You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

May 15, 2024

Thailand Issues Draft Cybersecurity Standards for Cloud Services

On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations.

The key points of the draft Cloud Cybersecurity Standards are below.

Scope

  • The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below).
  • The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above.

Definitions

  • Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider.
  • Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers.

Application

  • In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023).
  • The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards must be adopted.
  • In-scope organizations must report their implementation of the Cloud Cybersecurity Standards to the National Cyber Security Agency (NCSA) within 30 days of completing the implementation.
  • The draft Cloud Cybersecurity Standards will come into force one year from their publication in the Government Gazette.

Structure

The requirements in the Cloud Cybersecurity Standards are divided into two areas, (1) cloud security governance and (2) cloud infrastructure and operations:

Requirement Area 1: Cloud Security Governance

  • Information security policies
  • Organization of information security
  • External supplier relationships
  • Compliance

Requirement Area 2: Cloud Infrastructure Security and Operations  

  • Human resource security
  • Asset management
  • Access control
  • Cryptography
  • Physical and environmental security
  • Operational security
  • Communication security
  • System acquisition, development, and maintenance
  • External supplier relationships
  • Information security incident management

Impact Levels and Requirements

The stipulations of the Cloud Cybersecurity Standards vary depending on the data or information systems’ level of impact. The requirements for each level are summarized in the table below.

For more information on the draft Cloud Cybersecurity Standards, or on any aspect of cybersecurity and cloud-related laws in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected] and Thammapas Chanpanich at [email protected].

RELATED INSIGHTS​ 

July 26, 2023
Thailand’s Electronic Transactions Development Agency (ETDA) held a briefing session on July 20, 2023, laying out the changes and new requirements in draft sublaws under the Royal Decree on Digital Platform Services. These sublaws are expected to be announced in August 2023. The key changes and new requirements are listed below. The ETDA has drafted guidelines on the methods for identifying active users to give digital platform service operators a better understanding of the calculation methods. The definition of “users” for calculating annual monthly active users (AMAUs) has been reduced in scope to cover only users in Thailand. E-marketplace digital platform services that will suspend or terminate operations for specific users must inform the affected users and provide a period for them to challenge the suspension or termination. Digital platform service operators cannot use the requirements to identify their active users as a legal basis for processing users’ personal data, especially for profiling and tracking activities. The sublaws on announcement of terms and conditions (T&Cs) and changes to T&Cs, once issued, will take effect on January 3, 2024, while the other sublaws will take effect immediately (i.e., August 21, 2023). This shows that the ETDA has acknowledged the private sector’s feedback that the requirements on T&Cs will take more time for operators to comply with. The requirements for changing T&Cs have been adjusted. Under the current draft, the required advance notification period can be exempted if a change in the T&Cs is for the purpose of, for example, rolling out new products or services and improving the platform. Required submissions under the Royal Decree for Digital Platform Services and its sublaws will be made through the ETDA’s online portal. There will likely be no extensions granted for compliance with the Royal Decree for Digital Platform Services and its sublaws
July 14, 2023
The Bank of Thailand (BOT) has issued new notifications amending regulations for payment businesses that fall under the Payment Systems Act B.E. 2560 (2017) to promote transparency and good governance in the payment industry. Notification No. SorKorChor 2/2566 (“Notification 2”) increases the required qualifications for applicants seeking a license to provide payment services designated as being under the BOT’s supervision, and Notification No. SorKorChor 4/2566 (“Notification 4”) stipulates additional duties and exemptions for certain types of business operators. The notifications were published in the Government Gazette on July 7, 2023, and came into effect the following day. Additional Qualifications Notification 2 expands the list of prohibited characteristics for business operators applying for a license or registration to engage in a designated payment service, and their directors. For example, applicants must not have been ordered to suspend or cease their operations, and their registration or license to engage in financial business or operate a designated payment system or service must not have been revoked. The notification defines “financial business” as including financial institutions, credit card business, personal loan business, securities business, and so on. In addition, applicants’ directors and management must not have prohibited characteristics, such as being involved in the management of a financial business or designated payment system or service that was ordered to suspend or cease its operations. The applicable registration or license also must not have been revoked. Reporting Requirements During the application process, Notification 2 requires applicants to disclose information on shareholders and related parties (including spouses) who hold an aggregate 10 percent or more of the total paid-up shares. Notification 4 imposes this same reporting duty regarding shareholders and related parties but applies it to licensed operators in an ongoing manner. Existing payment service operators must make their first report of this information to
July 12, 2023
On June 30, 2023, Vietnam’s Ministry of Information and Communications (MIC) issued Circular No. 06/2003/TT-BTTTT to provide implementing guidelines for Decree 71 on editing, ratings, and warnings for video on demand (VOD) sports and entertainment content provided over radio and TV services. Circular 06 will take effect on August 15, 2023. Because Decree 71 allows VOD providers to self-edit and self-rate this type of content, it is important for them to know how the process is regulated in order to fully comply before providing VOD sports and entertainment programs to Vietnamese users. Under Circular 06, radio and TV service providers are required to display ratings and warnings on their programs, following the principles set out in the circular. These service providers must also compile dossiers in a stipulated form on the editing, ratings, and warnings of their programs for reporting to the authority and inspection. The main contents of Circular 06 are as follows. 1. Content Editing The main principles for editing VOD sports and entertainment programs include: Protection of children and other vulnerable people from inappropriate or potentially harmful content. Removal of all illegal/prohibited content, as well as content related to controversial issues or issues not recognized by Vietnamese law. Removal of content or dialogue that disparages the origins of others or makes fun of others’ physical weaknesses, and content that is contrary to Vietnamese culture, morality and fine customs and traditions; Removal of programs if it is discovered during the editing process that in the program or at the venue of the event, there are images or activities violating the prohibitions of the law, violating Vietnamese fine customs and traditions, or containing sensitive political elements. In addition to compliance with the above-mentioned principles, sports and entertainment programs related to health, education, and online gaming must additionally meet
July 11, 2023
Can computer programs resolve legal disputes? For decades, the answer from much of the legal community has been no. However, developments in artificial intelligence (AI), and in particular natural language processing and machine learning, have led to renewed discussions of this possibility. Increasingly, tools are being developed to assist parties with litigation outcome prediction and judges with litigation outcome determination. However, while some argue that the use of AI in legal disputes can reduce the length of proceedings, cut costs, and improve access to justice, others raise concerns that “black box” AI systems could reduce transparency, entrench bias, and harm the development of the law. Litigation Outcome Prediction The use of computers to predict the outcome of legal cases is not new. As early as the 1980s, researchers developed outcome prediction tools, often in the form of decision-tree algorithms. However, developments in AI have allowed the creation of more sophisticated prediction models. In 2017, a model built by Katz et al. predicted US Supreme Court decisions with an accuracy of 70.2%, while in 2019, a model built by Medvedeva et al. predicted decisions of the European Court of Human Rights with an accuracy of 75%. In various studies, AI tools have been able to predict case outcomes more accurately than expert lawyers. Companies such as Solomonic and Lex Machina, owned by LexisNexis, now provide commercial litigation prediction and analytics tools. Outcome prediction tools can be used by parties and their legal representatives to craft arguments and facilitate settlement negotiations, or by third-party litigation financers to assess the risk of providing funding. More broadly, outcome prediction may be used by the likes of insurance companies to help calculate claim payouts. However, those using such tools must take care to ensure that they do not breach any professional or legal obligations.