Skip to content

NCSA Cloud Security for Cloud Service Customers

The NCSA Cloud Security Assessment for Cloud Service Customers (CSC) is part of Thailand’s National Cloud Security Framework established by the National Cyber Security Agency (NCSA). The assessment enables organizations using cloud services to evaluate and demonstrate the security of their cloud environments based on the confidentiality, integrity, and availability (CIA) of information and systems. It is applicable to government agencies, Critical Information Infrastructure (CII) organizations, and other regulated entities utilizing cloud services from Cloud Service Providers (CSPs)

Request a proposal

Type of Audit

The assessment approach is determined by the impact level of the information or information system:

  • Low Impact: Self-assessment against applicable cloud security requirements.
  • Moderate Impact: Independent certification assessment by a registered Certification Body (CB).
  • High Impact: Comprehensive certification assessment with enhanced security control requirements due to the significant impact on operations, public services, or national interests.

The impact level is determined by evaluating the potential effects of loss of confidentiality, integrity, or availability of information and services

Audit Process

1

01

Classify Information and Systems according to impact level (Low, Moderate, or High).

2

02

Perform Risk Assessment and implement appropriate cloud security controls.

3

03

Prepare Required Documentation, including policies, asset inventories, risk assessments, and cloud service agreements.

4

04

4. Submit Application to a registered Certification Body (CB).

5

05

Undergo Assessment, including documentation review and operational verification.

6

06

Address Nonconformities identified during the assessment.

7

07

Receive Certification and Registration upon successful completion of the assessment.

Reference

  • National Cyber Security Agency (NCSA). Thailand National Cloud Security Framework (TNCSF). Bangkok, Thailand: National Cyber Security Agency.
  • National Cyber Security Committee (NCSC). Cloud Security Standard B.E. 2567 (2024). Bangkok, Thailand: National Cyber Security Committee.
  • National Cyber Security Committee (NCSC). Notification on Cyber Security Standards for Cloud Systems B.E. 2567 (2024). Bangkok, Thailand: National Cyber Security 

Secure Your Cloud with Confidence

Enhance the security of cloud services while improving risk management and customer confidence in a systematic manner.

Assessment of cloud security in accordance with the NCSA guidelines helps increase confidence and reduce information security risks.