Siam Thanat Hack Co., Ltd.

Office of Insurance Commission (OIC)

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

Executive Summary and Mandate Overview
Target Audience Life and Non-Life Insurance Companies, Corporate Brokers, and InsurTech Platforms
Mandatory Frequency At least annually according to OIC IT Security Regulations
Required Scope Policy Management Systems, Claims Processing Apps, Web Portals, Customer Databases
Non-Compliance Risk OIC regulatory audit orders, administrative warnings, or forced system remediation

Using test evidence in OIC IT-risk management

OIC requirements emphasise governance, information-asset management, and IT-risk management. Testing is valuable when risk-selected and connected to follow-up.

Thai infographic explaining: Using test evidence in OIC IT-risk management
Visual summary: Using test evidence in OIC IT-risk management
  • Start with an information-asset inventory and criticality for core insurance systems, customer or agent portals, mobile applications, APIs, and infrastructure.
  • Use risk assessment to choose scope, method, and cadence. Do not make Black-box, Grey-box, or White-box the universal answer for every system.
  • Link findings to control owners, risk treatment, due dates, and retest evidence so they can demonstrate control effectiveness.
  • The notifications do not prescribe one fixed penetration-test form or frequency. Confirm any additional requirement that applies to the company and service.

OFFICE OF INSURANCE COMMISSION / IT RISK

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

Risk-based evidence ไม่ใช่ข้อบังคับ Pentest แบบตายตัว

  • ใช้กับบริษัทประกันภัยที่อยู่ภายใต้การกำกับของสำนักงาน คปภ. เพื่อให้มี Governance, Information Asset Management, IT Risk Management และ Cybersecurity controls ที่เหมาะสม
  • ประกาศหลักไม่ได้กำหนดรูปแบบหรือความถี่ของ Penetration Testing โดยตรง และไม่ได้บังคับว่าจะต้องเป็น Black-box, Grey-box หรือ White-box
  • Penetration Testing สามารถใช้เป็นหลักฐานเชิงเทคนิคเพื่อประเมินประสิทธิผลของมาตรการควบคุมและความเสี่ยงที่โจมตีได้จริง โดยเลือก Scope จาก Information Asset Inventory และผล Risk Assessment
  • ระบบที่ควรพิจารณาตามความเสี่ยง ได้แก่ Core Insurance Systems, Customer/Agent Portals, Mobile Applications, APIs, External-facing systems และ Infrastructure ที่จัดเก็บข้อมูลสำคัญ
ประโยชน์ต่อการบริหารความเสี่ยง

Penetration Testing ช่วยให้องค์กรมีหลักฐานที่ตรวจสอบได้สำหรับการบริหารความเสี่ยงด้านเทคโนโลยีสารสนเทศ และประเมินประสิทธิผลของมาตรการควบคุม โดยขอบเขตและรอบการทดสอบควรกำหนดตามความเสี่ยงของระบบและข้อกำหนดที่ใช้กับองค์กรของคุณ

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
OIC Notification 2020 IT Risk Governance and Security Standards for Insurance Companies Online Policy Systems, Claims Management Apps, Core Insurance Databases At least annually
InsurTech Guidelines 2023 Security Verification for Electronic Insurance Platforms Web Portals, Mobile Apps, Insurance APIs, Payment Gateways Pre-launch and annual

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofOIC IT risk management notification (life insurance)

OIC IT risk management notification (life insurance)

By OIC

Open document (PDF) Source

First-page preview ofOIC IT risk management notification (non-life insurance)

OIC IT risk management notification (non-life insurance)

By OIC

Open document (PDF) Source