These rules are here to protect us
A security incident does not stop with the person who caused it. It is a contract that can be lost, a customer's trust that has to be rebuilt from nothing, and a cost the company carries — at a scale well beyond what any one of us could answer for on our own.
So what actually protects us is not handling an incident well after it happens. It is the small things done right every day: locking the screen before stepping away, checking the recipient before hitting send, asking when we are not sure.
And when something looks wrong, say so straight away. Reporting early is always the right call — including the times it turns out to be nothing.
Information security — what you must do
Three documents govern this: the handbook, the regulation and the process. This page pulls out the parts that apply to you daily, and the penalty schedule that applies when they are broken. Every rule here is traceable to an article number — the signed PDFs are attached.
Applies to every staff member of Techvify who has signed a probation or labour contract, at all offices and at customer sites. Everyone signs an information-security undertaking and attends security training at least once a year.
02v-QD/ISM/HDCV29 articles plus the penalty schedule. The rules you are held to, and what each breach costs.Information Security Process01v-QT/ISM/HDCVHow the controls actually run: access grant and revocation, asset handling, classification, backup, incidents.Information Security HandbookISO-STBM.01The full Annex A control set — organisational, people, physical and technical. Mostly for ISMS and IT.Exception access: wifi, firewall bypass, remote connection
The company has put a lot of layers in place — a controlled network, a proxy and firewall, no self-made remote connections. Those layers only work if the exceptions to them stay rare. In practice we are seeing requests raised for a whole team at once, which quietly takes the layer away for everyone on it.
- ✕An outside wifi or network connection requested for a whole team
- ✕A firewall or proxy exception opened so one tool can be used
- ✕Remote connection into office machines granted to several people
- ✕Once granted, it stays open — nobody reviews it or takes it back
- ✓One or two key people per team, named — not the whole team
- ✓Held for genuinely urgent checks, not for everyday convenience
- ✓Registered with ISMS and configured by them, with an end date
- ✓Reviewed on a schedule and withdrawn as soon as the need is gone
Article 3.7.1 puts the risk assessment on the approver, before approval — not on ISMS afterwards. Three questions worth answering in writing:
- Who exactly needs this, by name — and why can the work not be done without it?
- What is the smallest version that solves the problem, and for how long?
- Who takes it back, and on what date?
17.5 · #63Software or a website used to get around the proxy or firewall, in any formThe regulation adds "including for work purposes" — there is no work-related exemption written into it.from 10,000,000 VNĐ — on the first offence6.2 · #16Setting up a remote connection into an office machine without ISMS controlArticle 6.2 uses the word "prohibited", not "requires approval".1,000,000 – 2,000,000 VNĐ, then 5,000,000 – 10,000,00018.2 · #66Using a device as a wifi hotspot so others can reach the company network or the internetAny network device has to be registered and configured by ISMS (18.3 · #67).1,000,000 – 2,000,000 VNĐ, then 5,000,000 – 10,000,00020.5 · #87Standing up a proxy, firewall, Web, FTP, SVN, DC, DNS or DHCP server yourselfIncludes anything stood up "just for the team" outside ISMS.5,000,000 – 10,000,000 VNĐ, then from 10,000,00020.1 / 3.7.1 · #84Granting access without assessing the risk first or checking afterwards, ending in access that is too broad or breaks the "enough to do the job" principleThis one lands on the person who approved it, not on the person who asked.1,000,000 – 2,000,000 VNĐ, then 5,000,000 – 10,000,000Article 3.7.3 makes the manager of a unit carry the highest responsibility for security in that unit. Approving a broad exception does not move that responsibility to ISMS or to the person who asked — it keeps it, and adds a line of its own.
You are expected to recognise which level the information you handle belongs to and label it yourself. If you cannot tell, ask the ISMS team rather than guessing (8.2.2).
Already released publicly. No restriction on handling.
- Storage: no special requirement
- Fax: allowed
- Email: no password needed
The default for work material. Inside Techvify only. Every page of these three policy documents carries this label.
- Reusing the blank side of a printed sheet: forbidden
- Copying: keep to the minimum the work requires
- Taking it outside: only with the responsible person's permission
Customer data, personal data, source code, contracts, designs. Most of what a project touches sits here.
- Storage: in a locked place
- Email: password-protect or encrypt the attachment — and only with approval
- Sending outside: wrap it so the content cannot be read through
- Destruction: shred or pulp — never the recycling bin
Access is named by the CEO. If you have not been named, you have no business opening it.
- Fax: forbidden outright
- Storage: in a locked place
- Access: leadership and delegated managers only
- Storage media: wipe the content before disposal or reuse
None of these are hard. All of them are on the penalty list, most at 500,000 – 1,000,000 VNĐ for a first offence.
10.1 – 10.4Wear the access card at all times on site. Never lend it, never borrow one, never badge in for someone else and never ask someone to badge you in — that penalty is multiplied by the number of times. Do not hold the door open for anyone unvouched. Forgot or lost it: tell the card administrator within 2 hours, borrow a temporary card from Admin, and return it within 7 working days.
16.3 · 11.2.8Screen saver set to no more than 5 minutes, with a password. Lock the screen whenever you leave your seat — not only when you leave the building. Shut the machine down before going home; if it has to run overnight for work, register with the office and get your department's approval.
14.1 · 14.2 · 11.2.9No confidential paper left on the desk, at the printer, at the photocopier or in a meeting room. Hard-copy confidential files live in a locked cabinet. When you leave for the day, nothing with personal or important information stays on or around the desk — and nothing confidential stays loose on your desktop screen either.
12.1 – 12.3 · 11.2.8cTake the pages off the printer, copier, scanner or fax the moment they come out. Print only what the work needs. When you destroy confidential paper, use the shredder — there is a penalty for not using it.
11.1 · 11.2No camera, video or voice recording — phone included — anywhere marked as restricted, in an ODC, or where customer information is visible, at our site or the customer's. If you need to, get the authorised approver's consent first.
11.2.8b · 16.7Do not lend your machine and do not work on someone else's. When you leave it for a while, secure it with a cable lock or put it in a locked cabinet. Do not open it up or install hardware yourself — ask ISMS.
The regulation says only "follow the company password policy"; the actual policy is in the process document at 9.3.1. Here it is in full.
- ✓At least 8 characters
- ✓At least 3 of the 4 groups: A–Z, a–z, 0–9, symbols
- ✓Must not contain your account name, or more than 2 characters of your name
- ✓Must not repeat any of your last 5 passwords
- ✓At least 3 days between two changes
- ✓Change it within 90 days
- ✓MFA on sign-in
- ✓Change a temporary password immediately on first use
- ✕Never let the system remember your password
- ✕Never stick it to your desk
- ✕Never share your account or sign in as someone else — either way round, and the same for customer accounts
- ✕Never go looking for someone else's password
Eighteen rules sit under article 19. These are the ones that actually catch people.
- ✓Your company mailbox, for work
- ✓A mailbox the company has explicitly allowed
- ✓Mobile access — after registering the device with ISMS, with a device password and data encryption
- ✕Use Gmail, Hotmail or any other free mailbox at work — sending or receiving
- ✕Forward company mail to an outside mailbox, manually or by rule
- ✕Register your company address on forums or social media
- ✕Use the company mail system for testing, or stand up your own mail server
- ✕Forward someone's mail on without the original sender's permission
- Check To, Cc and Bcc — one wrong recipient with confidential content is a 2,000,000 – 5,000,000 VNĐ first offence
- Check the subject, body, attachment and signature
- Virus-scan the attachment
- Confidential content: get approval, then zip and password-protect it
Do not open it, do not click anything in it, do not reply, and never give out your credentials. Attachments ending .exe, .pif or .scr are not opened at all. Report it to ISMS — failing to report is itself an offence (row 79).
8.1 · 8.2 · 18.1- Using a personal phone, laptop or network device for work needs prior approval from the authorised approver
- Anything that connects to company systems is first checked, configured and given antivirus by ISMS
- A personal machine does not go on the internal network; if it must, scan it with the tool the system manager specifies
8.3.1 · 4.7- Bringing removable storage in, or taking company storage out, needs permission from both ISMS and your department head
- When not in use it goes in a locked cabinet — not on the desk, not on a shelf
- A customer's USB or memory card must be virus-scanned before you use it
- Important and confidential information lives on company servers, not on your local drive or a portable device
17.1 – 17.5 · 12.6.2- Whitelist only: install nothing that is not on the company's approved software list. If the work needs something else, get the system manager's agreement first
- No cracked or unlicensed software. First offence 2,000,000 – 5,000,000 VNĐ; if it infects the network it is 10,000,000+ straight away
- No peer-to-peer, file-sharing or screen-sharing software — 10,000,000+ on the first offence
- No scanning, monitoring or attack tooling, not even to test — 10,000,000+ on the first offence
- Nothing that gets around the proxy or firewall — Tor, FreeGate, UltraSurf, Proxifier, HotspotShield or similar — and the regulation says this holds even for work purposes
21.1 – 21.4- Antivirus stays installed, current and scheduled. You may not turn it off or remove it
- Check that OS and software patches are applying, and tell ISMS when they fail
- Suspect an infection: pull the network cable and turn off wifi immediately, then tell ISMS and help them deal with it
20.3 – 20.11 · 18.2- Do not configure the network or set up internet access for machines yourself
- Do not stand up Web, FTP, SVN, proxy, firewall, DC, DNS or DHCP servers — 5,000,000 – 10,000,000 VNĐ first offence
- Do not turn a device into a wifi hotspot for others to reach the company network or the internet
- Any cloud service used for work needs the head of ISMS to approve it
- Never upload company or customer material to public internet storage — Google Drive is named explicitly. 5,000,000 – 10,000,000 VNĐ first offence
- Do not paste confidential text into a public online translator
Security-wise, a day at home is held to exactly the same standard as a day in the office. These requirements are on top of the D3 conditions on the timekeeping page.
The rules that bite in a project
Source code, object code, databases and build tooling are all classified as confidential information by name (2.1.1). These are the obligations that fall on you rather than on ISMS.
9.4.5 · 12.5.1a · 14.2.6bStore source in a location governed by access rights, and only people on the work may reach the code and the build files. Do not keep development or build source on a production system.
14.3.1Do not use personal data as test data. If a case genuinely needs production data, get the system manager's agreement, and delete it the moment testing ends — then report the deletion back to them.
4.8 · 4.9When work on a project ends, project information belongs on the project server — not on your machine or a portable device. If the customer asked for deletion, it comes off your machine, your mailbox and everywhere else you put it.
20.1 · 4.1Access is granted on four words — right role, enough to know, enough to use, enough to do the job. Opening data you were not granted, even out of curiosity and even on a system you can technically reach, is row 83: 1,000,000 – 2,000,000 VNĐ first offence.
22.1 – 22.7 · 7.5 · 14.2.1bInfrastructure, accounts, passwords, mailboxes and connections the customer provides are the customer's property. Follow their policy where they have one and ours where they do not; working onsite, follow their security rules. Hand everything back when you change role — not doing so is 2,000,000 – 5,000,000 VNĐ.
14.2.1aConfirm completion of each stage — design, development, testing — with your manager, and keep access to development documents at the minimum necessary.
The three documents predate today's AI coding tools and do not name them. The rule at D3 is simple: follow your department head's instructions on this, without exception. Using any personal tool, account or service for work before it has been approved is a penalised act in its own right — personal devices and accounts under article 8.1 (1,000,000 – 2,000,000 VNĐ on a first offence, 5,000,000 – 10,000,000 VNĐ after that), and any cloud service used for work under article 20.11. If you want to use something, ask first.
A loss, a theft, an unauthorised disclosure, a sign that a rule has been broken, or anything that looks like a security incident — the clock starts when you notice it, not when you are sure.
- Suspected virus → disconnect the network cable and switch off wifi, then tell ISMS
- Phishing or odd email → do not open or click, tell ISMS
- Lost or forgotten access card → tell the card administrator within 2 hours
- Lost laptop with confidential data → report immediately; the penalty is 2,000,000 – 5,000,000 VNĐ, but concealing it is worse
Chapter V of the regulation, reproduced in full — 111 acts across 21 articles. Search it, or filter by article and by band. Band I is a first offence, band II a second or later one.
Nothing matches that search.
- Build, run and control the company's information-security system.
- Audit compliance across departments and staff, and impose remedies for breaches.
- Prepare security training programmes and materials.
- Handle external bodies on security matters.
- Review and update this regulation every year.
- Build and run the network and information systems.
- Run access monitoring and control to stop unauthorised access.
- Run backup, system and access logging, traffic monitoring and attack protection.
- Propose and apply technical security measures.
- Physical and environmental security, including power, air conditioning and fire safety.
- Manage and report on physical assets and office equipment.
- Manage the door system and camera system and their access rights.
- Manage service providers entering the workplace and make sure they follow our rules.
- Get the security undertaking signed and keep the records.
- Request new system accounts once the undertaking and contract are signed.
- Request that an account be cut or updated the moment someone leaves, pauses or changes role.
- Maintain and review the staff account list.
- Internal audit and compliance control of security requirements at project level.
- List the critical projects and review their security requirements with the ISMS team.
- Assess the risk before approving any special request for information, assets or access rights.
- Raise security awareness in their own unit.
- Carry ultimate responsibility for security in the unit they run.
- Work with the ISMS team on incidents.
- Know the security requirements set out in the policy, the regulation, the process descriptions, job descriptions, work instructions, forms and anything the customer supplies.
- Understand them fully and comply with them.
Reading notes from D3, not part of the policies. Where this page and a PDF differ, the PDF governs — these are places where the PDFs differ from each other or are unclear, and they are worth confirming with ISMS.
The regulation says no more than 5 minutes (16.3); the process says set it to 3 minutes and lock the laptop if you leave for 5 minutes or more (11.2.8a, 11.2.9b). Setting 3 minutes satisfies both.
"Bộ phận BMTT" and "bộ phận ISMS" are used interchangeably across the documents, and article 29.2 introduces a third name, "Ban đảm bảo thông tin". Article 24.1 tells you to report to the head of BMTT while the matching penalty row names the head of ISMS. Ask once who the current named person is, and report to them.
Article 19.12 requires Confidential attachments to be zipped and password-protected, then says the decryption password "must be sent by email or by another means". Sending the password down the same channel as the file removes the protection; the process document (13.2.1b) says a different email or another means. Use a different channel.
Article 17.3 bans using or even testing scanning, monitoring or attack software, at 10,000,000+ on the first offence, with no carve-out for a security or QA engineer doing authorised work. If your role needs such a tool, get it written down before you run it.
The regulation is version 1.0, in force 15/04/2021, and article 3.1.5 requires an annual review. It still has an article on fax machines, still refers to the old ID-card number, and names SVN as the example source-control server.