Under Section 49 of the Cybersecurity Act B.E. 2562 (2019),
the National Cyber Security Committee (NCSC) has the authority
to designate organizations in critical sectors as
Critical Information Infrastructure (CII).
The committee shall establish national cybersecurity policies and plans which must be followed by government agencies, regulators, and CII organizations.
Organizations must develop cybersecurity standards and practices aligned with national cybersecurity policies.
CII organizations must prevent, respond to, and mitigate cybersecurity risks in accordance with established standards.
Organizations must provide contact information for cybersecurity coordination personnel.
CII organizations must conduct cybersecurity risk assessments and audits at least annually.
CII organizations must establish cyber threat monitoring systems and participate in cybersecurity readiness exercises.
Significant cyber incidents must be reported to the relevant authority and regulator.
Organizations must investigate cyber threats and implement mitigation measures.