Critical Information Infrastructure
Critical Information Infrastructure CII
Under Section 49 of the Cybersecurity Act, the NCSC has the authority to set out general cybersecurity policies and action plans as well as minimum standards for computer systems used in both government agencies and CII entities.
Definition
Critical Information Infrastructure: CII
Under Section 49 of the Cybersecurity Act, the NCSC has the authority to set out general cybersecurity policies and action plans as well as minimum standards for computer systems used in both government agencies and CII entities in the following services.
National security
National Security
Material public service
Material Public Service
Banking and finance
Banking and Finance
Information technology and telecommunications
Information Technology and Telecommunications
Transportation and logistics
Transportation and Logistics
Energy and public utilities
Energy and Public Utilities
Public health
Public Health
Other areas that may be further prescribed
Other Areas
CII Identification
Internal guidelines for managing cybersecurity issues
Under the Cybersecurity Act, these companies must put in place internal guidelines for managing cybersecurity issues as follows.
Identify significant processes
Identify processes or services that are significant to the organization’s essential mission or public service.
Analyze the situation and evaluate the effect from denial-of-service attack
Analyze possible situations and evaluate the effect that may occur if key services or systems are disrupted or unavailable.
Evaluate an acceptable out-of-service duration
Determine the acceptable duration of service interruption before it causes significant impact.
Determine significant processes and Information asset identification
Determine significant processes and identify related information assets, systems, data, and resources.
Identify Critical Information Infrastructure
Identify organizations or services that may be considered Critical Information Infrastructure under the relevant criteria.
Legal Responsibilities
Sections in the Cybersecurity Act 2019
Protection
Duties relating to cybersecurity policy, code of practice, standard framework, risk assessment, coordination, and preparedness.
The Committee shall prepare a policy and plan for Maintaining Cybersecurity in accordance with section 42 to propose to the Cabinet for approval, which shall be published in the Government Gazette. Once published, Government Agencies, Supervising or Regulating Organizations, and Organizations of Critical Information Infrastructure as determined in the plan on Maintaining Cybersecurity shall take action to be in accordance with such policy and plan.
In preparing the policy and plan under paragraph one, the Office shall hold a hearing or meeting with the Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure.
The Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure shall prepare a Code of Practice and standard framework for Maintaining Cybersecurity of each organization in accordance with the policy and plan on Maintaining Cybersecurity without delay.
The Code of Practice for Maintaining Cybersecurity under paragraph one, at least, shall consist of the following:
- (1) the plan for examining and assessing risks related to Maintaining Cybersecurity by an examiner, internal auditor, or independent external auditor, at least once per year;
- (2) the plan for coping with Cyber Threats.
For the benefit of preparing the Code of Practice for Maintaining Cybersecurity in paragraph one, the Office, upon the approval of the Committee, shall prepare a Code of Practice and standard framework for the Government Agency, Supervising or Regulating Organization, or Organization of Critical Information Infrastructure to use as a guideline to prepare or exercise as a Code of Practice of the Government Agency, Supervising or Regulating Organization, or Organization of Critical Information Infrastructure. In case such organizations do not yet have or have but incomplete or is not in accordance with the Code of Practice and standard framework, such Code of Practice and standard framework shall be enforced.
The Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure have a duty to prevent, cope with, and mitigate risks from Cyber Threats in accordance with the Code of Practice and standard framework for Maintaining Cybersecurity of each organization and shall act in order to be in compliance with the Code of Practice and standard framework for Maintaining Cybersecurity in accordance with section 13 paragraph one (4).
In case the Government Agency, Supervising or Regulating Organization, or Organization of Critical Information Infrastructure could not act or comply in accordance with paragraph one, the Office may grant assistance in the personnel or technological aspects to such organization as requested.
For the benefit of Maintaining Cybersecurity, the Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure shall notify the name of executive officials and operational officials for the coordination of Maintaining Cybersecurity to the Office.
In the event there is a change to the officials under paragraph one, the Government Agency, Supervising or Regulating Organization, and Organization of Critical Information Infrastructure shall notify the Office without delay.
For the benefit of coordination, the Organization of Critical Information Infrastructure shall notify the name and contact information of the owner, the person possessing the computer, and the person monitoring the computer system to the Office, its Supervising or Regulating Organization, and the organization under section 50, within thirty days from the date the Committee prescribes the notification in accordance with section 49 paragraph two and section 50 paragraph two, or from the date the Committee issues a final judgement in accordance with section 51, as the case may be; the owner, the person possessing the computer, and the person monitoring the computer system shall at least be a person responsible for the management of such Organization of Critical Information Infrastructure.
In case there is any change to the owner, the person possessing the computer and the person monitoring the computer system in accordance with paragraph one, notice of change to the relevant organizations under paragraph one shall be given not less than seven days in advance, unless there is reasonable cause which is inevitable, it shall be notified without delay.
The Organization of Critical Information Infrastructure shall conduct risk assessment on Maintaining Cybersecurity by having an examiner, including examination in the cybersecurity aspect by the information security auditor, internal auditor or external independent auditor, at least once per year.
The Organization of Critical Information Infrastructure shall submit a summary report of the operation result to the Office within thirty days after the operation has been finished.
Coping
Duties relating to monitoring, reporting, examining, preventing, coping with, and mitigating risks from Cyber Threats.
The Organization of Critical Information Infrastructure shall establish a mechanism or process to monitor Cyber Threats or Cybersecurity Incidents which relates to its Critical Information Infrastructure in accordance with the standards as determined by the Supervising or Regulating Organization and in accordance with Code of Practice, including the system of Cybersecurity Solution as determined by the Committee or the CRC, and shall participate in the assessment on the readiness in coping with Cyber Threats as held by the Office.
In the event of a Cyber Threat significantly occurring to the system of the Organization of Critical Information Infrastructure, the Organization of Critical Information Infrastructure shall report to the Office and the Supervising or Regulating Organization and cope with the Cyber Threats as prescribed in Part 4, the CRC may prescribe criteria and method of the reporting.
In the case there is or may be a Cyber Threat to an information system that is under the responsibility of a Government Agency or an Organization of Critical Information Infrastructure, such organization shall examine its related information, computer data, and the computer system, including the surrounding circumstances to assess whether a Cyber Threat has occurred. If the examination results show that there is or may be a Cyber Threat, the organization shall prevent, cope with, and mitigate the risks from such Cyber Threat in accordance with the Code of Practice and standard framework in Maintaining Cybersecurity and shall notify the Office and its Supervising or Regulating Organization without delay.
In case the agency or organization, or any person, finds an obstacle or issues in preventing, coping with, or mitigating the risks from a Cyber Threat, such agency, or organization or person may request assistance from the Office.
CII Infographic
ThaiCERT
Follow cybersecurity news and threat alerts
Access news, recommendations, and information related to cybersecurity to support protection, coping, and risk mitigation against Cyber Threats.
