| THE PRIME MINISTER ------- | SOCIALIST REPUBLIC OF VIET NAM Independence - Freedom - Happiness ---------- |
| No. 63/QD-TTg | Hanoi, January 13, 2010 |
DECISION
APPROVING THE NATIONAL PLANNING ON DEVELOPMENT OF DIGITAL INFORMATION SECURITY THROUGH 2020
THE PRIME MINISTER
Pursuant to the December 25, 2001 Law on Organization of the Government;
Pursuant to the May 25, 2002 Ordinance on Post and Telecommunications;
Pursuant to the November 29, 2005 Law on Transactions;
Pursuant to the June 29, 2006 Law on Information Technology;
Pursuant to the Government's Decree No. 160/2004/ND-CP of September 3, 2004, detailing the implementation of a number of articles of the Ordinance on Post and Telecommunications regarding telecommunications;
Pursuant to the Government's Decree No. 26/ 2007/ND-CP of February 15, 2007, detailing the implementation of the Law on E-Transactions regarding digital signatures and digital signature certification services;
Pursuant to the Government's Decree No. 64/ 2007/ND-CP of April 10, 2007, providing for the applicative of information technology in state agencies operations;
Pursuant to the Government's Decree No. 97/ 2008/ND-CP of August 28, 2008, providing for the management, provision and use of Internet services and e-information on the Internet;
At the proposal of the Minister of Information and Communications,
DECIDES:
Article 1. To approve the national planning on development of digital information security through 2020, with the following principal contents:
I. PLANNING VIEWPOINTS
1. The concept of digital information security:
"Digital information security" is a term used to refer to the protection of digital information and information systems from natural risks and illegal access, use, disclosure, sabotage, modification or destruction, aiming to ensure the accurate and reliable operations of information systems in service of proper users (below referred to as information security).
Information security denotes the protection of network and information infrastructure safety, computer and data safety and information technology application.
2. Assurance of information security should be comprehensively considered from the following aspects:
a/ Ensuring the Planning's compliance with laws on information technology in general and information security in particular.
b/ Ensuring the management of information systems under prescribed processes, standards and technical regulations from the stage of planning, designing, development and operation to liquidation.
c/ All subjects entitled to lawful access to information systems must be protected and have responsibility to ensure information security for the systems.
3. The Government encourages organizations and individuals to protect and develop information security in different forms within the law-established frame in order to contribute to stepping up information technology application and development.
4. The Government encourages domestic organizations and individuals to research into and develop information security products and solutions for combined use with imported products, striving to achieve complete mastery of technologies so as to ensure information security for national key information systems at an increasing level.
II. GENERAL OBJECTIVES THROUGH 2020
1. Ensuring network and information infrastructure safety
a/ Information security for national key information systems will be guaranteed by special-use security systems of high reliability;
b/ Operations of digital signature certification systems and public code infrastructure systems will be controlled in conformity with relevant technical standards;
c/ A network for coordination of response to, incidents in national information networks and infrastructure will be set up, involving various economic sectors;
d/ By 2020, network and information infrastructure safety will be guaranteed to meet development requirements of the information technology industry.
2. Ensuring safety for data and information technology applications
a/ Information security for e-government and e-commerce applications will be guaranteed at the highest level during the process of providing online services to the public;
b/ Information security for national key information systems will satisfy international standards;