the system must be based on functionality, with at least the following
zones:
i. Internal network
zones;
ii. Perimeter network
zone;
iii. DMZ zone (demilitarized
zone).
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
v. Wireless network zone
(if any) separated and independent from other network zones;
vi. Database server
network zone;
vii. Administration zone.
b) Design plan must
ensure the following:
i. Safe access management
and remote system administration using virtual private networks or equivalents;
use of virtual private network products for information systems handling state
secrets or information systems prescribed in Point c Clause 2 Article 9 of
Decree No. 85/2016/ND-CP;
ii. Access management
among network zones, intrusion prevention, and use of firewalls integrated with
intrusion prevention features or network-layer intrusion prevention systems;
iii. Load balancing and
hot standby for core network devices, including at least center switches or
equivalents, core firewalls, WAFs, centralized storage systems, and database
firewalls (if any);
iv. Security assurance
for database servers; use of database firewalls for centralized database
systems meeting the criteria prescribed in Clause 3 Article 9 of Decree No.
85/2016/ND-CP;
v. Malware filtering on
the network environment using firewalls integrated with anti-malware features
on the network environment or equivalents;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
vii. Cyberattack
prevention for web applications; use of a WAF for information systems
prescribed in Clause 2 Article 8 of Decree No. 85/2016/ND-CP;
viii. Assurance of
information security for email systems; use of information security products
for email systems for systems with email functionality meeting the criteria
prescribed in Clause 2 Article 9 of Decree Nol. 85/2016/ND-CP;
ix. Network-layer access
management; use of network-layer access management products for internal
network systems and centers for network information security operation
supervision meeting the criteria prescribed in Clause 3 Article 9 of Decree No.
85/2016/ND-CP;
x. Supervision of
centralized information systems;
xi. Supervision of the
security of centralized information systems using Security Information and
Event Management (SIEM) products or equivalents;
xii. Centralized
backup/recovery management using centralized storage systems and centralized
storage management products;
xiii. Management of
anti-malware software on servers/user computers, use of anti-malware products
and/or endpoint detection and response (EDR) products with a centralized
management function;
xiv. Data loss
prevention; use of data loss prevention products for information systems
handling state secrets or information systems prescribed in Point c Clause 2
Article 9 of Decree No. 85/2016/ND-CP;
xv. Internet connection
backup plans for service servers;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2. System
establishment and configuration requirements
NO.
Requirement
TCVN 11930:2017
1.1
Network security
assurance
Section 7.2.1
1.1.1
External access control
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1.2
Internal access control
Section 7.2.1.3
1.1.3
System logs
Section 7.2.1.4
1.1.4
Intrusion prevention
Section 7.2.1.5
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Anti-malware on network
environment
Section 7.2.1.6
1.1.6
System device
protection
Section 7.2.1.7
1.2
Server security assurance
Section 7.2.2
1.2.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 7.2.2.1
1.2.2
Access control
Section 7.2.2.2
1.2.3
System logs
Section 7.2.2.3
1.2.4
Intrusion prevention
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.2.5
Anti-malware
Section 7.2.2.5
1.2.6
Server handling upon
handover
Section 7.2.2.6
1.3
Application security
assurance
Section 7.2.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Authentication
Section 7.2.3.1
1.3.2
Access control
Section 7.2.3.2
1.3.3
System logs
Section 7.2.3.3
1.3.4
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 7.2.3.4
1.3.5
Non-repudiation
Section 7.2.3.5
1.3.6
Application and source
code security
Section 7.2.3.6
1.4
Data security
assurance
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.4.1
Data integrity
Section 7.2.4.1
1.4.2
Data confidentiality
Section 7.2.4.2
1.4.3
Backup and recovery
Section 7.2.4.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
APPENDIX IV
BASIC REQUIREMENTS FOR
INFORMATION SYSTEM SECURITY FOR LEVEL-4 INFORMATION SYSTEMS
(Enclosed with Circular No. 12/2022/TT-BTTTT dated August 12, 2022 of the
Minister of Information and Communications of Vietnam)
I. MANAGEMENT
REQUIREMENTS
NO.
Requirement
TCVN 11930:2017
1.1
Establishment of
information security policies
Section 8.1.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Information security
policies
Section 8.1.1.1
1.1.2
Development and
announcement
Section 8.1.1.2
1.1.3
Review and revision
Section 8.1.1.3
1.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 8.1.2
1.2.1
Specialized units for
information security
Section 8.1.2.1
1.2.2
Cooperation with
competent agencies/organizations
Section 8.1.2.2
1.3
Assurance of
personnel sources
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.3.1
Recruitment
Section 8.1.3.1
1.3.2
During employment
Section 8.1.3.2
1.3.3
Termination or job
transfer
Section 8.1.3.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Management of system
design and development
Section 8.1.4
1.4.1
Information system
security design
Section 8.1.4.1
1.4.2
Contracting software
development
Section 8.1.4.2
1.4.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 8.1.4.3
1.5
Management of system
operation
Section 8.1.5
1.5.1
Network security
management
Section 8.1.5.1
1.5.2
Server and application security
management
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.5.3
Data security
management
Section 8.1.5.3
1.5.4
Endpoint device
security management
Section 8.1.5.4
1.5.5
Anti-malware management
Section 8.1.5.5
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Information system
security supervision management
Section 8.1.5.6
1.5.7
Information security
weakness management
Section 8.1.5.7
1.5.8
Information security
incident management
Section 8.1.5.8
1.5.9
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 8.1.5.9
1.6
Plan to manage
information security risks
1.7
Plan for
decommissioning, utilization, liquidation, and termination
II. TECHNICAL
REQUIREMENTS
1. System design
requirements
a) The design of network
zones in the system must be based on functionality, with at least the following
zones:
i. Internal network
zones;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
iii. DMZ zone
(demilitarized zone).
iv. Internal server zone;
v. Wireless network zone
(if any) separated and independent from other network zones;
vi. Database server
network zone;
vii. Administration zone;
viii. System device
administration zone.
b) Design plan must
ensure the following:
i. Safe access management
and remote system administration using virtual private networks or equivalents;
use of virtual private network products for information systems handling state
secrets;
ii. Access management
among network zones, intrusion prevention, and use of firewalls integrated with
intrusion prevention features or network-layer intrusion prevention systems;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
iv. Security assurance
for database servers; use of database firewalls for shared database systems
meeting the criteria prescribed in Clause 3 Article 10 of Decree No.
85/2016/ND-CP;
v. Malware filtering on
the network environment using firewalls integrated with anti-malware features
on the network environment or equivalents;
vi. Denial-of-service
attack prevention; use of services of enterprises or denial-of-service attack
prevention products for information systems prescribed in Clause 2 Article 10
of Decree No. 85/2016/ND-CP or data center systems, cloud computing platforms,
systems for electronic identification, electronic authentication, electronic
certification, digital signatures, and data sharing and integration systems
meeting the criteria prescribed in Clause 3 Article 9 of Decree No.
85/2016/ND-CP;
vii. Denial-of-service
attack prevention for web applications; use of services of enterprises or
denial-of-service attack prevention products for information systems prescribed
in Clause 2 Article 10 of Decree No. 85/2016/ND-CP or data center systems,
cloud computing platforms, systems for electronic identification, electronic
authentication, electronic certification, digital signatures, and data sharing
and integration systems meeting the criteria prescribed in Clause 3 Article 9
of Decree No. 85/2016/ND-CP;
viii. Assurance of information
security for email systems; use of information security products for email
systems;
ix. Network-layer access
management; use of network-layer access management products for internal
network systems and centers for network information security operation
supervision meeting the criteria prescribed in Clause 3 Article 10 of Decree
No. 85/2016/ND-CP;
x. Supervision of
centralized information systems using centralized information system
supervision products;
xi. Supervision of the
security of centralized information systems using SIEM products or equivalents;
xii. Centralized
backup/recovery management using centralized storage systems and centralized
storage management products;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
xiv. Data loss
prevention; use of data loss prevention products for information systems
handling state secrets or shared database information meeting the criteria
prescribed in Clause 3 Article 10 of Decree No. 85/2016/ND-CP;
xv. Internet connection
backup plans for service servers;
xvi. Wireless network
security assurance (if any);
xvii. Privileged account
management using privileged access management (PAM) products.
2. System
establishment and configuration requirements
NO.
Requirement
TCVN 11930:2017
1.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 8.2.1
1.1.1
External access control
Section 8.2.1.2
1.1.2
Internal access control
Section 8.2.1.3
1.1.3
System logs
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1.4
Intrusion prevention
Section 8.2.1.5
1.1.5
Anti-malware on network
environment
Section 8.2.1.6
1.1.6
System device
protection
Section 8.2.1.7
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Server security
assurance
Section 8.2.2
1.2.1
Authentication
Section 8.2.2.1
1.2.2
Access control
Section 8.2.2.2
1.2.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 8.2.2.3
1.2.4
Intrusion prevention
Section 8.2.2.4
1.2.5
Anti-malware
Section 8.2.2.5
1.2.6
Server handling upon
handover
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.3
Application security
assurance
Section 8.2.3
1.3.1
Authentication
Section 8.2.3.1
1.3.2
Access control
Section 8.2.3.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
System logs
Section 8.2.3.3
1.3.4
Contact information
confidentiality
Section 8.2.3.4
1.3.5
Non-repudiation
Section 8.2.3.5
1.3.6
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 8.2.3.6
1.4
Data security
assurance
Section 8.2.4
1.4.1
Data integrity
Section 8.2.4.1
1.4.2
Data confidentiality
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.4.3
Backup and recovery
Section 8.2.4.3
APPENDIX V
BASIC REQUIREMENTS FOR
INFORMATION SYSTEM SECURITY FOR LEVEL-5 INFORMATION SYSTEMS
(Enclosed with Circular No. 12/2022/TT-BTTTT dated August 12, 2022 of the
Minister of Information and Communications of Vietnam)
I. MANAGEMENT
REQUIREMENTS
NO.
Requirement
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1
Establishment of
information security policies
Section 9.1.1
1.1.1
Information security
policies
Section 9.1.1.1
1.1.2
Development and
announcement
Section 9.1.1.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Review and revision
Section 9.1.1.3
1.2
Assurance of information
security
Section 9.1.2
1.2.1
Specialized units for
information security
Section 9.1.2.1
1.2.2
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 9.1.2.2
1.3
Assurance of
personnel sources
Section 9.1.3
1.3.1
Recruitment
Section 9.1.3.1
1.3.2
During employment
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.3.3
Termination or job
transfer
Section 9.1.3.3
1.4
Management of system
design and development
Section 9.1.4
1.4.1
Information system
security design
Section 9.1.4.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Contracting software
development
Section 9.1.4.2
1.4.3
System testing and
acceptance
Section 9.1.4.3
1.5
Management of system
operation
Section 9.1.5
1.5.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 9.1.5.1
1.5.2
Server and application
security management
Section 9.1.5.2
1.5.3
Data security
management
Section 9.1.5.3
1.5.4
Endpoint device
security management
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.5.5
Anti-malware management
Section 9.1.5.5
1.5.6
Information system
security supervision management
Section 9.1.5.6
1.5.7
Information security
weakness management
Section 9.1.5.7
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Information security
incident management
Section 9.1.5.8
1.5.9
End-user security
management
Section 9.1.5.9
1.6
Plan to manage
information security risks
1.7
Plan for decommissioning,
utilization, liquidation, and termination
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1. System design
requirements
a) The design of network
zones in the system must be based on functionality, with at least the following
zones:
i. Internal network
zones;
ii. Perimeter network
zone;
iii. DMZ zone
(demilitarized zone).
iv. Internal server zone;
v. Wireless network zone
(if any) separated and independent from other network zones;
vi. Database server
network zone;
vii. Administration zone;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
b) Design plan must
ensure the following:
i. Safe access management
and remote system administration using virtual private networks;
ii. Access management
among network zones, intrusion prevention, and use network-layer intrusion
prevention systems;
iii. Load balancing and
hot standby for network devices;
iv. Security assurance
for database servers; use of database firewalls for information systems
prescribed in Clause 2 Article 11 of Decree No. 85/2016/ND-CP;
v. Malware filtering on
the network environment using firewalls integrated with anti-malware features
on the network environment or equivalents;
vi. Denial-of-service
attack prevention; use of services of enterprises or denial-of-service attack
prevention products for information systems prescribed in Clauses 2 and 3
Article 11 of Decree No. 85/2016/ND-CP;
vii. Cyberattack
prevention for web applications; use of a WAF for information systems
prescribed in Clause 2 Article 11 of Decree No. 85/2016/ND-CP;
viii. Assurance of
information security for email systems and use of information security products
for email systems;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
x. Supervision of
centralized information systems using centralized information system
supervision products;
xi. Supervision of the
security of centralized information systems using SIEM products or equivalents;
xii. Centralized
backup/recovery management using centralized storage systems and centralized
storage management products;
xiii. Management of
anti-malware software on servers/user computers, use of anti-malware products
and/or EDR products with a centralized management function;
xiv. Data loss
prevention; use of data loss prevention products for information systems
handling state secrets or information systems prescribed in Clause 2 Article 11
of Decree No. 85/2016/ND-CP;
xv. Internet connection
backup plans for service servers;
xvi. Wireless network
security assurance (if any);
xvii. Privileged account
management using PAM products;
xviii. Backup systems
located in different geographical locations, at least 30 km apart from each
other;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2. System
establishment and configuration requirements
NO.
Requirement
TCVN 11930:2017
1.1
Network security
assurance
Section 9.2.1
1.1.1
External access control
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.1.2
Internal access control
Section 9.2.1.3
1.1.3
System logs
Section 9.2.1.4
1.1.4
Intrusion prevention
Section 9.2.1.5
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Anti-malware on network
environment
Section 9.2.1.6
1.1.6
System device
protection
Section 9.2.1.7
1.2
Server security
assurance
Section 9.2.2
1.2.1
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 9.2.2.1
1.2.2
Access control
Section 9.2.2.2
1.2.3
System logs
Section 9.2.2.3
1.2.4
Intrusion prevention
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.2.5
Anti-malware
Section 9.2.2.5
1.2.6
Server handling upon
handover
Section 9.2.2.6
1.3
Application security
assurance
Section 9.2.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Authentication
Section 9.2.3.1
1.3.2
Access control
Section 9.2.3.2
1.3.3
System logs
Section 9.2.3.3
1.3.4
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Section 9.2.3.4
1.3.5
Non-repudiation
Section 9.2.3.5
1.3.6
Application and source
code security
Section 9.2.3.6
1.4
Data security assurance
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1.4.1
Data integrity
Section 9.2.4.1
1.4.2
Data confidentiality
Section 9.2.4.2
1.4.3
Backup and recovery
Section 9.2.4.3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.