Siam Thanat Hack Co., Ltd.

Office of Insurance Commission (OIC)

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

Using test evidence in OIC IT-risk management

OIC requirements emphasise governance, information-asset management, and IT-risk management. Testing is valuable when risk-selected and connected to follow-up.

Thai infographic explaining: Using test evidence in OIC IT-risk management
Visual summary: Using test evidence in OIC IT-risk management
  • Start with an information-asset inventory and criticality for core insurance systems, customer or agent portals, mobile applications, APIs, and infrastructure.
  • Use risk assessment to choose scope, method, and cadence. Do not make Black-box, Grey-box, or White-box the universal answer for every system.
  • Link findings to control owners, risk treatment, due dates, and retest evidence so they can demonstrate control effectiveness.
  • The notifications do not prescribe one fixed penetration-test form or frequency. Confirm any additional requirement that applies to the company and service.

OFFICE OF INSURANCE COMMISSION / IT RISK

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

Risk-based evidence ไม่ใช่ข้อบังคับ Pentest แบบตายตัว

  • ใช้กับบริษัทประกันภัยที่อยู่ภายใต้การกำกับของสำนักงาน คปภ. เพื่อให้มี Governance, Information Asset Management, IT Risk Management และ Cybersecurity controls ที่เหมาะสม
  • ประกาศหลักไม่ได้กำหนดรูปแบบหรือความถี่ของ Penetration Testing โดยตรง และไม่ได้บังคับว่าจะต้องเป็น Black-box, Grey-box หรือ White-box
  • Penetration Testing สามารถใช้เป็นหลักฐานเชิงเทคนิคเพื่อประเมินประสิทธิผลของมาตรการควบคุมและความเสี่ยงที่โจมตีได้จริง โดยเลือก Scope จาก Information Asset Inventory และผล Risk Assessment
  • ระบบที่ควรพิจารณาตามความเสี่ยง ได้แก่ Core Insurance Systems, Customer/Agent Portals, Mobile Applications, APIs, External-facing systems และ Infrastructure ที่จัดเก็บข้อมูลสำคัญ
ประโยชน์ต่อการบริหารความเสี่ยง

Penetration Testing ช่วยให้องค์กรมีหลักฐานที่ตรวจสอบได้สำหรับการบริหารความเสี่ยงด้านเทคโนโลยีสารสนเทศ และประเมินประสิทธิผลของมาตรการควบคุม โดยขอบเขตและรอบการทดสอบควรกำหนดตามความเสี่ยงของระบบและข้อกำหนดที่ใช้กับองค์กรของคุณ

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofOIC IT risk management notification (life insurance)

OIC IT risk management notification (life insurance)

By OIC

Open document (PDF) Source

First-page preview ofOIC IT risk management notification (non-life insurance)

OIC IT risk management notification (non-life insurance)

By OIC

Open document (PDF) Source