8. Information security risk means a subjective or objective factor that potentially affects the status of network information security. 9. Information security risk assessment means detection, analysis and estimation of a damage or threat to information or information system. 10. Information security risk management means providing a set of measures to reduce network information security risks. 11. Malicious software (Malware) means a software that is able to cause any abnormal operation to an information system in part or in whole, or to illegally reproduce, change, or delete information stored in the information system. 12. Malware filter system means a combination of hardware and software connected to a network in order to detect, block, filter and reckon malware up. 13. Electronic address means an address in use for sending and receiving cyber information that can be an email address, telephone number, Internet address and other smiliar forms. 14. Information conflict means two or more local and foreign organizations taking measures of information technology or technique to damage an information system, a program or an information source. 15. Personal information means information associated with the identity of a specific person. 16. Personal information owner means the person identified by the personal information. 17. Handling personal information means performance of one or more operations to collect, edit, use, store, supply, share, and disperse personal information in the network for commercial purposes. 18. Civil cryptography means cryptographic techniques and encrypted products in use for confidentiality or authentication of the information which is beyond the domain of state secret. 19. Network information security product means any hardware or software product which is functioned to protect information and information system. 20. Network information security service means the service to protect information and information system. Article 4. Principles of network information security 1. Organizations, individuals shall be responsible for ensuring network information security. Information security activities of organizations, individuals shall comply with regulations of laws, secure national security, state secrets, maintain political stability and promote economic and social developments. 2. Organizations, individuals taking part in online activities shall not violate network information security of other organizations, individuals. 3. Handling of information incidents shall ensure legitimate rights and benefits of individuals, organizations, without infringement upon the private and secret life of individuals, family secrets of individuals and private information of organizations. 4. Activities of network information security guarantee shall be performed frequently, continuously, and effectively. 2

Select target paragraph3