With reference to a public hearing on the proposed revision to the IT Standard conducted between 14 June and 15 July 2024, the SEC received a wide range of valuable responses from stakeholders. The respondents’ feedback and recommendations were carefully considered for the drafting of relevant amendments.
The SEC is conducting this public hearing on the proposed amendments to the IT Regulations and Guidelines, which cover the following key points:
(1) To reduce the submission frequency of IT audit reports suitable for the risk level of small business operators and low-risk business operators to every three years or upon occurrence of a widespread adverse incident;
(2) To adjust the submission schedule for the Risk Level Assessment (RLA) report and IT audit report to be within the same period (during the first quarter of each calendar year);
(3) To adjust security measures to be in line with the risks of small business operators, such as reducing the penetration testing frequency to once every three years, covering additional access control measures to include both user accounts (or non-administrator accounts) and privileged accounts, and maintaining incident records with root cause analysis for at least two years;
(4) To adjust the applicable scope of investment advisory business operators to ensure their implementation of sufficient controls over the management of IT-related risks arising from the use of technology; and
(5) To Improve other details of the rules to better communicate the intent and enable effective risk control implementation.
The public hearing documents are available on the SEC website at: https://www.sec.or.th/TH/Pages/PB_Detail.aspx?SECID=1014 and the central legal hub at: www.law.go.th. Stakeholders and the interested public are welcome to submit comments and/or suggestions via the aforesaid websites or email: cyberteam@sec.or.th. The public hearing ends on 15 October 2024.