Before you read on

These rules are here to protect us

A security incident does not stop with the person who caused it. It is a contract that can be lost, a customer's trust that has to be rebuilt from nothing, and a cost the company carries — at a scale well beyond what any one of us could answer for on our own.

So what actually protects us is not handling an incident well after it happens. It is the small things done right every day: locking the screen before stepping away, checking the recipient before hitting send, asking when we are not sure.

And when something looks wrong, say so straight away. Reporting early is always the right call — including the times it turns out to be nothing.

Techvify Software · ISMS · ISO/IEC 27001

Information security — what you must do

Three documents govern this: the handbook, the regulation and the process. This page pulls out the parts that apply to you daily, and the penalty schedule that applies when they are broken. Every rule here is traceable to an article number — the signed PDFs are attached.

Breaching information security carries a money penalty. The regulation lists 111 specific acts, from 500,000 to over 10,000,000 VNĐ, and repeat offences move up a band. It can also affect your performance rating and, in serious cases, lead to labour discipline and compensation.

Applies to every staff member of Techvify who has signed a probation or labour contract, at all offices and at customer sites. Everyone signs an information-security undertaking and attends security training at least once a year.

D3 rule · for team leads

Exception access: wifi, firewall bypass, remote connection

The company has put a lot of layers in place — a controlled network, a proxy and firewall, no self-made remote connections. Those layers only work if the exceptions to them stay rare. In practice we are seeing requests raised for a whole team at once, which quietly takes the layer away for everyone on it.

What is happening
  • ✕An outside wifi or network connection requested for a whole team
  • ✕A firewall or proxy exception opened so one tool can be used
  • ✕Remote connection into office machines granted to several people
  • ✕Once granted, it stays open — nobody reviews it or takes it back
What it should be
  • ✓One or two key people per team, named — not the whole team
  • ✓Held for genuinely urgent checks, not for everyday convenience
  • ✓Registered with ISMS and configured by them, with an end date
  • ✓Reviewed on a schedule and withdrawn as soon as the need is gone
Before you sign off on a request like this

Article 3.7.1 puts the risk assessment on the approver, before approval — not on ISMS afterwards. Three questions worth answering in writing:

  1. Who exactly needs this, by name — and why can the work not be done without it?
  2. What is the smallest version that solves the problem, and for how long?
  3. Who takes it back, and on what date?
What these carry in the penalty schedule
17.5 · #63Software or a website used to get around the proxy or firewall, in any formThe regulation adds "including for work purposes" — there is no work-related exemption written into it.from 10,000,000 VNĐ — on the first offence
6.2 · #16Setting up a remote connection into an office machine without ISMS controlArticle 6.2 uses the word "prohibited", not "requires approval".1,000,000 – 2,000,000 VNĐ, then 5,000,000 – 10,000,000
18.2 · #66Using a device as a wifi hotspot so others can reach the company network or the internetAny network device has to be registered and configured by ISMS (18.3 · #67).1,000,000 – 2,000,000 VNĐ, then 5,000,000 – 10,000,000
20.5 · #87Standing up a proxy, firewall, Web, FTP, SVN, DC, DNS or DHCP server yourselfIncludes anything stood up "just for the team" outside ISMS.5,000,000 – 10,000,000 VNĐ, then from 10,000,000
20.1 / 3.7.1 · #84Granting access without assessing the risk first or checking afterwards, ending in access that is too broad or breaks the "enough to do the job" principleThis one lands on the person who approved it, not on the person who asked.1,000,000 – 2,000,000 VNĐ, then 5,000,000 – 10,000,000

Article 3.7.3 makes the manager of a unit carry the highest responsibility for security in that unit. Approving a broad exception does not move that responsibility to ISMS or to the person who asked — it keeps it, and adds a line of its own.

2 hours
to report an incident
From the moment you notice it, to your line manager and the head of ISMS. Not reporting is itself a penalised offence.
8
characters · password minimum
At least 3 of the 4 character groups, not one of your last 5 passwords, changed within 90 days, with MFA.
4
classification levels
Public · Internal Use · Confidential · Top Secret. You classify what you create; ask ISMS if unsure.
111
penalised acts
Listed one by one in Chapter V of the regulation, each with a first-offence and a repeat-offence band.
1×/year
security training
Mandatory. Access rights and the asset register are also reviewed at least once a year.

You are expected to recognise which level the information you handle belongs to and label it yourself. If you cannot tell, ask the ISMS team rather than guessing (8.2.2).

1
Public

Already released publicly. No restriction on handling.

  • Storage: no special requirement
  • Fax: allowed
  • Email: no password needed
2
Internal UseNội Bộ

The default for work material. Inside Techvify only. Every page of these three policy documents carries this label.

  • Reusing the blank side of a printed sheet: forbidden
  • Copying: keep to the minimum the work requires
  • Taking it outside: only with the responsible person's permission
3
ConfidentialMật

Customer data, personal data, source code, contracts, designs. Most of what a project touches sits here.

  • Storage: in a locked place
  • Email: password-protect or encrypt the attachment — and only with approval
  • Sending outside: wrap it so the content cannot be read through
  • Destruction: shred or pulp — never the recycling bin
4
Top SecretTuyệt Mật

Access is named by the CEO. If you have not been named, you have no business opening it.

  • Fax: forbidden outright
  • Storage: in a locked place
  • Access: leadership and delegated managers only
  • Storage media: wipe the content before disposal or reuse
Personal data has extra handling notes: never reuse a sheet that has personal data on it; when carrying it outside, do not leave it in a vehicle, do not let it out of your hands, and do not detour anywhere other than where you are going.

None of these are hard. All of them are on the penalty list, most at 500,000 – 1,000,000 VNĐ for a first offence.

Wear your card, use only your own10.1 – 10.4

Wear the access card at all times on site. Never lend it, never borrow one, never badge in for someone else and never ask someone to badge you in — that penalty is multiplied by the number of times. Do not hold the door open for anyone unvouched. Forgot or lost it: tell the card administrator within 2 hours, borrow a temporary card from Admin, and return it within 7 working days.

Lock the screen, every time16.3 · 11.2.8

Screen saver set to no more than 5 minutes, with a password. Lock the screen whenever you leave your seat — not only when you leave the building. Shut the machine down before going home; if it has to run overnight for work, register with the office and get your department's approval.

Clean desk14.1 · 14.2 · 11.2.9

No confidential paper left on the desk, at the printer, at the photocopier or in a meeting room. Hard-copy confidential files live in a locked cabinet. When you leave for the day, nothing with personal or important information stays on or around the desk — and nothing confidential stays loose on your desktop screen either.

Collect your printout immediately12.1 – 12.3 · 11.2.8c

Take the pages off the printer, copier, scanner or fax the moment they come out. Print only what the work needs. When you destroy confidential paper, use the shredder — there is a penalty for not using it.

No photos in restricted areas11.1 · 11.2

No camera, video or voice recording — phone included — anywhere marked as restricted, in an ODC, or where customer information is visible, at our site or the customer's. If you need to, get the authorised approver's consent first.

Your laptop is yours alone11.2.8b · 16.7

Do not lend your machine and do not work on someone else's. When you leave it for a while, secure it with a cable lock or put it in a locked cabinet. Do not open it up or install hardware yourself — ask ISMS.

The regulation says only "follow the company password policy"; the actual policy is in the process document at 9.3.1. Here it is in full.

Your password must
  • ✓At least 8 characters
  • ✓At least 3 of the 4 groups: A–Z, a–z, 0–9, symbols
  • ✓Must not contain your account name, or more than 2 characters of your name
  • ✓Must not repeat any of your last 5 passwords
  • ✓At least 3 days between two changes
  • ✓Change it within 90 days
  • ✓MFA on sign-in
  • ✓Change a temporary password immediately on first use
Never
  • ✕Never let the system remember your password
  • ✕Never stick it to your desk
  • ✕Never share your account or sign in as someone else — either way round, and the same for customer accounts
  • ✕Never go looking for someone else's password
Use a non-administrator account for everyday work — browsing and email included — and a separate local admin account only when a task genuinely needs elevation (9.3).

Eighteen rules sit under article 19. These are the ones that actually catch people.

Use
  • ✓Your company mailbox, for work
  • ✓A mailbox the company has explicitly allowed
  • ✓Mobile access — after registering the device with ISMS, with a device password and data encryption
Do not
  • ✕Use Gmail, Hotmail or any other free mailbox at work — sending or receiving
  • ✕Forward company mail to an outside mailbox, manually or by rule
  • ✕Register your company address on forums or social media
  • ✕Use the company mail system for testing, or stand up your own mail server
  • ✕Forward someone's mail on without the original sender's permission
Before you hit send
  1. Check To, Cc and Bcc — one wrong recipient with confidential content is a 2,000,000 – 5,000,000 VNĐ first offence
  2. Check the subject, body, attachment and signature
  3. Virus-scan the attachment
  4. Confidential content: get approval, then zip and password-protect it
A suspicious message

Do not open it, do not click anything in it, do not reply, and never give out your credentials. Attachments ending .exe, .pif or .scr are not opened at all. Report it to ISMS — failing to report is itself an offence (row 79).

Your own device8.1 · 8.2 · 18.1
  • Using a personal phone, laptop or network device for work needs prior approval from the authorised approver
  • Anything that connects to company systems is first checked, configured and given antivirus by ISMS
  • A personal machine does not go on the internal network; if it must, scan it with the tool the system manager specifies
USB and external storage8.3.1 · 4.7
  • Bringing removable storage in, or taking company storage out, needs permission from both ISMS and your department head
  • When not in use it goes in a locked cabinet — not on the desk, not on a shelf
  • A customer's USB or memory card must be virus-scanned before you use it
  • Important and confidential information lives on company servers, not on your local drive or a portable device
Software17.1 – 17.5 · 12.6.2
  • Whitelist only: install nothing that is not on the company's approved software list. If the work needs something else, get the system manager's agreement first
  • No cracked or unlicensed software. First offence 2,000,000 – 5,000,000 VNĐ; if it infects the network it is 10,000,000+ straight away
  • No peer-to-peer, file-sharing or screen-sharing software — 10,000,000+ on the first offence
  • No scanning, monitoring or attack tooling, not even to test — 10,000,000+ on the first offence
  • Nothing that gets around the proxy or firewall — Tor, FreeGate, UltraSurf, Proxifier, HotspotShield or similar — and the regulation says this holds even for work purposes
Antivirus and patches21.1 – 21.4
  • Antivirus stays installed, current and scheduled. You may not turn it off or remove it
  • Check that OS and software patches are applying, and tell ISMS when they fail
  • Suspect an infection: pull the network cable and turn off wifi immediately, then tell ISMS and help them deal with it
Network and cloud20.3 – 20.11 · 18.2
  • Do not configure the network or set up internet access for machines yourself
  • Do not stand up Web, FTP, SVN, proxy, firewall, DC, DNS or DHCP servers — 5,000,000 – 10,000,000 VNĐ first offence
  • Do not turn a device into a wifi hotspot for others to reach the company network or the internet
  • Any cloud service used for work needs the head of ISMS to approve it
  • Never upload company or customer material to public internet storage — Google Drive is named explicitly. 5,000,000 – 10,000,000 VNĐ first offence
  • Do not paste confidential text into a public online translator

Security-wise, a day at home is held to exactly the same standard as a day in the office. These requirements are on top of the D3 conditions on the timekeeping page.

Approval firstRemote work needs approval from the BU or functional head (6.1); the process document also requires the head of information security to have approved it (6.2.2).
No self-made remote connectionSetting up a remote connection from home into your office machine without ISMS control is prohibited outright (6.2).
The machine is not the family'sA machine used at home counts as company-loaned equipment: it is not shared with family or housemates, and it runs the required antivirus (6.2.2).
Not on open public wifiDo not connect to a free wifi hotspot with unrestricted users; use a connection device borrowed from the company instead (11.2.6a). Do not carry confidential files on a laptop you take out unless you must — and then password-protect them.
D3's own conditions for approving a remote day are on the timekeeping page
For software engineers

The rules that bite in a project

Source code, object code, databases and build tooling are all classified as confidential information by name (2.1.1). These are the obligations that fall on you rather than on ISMS.

Source code lives behind access control9.4.5 · 12.5.1a · 14.2.6b

Store source in a location governed by access rights, and only people on the work may reach the code and the build files. Do not keep development or build source on a production system.

Real data is not test data14.3.1

Do not use personal data as test data. If a case genuinely needs production data, get the system manager's agreement, and delete it the moment testing ends — then report the deletion back to them.

Clear down at the end of a project4.8 · 4.9

When work on a project ends, project information belongs on the project server — not on your machine or a portable device. If the customer asked for deletion, it comes off your machine, your mailbox and everywhere else you put it.

"Enough to do the job"20.1 · 4.1

Access is granted on four words — right role, enough to know, enough to use, enough to do the job. Opening data you were not granted, even out of curiosity and even on a system you can technically reach, is row 83: 1,000,000 – 2,000,000 VNĐ first offence.

Customer assets follow the customer's rules22.1 – 22.7 · 7.5 · 14.2.1b

Infrastructure, accounts, passwords, mailboxes and connections the customer provides are the customer's property. Follow their policy where they have one and ours where they do not; working onsite, follow their security rules. Hand everything back when you change role — not doing so is 2,000,000 – 5,000,000 VNĐ.

Confirm at each stage14.2.1a

Confirm completion of each stage — design, development, testing — with your manager, and keep access to development documents at the minimum necessary.

AI tools, and anything else the policies do not nameD3 reading

The three documents predate today's AI coding tools and do not name them. The rule at D3 is simple: follow your department head's instructions on this, without exception. Using any personal tool, account or service for work before it has been approved is a penalised act in its own right — personal devices and accounts under article 8.1 (1,000,000 – 2,000,000 VNĐ on a first offence, 5,000,000 – 10,000,000 VNĐ after that), and any cloud service used for work under article 20.11. If you want to use something, ask first.

A loss, a theft, an unauthorised disclosure, a sign that a rule has been broken, or anything that looks like a security incident — the clock starts when you notice it, not when you are sure.

You notice somethingYou do not have to be certain. A suspicion of a weakness or a threat is enough to report (16.1.3).
Within 2 hours, tell two peopleYour line manager, and the head of the information-security team. Article 24.1 says "head of BMTT"; the penalty row says "head of ISMS" — they are the same team under two names.
Then help fix itYou are required to cooperate with the response when the company or the customer asks. Not cooperating is row 112.
Customer terms come on topIf the project agreed an incident-reporting arrangement with the customer, that arrangement must be honoured too — breaching it is 5,000,000 – 10,000,000 VNĐ on the first offence.
Act first, then report
  • Suspected virus → disconnect the network cable and switch off wifi, then tell ISMS
  • Phishing or odd email → do not open or click, tell ISMS
  • Lost or forgotten access card → tell the card administrator within 2 hours
  • Lost laptop with confidential data → report immediately; the penalty is 2,000,000 – 5,000,000 VNĐ, but concealing it is worse

Chapter V of the regulation, reproduced in full — 111 acts across 21 articles. Search it, or filter by article and by band. Band I is a first offence, band II a second or later one.

111 acts shown
1Taking confidential information outside the Company, or disclosing confidential information to a third party, causing damage to or harming the Company's image and reputation.1st offencefrom 10,000,000 VNĐRepeatnot specified
2Sending confidential information to a customer in error.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
3Using confidential information or information assets for personal purposes or for any purpose outside of work.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
4Providing personal data of customers, partners or staff members to anyone outside the Company, or to anyone not involved in the work, without approval from the authorised approver of the Company.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
5Uploading or storing Company information on a Website, on public or personal internet storage, or on a personally owned mobile device.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
6Storing important or confidential information anywhere other than the Company's designated storage locations.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
7Failing to delete work or project information from a computer or portable storage device when the work or project ends.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
8Failing to delete project information from computers, email and other storage locations where the customer has asked for project information to be deleted at the end of the project.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
9Uploading or storing customer or Company information assets on the public internet, including but not limited to google drive, etc.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
10Taking Company assets or information outside the work area without asking for and obtaining approval from the authorised approver.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
11Taking customer assets or information outside the work area without asking for and obtaining approval from the authorised approver.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
12Failing to apply appropriate security measures when taking the Company's information or information assets off site.1st offence1,000,000 – 2,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
13Failing to apply appropriate security measures when taking a customer's information or information assets off site.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
14Working remotely or working from home without asking for or obtaining approval from the authorised approver.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
15When working remotely or from home, failing to keep information as secure and protected as it would be at the Company.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
16Failing to comply with the requirements on the setup and use of mobile devices and of remote connections to the Company's information systems. / Setting up a remote connection from outside or from home into a computer at the Company without control by the ISMS team.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
17A staff member failing to sign the information security undertaking when signing their employment contract with the Company.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
18A staff member failing to sign an information security undertaking with a customer where the customer requires it as an information security requirement.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
19Failing to attend the information security training courses run by the Company before contract signing, the annual refresher courses, the role-specific courses, or the specialised courses required by a contract or project.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
20A line manager who, when hiring external personnel, fails to have them sign an information security undertaking and fails to give them information security training.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
21Failing to comply with the working rules and the information security rules at a customer's site.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
22Using personally owned assets (mobile devices, computers, network equipment, etc.) for work purposes without asking for and obtaining approval from the authorised approver before use.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
23Personally owned assets that connect to the Company's information systems being used before the ISMS team has reviewed, inspected and configured them and installed appropriate protection software.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
24Letting another person use your Company account to access the Company's information systems.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
25Letting another person use your account, or disclosing your access password, to access the information systems of a customer or of a third-party provider.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
26Using or accessing the Company's information systems with another person's account.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
27Using or accessing the information systems of a customer or of a third-party provider with another person's account.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
28Failing to comply with the Company's policy on setting and changing passwords. / Failing to keep your password secret, failing to change it, or setting a simple, easily guessed password.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
29Failing to comply with the customer's or third party's policy on setting and changing passwords, where the account and password are provided by that customer or third party.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
30Deliberately searching for or attempting to guess another person's password.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
31Borrowing another person's entry/exit card, or letting another person use your access card, to enter or leave the workplace, including a staff member badging in on someone else's behalf or asking someone else to badge in for them (the penalty is multiplied by the number of violations).1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
32Opening the door for another person from inside the Company, or for someone from outside the Company, when no one has vouched for them.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
33Not wearing your access card at the workplace.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
34Failing to notify the card administrator within 2 hours when you forget or lose your access card, so that it can be dealt with.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
35Failing to borrow a temporary card from the Administration team when you forget or lose your access card. / Or failing to return the temporary card to the Administration team within 7 working days.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
36A card administrator lending out a card without recording the time the card was handed over and returned.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
37Entering or leaving a restricted area without permission or without having asked for permission. / Failing to comply with prohibition signs and instruction signs at Company or customer sites.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
38The responsible officer in the Administration team failing to put an entry/exit logbook in place at locations that have their own access card system.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
39Using video or audio recording devices without permission in areas marked as prohibiting photography, filming or recording, such as restricted areas, an ODC, or areas holding customer information at Company or customer sites.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
40Taking photographs, filming or making audio recordings in the areas listed in section 11.1 without asking for and obtaining the consent of the authorised approver.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
41Using Company printers to print documents that are not necessary for work.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
42Failing to use a paper shredder or another method of complete destruction when confidential documents or records need to be destroyed.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
43Faxing documents or records without permission from the authorised approver.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
44Sending confidential information by fax.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
45Leaving documents or records that need to be kept confidential lying around in shared places such as printers, photocopiers, meeting rooms, desks, or unlocked cabinets.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
46Failing to classify, organise, protect and store confidential hard-copy documents and records in a locked cabinet that others cannot get into.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
47Failing to use a reputable courier service that offers a guarantee when sending documents or devices containing confidential information, except in an emergency.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
48Transporting documents or assets containing confidential information unsafely, resulting in the loss of the document or asset or in the disclosure of information.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
49Using Company-issued computers and IT equipment for purposes outside of work.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
50Dismantling or reassembling computers and IT equipment without authorisation, or failing to comply with the Company's requirements on installation, use and care.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
51Not setting a screen saver, or setting the screen saver to more than 5 minutes.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
52Failing to lock your computer screen when you leave your desk or leave the work area.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
53Failing to shut down your computer and equipment before going home, except where the machine has to be left on overnight.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
54Leaving a machine on overnight for work reasons without registering it with the Company Office and obtaining permission from the relevant department.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
55Sharing local drives, folders or files on your computer over a wired or wireless network or through software.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
56Lending your computer to another person or borrowing another person's computer. / Working on a computer registered in another person's name.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
57Losing a laptop, device or asset, whether issued by the Company or personally owned, that contains confidential information, customer information or project information.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
58A line manager failing to assign someone to manage and periodically check the unit's shared computers or IT equipment.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
59Downloading, cracking, using or storing unlicensed or unauthorised software.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
60Downloading, cracking, using or storing unlicensed software that infects the internal network or a customer's network with a virus, infects documents sent to a customer, or affects project progress.1st offencefrom 10,000,000 VNĐRepeatnot specified
61Using software on the prohibited list. Using or testing any form of scanning, monitoring, attack or unauthorised access software within the Company.1st offencefrom 10,000,000 VNĐRepeatnot specified
62Using peer-to-peer networking software, data-sharing software or screen-sharing software.1st offencefrom 10,000,000 VNĐRepeatnot specified
63Using software or websites to get around the Company's proxy or firewall in any form.1st offencefrom 10,000,000 VNĐRepeatnot specified
65A mobile device connecting to the Company's network or IT services that does not meet the Company's requirements on registration, use, installation and security (access password, data encryption, etc.).1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
66Using devices that can create a network connection or broadcast Wifi as a bridge for other devices to connect to the Company's network or to the Internet.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
67Using network equipment that is not configured and managed by the ISMS team.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
68Using Company email, or an email account the Company has authorised, for purposes outside of work.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
69Using free email, personal email, or any other email account or email system at the Company besides the email provided by the Company or by the customer.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
70Sending an email to the wrong recipient, with the wrong content, with the wrong attachment, or with a virus in the attachment.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
71Using the Company's email system for testing, or installing email servers without authorisation.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
72Using another person's email account, or borrowing or lending an email account.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
73Spoofing email, cracking passwords, breaking into or attacking the Company's email system or an email system outside the Company.1st offencefrom 10,000,000 VNĐRepeatnot specified
74Sending bulk email (spam email) to the Company's email system or to email systems outside the Company.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
75Sending or forwarding email whose content insults or attacks an individual or an organisation, opposes or runs counter to national traditions or customs, or contains information that harms national security.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
76Forwarding Company email to an external email system, whether manually or automatically.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
77Using a Company email address to register on forums or social networks.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
78Sending information classified as “Confidential” by email without password-protecting or encrypting it.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
79Opening or clicking links in phishing or suspicious emails, replying to phishing or suspicious emails, or providing personal information, usernames and passwords. / Failing to report a phishing or suspicious email to the ISMS team.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
80Misusing the Company's email system. Actions considered misuse include, but are not limited to: using email for personal business, seeking career opportunities outside the Company, taking part in online money-making activities, taking part in political activities or in fundraising appeals on religious grounds, or any other activity of a similar nature.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
81A staff member failing to register with the ISMS team before using a mobile device to access the Company's email system, and/or failing to comply with the requirements to set a device password and encrypt data.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
82Failing to hand over the mailing lists and special email addresses you manage, if any, to the responsible person when you change job position.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
83Accessing information or data that you are not permitted or authorised to access, or that is unrelated to the work assigned to you.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
84The authorised approver granting access rights to information systems or data without assessing the risk beforehand and without re-checking afterwards, resulting in rights being granted to the wrong person or in breach of the “enough to do the job” principle.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
85Using the internal network, information systems, servers and Internet connection for purposes other than work.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
86Using a server that provides services to the internet without it being inspected and managed by the ISMS team.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
87Installing service servers such as Web, FTP, SVN, Proxy, Firewall, DC, DNS, DHCP, etc. without authorisation.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
88Configuring the network, or setting up internet connections for machines on the Company's internal network, without authorisation.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
89Accessing websites unrelated to work purposes, or using intermediary proxy sites to access the internet of the Company or of a customer.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
90Using online tools, public websites or unapproved tools to translate or convert text that contains the Company's confidential information.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
91Misusing the Company's network infrastructure, equipment and resources for purposes outside of work, including but not limited to: personal business, seeking career opportunities outside the Company, taking part in online money-making activities, taking part in political activities or in fundraising appeals on religious grounds, or any other activity of a similar nature.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
92Attacking the Company's network or servers, or using the Company's network infrastructure, equipment and resources to attack networks or servers outside the Company.1st offencefrom 10,000,000 VNĐRepeatnot specified
93Using cloud computing services without review and approval by the ISMS team.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
94Downloading or copying information or documents from the internet, from another computer or from another device and getting infected with a virus.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
95Computers and IT equipment used on the Company network not having the latest version of anti-virus software installed and updated.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
96Spreading malicious programs into the network and onto servers.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
97Turning off or deleting the anti-virus program, the periodic version updates or the periodic virus scans without authorisation.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
98Failing to check that operating system and software patches are up to date, and failing to report to the ISMS team when a problem occurs.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
99Failing to notify the ISMS team, failing to disconnect from the network when you suspect your computer is infected with a virus, and failing to cooperate in dealing with it.1st offence500,000 – 1,000,000 VNĐRepeat2,000,000 – 5,000,000 VNĐ
100Failing to comply with the customer's asset management policy or guidelines when customer assets are provided to you or used. / Not using customer assets for the purpose originally designated.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
101Failing to use and look after the customer's equipment, accounts, passwords, email and access rights granted to you on the “enough to do the job” principle.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
102Misusing customer assets. Actions considered misuse include, but are not limited to: personal business, seeking career opportunities outside the Company, taking part in online money-making activities, taking part in political activities or in fundraising appeals on religious grounds, or any other activity of a similar nature.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
103Attacking the customer's network or servers, or using customer assets to attack networks or servers outside the Company.1st offencefrom 10,000,000 VNĐRepeatnot specified
104Failing to hand over customer assets, if any, to the responsible person when you change job position.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
105Losing a customer asset.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
106Posting, sharing or disclosing information or images that the Company or a customer requires to be kept confidential when blogging or using social media.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
107Posting, sharing or disclosing customers' personal data or photographs of them on social media.1st offence2,000,000 – 5,000,000 VNĐRepeatfrom 10,000,000 VNĐ
108Posting, sharing or disclosing on social media information about or images of a customer's work area, or of a Company work area where photography and filming are prohibited.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
109Posting, sharing or disclosing on social media information about the work schedule, work location or work of yourself or of a line manager.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
110Failing to notify your line manager or the head of the ISMS team immediately, within 2 hours, on discovering the loss, theft or unauthorised disclosure of a Company information asset, signs of a violation, or an information security incident, so that a course of action can be decided.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
111Failing to comply with the customer's requirements on reporting information security incidents, where the way incidents are to be handled has already been agreed with the customer.1st offence5,000,000 – 10,000,000 VNĐRepeatfrom 10,000,000 VNĐ
112Failing to cooperate in dealing with an information security incident when required to do so by the Company or the customer.1st offence1,000,000 – 2,000,000 VNĐRepeat5,000,000 – 10,000,000 VNĐ
Which band applies is decided on four things (article 25): the act itself, how much risk of leakage or loss it created, the actual damage — material and to the company's reputation — and whether it was deliberate or careless.
Beyond the money, a breach can mean retaking security training, a lower performance rating, compensation under the law, and labour discipline under the company's internal labour rules (article 26).
Hand backBusiness cards, employee badge and ID card; the company laptop and phone; paper records returned or destroyed (8.1.4).
Hand overAny mailing list or special mailbox you administer, and any customer asset you hold. Both are penalised if skipped (rows 82 and 104).
Access is cutYour department head requests removal from the system manager; HR asks for the account to be disabled. On a transfer, the receiving department head requests the new rights (9.2.6).
The undertaking outlives the contractYour confidentiality obligation continues for a period after the labour contract ends or your role changes (13.2.4a).
Information Security team (BMTT / ISMS)
  • Build, run and control the company's information-security system.
  • Audit compliance across departments and staff, and impose remedies for breaches.
  • Prepare security training programmes and materials.
  • Handle external bodies on security matters.
  • Review and update this regulation every year.
IT team
  • Build and run the network and information systems.
  • Run access monitoring and control to stop unauthorised access.
  • Run backup, system and access logging, traffic monitoring and attack protection.
  • Propose and apply technical security measures.
Admin – Assets
  • Physical and environmental security, including power, air conditioning and fire safety.
  • Manage and report on physical assets and office equipment.
  • Manage the door system and camera system and their access rights.
  • Manage service providers entering the workplace and make sure they follow our rules.
HR
  • Get the security undertaking signed and keep the records.
  • Request new system accounts once the undertaking and contract are signed.
  • Request that an account be cut or updated the moment someone leaves, pauses or changes role.
  • Maintain and review the staff account list.
PQA
  • Internal audit and compliance control of security requirements at project level.
  • List the critical projects and review their security requirements with the ISMS team.
Managers at every level
  • Assess the risk before approving any special request for information, assets or access rights.
  • Raise security awareness in their own unit.
  • Carry ultimate responsibility for security in the unit they run.
  • Work with the ISMS team on incidents.
Every staff member
  • Know the security requirements set out in the policy, the regulation, the process descriptions, job descriptions, work instructions, forms and anything the customer supplies.
  • Understand them fully and comply with them.

Reading notes from D3, not part of the policies. Where this page and a PDF differ, the PDF governs — these are places where the PDFs differ from each other or are unclear, and they are worth confirming with ISMS.

Screen saver: 5 minutes or 3?

The regulation says no more than 5 minutes (16.3); the process says set it to 3 minutes and lock the laptop if you leave for 5 minutes or more (11.2.8a, 11.2.9b). Setting 3 minutes satisfies both.

Two names for one team

"Bộ phận BMTT" and "bộ phận ISMS" are used interchangeably across the documents, and article 29.2 introduces a third name, "Ban đảm bảo thông tin". Article 24.1 tells you to report to the head of BMTT while the matching penalty row names the head of ISMS. Ask once who the current named person is, and report to them.

The decryption password clause

Article 19.12 requires Confidential attachments to be zipped and password-protected, then says the decryption password "must be sent by email or by another means". Sending the password down the same channel as the file removes the protection; the process document (13.2.1b) says a different email or another means. Use a different channel.

No exemption for security tooling

Article 17.3 bans using or even testing scanning, monitoring or attack software, at 10,000,000+ on the first offence, with no carve-out for a security or QA engineer doing authorised work. If your role needs such a tool, get it written down before you run it.

Overdue for review

The regulation is version 1.0, in force 15/04/2021, and article 3.1.5 requires an annual review. It still has an article on fax machines, still refers to the old ID-card number, and names SVN as the example source-control server.

This page summarises three signed documents. Where they differ from this page, they govern. Open the regulation