Siam Thanat Hack Co., Ltd.

NCSA Zero Trust Guidelines

A source-based guide to NCSA's Zero Trust Guidelines, published as version 1.0, for executives, policy owners, technical teams, system administrators, and security engineers planning a risk-based transition from perimeter security to continuous verification.

Executive Summary and Mandate Overview
Target Audience Government Agencies, State Enterprises, Financial Institutions, and Enterprise Organizations
Mandatory Frequency Continuous policy review and access posture verification (At least annually)
Required Scope Identity Providers (IdP), EDR Endpoints, Micro-segmentation, Cloud APIs, DLP Data Safeguards
Non-Compliance Risk Exposure to unchecked lateral movement during internal breaches and NCSA compliance gaps

Zero Trust principles and adoption scope

The guidance shifts the assumption from trusting an internal network to verifying every access request against identity, device posture, and session context.

Thai infographic explaining: Zero Trust principles and adoption scope
Visual guide: Zero Trust principles and adoption scope
  • All resources, including data, applications, services, and devices, should be treated as assets that need protection regardless of where they reside.
  • Access should be granted per session and adjusted to risk using relevant evidence such as identity, device posture, location, and behavior.
  • The seven Zero Trust principles emphasize strict authentication and authorization, continuous security monitoring of assets, and using collected information to improve controls.

Architecture and policy decision points

The document explains that requesters and their devices pass through policy decision points before they can reach a resource, separating decision, session-management, and enforcement responsibilities.

Thai infographic explaining: Architecture and policy decision points
Visual guide: Architecture and policy decision points
  • The Policy Engine evaluates policy and supporting information to decide whether access is permitted.
  • The Policy Administrator establishes or terminates communication paths and manages session credentials according to that decision.
  • The Policy Enforcement Point opens, monitors, or terminates connections and should draw on identity, device, security telemetry, and other relevant information sources.

A five-step risk-based transition

The guidance starts with a defined protect surface and expands incrementally instead of changing every system at once.

Thai infographic explaining: A five-step risk-based transition
Visual guide: A five-step risk-based transition
  • Define the Protect Surface and a risk-based strategy, then map Transaction Flows to understand the relationship among data, applications, assets, and services.
  • Design the Zero Trust architecture for that surface, considering identity, segmentation, microsegmentation, cloud, or hybrid approaches according to context and risk.
  • Define policy through the 5W1H framework: Who, What, When, Where, Why, and How. Then monitor, log, alert, and continually review protect surfaces and policy.

Gap analysis, maturity, and continuous operations

Gap analysis needs to cover strategy, governance, data, assets, operations, and control effectiveness rather than comparing tool inventories alone.

Thai infographic explaining: Gap analysis, maturity, and continuous operations
Visual guide: Gap analysis, maturity, and continuous operations
  • Use the Risk Management Framework to structure the gap analysis across preparation, categorization, control selection, assessment, authorization, and monitoring.
  • Use the Zero Trust Maturity Model to assess the five pillars of identity, devices, networks, applications and workloads, and data, with connected risk indicators.
  • Establish roles, accountability, communication, training, and feedback loops so policy can adapt to incidents and changing environments.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
Pillars 1 and 2 (NCSA ZTA) Explicit Identity Verification and Device Posture Assessment IAM, Multi-Factor Authentication, EDR, Device Posture Audits Real-time verification per access request
Pillars 3 to 5 (NCSA ZTA) Network Micro-Segmentation, Application Protection, and Data Encryption Micro-segmentation, API Gateways, DLP, Data Encryption Annual configuration audit

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofNCSA Zero Trust Guidelines

NCSA Zero Trust Guidelines

By NCSA

Open document (PDF) Source