An Online Gap Analysis on Cyber Security Principles for Thailand Organizations Based on ISO/IEC 27001:2013 Standard

Narong Chaiwut, Worasak Rueangsirarak · 2022

The cybersecurity act enforcement in Thailand has been promulgated since 2019. Especially the Personal Data Protection Act (PDPA) forces all organizations to comply. However, there is no security standard relying on PDPA. The most well-known security standard is ISO/IEC 27001:2013, which can use as a security guideline for various organization sizes. Unfortunately, ISO/IEC 27001:2013 requires a high budget to analyze and adapt it to the organization. Therefore, we proposed an online ISO/IEC 27001:2013 gap analysis to provide the preliminary guidance for the organizations to sketch up their cyber security policy. This proposed web application enables users to evaluate their organization based on the ISO/IEC 27001:2013, Annex A. The online gap analysis covers a1114 security standard domains, generating the average score and security safety level for the organizations. We evaluated this online system with twelve organizations in various sectors both from industry and government. The result reveals that the industrial sectors scored higher than the governmental sectors in overall security level. Therefore, the proposed system is practical to be implemented as one part of the Information Security Management System (ISMS).

Read the paper · More papers on PaperTik