Guidelines for Applying Website Security Standards to Enhance Cybersecurity in Local Government

Main Article Content

Sahathust Chotivong
Supaporn Sridee
Kawit Srisamrit

Abstract

This academic article aims to propose guidelines for maintaining website security in Local Government in compliance with the Website Security Standards B.E. 2568 (2025) issued by the National Cyber Security Committee (NCSC). Employing documentary research, this study synthesizes data from relevant laws, international standards, and the specific context of LAOs, which often face constraints regarding budget and personnel. The findings suggest that effective implementation of the standards requires a three-phase approach: 1) Governance Phase, focusing on designating a Risk Owner and optimizing Terms of Reference (TOR) to control outsourcing quality through mandatory Vulnerability Assessments; 2) Technical Protection Phase, emphasizing fundamental secure configurations and patch management; and 3) Monitoring Phase, encouraging the use of self-assessment tools, actionable incident response plans, and inter-municipal collaboration for resource sharing. Implementing these guidelines will essentially enhance cybersecurity resilience and foster sustainable Digital Trust among citizens.

Article Details

How to Cite
Chotivong, S., Sridee, S., & Srisamrit, K. (2026). Guidelines for Applying Website Security Standards to Enhance Cybersecurity in Local Government. Journal of Graduate Studies for Lifelong Learning (JGSLL), 3(2), 41–50. retrieved from https://so15.tci-thaijo.org/index.php/GSLL/article/view/2820
Section
Academic article

References

กรมส่งเสริมการปกครองท้องถิ่น, ศูนย์เทคโนโลยีสารสนเทศท้องถิ่น. (2558, 24 กันยายน). การพัฒนาและปรับปรุงระบบยืนยันตัวตน (SSO) กรมส่งเสริมการปกครองท้องถิ่น (ที่ มท 0806.2/ว4365) [หนังสือภายนอก]. ศูนย์เทคโนโลยีสารสนเทศท้องถิ่น กรมส่งเสริมการปกครองท้องถิ่น. https://fa2.naxapi.com/localthai.org/dnm_file/st/1758762900090_29788_side1.pdf

ประกาศคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ เรื่อง มาตรฐานการรักษาความมั่นคงปลอดภัยสำหรับเว็บไซต์ พ.ศ. 2568. (2568, 16 กันยายน). ราชกิจจานุเบกษา. เล่ม 142 ตอนพิเศษ 304 ง. หน้า 33-35.

สลิลธร ทองมีนสุข และโชติกา เซี่ยงหลิว. (2568, 22 พฤษภาคม). PDPA กับความเข้าใจผิดของรัฐ สู่การปิดบังข้อมูลสาธารณะ. สถาบันวิจัยเพื่อการพัฒนาประเทศไทย (TDRI), https://tdri.or.th/2025/05/misunderstood-pdpa-concealing-public-information-article/.

สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ. (2566). คู่มือกฎหมายไซเบอร์สำหรับประชาชน. https://www.ncsa.or.th/

สุมาลี สีสุพรรณ์ และ อภิรดี เพียรขุนทด. (2565). วัฒนธรรมปรับตัวเพื่อไปสู่การเป็นองค์กรดิจิทัล กรณีศึกษา องค์กรปกครองส่วนท้องถิ่นในเขตพื้นที่อำเภอเมือง จังหวัดขอนแก่น. วารสารวิชาการร้อยแก่นสาร, 7(8), 246–264

สุภาภรณ์ สีสุพรรณ์ และอจิรภาส์ เพียรขุนทด. (2565). การปรับตัวเพื่อเข้าสู่การเปลี่ยนแปลงเป็นองค์กรดิจิทัลขององค์กรปกครองส่วนท้องถิ่นในเขตอำเภอเมือง จังหวัดขอนแก่น. Journal of Roi Kaensarn Academi, 7(8), 246-264. https://so02.tci-thaijo.org/index.php/JRKSA/article/view/255394/173313

Castelfranchi, C., & Falcone, R. (2010). Trust Theory: A Socio-Cognitive and Computational Model. Markono. https://content.e-bookshelf.de/media/reading/L-574379-2b6320d159.pdf

National Institute of Standards and Technology. (2017). Digital Identity Guidelines: Authentication and Lifecycle Management (NIST Special Publication 800-63B). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-63b

OWASP Foundation. (2025). OWASP Top 10: 2025. https://owasp.org/Top10/2025/

Taskin, N., Özkeleş Yıldırım, A., Ercan, H. D., Wynn, M., & Metin, B. (2025). Cyber insurance adoption and digitalisation in small and medium-sized enterprises. Information, 16(1), 66. https://doi.org/10.3390/info16010066