The National Cyber Security Committee of Thailand published two notifications on 18 January 2024 that require critical information infrastructure operators ("CIIOs") to classify their data and information systems and implement cybersecurity protection measures.
The Notification on Standards for Determination of the Security Category for Data or Information Systems requires CIIOs to self-assess their data and information systems and assign them a risk level (low, medium, or high) based on their confidentiality, integrity, and availability. The assessment should also consider the potential impact on the CIIOs, the users, the public, and national security.
The Notification on Minimum Standards for Data or Information Systems requires CIIOs to implement minimum cybersecurity measures according to the risk level of their data and information systems. The measures include implementing a cybersecurity audit plan, risk assessment, incident response plan, and various risk protection, detection, response, and recovery actions.
The notifications will take effect one year after the date of publication, or on 18 January 2025.
For more information, click here to read our Legal Update.