Siam Thanat Hack Co., Ltd.

Penetration Testing Requirements for NDID Members

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

Preparing assessment evidence for NDID

Onboarding criteria can differ by member role and package. The latest NDID criteria must be the controlling document for scope, tester eligibility, and report format.

Thai infographic explaining: Preparing assessment evidence for NDID
Visual summary: Preparing assessment evidence for NDID
  • Define the member systems connected to the NDID Platform and do not extend testing to an NDID Node unless the received criteria explicitly requires it.
  • Confirm tester eligibility and independence under the criteria NDID accepts, including certification evidence where required.
  • Test relevant web, mobile, API, network, and operating-system layers using the method named in the package, such as OSSTMM, NIST SP 800-115, or OWASP guidance.
  • Treat Critical, High, and Medium findings under the criteria, document any permitted low-risk rationale, and submit the final report with retest evidence through the onboarding process.

NATIONAL DIGITAL ID

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

สิ่งที่สมาชิกต้องเตรียมสำหรับ Security Assessment

  • ทดสอบระบบ Application, Web, Network layer และ Operating System ของสมาชิกที่เกี่ยวข้องกับระบบที่เชื่อมต่อกับ NDID Platform โดยไม่รวม NDID Node เว้นแต่เกณฑ์ที่ได้รับระบุเป็นอย่างอื่น
  • เกณฑ์ onboarding ที่ผู้ใช้ให้มาระบุให้ใช้ผู้ทดสอบจากนิติบุคคลภายนอก และแนบหลักฐานคุณสมบัติผู้ทดสอบ เช่น GPEN, eCPPT, OSCP หรือใบรับรองอื่นตามรายการที่ NDID ยอมรับสำหรับบทบาทนั้น
  • แนวทางทดสอบอ้างอิง OSSTMM หรือ NIST SP 800-115 ร่วมกับ OWASP Web/Mobile Testing Guide หรือใช้ PTES/ISSAF ตามเกณฑ์ฉบับที่ NDID ส่งให้สมาชิก
  • Critical, High และ Medium ต้องได้รับการแก้ไข ส่วน Low ต้องแก้ไขหรือบันทึกเหตุผล พร้อม Retest ช่องโหว่ที่แก้ไขแล้ว
  • จัดส่ง Final Penetration Test Report และใบรับรองผู้ทดสอบให้ NDID พิจารณา โดยเกณฑ์ที่ให้มาระบุความถี่อย่างน้อยปีละครั้งและหลัง Significant Change
ยืนยัน Criteria ล่าสุด

รายละเอียดอาจแตกต่างตามบทบาทสมาชิกและ onboarding package ข้อความนี้สรุปจากเกณฑ์ที่ผู้ใช้ให้มา ไม่ใช่เอกสารสาธารณะฉบับควบคุม สมาชิกควรใช้ Criteria ล่าสุดที่ได้รับจาก NDID เป็นหลัก

Official source documents

See NDID platform standards and membership on the official NDID website.

Go to the official source