Risk and compliance
Objectives
Section titled “Objectives”- Name the basic security practices for an IoT device and a reference standard
- Decide whether a product collects personal or sensitive data, and know who regulates it
- Know which kind of product must be checked with which agency for standards
- Name supply-chain risks and how to reduce them
Please note This lesson gives an overview to help you ask the right questions; it is not legal advice. Before selling a real product, check directly with the relevant agencies and consult a lawyer or an accredited test laboratory. Rules and notices change, so always look at the latest version from the official source.
Before you start
Section titled “Before you start”- From the previous lesson, which cost bucket does certification testing sit in?
- Does your device send or receive radio signals (WiFi, Bluetooth, LoRa, cellular)?
See it work first
Section titled “See it work first”Read these two short stories, then ask yourself which one is more expensive.
Story one A company sells home cameras that all share the same default password, with no way to update the firmware. One day, someone finds a way to access every camera from the internet. Story two A company finishes designing a device and orders the first production batch, only to discover that a key part has a single vendor, and that vendor has just announced it is discontinuing it.
Both stories are hypothetical but genuinely possible, and both can be prevented at the design stage at far lower cost than fixing them later.
Concepts
Section titled “Concepts”1. Cyber security of the device itself
Section titled “1. Cyber security of the device itself”Several basic principles agree across international IoT standards, for example
- No identical default password on every unit
- Software can be updated safely, for the whole life of the product, with customers told how long it will be supported
- Keys and secrets are stored safely, for example in a secure element, rather than in general-purpose memory
- Communication is encrypted, for example with TLS, with both the device and the server authenticated
- There is a channel to report vulnerabilities, with someone responsible for responding
References you can use as a framework
- ETSI EN 303 645 V3.1.3 (2024-09) Cyber Security for Consumer Internet of Things: Baseline Requirements https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf
- NIST IR 8259 Foundational Cybersecurity Activities for IoT Device Manufacturers https://csrc.nist.gov/pubs/ir/8259/final
- OWASP Internet of Things Project https://owasp.org/www-project-internet-of-things/
These standards are European and American, not Thai law, but they make a good checklist, and they are necessary if you plan to export. If you would like to know how engineers handle these things on a real board, the course Secure IoT with OPTIGA™ Trust M covers it in detail.
2. Personal data under the PDPA
Section titled “2. Personal data under the PDPA”The Personal Data Protection Act B.E. 2562 (2019) was published in the Royal Gazette, Volume 136, Part 69 A, on 27 May 2019 (the text from the Royal Gazette). The regulator is the Office of the Personal Data Protection Committee (PDPC), https://www.pdpc.or.th/
Questions you must be able to answer from the design stage
- Can the data the device collects identify a person? A face image, a recorded voice, one person’s location, or a value tied to a username are usually personal data.
- Is it sensitive data? Section 26 names certain categories that need stricter care, such as health data and biometric data. Health devices need particular care here.
- Are you collecting only what you need? If the problem only needs to know “is someone in the room”, using a sensor that captures no image (such as radar), or processing on the device and sending only the result, reduces how much personal data you need to look after (this is one reason edge, from an earlier lesson, matters).
- Who is the data controller, and who is the data processor? If you use another provider’s cloud, you need a clear agreement.
- How long is data kept, how is it deleted, and how are data subjects notified?
3. Standards and certification before you sell
Section titled “3. Standards and certification before you sell”| If your product… | Agency to check with | Official website |
|---|---|---|
| Sends or receives radio signals (WiFi, Bluetooth, LoRa, cellular) | The Office of the National Broadcasting and Telecommunications Commission (NBTC), which checks what certification or filing a device needs before import or sale | https://www.nbtc.go.th/ |
| Is an electrical or electronic appliance that may fall under a Thai Industrial Standard (TIS/มอก.), some of which are mandatory | The Thai Industrial Standards Institute (TISI), Ministry of Industry | https://www.tisi.go.th/ |
| Claims a medical benefit, such as diagnosing or monitoring a disease, including software and AI that may qualify as a medical device | The Medical Device Control Division, Thai Food and Drug Administration (Thai FDA) | https://medical.fda.moph.go.th/samd-head |
Practical advice: ask a test laboratory from the prototype stage what your product needs to be tested for, how long it takes, and whether choosing an already-certified radio module can narrow the scope of testing. If you plan to export, each country has its own requirements and must be checked separately.
4. Supply chain
Section titled “4. Supply chain”- A part has only one vendor Line up a second source at the design stage.
- A part is nearing end of life Ask about the lifecycle status of key parts, and choose versions the manufacturer still supports for the long term.
- Long lead times Plan stock for critical parts.
- Counterfeit parts Buy from authorised distributors.
- Provisioning keys and firmware at the factory If a contract manufacturer is the one loading encryption keys onto the device, agree who holds the keys and how leaks are prevented.
Practice
Section titled “Practice”Build a risk register for your project with at least four rows, one per risk group.
| Group | Risk | Likelihood (low/medium/high) | Impact (low/medium/high) | Mitigation | Owner |
|---|---|---|---|---|---|
| Cyber security | |||||
| Personal data | |||||
| Standards and certification | |||||
| Supply chain |
Check your understanding
Section titled “Check your understanding”Answer the questions in quiz.yaml. A score of 80% or more passes.
Going further
Section titled “Going further”The risk register from this lesson will be carried into the decision canvas in the final lesson. The next lesson covers build, buy or partner, which changes who carries each of these risks.
Reflect
Section titled “Reflect”Which risk in your register, if it happened, could never be fixed afterward? That one should be funded first.
Review questions
Answer on your own first, then open the answer.
-
Which are basic IoT device security practices? (choose all that apply) (Objective 1)
- ใช้รหัสผ่านเริ่มต้นเดียวกันทุกเครื่องเพื่อให้ซัพพอร์ตง่าย
- อัปเดตซอฟต์แวร์ได้อย่างปลอดภัยตลอดอายุผลิตภัณฑ์
- เก็บกุญแจเข้ารหัสในที่ปลอดภัย เช่น ชิปความปลอดภัย
- สื่อสารแบบเข้ารหัส
- มีช่องทางรับแจ้งช่องโหว่
Show answer
Answer: B. อัปเดตซอฟต์แวร์ได้อย่างปลอดภัยตลอดอายุผลิตภัณฑ์ · C. เก็บกุญแจเข้ารหัสในที่ปลอดภัย เช่น ชิปความปลอดภัย · D. สื่อสารแบบเข้ารหัส · E. มีช่องทางรับแจ้งช่องโหว่
รหัสผ่านเริ่มต้นที่เหมือนกันทุกเครื่องเป็นสิ่งที่มาตรฐานอย่าง ETSI EN 303 645 ห้ามไว้ชัดเจน ข้ออื่นเป็นหลักพื้นฐานทั้งหมด
-
Which document is the consumer IoT cyber-security baseline standard cited in this lesson? (Objective 1)
- ETSI EN 303 645
- พ.ร.บ.เครื่องมือแพทย์
- มาตรฐานการบัญชี
- คู่มือการใช้ WiFi ในบ้าน
Show answer
Answer: A. ETSI EN 303 645
ETSI EN 303 645 คือ Cyber Security for Consumer Internet of Things - Baseline Requirements ส่วน NIST IR 8259 และ OWASP IoT ก็ใช้อ้างอิงได้
-
A blood-pressure device sends readings with the user's name to the cloud. What is this data under the PDPA? (Objective 2)
- ไม่ใช่ข้อมูลส่วนบุคคล เพราะเป็นแค่ตัวเลข
- ข้อมูลส่วนบุคคลที่เป็นข้อมูลอ่อนไหว เพราะเป็นข้อมูลสุขภาพที่ระบุตัวบุคคลได้
- ข้อมูลสาธารณะ
- ข้อมูลของบริษัทคลาวด์
Show answer
Answer: B. ข้อมูลส่วนบุคคลที่เป็นข้อมูลอ่อนไหว เพราะเป็นข้อมูลสุขภาพที่ระบุตัวบุคคลได้
ค่าที่ผูกกับชื่อระบุตัวบุคคลได้ และข้อมูลสุขภาพอยู่ในกลุ่มข้อมูลที่มาตรา 26 กำหนดให้ดูแลเข้มกว่า
-
Which agency regulates personal data protection in Thailand? (Objective 2)
- สำนักงาน กสทช.
- สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.)
- สำนักงานมาตรฐานผลิตภัณฑ์อุตสาหกรรม (สมอ.)
- กรมสรรพากร
Show answer
Answer: B. สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.)
สคส. (PDPC) เป็นหน่วยงานที่ตั้งขึ้นตาม พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562
-
A WiFi fridge monitor: which agency do you check with first about radio equipment certification? (Objective 3)
- สำนักงาน กสทช.
- อย.
- สคส.
- ไม่ต้องตรวจกับใคร
Show answer
Answer: A. สำนักงาน กสทช.
อุปกรณ์ที่ส่งหรือรับคลื่นวิทยุต้องตรวจกับสำนักงาน กสทช. ว่าต้องผ่านการรับรองหรือแจ้งแบบใดก่อนนำเข้าหรือขาย
-
An AI app claiming to "detect irregular heartbeat" should check with which agency about medical device status? (Objective 3)
- สำนักงานมาตรฐานผลิตภัณฑ์อุตสาหกรรม (สมอ.)
- กองควบคุมเครื่องมือแพทย์ สำนักงานคณะกรรมการอาหารและยา (อย.)
- สำนักงาน กสทช.
- ไม่ต้องตรวจ เพราะเป็นซอฟต์แวร์
Show answer
Answer: B. กองควบคุมเครื่องมือแพทย์ สำนักงานคณะกรรมการอาหารและยา (อย.)
ซอฟต์แวร์และ AI ที่อ้างสรรพคุณทางการแพทย์อาจเข้าข่ายเครื่องมือแพทย์ อย. มีหลักเกณฑ์คัดกรองเรื่องนี้โดยเฉพาะ
-
Which reduce supply-chain risk? (choose all that apply) (Objective 4)
- หาชิ้นส่วนทดแทนจากผู้ขายรายที่สองตั้งแต่ขั้นออกแบบ
- ซื้อชิ้นส่วนจากผู้แทนจำหน่ายที่ได้รับแต่งตั้ง
- เลือกชิ้นส่วนราคาถูกที่สุดโดยไม่ดูสถานะการผลิต
- ตกลงให้ชัดว่าใครถือกุญแจเข้ารหัสที่ใส่ในโรงงาน
Show answer
Answer: A. หาชิ้นส่วนทดแทนจากผู้ขายรายที่สองตั้งแต่ขั้นออกแบบ · B. ซื้อชิ้นส่วนจากผู้แทนจำหน่ายที่ได้รับแต่งตั้ง · D. ตกลงให้ชัดว่าใครถือกุญแจเข้ารหัสที่ใส่ในโรงงาน
ชิ้นส่วนที่ถูกที่สุดแต่ใกล้หยุดผลิตหรือมาจากแหล่งไม่น่าเชื่อถือ มักแพงที่สุดเมื่อคิดรวมความเสียหายภายหลัง
Cite this lesson
If you teach from this lesson or reuse it in slides or documents, credit it with the text below. If you changed it, add (adapted) after the title.
"Risk and compliance" from TESA Open Knowledge by the Thai Embedded Systems Association (TESA), https://github.com/tesaiot/tesa-qualification-program, licensed under CC BY-NC 4.0
Thai attribution: "ความเสี่ยงและการปฏิบัติตามกฎ" จาก TESA Open Knowledge โดยสมาคมสมองกลฝังตัวไทย (Thai Embedded Systems Association: TESA) https://github.com/tesaiot/tesa-qualification-program สัญญาอนุญาต CC BY-NC 4.0
TESA Open Knowledge · © 2026 สมาคมสมองกลฝังตัวไทย (TESA) · CC BY-NC 4.0
Content is licensed CC BY-NC 4.0. Reuse it non-commercially and credit the Thai Embedded Systems Association (TESA) every time. · How to cite TESA