Siam Thanat Hack Co., Ltd.

NCSA Website Security Standard B.E. 2568

The Website Security Standard covers governance and security operations across website architectures.

Making the NCSA website standard an operational cycle

The standard connects governance, impact assessment, self-assessment, and improvement. Technical testing should therefore cover the website's real architecture.

Thai infographic explaining: Making the NCSA website standard an operational cycle
Visual summary: Making the NCSA website standard an operational cycle
  • Confirm that the entity and site are in scope, then classify impact before selecting controls and evidence.
  • The Form Kor 1 self-assessment cycle should draw on evidence from relevant web applications, web servers, databases, and cloud or web-hosting components.
  • For nonconformity, create a Form Kor 2 improvement plan with owner, due date, and follow-up method instead of closing an issue with a test report alone.
  • Pentesting is technical evidence for website-security operations. It does not automatically turn the standard into a mandatory annual pentest for every site.

NCSA / WEBSITE SECURITY STANDARD

The Website Security Standard covers governance and security operations across website architectures.

ใครต้องทำและ Penetration Testing เกี่ยวข้องอย่างไร

  • ใช้บังคับกับหน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) ส่วนเอกชนทั่วไปได้รับการส่งเสริมให้นำไปใช้
  • ประกาศลงวันที่ 16 กันยายน 2568 และมีผลเมื่อพ้นหนึ่งปี จึงมีผลวันที่ 16 กันยายน 2569
  • หน่วยงานในขอบเขตต้องประเมินตนเองตามแบบ ค๑ อย่างน้อยปีละ 1 ครั้ง ประเมินระดับผลกระทบ รายงานตามระดับ และจัดทำแผนแก้ไขแบบ ค๒ เมื่อไม่สอดคล้อง
  • มาตรฐานไม่ได้ทำให้การประเมินตนเองกลายเป็นข้อบังคับ Penetration Testing รายปีโดยอัตโนมัติ แต่ Penetration Testing เป็นหลักฐานเชิงเทคนิคเพื่อพิสูจน์ Website Security Operation และช่องโหว่ที่โจมตีได้จริง
เลือก Scope จาก Impact

Scope ควรครอบคลุม Web Application, Web Server, Database และ Cloud หรือ Web Hosting ที่เกี่ยวข้อง ตามสถาปัตยกรรมและระดับผลกระทบของเว็บไซต์ ไม่ใช่ตรวจเฉพาะหน้าเว็บ

Practical guidance and tools for the Website Security Standard

WSS by STH turns the Website Security Standard B.E. 2568 (2025) into an actionable checklist for governance, risk assessment, development, operations, and remediation evidence.

Open WSS by STH

Educational video: Website Security Standard

Watch this educational video for an introduction to the standard and its application to organizational websites.

YouTube

Who should act

Appendix Kor includes Form Kor 1 for state agencies, regulators, critical information infrastructure organisations, and private entities. For private entities, the standard encourages adoption rather than imposing the same duty level as for state agencies, regulators, or CII organisations.

Infographic explaining which organisations should consider acting under the NCSA Website Security Standard
Summary of the organisation groups and the operational cycle for the Website Security Standard

State agencies

Inventory agency sites that provide public information or online services, then identify the system owner and URL.

Regulators

Assign accountable owners, follow up on compliance, and retain evidence that can be audited.

CII organisations

Consider service criticality and infrastructure dependencies before prioritising remediation.

Private entities (encouraged to adopt)

Private organisations with public-facing information or online-service sites are encouraged to adopt the guidance, beginning with the site and dependencies such as cloud or web hosting.

A category appearing in Form Kor 1 does not replace the scope assessment or duties that may apply under a specific law or organisational requirement.

Using Forms Kor 1 and Kor 2

Form Kor 1 records the self-assessment. Form Kor 2 creates a remediation plan for items that the assessment identifies as still requiring improvement. Together they give every finding an owner, evidence, and follow-up path.

Infographic explaining Form Kor 1 and Form Kor 2 under the NCSA Website Security Standard
Summary of the self-assessment, remediation, and follow-up sequence using Forms Kor 1 and Kor 2

Form Kor 1: self-assess and retain evidence

  • Record site information: entity, site owner, URL, service type, and implementation model such as on-premises, cloud service, or web hosting.
  • Assess requirements and recommendations, retaining evidence such as configurations, operating records, test reports, or provider documentation.
  • Use the status that matches reality: completed, in progress, or not started. Mark a requirement as still needing improvement when it is not complete.

Form Kor 2: turn remaining items into remediation

  • Bring forward only items from Form Kor 1 that still need improvement, rather than duplicating completed items as plan work.
  • Record the outstanding requirement, cause, initial remediation, and the remediation work that remains.
  • Assign an owner and due date, then follow up and review the evidence after remediation before updating the next assessment cycle.

Field names and usage guidance are based on Appendix Kor, pages 47-49, and Form Kor 2, page 69, of the hosted standard.

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofNCSA Website Security Standard B.E. 2568 (2025)

NCSA Website Security Standard B.E. 2568 (2025)

By NCSA

Open document (PDF) Source