Siam Thanat Hack Co., Ltd.

Penetration Testing Requirements for NDID Members

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

Executive Summary and Mandate Overview
Target Audience NDID Members: Relying Parties (RP), Identity Providers (IdP), Authoritative Sources (AS)
Mandatory Frequency At least annually prior to node onboarding or annual re-certification
Required Scope NDID Proxy Nodes, HSM Key Modules, OAuth2 and OIDC Endpoints, Encryption Gateways
Non-Compliance Risk Suspension from NDID network and revocation of cross-organizational ID verification rights

Preparing assessment evidence for NDID

Onboarding criteria can differ by member role and package. The latest NDID criteria must be the controlling document for scope, tester eligibility, and report format.

Thai infographic explaining: Preparing assessment evidence for NDID
Visual summary: Preparing assessment evidence for NDID
  • Define the member systems connected to the NDID Platform and do not extend testing to an NDID Node unless the received criteria explicitly requires it.
  • Confirm tester eligibility and independence under the criteria NDID accepts, including certification evidence where required.
  • Test relevant web, mobile, API, network, and operating-system layers using the method named in the package, such as OSSTMM, NIST SP 800-115, or OWASP guidance.
  • Treat Critical, High, and Medium findings under the criteria, document any permitted low-risk rationale, and submit the final report with retest evidence through the onboarding process.

NATIONAL DIGITAL ID

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

สิ่งที่สมาชิกต้องเตรียมสำหรับ Security Assessment

  • ทดสอบระบบ Application, Web, Network layer และ Operating System ของสมาชิกที่เกี่ยวข้องกับระบบที่เชื่อมต่อกับ NDID Platform โดยไม่รวม NDID Node เว้นแต่เกณฑ์ที่ได้รับระบุเป็นอย่างอื่น
  • เกณฑ์ onboarding ที่ผู้ใช้ให้มาระบุให้ใช้ผู้ทดสอบจากนิติบุคคลภายนอก และแนบหลักฐานคุณสมบัติผู้ทดสอบ เช่น GPEN, eCPPT, OSCP หรือใบรับรองอื่นตามรายการที่ NDID ยอมรับสำหรับบทบาทนั้น
  • แนวทางทดสอบอ้างอิง OSSTMM หรือ NIST SP 800-115 ร่วมกับ OWASP Web/Mobile Testing Guide หรือใช้ PTES/ISSAF ตามเกณฑ์ฉบับที่ NDID ส่งให้สมาชิก
  • Critical, High และ Medium ต้องได้รับการแก้ไข ส่วน Low ต้องแก้ไขหรือบันทึกเหตุผล พร้อม Retest ช่องโหว่ที่แก้ไขแล้ว
  • จัดส่ง Final Penetration Test Report และใบรับรองผู้ทดสอบให้ NDID พิจารณา โดยเกณฑ์ที่ให้มาระบุความถี่อย่างน้อยปีละครั้งและหลัง Significant Change
ยืนยัน Criteria ล่าสุด

รายละเอียดอาจแตกต่างตามบทบาทสมาชิกและ onboarding package ข้อความนี้สรุปจากเกณฑ์ที่ผู้ใช้ให้มา ไม่ใช่เอกสารสาธารณะฉบับควบคุม สมาชิกควรใช้ Criteria ล่าสุดที่ได้รับจาก NDID เป็นหลัก

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
NDID Security Standard 2.0 Security Requirements for Relying Party (RP) Members NDID Proxy Node, Application Integration, Webhook Endpoints At least annually
NDID IdP and AS Rules Security Requirements for Identity Providers (IdP) and Authoritative Sources (AS) HSM Key Modules, OAuth2 and OIDC Endpoints, Encryption Gateways At least annually prior to re-certification

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

See NDID platform standards and membership on the official NDID website.

Go to the official source