Cyber Security

Cyber Security

Centralized information and communications technology infrastructure management of the Provincial Electricity Authority (IT Infrastructure Design and Consolidation for PEA: ITiDC), virtual desktop infrastructure system development and disaster recovery center Center: DRC)

To make business operations flexible and agile (Business Agility) able to support future workloads. Systems can be quickly created to provide new services to businesses. Efficient and safe, as well as helping to reduce investment costs, including maintenance costs in hardware and software, the Provincial Electricity Authority has developed Cloud Infrastructure. In the form of service Infrastructure As A Service (Iaas) and to be able to develop applications on Cloud Infrastructure Safely and more efficiently, Provincial Electricity Authority Therefore, guidelines for developing and delivering secure software (DevSecOps) have been developed. There has also been a study and preparation of guidelines for providing services in the form of Platform As A Service (PaaS) to increase capabilities. Providing Cloud Infrastructure services of PEA

image1

In addition, in order to enhance the work efficiency of employees, they can use the Provincial Electricity Authority's applications. and specialized software from anywhere, at any time, and from a variety of device platforms such as computers, smart phones, and tablets, and increasing efficiency in maintaining security in accessing the Provincial Electricity Authority software. Therefore, a virtual application access system or Virtual Desktop Infrastructure (VDI) has been developed, starting to be rolled out at the end of 2022 for 4,000 Concurrent Users, including to provide management of the Provincial Electricity Authority's large amounts of data. Including providing information services (IT) including Cloud Infrastructure. It is stable and reduces the risk that the information system will be unusable if the data center is damaged. The Provincial Electricity Authority has therefore established a Disaster Recovery Site (DR Site) to be used in the event that the Main Site is unable to function. Currently, the backup data center has been activated It is in the process of expanding the installation of Cloud Infrastructure's data backup system.

Cyber Security Enhancement

From continuous digital development This causes the Provincial Electricity Authority to face risks from cyber security threats like never before. So that the Provincial Electricity Authority can effectively deal with such threats. To increase the security of the Provincial Electricity Authority's digital system, the Provincial Electricity Authority's Security Threat Surveillance Center (PEA SOC) has been established that operates 24 hours a day, 7 days, with the scope of surveillance covering both aspects. Information Technology and Operational Technology Support the implementation of strategies and standards Penetration testing has also been carried out to strengthen the cyber security of the Provincial Electricity Authority. In addition, the Provincial Electricity Authority has developed cyber security systems according to standards. ISO/IEC27001:2013 By expanding the scope to regional areas covering the entire country (all 12 districts) and main work systems Including creating awareness of information security (Security Awareness Program) for employees to have knowledge and understanding to protect the Provincial Electricity Authority. from cyber threats

Development of good governance and management standards in information technology

Development of information technology service standards and enterprise architecture governance and development. The Provincial Electricity Authority has continued to implement information technology governance (IT Governance) according to the COBIT framework. Because in 2022, it has passed an assessment to maintain its certification status. (Surveillance Audit 1st) in the scope of “Information Technology Governance System For the supervision of digital technology management of Provincial Electricity Authority” which confirms the operations of the Provincial Electricity Authority that meet international standards. ISO/IEC38500:2015 Including the development of information and communication services. that has received standard certification ISO20000-1:2018, such as receiving notifications of problems

Through the PEA Service Desk service center, electronic document service (DDOC), etc., in addition to providing analysis and development planning of the organization. especially the development of digital technology It is efficient. The Provincial Electricity Authority has adopted Enterprise Architecture (EA) as a tool for analyzing organizational changes, allowing visibility into the organization's operations. From business processes to Application DATA and Technology in a systematic and sustainable manner. It is presented as a picture of the current (As-is) and future (To-be) architecture, making it possible to analyze the reduction of work steps. Including developing/improving digital technology systems to support efficient operations.

iso27001 cobit nist iec
iso38500 iso20000-1