Office of Insurance Commission (OIC)
IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.
Using test evidence in OIC IT-risk management
OIC requirements emphasise governance, information-asset management, and IT-risk management. Testing is valuable when risk-selected and connected to follow-up.

- Start with an information-asset inventory and criticality for core insurance systems, customer or agent portals, mobile applications, APIs, and infrastructure.
- Use risk assessment to choose scope, method, and cadence. Do not make Black-box, Grey-box, or White-box the universal answer for every system.
- Link findings to control owners, risk treatment, due dates, and retest evidence so they can demonstrate control effectiveness.
- The notifications do not prescribe one fixed penetration-test form or frequency. Confirm any additional requirement that applies to the company and service.
OFFICE OF INSURANCE COMMISSION / IT RISK
IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.
Risk-based evidence ไม่ใช่ข้อบังคับ Pentest แบบตายตัว
- ใช้กับบริษัทประกันภัยที่อยู่ภายใต้การกำกับของสำนักงาน คปภ. เพื่อให้มี Governance, Information Asset Management, IT Risk Management และ Cybersecurity controls ที่เหมาะสม
- ประกาศหลักไม่ได้กำหนดรูปแบบหรือความถี่ของ Penetration Testing โดยตรง และไม่ได้บังคับว่าจะต้องเป็น Black-box, Grey-box หรือ White-box
- Penetration Testing สามารถใช้เป็นหลักฐานเชิงเทคนิคเพื่อประเมินประสิทธิผลของมาตรการควบคุมและความเสี่ยงที่โจมตีได้จริง โดยเลือก Scope จาก Information Asset Inventory และผล Risk Assessment
- ระบบที่ควรพิจารณาตามความเสี่ยง ได้แก่ Core Insurance Systems, Customer/Agent Portals, Mobile Applications, APIs, External-facing systems และ Infrastructure ที่จัดเก็บข้อมูลสำคัญ
Penetration Testing ช่วยให้องค์กรมีหลักฐานที่ตรวจสอบได้สำหรับการบริหารความเสี่ยงด้านเทคโนโลยีสารสนเทศ และประเมินประสิทธิผลของมาตรการควบคุม โดยขอบเขตและรอบการทดสอบควรกำหนดตามความเสี่ยงของระบบและข้อกำหนดที่ใช้กับองค์กรของคุณ
