|
THE PRIME MINISTER |
SOCIALIST REPUBLIC OF VIETNAM |
|
No. 1622/QD-TTg |
Hanoi, October 25, 2017 |
DECISION
APPROVAL FOR SCHEME FOR INTENSIFYING OPERATION OF CERT NETWORK, CAPACITY BUILDING FOR STAFF, SPECIALIZED DIVISION OF CYBERSECURITY EMERGENCY RESPONSE NATIONWIDE TO 2020, WITH AN ORIENTATION TO 2025
PRIME MINISTER
Pursuant to the Law on Government Organization dated June 19, 2015;
Pursuant to the Law on Information Technology dated June 29, 2006;
Pursuant to the Law on Telecommunication dated December 4, 2009;
Pursuant to the Law on Cyber information Security dated November 19, 2015;
Pursuant to the Government's Decree No. 72/2013/ND-CP dated July 15, 2013 on management, provision and use of Internet services and cyber information;
Pursuant to the Government's Decree No. 85/2016/ND-CP dated July 1, 2016 on the security of information systems by classification;
Pursuant to the Government's Decree No. 17/2017/ND-CP dated February 17, 2017 defining the functions, tasks, entitlements and organizational structure of the Ministry of Information and Communications;
Pursuant to Decision No. 05/2017/QD-TTg dated March 16, 2017 of the Prime Minister promulgating regulations on national cyber security emergency response system;
At the request of Minister of Information Technology and Communications,
HEREBY DECIDES:
Article 1. Approve the “Scheme for intensifying operation of CERT network, capacity building for staff, specialized division of cyber security emergency response nationwide to 2020, with an orientation to 2025” (hereinafter referred to as the Scheme) below:
I. OBJECTIVES OF THE SCHEME
1. Orientation to 2025
- Build the Vietnam Computer Emergency Response Team (VNCERT) – also the National Cyber security Emergency Response and Coordination Center (hereinafter referred to as VNCERT) to become a strong and professional unit with staff and technology qualified for dealing with computer security emergency nationwide, giving quick responses and timely and effective coordination to serious emergency, playing a key role to maintain national computer security;
- Build a national CERT network (CERT network) to become a strong and professional unit which associates with subsidiaries to cooperate and coordinate other forces consistently and effectively to respond to cyber security emergency, anti-cyberattack;
- Build computer emergency response teams (hereinafter referred to as CERTs) of Ministries, regulatory bodies, and local governments, groups, big corporates, companies which have professional competence to prevent effectively, ready for quick responses, and respond to cyber emergency and cyberattack in a timely manner;
- Provide refresher courses for CERTs from network members who have professional knowledge, good skills, analysis and research ability, are professionally proficient and disciplined, comply with predetermined process, ready for quick, accurate and timely responses to cyber security emergency and cyberattack.
2. Specific objectives to 2020
- Enhance CERT’s capacity through formulating processes, management and coordination practices; invest systems to monitor and gather information about emergency; system to receive, save and process emergency information; improve the administration and sharing of emergency information;
- Accelerate activities of CERT network and CERTs;
- Enhance capacity to monitor, gather, analyze, discover emergency and coordinate and respond to emergency across the network;
- Provide refresher courses for CERTs to maintain computer security;
- Raise awareness of knowledge about cyber threats and emergency, computer security emergency responses and coordination;
- Accelerate international cooperation, share information and experience, intensify the cooperation between CERTs nationwide.
II. PRIMARY TASKS
1. Task 1: Improve performance of VNCERT
a) Procure, upgrade hardware, software, facilities to maintain operation of VNCERT, facilitating emergency responses;
b) Operate National Cyber Security Center with basic component systems as follows:
- Vietnam Cyber Security Operations Center;
- CERTs Network Portal and Communication Media;
- cyber security threat process system; cyber security analysis, verification and classification system;
c) Operate VNCERT Security and Verification Lab;
d) Procure and operate the system to test security skills and attack and defense simulation system for computer security emergency response drill;
dd) Formulate a scheme for transforming organization and intensifying performance of VNCERT.
The components from Point a to d of this Clause shall be invested comprehensively as follows:
- Invest technical system with advanced technology;
- Apply processes, practices, operation methods that are modern and effective;
- Provide refresher courses and maintain highly-qualified staff and hire technical services to maintain the operation of the system.
2. Task 2: Reinforce and improve performance of CERT network
a) Prepare and initiate annual operation plans of the following entities: CERT network and Network Board of Management; Steering Committee and Standing board of emergency response coordination, VNCERT and incident response specialized units; incident response teams; emergency response divisions; expert groups in charge of cyber security analysis and serious emergency responses;
b) Prepare and initiate plans for national cyber security incident responses;
c) Accelerate general activities of CERT network: Annually, hold 4 meetings of network briefing; 3 seminars on experience and practice sharing; 6 business trips to survey, inspect and cooperate work of incident response and coordination;
d) Carry out acquisition, analysis, verification, digital forensics and procure incident information services to build database, make reports and evaluate cyber security incidents, malware, and cyberattack and cyber security;
dd) Study new technology to apply them in coordination, response and prevention of cyberattack; apply processes and regulations on coordination of response network as the case may be, corresponding to each type of incidents.
3. Task 3. Enhance the collection, analysis, verification and warning, coordination, responses to cyber security incidents of VNCERT and members of CERT network
a) Intensify the monitoring, collection, analysis, verification and evaluation of threats for early detection and timely warning of cyber security incidents:
- Carry out or engage service providers to continuously monitor, collect and analyze incidents from CERT network and domestic organizations; from foreign incident response teams and foreign cyber security teams; from credit cyber security forums and websites; and from national cyber security surveillance centers;
- Investigate and analyze digital data, verify and classify incidents;
- Give timely warning to network members, relevant entities when detecting cyber security incidents and threats.
b) Conduct incident coordination and response:
- Prepare and initiate plans for cyber security incident responses and cyber security emergency responses;
- Promptly coordinate ISPs, telecommunication enterprises and network members to prevent and rectify incidents;
- Study and prepare plans and promptly instruct entities facing with incidents to rectify incidents;
- Respond to and deal with incidents happened to significant IT systems of regulatory agencies and electronic government when dedicated units, internal CERTs and system managing units fail to manage themselves;
- Provide guidelines for determination of workload, loss and payment made to organizations or enterprises participating in incident responses under coordination of competent authorities.
4. Task 4: Hold CERT incident drills
a) National level:
- Annually, hold 1 national drill and 3 regional or sectoral drills;
- Annually, hold 3 to 5 international drills, including: Hold drills with Asia Pacific Computer Emergency Response Team (APCERT); hold drills with ASEAN - JAPAN; hold ASEAN CERT Incident Drill (ACID) and other international drills;
- Study, make, hire, purchase equipment and software fit for simulation and performance of scenarios for drills and their expansion.
b) Ministerial and provincial level:
Annually, each Ministry and province shall hold at least 1 CERT drill; cooperate and participate in national and international drills held by VNCERT or the Ministry of Information and Communications.
5. Task 5. Develop capacity of CERT staff
a) Provide training courses, examinations for granting certificates to CERT staff, including: Training in coordination, response, analysis, forensics of threats and incidents; training in cyber security technology; training in cyberattack, phishing;
b) Provide refresher courses, raise awareness of relevant knowledge including training in process, risk management, international standards for cyber security; training in advancement of special foreign language, legal knowledge, professional ethics and other matters for regulatory agencies and CERT network members;
c) Develop internal staff and engage highly-qualified staff to maintain CERTs and expert groups, CERTs; create and maintain forums for cyber security;
d) Formulate and issue qualifications and certificates required for experts in monitoring, coordination, response, analysis, classification, and forensics of threats, incidents, malware and other technical specialists in terms of cyber security;
dd) Formulate and submit peculiar mechanism and incentive policies to competent authorities for issuance so as to appeal and build capacity of personnel who coordinate and respond to cyber security incidents of CERT network and VNCERT.
6. Task 6: Intensify capacity and operation of CERTs nationwide.
a) Ministries, ministerial-level agencies, central-affiliated cities and provinces (hereinafter referred to as provinces):
- Build and operate technical system for cyber security incident response within the ministries, agencies and provinces;
- Build and initiate plans for cyber security incident response of ministries, agencies, and provinces;
- Take initiative and cooperate with VNCERT in monitoring, collecting, saving journals, logs in systems under their management; analyze and verify incidents within the agencies or provinces; notify when detecting incidents and sharing information, journals and logs to national coordination centers in systems under their management;
- Regularly receive and process warnings, requests for coordination from VNCERT and notify relevant entities for coordination;
- Respond to incidents within the sectors and provinces;
- Request emergency responses in case of beyond capacity; report coordination order execution;
- Initiate or hire cyber security services for IT systems under their management.
b) Telecommunication, Internet enterprises
- Take initiative and cooperate with VNCERT in initiating monitoring devices, collecting, saving journals, logs in systems and Internet under their management; analyze and verify incidents within the agencies or provinces; notify when detecting incidents and sharing information, journals and logs to national coordination centers in systems and Internet under their management;
- Abide by emergency coordination orders from VNCERT, mobile resources to promptly deal with, prevent attack, and rectify consequences following incidents;
- Meet technical requirements to install monitoring devices and connect to central system of VNCERT for cyber security emergency response and coordination.
7. Task 7: Formulate, apply international standards to standardize cyber security loss prevention and protection
a) Formulate, apply and evaluate process to manage risks, cyber security under ISO/IEC 27xxx and other standards for cyber security for CERT network members and managing units of significant data and information system centers of Ministries, ministerial-level agencies, People’s Committees of provinces, telecommunication, Internet enterprises, data centers, financial institutions, banks, governing bodies of national important IT systems;
b) Provide training courses in set of standards ISO/IEC 27xxx and other cyber security standards for CERTs, administrative officers of data and information system centers as provided in Point a hereof.
III. FUNDING
1. Sources of Funds
Central state budget, local state budgets, Vietnam Public-utility Telecommunication Service Fund – VTF, revenue sources of entities which are permitted to retain revenues as prescribed, grant aids and other legal sources of funds.
2. Capital structure
a) Sources of funds from central state budget, local state budget, VTF and other sources under management of the central ministries to perform tasks and projects under this Decision led by Ministries, ministerial-level agencies, Governmental agencies and other tasks prescribed in Appendices enclosed; Ministries, ministerial-level agencies, Governmental agencies shall, based on tasked assigned in this Decision, prepare plans, projects, budget estimates and approve and finance funding as per the law in force;
b) The local state budget and other sources of funds under management of the local government for other tasks and projects prescribed in this Decision shall be set aside by local agencies; the People’s Committee of province shall, based on assigned tasks, prepare plans, budget estimates and approve within their competence or submit them to the People's Council for approval as per the law in force;
c) Prioritize science and technology source of fund to initiate research, analysis of technology, threats, attack methods and prevention solutions so as to improve the research and analysis capacity for the CERTs and other tasks and projects under this Decision.
3. Regarding tasks financed by state budget, relevant agencies shall, based on the assigned tasks prescribed in this Decision, make and aggregate state budget estimates with their budget plan, then send it to finance authority at the same administrative level for consolidation, and then submit them to competent authority for approval in accordance with law on state budget.
4. Regarding tasks priorly financed by VTF as prescribed in Appendix II issued herewith, the Ministry of Information and Communications shall, based on the assigned tasks, prepare specific plans, budget estimates, follow approval procedures as prescribed; if it is unable to finance funding form VTF, the Ministry shall consider financing funding from central state budget. When it reaches the period to prepare or amend investment budget plan 2018 - 2020 and 2021 - 2025, the Ministry of Information and Communications shall take charge and cooperate with the Ministry of Planning and Investment, the Ministry of Finance in checking tasks or projects mentioned in Appendix I and Appendix II issued herewith which have not been financed, and then including them in the following budget plan.
IV. IMPLEMENTATION
1. The Ministry of Information and Communications
a) Take charge and cooperate with ministries, agencies, the People’s Committees of provinces and relevant entities in initiating, regularly inspecting, reporting and evaluating the implementation of this Decision; send reports to the Prime Minister and propose necessary amendments to this Decision;
b) Establish a Board of Management to coordinate, expedite, inspect and guide the implementation of this Decision, in which the leader of the Ministry of Information and Communications shall act as the Board Chief and the standing board is VNCERT; perform tasks prescribed in this Decision at the national level;
c) Assume the prime responsibility for formulating CERT plans and cooperating relevant entities in initiating them;
d) Make public knowledge and laws on cyber security and raise awareness of coordination, incident response, prevention and combating of cyberattack and phishing.
2. The Ministry of Science and Technology
a) Take charge and cooperate with the Ministry of Information and Communications in studying and developing cyber security incident response products and solutions to enable Vietnam to take control of technology;
b) Priorly using science and technology funds, funds from national program for high technology development, program for national product development to develop local products, services, and solutions to facilitate the activities of CERTs and perform the tasks specified in this Decision.
3. The Ministry of Finance
a) Set aside amounts of recurrent expenditures or public expenditures in the state budget to perform the tasks under this Decision;
b) Cooperate with the Ministry of Information and Communications in performing the tasks under this Decision from VTF’s fund.
4. The Ministry of Planning and Investment
a) Set aside amounts of capital expenditures in the state budget to perform the tasks under this Decision;
b) Consider including the tasks under this Decision in public investment programs/plans, target program of information technology and relevant programs/plans, and allocate these source of funds to accelerate the implementation of these tasks.
5. a) Ministries, ministerial-level agencies, Governmental agencies, the People’s Committees provinces:
a) The heads of Ministries, regulatory bodies, and local governments, relevant agencies shall urge formulation of regulations and annual action plans in order for CERTs to perform actively and effectively; enable CERTs to participate in all activities of the CERT network actively;
b) Take charge and cooperate with the Ministry of Information and Communications in performing the tasks of the Scheme within their management;
c) Formulate and issue regulations on incident response and coordination and action plans of CERTs within their management;
d) Assume the prime responsibility for making and initiating plans for cyber security emergency responses within their management;
dd) Direct groups, corporations, enterprises having material communications infrastructure in the administrative division under their management to establish their internal CERTs and cooperate with VNCERT closely. Promptly preparing scenarios and plans for incident prevention and responses;
e) Direct managing units of significant information systems within their management to perform the task prescribed in Point a Clause 7 Section II of this Article to apply information security management model in accordance with the set of standard TCVN ISO/IEC 27xxx.
6. Telecommunication enterprises, ISP and cyber security enterprises
a) Participate in all activities of the CERT network in a responsible way; develop CERTS and the CERT network;
b) Appoint leader in charge of cyber security; establish or designate specialized CERTs; closely coordinate and adhere to coordination of VNCERT in cyber security emergency response;
c) Strictly execute any request for coordination, prevention and response to incidents made by competent authorities.
7. Vietnam Information Security Association (VNISA) and other associations
a) Cooperate with the Ministry of Information and Communications in performing the tasks of the Scheme;
b) Mobilize associates, members of the association to participate in the network and share information about cyber security and cyberattack to the coordination center.
Article 2. This Decision comes into force as of from the date of signing.
Article 3. Ministers, Heads of ministerial-level agencies, Heads of Governmental agencies, the Presidents of People’s Committees of central-affiliated cities and provinces shall implement this Decision./.
|
|
PRIME MINISTER |
APPENDIX I
LIST OF PROJECTS FINANCED BY STATE BUDGET
(Issued together with Decision No. 1622/QD-TTg dated October 25, 2017 of the Prime Minister)
|
No. |
Project, task |
Authority in charge |
Coordinating authority |
Period |
||||
|
I |
Projects and tasks financed from capital investment source of central state budget |
Projects and tasks financed from capital investment source of central state budget |
Projects and tasks financed from capital investment source of central state budget |
Projects and tasks financed from capital investment source of central state budget |
||||
|
1 |
Invest, upgrade equipment, software, facilities to maintain operation of VNCERT |
Ministry of Information and Communications and designated authorities |
|
2018-2025 |
|
|
|
|
|
2 |
Invest hardware, software, facilities for incident responses, hire technical procedures, provide training courses for CERTs of Ministries and central agencies |
Ministries, ministerial-level agencies, Governmental agencies, central agencies |
The Ministry of Information and Communications |
2018-2025 |
|
|
|
|
|
3 |
Build and operate technical system for cyber security incident responses for operation of electronic government system and IT services and systems under the list of prioritized systems for cyber security |
Ministry of Information and Communications and designated authorities |
Ministries and provinces, telecommunication enterprises, Internet |
2018-2025 |
|
|
|
|
|
4 |
Build and operate the system of cyber security incident response and coordination |
The Ministry of Information and Communications |
CERT network members |
2018-2025 |
|
|
|
|
|
5 |
Invest equipment, enhance capacity and performance of CERTs in Ministries, central and local agencies |
The Ministry of Information and Communications |
Ministries, central and local agencies whose budgets have not been balanced |
2018-2025 |
|
|
|
|
|
6 |
Invest equipment, operate Lab, procedures and materials for research, experiment, training and test of security skills. |
The Ministry of Information and Communications |
CERT network members |
2018-2020 |
|
|
|
|
|
7 |
Projects and tasks which cannot be financed although they are under list of projects and tasks priorly financed from VTF mentioned in Appendix II of this Decision. |
The Ministry of Information and Communications |
CERT network members |
2018-2025 |
|
|
|
|
|
II |
Projects and tasks financed from public sources of central state budget |
Projects and tasks financed from public sources of central state budget |
Projects and tasks financed from public sources of central state budget |
Projects and tasks financed from public sources of central state budget |
||||
|
1 |
Maintain operation and hire technical services to ensure the cyber security systems of VNCERT. |
The Ministry of Information and Communications |
CERT network members |
2017-2025 |
|
|
|
|
|
2 |
Operate CERT network and Board of Management of the Scheme, CERT network, VNCERT as prescribed in Task 2 Appendix II of this Decision. |
The Ministry of Information and Communications |
CERT network members |
2017-2025 |
|
|
|
|
|
3 |
Initiate collection, analysis, verification and warning, coordination, cyber security incident response at national level prescribed in Task 3 Part II of this Decision. |
The Ministry of Information and Communications |
CERT network members |
2017-2025 |
|
|
|
|
|
4 |
Hold CERT incident drills at national level as prescribed in Clause a Task 4 Part II of this Decision; provide training courses in cyber security incident responses and prevention as prescribed in Clauses a, b Task 5 Part II of this Decision. |
The Ministry of Information and Communications |
CERT network members |
2017 - 2025 |
|
|
|
|
|
5 |
Intensify capacity and operation of CERTs as prescribed in Point a Clause 6 Section II of this Decision. |
Ministries, ministerial-level agencies, Governmental agencies |
The Ministry of Information and Communications |
2018-2025 |
|
|
|
|
|
6 |
Formulate, apply international standards (ISO27xxx) and other standards for cyber security to standardize cyber security loss prevention and protection as prescribed in Clause 7 Section II of this Decision. |
The Ministry of Information and Communications |
Network members and managing units of database centers and information systems |
2018-2025 |
|
|
|
|
|
7 |
Organize international cooperation: a) Participate in bilateral, multilateral forums with CERTs of countries and global information security associations. b) Hold regular international seminars with the participation of CERTs and local and global cyber security organizations. |
The Ministry of Information and Communications |
CERT network members |
2017 - 2025 |
|
|
|
|
|
8 |
Hold training programs, test, and development of CERT staff as prescribed in Clause 5 Section II of this Decision. |
The Ministry of Information and Communications |
CERT network members |
2018-2025 |
|
|
|
|
APPENDIX II
LIST OF SOME PROJECTS AND TASKS PRIORLY FINANCED FROM VTF
(Issued together with Decision No. 1622/QD-TTg dated October 25, 2017 of the Prime Minister)
|
No. |
Project, task |
Authority in charge |
Coordinating authority |
Period |
|
1 |
Invest and upgrade Vietnam Cyber Security Operations Center |
The Ministry of Information and Communications |
CERT network members |
2018- 2020 |
|
2 |
Build, operate CERTs Network Portal and Communication Media |
The Ministry of Information and Communications |
CERT network members |
2017- 2019 |
|
3 |
Build, operate Cyber Threat Intelligent System |
The Ministry of Information and Communications |
CERT network members |
2017 - 2020 |
|
4 |
Build, operate VNCERT Security and Verification Lab |
The Ministry of Information and Communications |
CERT network members |
2018- 2020 |
|
5 |
Invest, build and operate the system to test security skills and attack and defense simulation system for computer security incident response drills |
The Ministry of Information and Communications |
CERT network members |
2018- 2020 |
|
6 |
Update and renew copyright of software, equipment, hire technical services, staff and maintain, operate special centers and technical systems of VNCERT |
The Ministry of Information and Communications |
CERT network members |
2017 -2025 |
|
7 |
Provide training courses, drills for CERTs of VNCERT, CERT network members and big groups, corporations of the state |
The Ministry of Information and Communications |
CERT network members |
2017 -2025 |
|
8 |
Make public knowledge and laws on cyber security and raise awareness of coordination, incident response, prevention and combating of cyberattack and phishing |
The Ministry of Information and Communications |
CERT network members |
2017-2025 |
---------------
This document is handled by Vinas Doc. Document reference purposes only. Any comments, please send to email: [email protected]