04 General Requirements on Information System Security Assurance

This content is stipulated in Circular 03/2017/TT-BTTTT issued by the Ministry of Information and Communications on April 24, 2017, providing guidance on ensuring the security of information systems by level.

Accordingly, Circular 03 stipulates that ensuring the safety of the information system must meet the following conditions:

- Ensuring the safety of the information system according to the level is carried out according to the basic requirements specified in this Circular; standards, technical regulations on information safety and other related technical standards and regulations.

- The basic requirements for each level specified in this Circular are the minimum requirements to ensure the safety of the information system and do not include physical safety requirements.

- The basic requirements include:

- Technical requirements: network infrastructure safety; server safety; application safety and data safety;- Management requirements: General policy; organization, personnel; design and construction management; operation management; inspection, evaluation and risk management.

- The development of plans to ensure information safety meeting the basic requirements according to each level shall be carried out according to the principles specified in Clause 2, Article 4 of Decree 85/2016/ND-CP. To be specific:

- For information systems of levels 1, 2, 3: The plan to ensure information safety must consider the possibility of sharing among information systems for protection solutions, sharing resources to optimize performance, avoiding redundant, overlapping, and wasteful investments. In case of new investment, there must be an explanation that the existing solutions do not meet the basic requirements;- For information systems of levels 4, 5: The plan to ensure information safety needs to be designed to ensure availability, separation, and limit the impact on the entire system when a component in the system or related to the system loses information safety.

View details Circular 03/2017/TT-BTTTT effective from July 1, 2017.

-Thao Uyen-

>> CLICK HERE TO READ THIS ARTICLE IN VIETNAMESE

0 lượt xem



  • Address: 19 Nguyen Gia Thieu, Vo Thi Sau Ward, District 3, Ho Chi Minh City
    Phone: (028) 7302 2286
    E-mail: [email protected]
Parent company: THU VIEN PHAP LUAT Ltd.
Editorial Director: Mr. Bui Tuong Vu - Tel. 028 3935 2079
P.702A , Centre Point, 106 Nguyen Van Troi, Ward 8, Phu Nhuan District, HCM City;