การวางมาตรการทางกฎหมายเพื่อป้องกันการละเมิดข้อมูลและการโจมตี ทางไซเบอร์ในมหาวิทยาลัย

Main Article Content

ชาตรี จำลองกุล
ญาติพิชัย กลิ่นเจริญ
พิสิฐพล พานุรัตน์
Pramote Sittijuk

Abstract

This research aims to (1) study the problems and impacts of data breaches and cyberattacks in universities and (2) develop a protection plan and regulations based on legal measures to prevent such threats. The key informants include the university rector, vice-rector for planning and development, IT staff, and legal academics, totaling 11 people. The research tools consist of two parts: (1) an interview form to study the problems and impacts of data breaches and cyberattacks and (2) a data collection form for brainstorming in a group discussion format to develop a protection plan and regulations in accordance with the Personal Data Protection Act (PDPA) of 2019. The research tools were validated by three experts in cybersecurity and law, with a content validity index of over 0.70, indicating alignment with the research objectives.


The research findings reveal that the problems and impacts of data breaches and cyberattacks in universities include (1) the publication of personal data on the university website, (2) ransomware attacks on the research database servers, and (3) attacks on WordPress-based websites, which affect data security and the institution's image. Proposed solutions include system and software updates, the use of preventive technologies such as encryption and multi-factor authentication, training personnel on PDPA and related laws, as well as improving the legal content to make it clearer and cover all breach scenarios. Additionally, promoting preventive measures at both organizational and individual levels and allocating resources to create a sustainable and comprehensive security system are recommended.

Article Details

Section
บทความวิจัย

References

กฤชณัท เหล่ากอ, & สมบูรณ์สุข สำราญ. (2567). การตระหนักถึงภัยคุกคามทางไซเบอร์ของผู้ใช้อินเทอร์เน็ตในจังหวัดปทุมธานี. วารสาร มจร อุบล ปริทรรศน์, 9(2), 2315–2330.

เกียรติเฉลิม รักษ์งาม, & สังเวียน เทพผา. (2567). มาตรการทางกฎหมายในการคุ้มครองป้องกันการนำเข้าข้อมูลส่วนบุคคลตามคอมพิวเตอร์ตามกฎหมายว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์. วารสารสังคมศาสตร์และวัฒนธรรม, 8(3), 14–24.

ชรินทร์ทิพย์ ปั้นสุวรรณ, & สุมนทิพย์ จิตสว่าง. (2565). แนวทางการกำกับดูแลการรับมือภัยคุกคามความมั่นคงปลอดภัยไซเบอร์ขององค์กรในยุคดิจิทัล. วิทยานิพนธ์จุฬาลงกรณ์มหาวิทยาลัย, 6715. https://digital.car.chula.ac.th/chulaetd/6715

สำนักงานราชบัณฑิตยสภา. (2562). พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒. ราชกิจจานุเบกษา, 136(50 ง), 1–37.

Amo-Filva, D., Mauri, S. A., Escudero, D. F., Sanchez-Sepulveda, M. V., Hasti, H., García-Holgado, A., ... & Paes, C. (2024). Empowering student data privacy in schools through open educational resources. In Innovation and technologies for the digital transformation of education: European and Latin American perspectives (pp. 253–263). Springer Nature Singapore.

Melchior, C., & Soler, U. (2024). Security of

personal data in cyberspace in the opinion of students of the University of Udine. Cybersecurity and Law, 11(1), 227–247.

Mehra, T. (2024). The role of encryption in securing

backup data against ransomware threats. International Journal of Science and Research Archive, 13(2), 1971–1974.

Miskam, S., Sholehuddin, N., Shahwahid, F. M.,

Aziz, T. N. R. A., & Mansor, N. (2023). Data privacy practices of private higher education institutions in Malaysia: A preliminary study. Malaysian Journal of Information and Communication Technology (MyJICT), 88–99.

Ting, T. T., Cheah, K. M., Khiew, J. X., Lee, Y. C.,

Chaw, J. K., & Teoh, C. K. (2024). Validation of cyber security behaviour among adolescents at Malaysia university: Revisiting gender as a role. International Journal of Innovative Research and Scientific Studies, 7(1), 127–137.