Regulations and standards for penetration testing
A source-based overview of Thai regulatory requirements, international standards, and AI governance frameworks that inform penetration testing and red-team assurance.
Financial Services, Banking & Insurance Standards
Mandatory security testing requirements for commercial banks, securities brokers, digital asset operators, and insurance companies.
-
Penetration testing under Bank of Thailand requirements
The Bank of Thailand defines security testing duties across several regulations, from the penetration testing guideline and iPentest to Mobile Banking and e-Money requirements. This page summarizes each one with links to
-
Penetration testing under Thai SEC requirements
The Thai Securities and Exchange Commission defines penetration testing duties for securities firms and digital asset businesses. This page summarizes both requirement sets with links to the source notifications.
-
Bank of Thailand Guidance for Mitigating ATM Malware Risk
A source-based guide to the Bank of Thailand letter RorPorTor.ForSor.(03) Wor. 1180/2559, dated 26 September 2016, on mitigating ATM malware risk. Addressed to commercial banks and specialized financial institutions, it
-
Penetration Testing Requirements for NDID Members
NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.
-
Office of Insurance Commission (OIC)
IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.
-
PCI DSS v4.0.1 and Penetration Testing
The security standard for entities that store, process, transmit, or can affect the security of payment card data.
NCSA Government Standards & Thai Cyber Laws
Thai national cybersecurity frameworks, government website and cloud standards, AI security, Zero Trust, and personal data protection.
-
Personal Data Protection Act B.E. 2562 (2019) and Penetration Testing
Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.
-
Cybersecurity Act B.E. 2562 (2019) and Penetration Testing
The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.
-
NCSA Website Security Standard B.E. 2568
The Website Security Standard covers governance and security operations across website architectures.
-
NCSA Cloud Security Standard B.E. 2567 (2024)
A source-based guide to the National Cyber Security Committee Notification on Cybersecurity Standards for Cloud Systems B.E. 2567 (Thailand National Cloud Security Framework), separating scope, customer/provider responsi
-
NCSA AI Security Guidelines: lifecycle and governance
A summary of NCSA's AI Security Guidelines, covering the 7-phase secure AI lifecycle, governance, risk management, and practical testing focus areas.
-
NCSA Zero Trust Guidelines
A source-based guide to NCSA's Zero Trust Guidelines, published as version 1.0, for executives, policy owners, technical teams, system administrators, and security engineers planning a risk-based transition from perimete
-
NCSA Guidelines for Post-Quantum Readiness
A source-based guide to NCSA's Guidelines for Post-Quantum Readiness for government agencies and critical information infrastructure organizations that process confidential information, focusing on risk assessment, asset
AI Governance and AI Security Frameworks
Frameworks for governing enterprise AI development and use, including risk management, threat modeling, AI red teaming, and controls for AI agents.
-
What ISO/IEC 42001:2023 means and how AI pentesting proves AIMS readiness
Policies alone do not prove that production AI is safe. This page explains ISO/IEC 42001:2023 and ISO/IEC 23894:2023, then shows how AI pentesting and red teaming produce decision-ready evidence for management and audito
-
What NIST AI Risk Management Framework 1.0 is and how to turn GenAI risk into a test plan
NIST AI RMF helps answer the questions leaders ask before adopting AI: what can go wrong, how will it be measured, and who decides? This page connects AI RMF 1.0, NIST AI 600-1, and evidence from AI red teaming.
-
What MITRE ATLAS is and how to build an AI red-team plan from it
AI attackers do not stop at prompt injection. They target datasets, models, RAG, agent tools, and cloud infrastructure. This page turns the large MITRE ATLAS matrix into practical test paths and detection evidence.
-
What Google Secure AI Framework 2.0 is and how it secures AI agents
SAIF maps AI risks, components, and controls from data through agents. This page explains the core elements, Risk Map, SAIF 2.0 agent guidance, and what red teaming should prove before impact becomes real.
Global Technical Frameworks & Security Standards
International frameworks for software vulnerability assessment, information security management, and threat modeling.
-
OWASP Top 10 guides for Web, Mobile, API, LLM, and Agentic
Explore the current OWASP Top 10 editions by technology area. Each guide has ten linkable risk sections, original high-level testing guidance, an educational diagram, and a link to the official OWASP source.
-
ISO/IEC 27001:2022 and Penetration Testing
An information security management system (ISMS) standard for systematically managing risks to information, people, processes, and technology.
-
MITRE ATT&CK v19.2: every Enterprise tactic for pentesting and red teaming
This reference maps the Enterprise ATT&CK v19.2 framework for proactive security assessments, aligning penetration testing and red teaming with real-world adversary behaviors based on authorized scope, critical assets, a
-
MPA Content Security v5.3.1 and Penetration Testing Requirements
An authoritative guide to Motion Picture Association (MPA) Content Security Best Practices v5.3.1, Trusted Partner Network (TPN) governance, the four-tier Shield system, and penetration testing mandates (Control TS-4.1)