Siam Thanat Hack Co., Ltd.

Cybersecurity Act B.E. 2562 (2019) and Penetration Testing

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

Executive Summary and Mandate Overview
Target Audience Critical Information Infrastructure (CII) entities across 7 designated sectors
Mandatory Frequency At least annually according to NCSA cybersecurity baselines
Required Scope CII Core Systems, Operational Technology (OT and SCADA), Enterprise Network
Non-Compliance Risk Court and NCSA enforcement orders, fines up to 300,000 THB and daily penalties (Sec 71 to 73)

Using testing in the cybersecurity risk-assessment cycle

The Act establishes assessment and audit expectations for in-scope entities. Penetration testing can evidence technical risk but does not replace the whole governance process.

Thai infographic explaining: Using testing in the cybersecurity risk-assessment cycle
Visual summary: Using testing in the cybersecurity risk-assessment cycle
  • Identify critical services, supporting systems, and infrastructure dependencies before fixing an assessment scope.
  • Section 54 states that CII organisations must arrange cybersecurity risk assessment and audit at least annually, subject to the Act's applicable conditions.
  • Assessment evidence should connect threat, vulnerability, impact, control owner, and remediation rather than consider a scan or pentest in isolation.
  • Confirm the reporting framework and 30-day timing against the actual entity and responsible authority.

NATIONAL CYBERSECURITY / RISK & AUDIT

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

หน้าที่ตามพระราชบัญญัติ

  • มาตรา 44 กำหนดให้หน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) จัดทำประมวลแนวทางปฏิบัติและกรอบมาตรฐาน โดยอย่างน้อยต้องมีแผนการตรวจสอบและประเมินความเสี่ยงด้านการรักษาความมั่นคงปลอดภัยไซเบอร์ประจำปี
  • มาตรา 54 กำหนดให้หน่วยงาน CII จัดให้มีการประเมินความเสี่ยงและการตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์อย่างน้อยปีละหนึ่งครั้ง และส่งผลสรุปให้สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติภายในสามสิบวันนับแต่วันที่ดำเนินการแล้วเสร็จ

บทบาทของ Penetration Testing

  • Penetration Testing เป็นหลักฐานทางเทคนิคที่ช่วยสนับสนุนการประเมินความเสี่ยงและการตรวจสอบ แต่ไม่ใช่การตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์ทั้งหมด
  • ประมวลแนวทางปฏิบัติและกรอบมาตรฐาน พ.ศ. 2564 ข้อ 21.3.4 และ 21.3.6 ใช้ถ้อยคำเชิงแนะนำให้พิจารณา Penetration Testing ตามความเสี่ยงและความจำเป็น โดยเน้นบริการสำคัญและระบบที่เชื่อมต่ออินเทอร์เน็ต
  • หากดำเนินการ ขอบเขตควรครอบคลุม Host, Network และ Application ที่เกี่ยวข้อง และผู้ทดสอบควรมีความเป็นอิสระจากระบบและกระบวนการที่ถูกทดสอบ
ขอบเขตข้อกำหนด

พระราชบัญญัติไม่ได้กำหนดให้ทุกองค์กรต้องทำ Penetration Testing ทุกปี ต้องแยกหน้าที่ตรวจสอบและประเมินความเสี่ยงตามกฎหมายออกจากวิธีทดสอบทางเทคนิคที่เลือกใช้

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Sections 49 to 54 CII Baseline Security Standards and Risk Assessment Critical Information Infrastructure (CII) across 7 sectors, OT and SCADA Systems At least annually
NCSA Directive 2022 Cybersecurity Incident Notification and Security Testing Framework Core Network Assets, Critical Enterprise Applications, Control Systems Regular NCSA evaluation cycle

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofCybersecurity Act B.E. 2562 (2019)

Cybersecurity Act B.E. 2562 (2019)

By Royal Thai Government Gazette

Open document (PDF) Source