Siam Thanat Hack Co., Ltd.

Regulations and standards for penetration testing

A summary of Thai regulatory requirements and international standards that involve penetration testing, referenced from each authority's source documents.

  • Penetration testing under Bank of Thailand requirements

    The Bank of Thailand defines security testing duties across several regulations, from the penetration testing guideline and iPentest to Mobile Banking and e-Money requirements. This page summarizes each one with links to

  • Penetration testing under Thai SEC requirements

    The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.

  • ISO/IEC 27001:2022 and Penetration Testing

    An information security management system (ISMS) standard for systematically managing risks to information, people, processes, and technology.

  • Personal Data Protection Act B.E. 2562 (2019) and Penetration Testing

    Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

  • Cybersecurity Act B.E. 2562 (2019) and Penetration Testing

    The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

  • NCSA Website Security Standard B.E. 2568

    The Website Security Standard covers governance and security operations across website architectures.

  • Bank of Thailand Guidance for Mitigating ATM Malware Risk

    A source-based guide to the Bank of Thailand letter RorPorTor.ForSor.(03) Wor. 1180/2559, dated 26 September 2016, on mitigating ATM malware risk. Addressed to commercial banks and specialized financial institutions, it

  • NCSA AI Security Guidelines

    A source-based orientation to the NCSA AI Security Guidelines for executive owners, AI development and operations teams, legal/DPO functions, and cybersecurity teams, organized around the AI lifecycle and risk governance

  • NCSA Cloud Security Standard B.E. 2567 (2024)

    A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsi

  • NCSA Guidelines for Post-Quantum Readiness

    A source-based guide to NCSA's Guidelines for Post-Quantum Readiness for government agencies and critical information infrastructure organizations that process confidential information, focusing on risk assessment, asset

  • NCSA Zero Trust Guidelines

    A source-based guide to NCSA's Zero Trust Guidelines, published as version 1.0, for executives, policy owners, technical teams, system administrators, and security engineers planning a risk-based transition from perimete

  • PCI DSS v4.0.1 and Penetration Testing

    The security standard for entities that store, process, transmit, or can affect the security of payment card data.

  • Penetration Testing Requirements for NDID Members

    NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

  • Office of Insurance Commission (OIC)

    IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

  • OWASP Top 10 guides for web, mobile, API, and LLM applications

    Explore the current OWASP Top 10 editions by technology area. Each guide has ten linkable risk sections, original high-level testing guidance, an educational diagram, and a link to the official OWASP source.

  • MITRE ATT&CK v19.1: every Enterprise tactic for pentesting and red teaming

    This guide uses Enterprise ATT&CK v19.1 as a common language for threat-informed testing. Select authorised behaviours from scope, critical assets, and business risk; it is not an instruction to attack live systems or a