1. Agencies, organizations, and individuals shall be responsible for prevention and blocking of malware as instructed or required by competent state bodies. 2. Owners of national important information systems shall deploy professional and technical systems to prevent, detect, block and handle malware in due time. 3. Organizations shall provide services of email, information transmission and storage shall have malware filtration systems in place during sending, receiving, and storing of information in their own systems and shall report to competent agencies as stipulated by laws. 4. Internet service providers shall take measures to manage, prevent, detect, and block the dispersal of malware and treatment thereof upon request of competent state bodies. 5. The Ministry of Information and Communications shall be in charge and cooperate with the Ministry of Defense, the Ministry of Public Security, relevant ministries, sectors for organizing to prevent, detect, block and handle malware that is causative of impacts in national defense and security. Article 12. Assurance of telecommunications resources 1. Organizations, individuals using telecommunication resources shall: a) Take managerial and technical measures to avoid information insecurity that is originated from their own frequencies, stocks of numbers, domain names and Internet addresses; b) Provide, upon request, information relating to security of telecommunications resources and cooperate with competent agencies. 2. Internet service providers shall manage, cooperate and avoid of information insecurity that is originated from their own Internet resources and clients, provide sufficient information upon request of competent state bodies; cooperate for connection and routing in order to secure safe and stable operations of the Vietnam domain name server system. 3. The Ministry of Information and Communications shall be responsible for network information security for the Vietnam domain name servers. Article 13. Response to network information security incidents 1. A response to network information security incidents means an activity to handle with and remedy any incidents causative of network information insecurity. 2. Any response to a network information security incident shall comply with the principles as follows: a) Timely, speedy, accurate and effective; b) Compliant with legal regulations on coordination of responses to network information security incidents; c) Cooperative between local and foreign agencies, organizations and businesses. 3. Ministries and equivalents, agencies under the Government, People’s Committees of provinces and cities subordinate to the Central Government, telecommunications companies, and owners of national important information systems shall establish or appoint specialized divisions in charge of responses to network information security incidents. 5

Select target paragraph3