8. Information security risk means a subjective or objective factor that potentially
affects the status of network information security.
9. Information security risk assessment means detection, analysis and estimation of a
damage or threat to information or information system.
10. Information security risk management means providing a set of measures to
reduce network information security risks.
11. Malicious software (Malware) means a software that is able to cause any abnormal
operation to an information system in part or in whole, or to illegally reproduce, change, or
delete information stored in the information system.
12. Malware filter system means a combination of hardware and software connected
to a network in order to detect, block, filter and reckon malware up.
13. Electronic address means an address in use for sending and receiving cyber
information that can be an email address, telephone number, Internet address and other
smiliar forms.
14. Information conflict means two or more local and foreign organizations taking
measures of information technology or technique to damage an information system, a
program or an information source.
15. Personal information means information associated with the identity of a specific
person.
16. Personal information owner means the person identified by the personal
information.
17. Handling personal information means performance of one or more operations to
collect, edit, use, store, supply, share, and disperse personal information in the network for
commercial purposes.
18. Civil cryptography means cryptographic techniques and encrypted products in use
for confidentiality or authentication of the information which is beyond the domain of state
secret.
19. Network information security product means any hardware or software product
which is functioned to protect information and information system.
20. Network information security service means the service to protect information and
information system.
Article 4. Principles of network information security
1. Organizations, individuals shall be responsible for ensuring network information
security. Information security activities of organizations, individuals shall comply with
regulations of laws, secure national security, state secrets, maintain political stability and
promote economic and social developments.
2. Organizations, individuals taking part in online activities shall not violate network
information security of other organizations, individuals.
3. Handling of information incidents shall ensure legitimate rights and benefits of
individuals, organizations, without infringement upon the private and secret life of
individuals, family secrets of individuals and private information of organizations.
4. Activities of network information security guarantee shall be performed frequently,
continuously, and effectively.
2