(Unofficial Translation)
No. 136 Chapter 69 Kor
Government Gazette
27 May 2019
other compensation in accordance with the rules determined by the Cabinet.
Part 2
Cybersecurity Regulating Committee
Section 12
In undertaking the duty and power of the Committee in accordance with
section 9, there shall be a Cybersecurity Regulating Committee abbreviated as "CRC,"
comprising:
(1) the Minister of the Digital Economy and Society as a chairperson;
(2) directors by position, comprising the Permanent Secretary of the Ministry of
Foreign Affairs, Permanent Secretary of the Ministry of Transport, Permanent
Secretary of the Ministry of Digital Economy and Society, Permanent Secretary of
the Ministry of Energy, Permanent Secretary of the Ministry of Interior, Permanent
Secretary of the Ministry of Public Health, Commissioner-General of the National
Police Bureau, Supreme Commander, Secretary-General of the National Security
Council, Director of the National Intelligence Agency, Governor of the Bank of
Thailand, Secretary-General of the Securities and Exchange Commission, and the
Secretary-General of the National Broadcasting and Telecommunications
Commission;
(3) honorary directors not exceeding four persons, who are appointed by the
Committee among the persons who have knowledge, expertise, and experience
which is remarkable and beneficial to Maintaining Cybersecurity.
The Secretary-General shall be a director and secretary, and the Secretary-General shall
appoint assistant secretaries from the officials of the Office not exceeding two persons.
The criteria and selection methods for the appropriate persons to appoint as honorary
directors shall comply with the rules as determined by the Committee.
Section 13
The CRC shall have the following duties and powers:
(1) monitor the undertaking in accordance with the policy and plan according to
section 9 (1) and section 42;
(2) monitor and undertake in order to cope with Cyber Threats at critical level in
accordance with section 61, section 62, section 63, section 64, section 65, and
section 66;
(3) regulate the undertaking of the national coordinating agencies for the security of
computer systems and the incident response and computer forensic science;
(4) determine the Code of Practice and standard framework in Maintaining
Cybersecurity which are the minimum requirement in the act of Maintaining
Cybersecurity for the Government Agency and the Organization of Critical
Information Infrastructure, including determining the measure for risk assessment
of, responses to, and coping with the Cyber Threats when there are any Cyber
Threats or incidents that affect or may significantly or severely affect or damage
the information system of the country for the quick, efficient, and united act of
Maintaining Cybersecurity;
(5) determine the duties of Organization of Critical Information Infrastructure and
duties of the Supervising or Regulating Organization which should at least
determine the duties for the Supervising or Regulating Organization to determine
the appropriate standards for each Organization of Critical Information
Infrastructure and Government Agency in coping with Cyber Threats;
(6) prescribe the level of Cyber Threats including the details of the measures to
5