NCSA AI Security Guidelines
A source-based orientation to the NCSA AI Security Guidelines for executive owners, AI development and operations teams, legal/DPO functions, and cybersecurity teams, organized around the AI lifecycle and risk governance.
Purpose and intended audiences
NCSA presents the document as guidance for developing, managing, and using AI systems securely and trustworthily.

- It spans policy-level decision making for executives and technical practice for AI development and operations teams.
- Its intended stakeholders include legal and data-protection functions, cybersecurity teams, employees, customers, data subjects, and supply-chain vendors.
- The guidance draws on international standards and technical material including ISO/IEC, ENISA, and OWASP alongside Thai laws and practices.
The secure AI lifecycle
The guidance structures security from pre-investment decisions through the disposal of data and AI assets.

- Phase 0: concept - establish business context, applicable legal and regulatory context, assets, threats, vulnerabilities, and risk before development begins.
- Phases 1-3: secure design, secure development, and security verification.
- Phases 4-6: secure deployment, secure operations and maintenance, then appropriate decommissioning and destruction.
Governance, risk, and accountability
Its governance chapter uses a GRC (Governance, Risk Management and Compliance) lens and says risk must be assessed in each organization's system context.

- Document security-related roles, authority, and accountability for the AI system.
- Integrate AI risk into enterprise risk management and track applicable Thai laws and regulations.
- Plan assurance, certification where appropriate, communication, and training so the use of AI remains controllable and auditable.
A practical starting point
Make the AI system's assets and relationships visible before selecting controls or defining a testing scope.

- Maintain an asset and data-flow inventory covering models, training data, interfaces, and third-party components.
- Retain risk assessments, verification results, and implementation evidence throughout the lifecycle.
- Tailor controls and testing to the system's purpose, architecture, data, and impact rather than applying one checklist unchanged to every system.
STH AI SECURITY TESTING
LLM-integrated App Pentest and AI Red Teaming
An LLM-integrated application has a wider attack surface than the model alone. The application, input paths, RAG or vector store, agent tools, identity, data, and event logging must be assessed together.

LLM-integrated application pentest
Validate controls at the system integration points, rather than limiting the assessment to model behaviour.
- User authorization, tenant and data separation, and data exposure through responses or retrieved documents.
- RAG, vector store, model-provider, API, and third-party tool integrations, including token and secret boundaries.
- Approval and authorization enforcement before an agent invokes a tool or performs an impactful action.
AI Red Teaming
Simulate adversarial behaviour within an authorized scope to demonstrate whether guardrails and protective workflows work in practice.
- Prompt injection and indirect prompt injection through documents or data used as context.
- Jailbreaking or attempts to move the system outside its intended purpose, with validation of unsafe-output handling.
- Agentic-AI risks where a prompt or tool invocation could affect data, accounts, or downstream systems.
Expected testing evidence
- An authorized scope, test environment and data, stop criteria, and emergency contacts.
- Evidence, severity, impact conditions, and remediation guidance that can be independently retested.
- A retest after remediation and a record of controls or risks that need production monitoring.
NCSA's Secure Verification phase gives active testing, LLM penetration testing for prompt injection and jailbreaking, data-leakage risks, and dangerous agent actions as examples of evidence to verify before release.
Talk to STH about LLM-integrated App Pentest and AI Red Teaming
