On April 24, 2017, the Ministry of Information and Communications issued Circular 03/2017/TT-BTTTT stipulating specific regulations on the assessment and detection of malicious code infiltrating systems.
Circular 03 stipulates that the assessment for detecting malware, vulnerabilities, weaknesses, and system penetration testing involves performing scans to detect system vulnerabilities and weaknesses, testing to attack system penetration, and evaluating potential risks and damages to the information system when attacked by an intruder.
The lead evaluation unit shall be one of the following organizations:
- Department of Information Security;- Specialized unit in information security;- State administrative organization with relevant functions and duties;- Enterprises licensed to provide network information security inspection and evaluation services or other organizations allowed to conduct malware, vulnerabilities, weaknesses detection, and system penetration testing by the information system owner.
Additionally, Circular 03 also stipulates that the lead evaluation unit responsible for detecting malware, vulnerabilities, weaknesses, and conducting system penetration testing must:
- Notify the information system owner about the detected information security weaknesses to remedy and prevent security incidents;- Ensure the safety of the data related to the evaluated system, and not disclose any related data without the consent of the information system owner;- Ensure that the assessment for detecting malware, vulnerabilities, weaknesses, and system penetration testing does not affect the normal operation of the system.
For more details, see Circular 03/2017/TT-BTTTT which takes effect from July 1, 2017.
-Thao Uyen-
Address: | 19 Nguyen Gia Thieu, Vo Thi Sau Ward, District 3, Ho Chi Minh City |
Phone: | (028) 7302 2286 |
E-mail: | [email protected] |