Thông tư 23/2020/TT-BTTTT

Circular No. 23/2020/TT-BTTTT dated September 9, 2020 on regulating particular contents of state-funded information technology service leases

Nội dung toàn văn Circular 23/2020/TT-BTTTT particular contents of state-funded information technology service leases


MINISTRY OF INFORMATION AND COMMUNICATIONS
--------

SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------

No. 23/2020/TT-BTTTT

Hanoi, September 9, 2020

 

CIRCULAR

REGULATING PARTICULAR CONTENTS OF STATE-FUNDED INFORMATION TECHNOLOGY SERVICE LEASES

Pursuant to the Law on Information Technology dated June 29, 2006;

Pursuant to the Government’s Decree No. 73/2019/ND-CP dated September 5, 2019, regulating the management of projects on investment in application of information technology funded by the state budget capital;

Pursuant to the Government's Decree No. 17/2017/ND-CP dated February 17, 2017, defining the functions, tasks, powers and organizational structure of the Ministry of Information and Communications;

Upon the request of the Director of the Computerization Agency,

The Minister of Information and Communications hereby promulgates the Circular on particular contents of state-funded information technology service leases.

Chapter I

GENERAL PROVISIONS

Article 1. Scope

This Circular sets out regulations regarding particular contents of the lease of information technology service not available on the market (hereinafter referred to as service) funded by state budget’s regular expenditures prescribed in the Government’s Decree No. 73/2019/ND-CP dated September 5, 2019, prescribing the management of investment in application of information technology funded by the state budget. 

Article 2. Subjects and principles of application

1. Subjects of application

a) This Circular shall apply to entities, organizations and individuals involved in or related to the lease of information technology services funded by the state budget's regular expenditures;

b) Other entities and persons related to the lease of information technology services funded by other sources of capital should apply specific instructions given herein.

2. Principles of application

a) According to the provisions of this Circular, entities and units must formulate specific conditions and terms for a service lease, ensuring the compliance with the law on contracts, bidding and conformance to the approved service lease plan;

b) Regulations laid down in this Circular must form the basis for related parties’ management of the quantity, quality, progress, conduct of the quality inspection, assessment, acceptance testing, payment and finalization of the service lease.

Chapter II

PARTICULAR CONTENTS OF THE STATE-FUNDED SERVICE LEASE

Article 3. Requirements concerning the service scope

1. Technical requirements set out in a service lease

a) The technical requirements shall be defined according to the criteria, ensuring conformance to the service quality requirements in the approved service lease plan, including: Professional function criteria; operating performance criteria; information security criteria; other non-functional criteria; user satisfaction criteria; service management criteria;

b) Specific quality criteria, requirements and output requirements of each criterion shall follow instructions given in Appendix I to this Circular;

c) In the course of implementation of the service lease, based on the particular and specific requirements of each entity or unit, the lead service lessee shall consider and choose to apply some or all of the criteria specified in this Clause, supplementing and updating other criteria (if necessary).

2. Other requirements set out in a service lease

a) Requirements and processes for transfer of information and data acquired during service lease operations

The lead service lessee and the service provider shall negotiate and agree on the request and processes for transfer of information and data acquired during the service leasing process to the lead service lessee with the following main contents:

- The lead service lessee and the service provider must transfer all information and data acquired during the service leasing process to the lead service lessee according to the plan agreed upon by contracting parties;

- Methods, tools, processes and roles and responsibilities of each party in the transfer process; plans to test the status of information and data acquired prior to transfer; plans for backup and restoration of data before transfer (if necessary); plans to check the status of information and data acquired after transfer; plans to check and review data after transfer; plans to delete information and data related to the lead service lessee on management systems of service providers after the completed transfer;

- Service provider’s commitments to be fulfilled after the completed transfer;

- Other requirements for transfer of information and data acquired during the service supply process.

b) Cybersecurity requirements

During the process of negotiating and agreeing on cybersecurity requirements, lead lessees and service providers must ensure conformance to legislative regulations on cybersecurity.

c) Lead lessee and the service provider shall negotiate and agree on requirements concerning service-related copyright and intellectual property rights and other requirements, depending on the nature, characteristics, requirements and actual demands with respect to the contractual service.

Article 4. Contract execution duration and plan

1. Contract execution duration, including:

a) Preparatory period: Service provider sets the time for design and development of the contractual service; testing or commissioning; training or guidance on use or operation of the contractual service (if any);

b) Service lease term: The term ranges from the time of acceptance testing, handover and operation of the contractual service to the end of the lease;

c) Time of transfer, handover and fulfillment of other contractual obligations: Time of transfer of information and data acquired during the service provision period and time of service provider’s fulfillment of other obligations and responsibilities as agreed upon in the service lease contract.

2. Service lease execution proposal

Service provider shall be responsible for formulating a proposal for execution of the service lease in order for the lead lessee to check and validate it. Each proposal must include but not limited to the followings:

a) Order and schedule of activities performed in each main stage within the period of execution of the contract as regulated in clause 1 of this Article;

b) Timelines of completion, handover of key works or products, service provider’s progress reports.

Article 5. Payment of contractual obligations

1. Payment method (i.e. payment period, time of payment) must be conformable to the method of determining the cost of service lease according to the approved service lease plan.

2. In case of change of the payment method, the lead lessee and the service provider shall enter into negotiation and agreement according to the principle of compliance with legal regulations on condition that the payment of contractual obligations does not exceed the winning bid, estimated cost or price of a bid.

Article 6. Service quality inspection and assessment

1. Service quality inspection and assessment conducted in the preparatory stage

a) Service quality inspection and assessment shall be carried out through testing or commissioning and inspection and evaluation methods (if any) corresponding to each specific criterion specified in Clause 1 of Article 3 of this Circular;

b) Service quality inspection and assessment results shall serve as the basis for acceptance testing and handover of the contractual service. Documents and records evidencing the acceptance testing shall comprise:

- Test or commissioning report;

- Inspection and assessment report (if any);

- Other related records and materials.

c) The lead lessee and service provider shall negotiate and sign the record of acceptance testing and handover of the contractual service before use by using the form No. 1 of Appendix II hereto as a basis for putting the contractual service into official use.

2. Service quality inspection and assessment conducted in the lease execution stage

a) The lead lessee shall be responsible for monitoring and overseeing the service provision by the service provider, and examining and evaluating the quality of the contractual service during the service lease term.

Service quality inspection and assessment shall be carried out through surveying, collecting, analyzing, and evaluating feedbacks of organizations and individuals using contractual services; or periodic and ad-hoc physical inspections of service delivery systems and inspections over service providers shall be carried out with the aim of evaluating the service quality according to defined specific criteria, or shall be carried out in combination with the above-stated approaches.

b) Service providers shall be responsible for providing the contractual services; reporting the results of the service provision during the service lease term to lead lessees on a periodic or irregular basis as agreed in contracts;

c) Service quality inspection and assessment results shall serve as a basis for the acceptance testing of the service provision results. Documents and records evidencing the acceptance testing shall comprise:

- Report on service provision results prepared by the service provider according to the form No. 2 of Appendix II hereto;

- Report on monitoring and oversight results prepared by the lead lessee according to the form No. 3 of Appendix II hereto;

- Record of transfer of information and data acquired during the service supply process (if any) using the form No. 4 of Appendix II hereto;

- Other related records and materials.

d) The lead lessee and service provider shall seek their mutual agreement and sign the record of the acceptance testing of service provision results by using the form No. 5 of Appendix II hereto as a basis for fulfillment of the contractual payment as agreed upon under contracts.

3. Example of technical requirements set out based on the service output quality, and inspection and evaluation methods corresponding to each stage during the contract performance period, which is shown in Appendix III to this Circular.

Chapter III

IMPLEMENTATION PROVISIONS

Article 7. Entry into force and transitional provisions

1. This Circular shall enter into force on October 25, 2020.

2. If a service lease has been concluded before the effective date of this Circular, terms and conditions set forth in this contract shall remain valid. In case where it is necessary to apply this Circular, the lead service lessee and the service provider shall reach an agreement to ensure continuity of contractual service activities.

Article 8. Implementation responsibilities

1. Entities, organizations and individuals involved in or related to the lease of information technology services funded by the state budget's regular expenditures shall be responsible for implementing this Circular.

2. Computerization Agency – the Ministry of Information and Communications - shall be responsible for communicating, providing guidance on and keeping track of implementation of this Circular.

3. In the course of implementing this Circular, if there is any difficulty that arises, persons and entities may send timely feedbacks to the Ministry of Information and Communications (Computerization Agency) to seek its approval of proper actions./.

 

 

MINISTER




Nguyen Manh Hung

 

APPENDIX I

TECHNICAL REQUIREMENTS SET OUT BASED ON THE SERVICE OUTPUT QUALITY CORRESPONDING TO EACH STAGE DURING THE CONTRACT PERFORMANCE PERIOD
(Issued together with the Circular No. 12/2018/TT-BTTTT dated September 9, 2020 of the Minister of Information and Communications)

No.

Criteria

Specific quality requirements

Output requirements

Preparatory stage

Lease execution stage

(1)

(2)

(3)

(4)

(5)

1

Operational function requirements

 

 

 

1.1

Adequacy of operational function

Requirements concerning the quantity of compulsorily or expectedly satisfactory operational functions

Satisfactory

Satisfactory

1.2

Accuracy of operational function

Requirements concerning the quantity of system functions giving accurate outcomes

Satisfactory

Satisfactory

1.3

Concordance between the function and the operation

Requirements concerning the quantity of functions compulsorily matched with the actual operation

Satisfactory

Satisfactory

2

Criteria concerning performance

 

 

 

2.1

Satisfactory service performance

Service performance requirements (including load bearing capacity, the number of simultaneous visitors, the number of simultaneous users, etc.)

Satisfactory

Satisfactory

2.2

Service extensibility

Requirements concerning the service extensibility (i.e. the number of transactions that can be processed at a time; the number of data that can be stored; the number of simultaneous users, etc.)

Satisfactory

Satisfactory

3

Information safety criteria

 

 

 

3.1

Information confidentiality

Requirements concerning cyber security vulnerabilities upon which a server system is obliged not to infringe

Satisfactory

Satisfactory

 

 

Requirements concerning the seriousness of cyber security vulnerabilities upon which a server system is obliged not to infringe

Satisfactory

Satisfactory

 

 

Requirements concerning the data integrity

 

Satisfactory

 

 

Requirements concerning protocols for preventing unauthorized access or data changes, whether unintentional or deliberate

Satisfactory

Satisfactory

3.2

Origin traceability

Requirements concerning the capability of tracing and tracking user’s activities

Satisfactory

User’s activities on the system may be traced or trackable

3.3

Information security commitments

Requirements and commitments regarding information security

Commitments are made

Avoid any infringement upon information security commitments

3.4

Graded protection of the information system

Requirements concerning the graded protection of information system (server system)

The information system will be graded and measures for protection of that information prescribed by laws will be taken

Ensuring safety for the information system according to its grade

4

Other non-functional requirements

 

 

 

4.1

Compliance with general technical requirements

 

 

 

4.1.1

Conformance to technical standards regarding application of information technology at state authorities

Requirements concerning conformance to technical standards, regulations currently in force, regarding application of information technology at state authorities

Satisfactory

 

4.1.2

Technology platform

Requirements under which a server system’s technology platform needs to be compatible and it itself needs to be relevant to the current status of application of information technology by the lead lessee

Satisfactory

 

4.2

Usability

 

 

 

4.2.1

Usability

Requirements concerning the retrievability of data created through use of the service

Satisfactory

Satisfactory

 

 

Requirements concerning retrieved data format

Satisfactory

Satisfactory

4.2.2

Capability of preventing users from common errors

Requirements under which errors that users may encounter need to be prevented or alerted 

Satisfactory

Satisfactory

4.2.3

Diverse capabilities of accessing and using the system

Requirements concerning forms, utilities, tools and applications that the contractual service may provides to support user's service access and use

Satisfactory

Satisfactory

Requirements concerning support for disabled users (i.e. those incapable of using mouses, keyboards, or seeing screens, etc.)

Satisfactory

Satisfactory

4.2.4

Easy-to-learn and easy-to-use

Requirements concerning the easy-to-learn and easy-to-use degree of operational functions

Satisfactory

Satisfactory

 

 

Requirements concerning the adequacy of user’s instructions

Satisfactory

Satisfactory

 

 

Requirements concerning approaches to providing user’s instructions

Satisfactory

Satisfactory

4.3

Reliability

 

 

 

4.3.1

Continuity and availability

Requirements concerning the acceptable frequency of service disconnections

 

Satisfactory

 

 

Requirements concerning acceptable intervals between incidents resulting in service disconnections

 

Satisfactory

4.3.2

Post-incident recoverability

Requirements concerning the duration needed for recovering the contractual service after incidents

 

Satisfactory

 

 

Requirements concerning the percentage of the service recovered after incident (i.e. the degree of absoluteness of recovery)

 

Satisfactory

 

 

Requirements concerning factors and data enabling a system recovery after incident

 

Satisfactory

4.4

Maintainability

 

 

 

4.4.1

Capability of incident analysis

Requirements concerning the duration of the service provider’s identification of causes and other recommended remedies

 

Satisfactory

4.4.2

Possibility of flexible replacement

Requirements concerning the server system’s parts that can be replaced without causing any impact on service operation and quality

 

Satisfactory

4.4.3

Incident forecasting capability

Requirements concerning methods of inspecting and overseeing the operational status of the system

 

Satisfactory

4.5

Adjustability

 

 

 

4.5.1

Capability of customizing all or some of service parts

Requirements concerning the quantity of functions and parts of the system that may be adjusted to meet user's needs

Satisfactory

Satisfactory

4.6

Capabilities of integration and connection

 

 

 

4.6.1

Data connection and sharing alternatives

Requirements concerning the service provider’s guarantee for the system’s conformity with the plan of data connection and sharing according to the current information technology application status of the lead lessee, the service provider’s compliance with the system construction documents, according to the standards, plans stated in the approved lease plan and current regulations

Satisfactory

Satisfactory

4.6.2

Capability of integrating, connecting the service with surveillance systems, third-party systems to meet the management, oversight and supervision needs of the lead lessee

Requirements concerning the integration with several particular third-party systems used for management, oversight and supervision purposes

Satisfactory

Satisfactory

4.7

Extent of service usage and operation during the assessment period

Agreements on methods for ensuring the effectiveness of the service used and operated

 

Satisfying agreements

5

Criteria concerning user’s satisfaction

 

 

 

5.1

Timeliness

Requirements concerning the duration during which the service provider is obliged to finish the provision of the contractual service to users compared to the prescribed duration

Satisfactory

Satisfactory

5.2

User’s feedbacks

Requirements concerning methods of recording opinions and contents of user’s opinions

 

Satisfactory

5.3

Capability of providing users with support

Requirements concerning the service provider's capability of providing support

 

Satisfactory

5.4

Service attitudes

Requirements concerning the service provider’s service attitudes

 

Satisfactory

6

Administrative criteria

 

 

 

6.1

Compliance with procedures

Requirements concerning the issuance of service management procedures and compliance with these procedures

Satisfactory

Satisfactory

6.2

Working environment

Requirements concerning the service provider’s working environment

Satisfactory

Satisfactory

 

 

Requirements concerning the service provider’s specialized department for service management and provision tasks

 

Satisfactory

6.3

Reporting

Requirements concerning the reporting regime and inclusions

Meeting these requirements in the preparatory stage

Meeting these requirements in the execution stage

6.4

Management of availability and continuity of the contractual service

Requirements concerning documentation or system of management of availability and continuity of the contractual service

 

Satisfactory

6.5

Change management

Requirements concerning documentation for management of changes in the contractual service

Satisfactory

Satisfactory

6.6

Release management and deployment

Requirements concerning release management and deployment documentation

Satisfactory

Satisfactory

 


------------------------------------------------------------------------------------------------------
This translation is made by THƯ VIỆN PHÁP LUẬT and for reference purposes only. Its copyright is owned by THƯ VIỆN PHÁP LUẬT and protected under Clause 2, Article 14 of the Law on Intellectual Property.Your comments are always welcomed

Đã xem:

Đánh giá:  
 

Thuộc tính Văn bản pháp luật 23/2020/TT-BTTTT

Loại văn bảnThông tư
Số hiệu23/2020/TT-BTTTT
Cơ quan ban hành
Người ký
Ngày ban hành09/09/2020
Ngày hiệu lực25/10/2020
Ngày công báo...
Số công báo
Lĩnh vựcTài chính nhà nước, Công nghệ thông tin
Tình trạng hiệu lựcCòn hiệu lực
Cập nhật4 năm trước
Yêu cầu cập nhật văn bản này

Download Văn bản pháp luật 23/2020/TT-BTTTT

Lược đồ Circular 23/2020/TT-BTTTT particular contents of state-funded information technology service leases


Văn bản bị sửa đổi, bổ sung

    Văn bản liên quan ngôn ngữ

      Văn bản sửa đổi, bổ sung

        Văn bản bị đính chính

          Văn bản được hướng dẫn

            Văn bản đính chính

              Văn bản bị thay thế

                Văn bản hiện thời

                Circular 23/2020/TT-BTTTT particular contents of state-funded information technology service leases
                Loại văn bảnThông tư
                Số hiệu23/2020/TT-BTTTT
                Cơ quan ban hànhBộ Thông tin và Truyền thông
                Người kýNguyễn Mạnh Hùng
                Ngày ban hành09/09/2020
                Ngày hiệu lực25/10/2020
                Ngày công báo...
                Số công báo
                Lĩnh vựcTài chính nhà nước, Công nghệ thông tin
                Tình trạng hiệu lựcCòn hiệu lực
                Cập nhật4 năm trước

                Văn bản thay thế

                  Văn bản được dẫn chiếu

                    Văn bản hướng dẫn

                      Văn bản được hợp nhất

                        Văn bản được căn cứ

                          Văn bản hợp nhất

                            Văn bản gốc Circular 23/2020/TT-BTTTT particular contents of state-funded information technology service leases

                            Lịch sử hiệu lực Circular 23/2020/TT-BTTTT particular contents of state-funded information technology service leases

                            • 09/09/2020

                              Văn bản được ban hành

                              Trạng thái: Chưa có hiệu lực

                            • 25/10/2020

                              Văn bản có hiệu lực

                              Trạng thái: Có hiệu lực