Siam Thanat Hack Co., Ltd.

Regulations and standards for penetration testing

A summary of Thai regulatory requirements and international standards that involve penetration testing, referenced from each authority's source documents.

Financial Services, Banking & Insurance Standards

Mandatory security testing requirements for commercial banks, securities brokers, digital asset operators, and insurance companies.

  • Penetration testing under Bank of Thailand requirements

    The Bank of Thailand defines security testing duties across several regulations, from the penetration testing guideline and iPentest to Mobile Banking and e-Money requirements. This page summarizes each one with links to

  • Penetration testing under Thai SEC requirements

    The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.

  • Bank of Thailand Guidance for Mitigating ATM Malware Risk

    A source-based guide to the Bank of Thailand letter RorPorTor.ForSor.(03) Wor. 1180/2559, dated 26 September 2016, on mitigating ATM malware risk. Addressed to commercial banks and specialized financial institutions, it

  • Penetration Testing Requirements for NDID Members

    NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

  • Office of Insurance Commission (OIC)

    IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

  • PCI DSS v4.0.1 and Penetration Testing

    The security standard for entities that store, process, transmit, or can affect the security of payment card data.

NCSA Government Standards & Thai Cyber Laws

Thai national cybersecurity frameworks, government website and cloud standards, AI security, Zero Trust, and personal data protection.

  • Personal Data Protection Act B.E. 2562 (2019) and Penetration Testing

    Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

  • Cybersecurity Act B.E. 2562 (2019) and Penetration Testing

    The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

  • NCSA Website Security Standard B.E. 2568

    The Website Security Standard covers governance and security operations across website architectures.

  • NCSA Cloud Security Standard B.E. 2567 (2024)

    A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsi

  • NCSA AI Security Guidelines: lifecycle and governance

    A summary of NCSA's AI Security Guidelines, covering the 7-phase secure AI lifecycle, governance, risk management, and practical testing focus areas.

  • NCSA Zero Trust Guidelines

    A source-based guide to NCSA's Zero Trust Guidelines, published as version 1.0, for executives, policy owners, technical teams, system administrators, and security engineers planning a risk-based transition from perimete

  • NCSA Guidelines for Post-Quantum Readiness

    A source-based guide to NCSA's Guidelines for Post-Quantum Readiness for government agencies and critical information infrastructure organizations that process confidential information, focusing on risk assessment, asset

Global Technical Frameworks & Security Standards

International frameworks for software vulnerability assessment, information security management, and threat modeling.