Tóm tắt Chỉ thị số 02/2004/CT-NHNN về việc tăng cường công tác bảo đảm an toàn trong hoạt động thanh toán điện tử liên ngân hàng
Chỉ thị số 02/2004/CT-NHNN được Thống đốc Ngân hàng Nhà nước Việt Nam ban hành nhằm mục đích nâng cao tính an toàn, bảo mật và hạn chế tối đa các rủi ro trong quá trình vận hành hệ thống thanh toán điện tử liên ngân hàng. Đây là văn bản chỉ đạo quan trọng đối với các tổ chức tín dụng và các đơn vị thuộc Ngân hàng Nhà nước trong bối cảnh hiện đại hóa công nghệ ngân hàng.
1. Mục tiêu và yêu cầu cấp bách về bảo đảm an toàn thanh toán
Hệ thống thanh toán điện tử liên ngân hàng đóng vai trò huyết mạch trong nền kinh tế. Để đảm bảo hệ thống hoạt động thông suốt, an toàn và tin cậy, Chỉ thị yêu cầu các đơn vị phải nhận thức rõ tầm quan trọng của công tác an ninh bảo mật. Các yêu cầu cốt lõi bao gồm:
- Tăng cường ý thức trách nhiệm của người đứng đầu các đơn vị và cán bộ trực tiếp tham gia vận hành hệ thống thanh toán.
- Tuân thủ nghiêm ngặt các quy trình kỹ thuật nghiệp vụ, quy chế quản lý và vận hành hệ thống đã được Ngân hàng Nhà nước ban hành.
- Kịp thời phát hiện, ngăn chặn và xử lý các hành vi vi phạm quy định an toàn bảo mật, hạn chế tối đa các sự cố kỹ thuật hoặc gian lận tài chính.
2. Các biện pháp kỹ thuật và quản lý nghiệp vụ cụ thể
Chỉ thị đưa ra các chỉ đạo chi tiết đối với công tác quản lý kỹ thuật nghiệp vụ tại các thành viên tham gia hệ thống:
- Quản lý mật mã và chữ ký điện tử: Thực hiện nghiêm ngặt quy trình tạo, bàn giao, lưu trữ và sử dụng khóa bảo mật, chữ ký điện tử. Tuyệt đối không để lộ mật mã hoặc chuyển giao thiết bị bảo mật cho người không có thẩm quyền.
- Phân quyền truy cập hệ thống: Thiết lập cơ chế phân quyền rõ ràng, chặt chẽ giữa các vai trò trong hệ thống (người lập lệnh, người kiểm soát, người phê duyệt). Đảm bảo nguyên tắc kiểm soát kép, không một cá nhân nào được tự ý thực hiện toàn bộ một giao dịch từ đầu đến cuối mà không có sự giám sát.
- Bảo vệ hạ tầng công nghệ thông tin: Định kỳ kiểm tra, bảo dưỡng hệ thống máy móc, thiết bị truyền thông, đường truyền dữ liệu dự phòng để đảm bảo tính sẵn sàng cao nhất.
3. Công tác kiểm tra, giám sát và phòng ngừa rủi ro
Để chủ động phòng ngừa các sự cố, Chỉ thị nhấn mạnh việc xây dựng cơ chế tự kiểm tra và giám sát thường xuyên:
- Các tổ chức tín dụng và chi nhánh Ngân hàng Nhà nước phải thường xuyên tổ chức tự kiểm tra việc chấp hành quy trình kỹ thuật nghiệp vụ thanh toán điện tử liên ngân hàng tại đơn vị mình.
- Xây dựng và hoàn thiện các kịch bản ứng phó sự cố khẩn cấp, bao gồm sự cố mất điện, hỏng đường truyền, lỗi phần mềm hoặc các thảm họa thiên tai khác.
- Tổ chức diễn tập định kỳ các phương án dự phòng để đảm bảo cán bộ vận hành có đủ kỹ năng xử lý tình huống khi có sự cố thực tế xảy ra.
4. Trách nhiệm triển khai thực hiện của các đơn vị
Chỉ thị phân công nhiệm vụ cụ thể cho từng nhóm đối tượng chịu sự tác động:
- Cục Công nghệ tin học ngân hàng: Chịu trách nhiệm theo dõi, giám sát kỹ thuật toàn bộ hệ thống; hỗ trợ kịp thời các thành viên khắc phục sự cố công nghệ; nghiên cứu nâng cấp giải pháp bảo mật tiên tiến.
- Vụ Thanh toán: Phối hợp theo dõi tình hình hoạt động nghiệp vụ, xử lý các vướng mắc phát sinh liên quan đến quy trình hạch toán và thanh toán.
- Thanh tra Ngân hàng Nhà nước: Đưa nội dung kiểm tra an toàn thanh toán điện tử liên ngân hàng vào kế hoạch thanh tra định kỳ đối với các tổ chức tín dụng.
- Các Tổ chức tín dụng thành viên: Người đại diện theo pháp luật của tổ chức tín dụng chịu trách nhiệm toàn diện về tính an toàn của hệ thống thanh toán tại đơn vị mình; thường xuyên đào tạo, nâng cao trình độ và đạo đức nghề nghiệp cho đội ngũ cán bộ thanh toán.
Tóm lại, Chỉ thị số 02/2004/CT-NHNN là cơ sở pháp lý quan trọng đặt nền móng cho việc chuẩn hóa quy trình an toàn bảo mật trong giao dịch điện tử liên ngân hàng, góp phần bảo vệ quyền lợi của khách hàng và giữ vững sự ổn định của hệ thống tài chính quốc gia.
Để sử dụng toàn bộ tiện ích nâng cao của Hệ Thống Pháp Luật vui lòng lựa chọn và đăng ký gói cước.
| THE STATE BANK OF VIETNAM | SOCIALIST REPUBLIC OF VIETNAM |
| No. 02/2004/CT-NHNN | Hanoi, February 6, 2004 |
DIRECTIVE
ON THE ENHANCEMENT OF PRUDENCE WORK IN THE INTER-BANK ELECTRONIC PAYMENT OPERATION
During recent years, the payment activity made through banks has been continuously reinforced, upgraded by the investment in the modern technological and technical equipment and the step-by-step perfection of appropriate legal system that makes the payment operation open and clear without funds stagnation, increases the capital turnover of enterprises; fully satisfies required liquidity for social-economic demands; contributes to the stability of currency value, stability of macro economy, creates favourable conditions for funds mobilization, efficiently serves social-economic development requirements, improves people's lives, speeds up the development of the entire economy. At the same time it has enhanced the State management role of the State Bank of Vietnam (SBV) in respect of banking activities and facilitates Banks of Vietnam to step by step integrate in international and regional financial community. The management of the electronic payment activity of several Credit Institutions, however, has shown signs of unsatisfied compliance with several provisions on prudential security such as: one person has been assigned to perform several processes of operation that should have been assigned to several persons in accordance with applicable laws; common use of secrecy code that has been separately granted to each user; authorization regime in the approval process of payment orders, etc.
With the view to enhancing the prudence, preventing and restricting potential risks in the inter-bank electronic payment activity, the Governor of the State Bank requires units of the SBV and Credit Institutions to take following actions:
I. IN RESPECT OF CREDIT INSTITUTIONS
1. To fully comply with provisions on the prudence in the inter-bank electronic payment activity stated in following legal documents: the Decree No. 64/2001/ND-CP dated 20 September, 2001 of the Governor on the payment activities through payment services suppliers, the Decision No. 44/2002/QD-TTg dated 21 March, 2002 of the Prime Minister on the use of electronic vouchers as accounting vouchers for funds accounting and payment by payment services suppliers, the Decision No. 353/1997/QD-NHNN2 dated 22 October, 1997 of the SBV's Governor on the issuance of the Regulation on electronic money transfer, the Decision No. 309/2002/QD-NHNN dated 9 April, 2002 of the SBV's Governor on the issuance of the Regulation on the inter-bank electronic payment and the Decision No. 349/2002/QD-NHNN dated 17 April, 2002 of the Governor of the State Bank providing for the setting up, issuance, management and use of secrecy codes in the inter-bank electronic payment.
2. To control, reconcile and update operational data within stipulated time. Timely discover, deal with errors, differences to ensure the accurate and safe accounting.
3. To examine the compliance with provisions on program and data preservation and backup methods to ensure the continuity of the operation of the inter-bank electronic payment system in the event of the occurrence of any breakdown.
...
...
...
- To regulate and intensify the internal examination, auditing and control at their unit, to ensure the strict control of all operational processes, avoid the occurrence of breakdown, which causes the loss of asset. To intensify the application of advanced technological, technical solutions for preventing, restricting potential risks in payment activity.
- To strictly verify the compliance with the procedure of the issuance, management and use of secrecy codes (electronic signatures) used for online data exchange, accessing codes of operational programs. Person, who is granted with a secrecy code, must keep it carefully, periodically change the key code and it is absolutely prohibited for a key code to be used by many users.
- For the safety, accuracy of accounting, payment operations for which electronic vouchers are applied within their system and of data transferred from the internal accounting to the inter-bank electronic payment system.
- To verify and fully comply with procedures in accordance with provisions of applicable laws on the authorization regime applicable to the approval process of payment orders.
II. IN RESPECT OF DEPARTMENTS OF THE SBV
1. Departments, within the scope of their function, assignment, should review policy, regimes, legal documents relating to the prudence of the inter-bank electronic payment.
2. Banking Information Technology Department shall:
- Intensify the verification and well perform the setting up, issuance and periodical change of the approved secrecy code in the inter-bank electronic payment system.
- Study and recommend solutions applying advanced technique, ensure the safety, secrecy during the process of data exploitation and banking operations settlement.
...
...
...
- Intensify the verification and well perform the setting up, issuance and periodical change of the secrecy code in the electronic money transfer system and inter-bank clearing system.
4. The State Bank Inspection shall:
- Intensify the supervisory activities in respect of their compliance with prudential, secrecy regime in the payment activity of credit institutions.
- Cooperate with the Banking Information Technology Department to set up and efficiently deploy solutions applying advanced technique, technology for the off-site supervision and early warning of risks to credit institutions.
III. IN RESPECT OF BRANCHES OF SBV IN PROVINCES, CITIES
General Managers of the branches of SBV in provinces, cities shall be responsible for the safety, accuracy of data and assets of their units and regularly monitor, verify, speed up local credit institutions to well perform provisions on the management, use of secrecy code and procedures for operations, ensure the safety in the payment activity at their unit and in respective locality.
Heads of units of the SBV, Chairperson of the Board of Directors, General Directors (Directors) of Credit Institutions shall be responsible for thorough deployment and good implementation of this Directive.
Any obstacle, which may arise during the implementing process, should be reported to the SBV's Governor for consideration and settlement.
...
...
...
THE GOVERNOR OF THE STATE BANK
Le Duc Thuy
- 1Circular No. 02/2020/TT-NHNN dated March 30, 2020 on guidelines for payment and money transfer related to transshipment of goods
- 2Decision No. 1571/2005/QD-NHNN of October 31, 2005, on the amendment, supplement of several articles of the regulation on inter-bank electronic payment issued in conjunction with the Decision No. 309/2002/QD-NHNN dated 9 April 2002 of the Governor of the State Bank
- 3Decision No. 349/2002/QD-NHNN of April 17th, 2002, on the issuance of the regulation on the setting up, issuance, management and use of secrecy code in the inter-bank electronic payment system.
- 4Decision No. 309/2002/QD-NHNN of April 09th, 2002, on the issuance of the regulation on inter-bank electronic payment.
- 5Decision No. 44/2002/QD-TTg, on the use of electronic vouchers as accounting documents for capital accounting and settlement by payment service-providing organizations, promulgated by the Prime Minister of Government
- 6Decree No. 64/2001/ND-CP promulgated, on payment activities via payment service-providing organization.
- 1Circular No. 02/2020/TT-NHNN dated March 30, 2020 on guidelines for payment and money transfer related to transshipment of goods
- 2Decision No. 1571/2005/QD-NHNN of October 31, 2005, on the amendment, supplement of several articles of the regulation on inter-bank electronic payment issued in conjunction with the Decision No. 309/2002/QD-NHNN dated 9 April 2002 of the Governor of the State Bank
- 3Decision No. 349/2002/QD-NHNN of April 17th, 2002, on the issuance of the regulation on the setting up, issuance, management and use of secrecy code in the inter-bank electronic payment system.
- 4Decision No. 309/2002/QD-NHNN of April 09th, 2002, on the issuance of the regulation on inter-bank electronic payment.
- 5Decree No. 64/2001/ND-CP promulgated, on payment activities via payment service-providing organization.
Directive No. 02/2004/CT-NHNN of February 6, 2004, on the enhancement of prudence work in the inter-bank electronic payment operation
- Số hiệu: 02/2004/CT-NHNN
- Loại văn bản: Chỉ thị
- Ngày ban hành: 06/02/2004
- Nơi ban hành: Ngân hàng Nhà nước
- Người ký: Lê Đức Thuý
- Ngày công báo: Đang cập nhật
- Số công báo: Đang cập nhật
- Ngày hiệu lực: 25/02/2004
- Tình trạng hiệu lực: Kiểm tra
