Siam Thanat Hack Co., Ltd.

Cybersecurity Act B.E. 2562 (2019) and Penetration Testing

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

Using testing in the cybersecurity risk-assessment cycle

The Act establishes assessment and audit expectations for in-scope entities. Penetration testing can evidence technical risk but does not replace the whole governance process.

Thai infographic explaining: Using testing in the cybersecurity risk-assessment cycle
Visual summary: Using testing in the cybersecurity risk-assessment cycle
  • Identify critical services, supporting systems, and infrastructure dependencies before fixing an assessment scope.
  • Section 54 states that CII organisations must arrange cybersecurity risk assessment and audit at least annually, subject to the Act's applicable conditions.
  • Assessment evidence should connect threat, vulnerability, impact, control owner, and remediation rather than consider a scan or pentest in isolation.
  • Confirm the reporting framework and 30-day timing against the actual entity and responsible authority.

NATIONAL CYBERSECURITY / RISK & AUDIT

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

หน้าที่ตามพระราชบัญญัติ

  • มาตรา 44 กำหนดให้หน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) จัดทำประมวลแนวทางปฏิบัติและกรอบมาตรฐาน โดยอย่างน้อยต้องมีแผนการตรวจสอบและประเมินความเสี่ยงด้านการรักษาความมั่นคงปลอดภัยไซเบอร์ประจำปี
  • มาตรา 54 กำหนดให้หน่วยงาน CII จัดให้มีการประเมินความเสี่ยงและการตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์อย่างน้อยปีละหนึ่งครั้ง และส่งผลสรุปให้สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติภายในสามสิบวันนับแต่วันที่ดำเนินการแล้วเสร็จ

บทบาทของ Penetration Testing

  • Penetration Testing เป็นหลักฐานทางเทคนิคที่ช่วยสนับสนุนการประเมินความเสี่ยงและการตรวจสอบ แต่ไม่ใช่การตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์ทั้งหมด
  • ประมวลแนวทางปฏิบัติและกรอบมาตรฐาน พ.ศ. 2564 ข้อ 21.3.4 และ 21.3.6 ใช้ถ้อยคำเชิงแนะนำให้พิจารณา Penetration Testing ตามความเสี่ยงและความจำเป็น โดยเน้นบริการสำคัญและระบบที่เชื่อมต่ออินเทอร์เน็ต
  • หากดำเนินการ ขอบเขตควรครอบคลุม Host, Network และ Application ที่เกี่ยวข้อง และผู้ทดสอบควรมีความเป็นอิสระจากระบบและกระบวนการที่ถูกทดสอบ
ขอบเขตข้อกำหนด

พระราชบัญญัติไม่ได้กำหนดให้ทุกองค์กรต้องทำ Penetration Testing ทุกปี ต้องแยกหน้าที่ตรวจสอบและประเมินความเสี่ยงตามกฎหมายออกจากวิธีทดสอบทางเทคนิคที่เลือกใช้

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofCybersecurity Act B.E. 2562 (2019)

Cybersecurity Act B.E. 2562 (2019)

By Royal Thai Government Gazette

Open document (PDF) Source