THAISE: A Web Security Assessment Framework and Empirical Study of 126 Thai Higher Education Institutions

Main Article Content

Tuul Triyason

Abstract

The security of university websites is a vital but often overlooked issue, especially in developing countries. This work introduces THAISE (Thai Higher Education Institutions Security Evaluator), a system created to measure and score the web security levels of Thai universities. THAISE assesses seven key areas, including TLS configuration, certificate validity, and security headers such as HTTP Strict Transport Security (HSTS) and Content Security Policy (CSP). These factors are combined into a single Web Security Score (WSS). We used this framework to evaluate all 126 institutions under the Ministry of Higher Education, Science, Research and Innovation (MHESI). Our findings established a national baseline with an average score of 55.9. To ensure accuracy, we compared our results with industry tools like SecurityHeaders.com and Qualys SSL Labs, which showed consistent alignment. The results highlighted that Content Security Policy (CSP) is the most significant weakness, as 92.1% of universities failed to use it. Interestingly, exploratory analysis did not identify statistically significant associations between WSS and institutional budget per student, enrolment size, international ranking status, or Reinventing University group classification in the analyzed dataset. These findings suggest that web security posture may depend less on institutional resources or prestige than on deliberate configuration practices, though further research is needed to confirm this interpretation. These insights offer important directions for national cybersecurity policies in Thai higher education.

Article Details

How to Cite
[1]
T. Triyason, “THAISE: A Web Security Assessment Framework and Empirical Study of 126 Thai Higher Education Institutions”, ECTI-CIT Transactions, vol. 20, no. 3, pp. 539–549, Jul. 2026.
Section
Research Article

References

Verizon, “2025 Data Breach Investigations Report,” Verizon Communications Inc., 2025. [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/

S. Grajek and the 2023–2024 EDUCAUSE Top 10 Panel, “2024 EDUCAUSE Top 10: Cybersecurity as a Core Competency,” EDUCAUSE, 2023. [Online]. Available: https://er.educause.edu/articles/2023/10/2024-educause-top-10-1-cybersecurity-as-a-core-competency

Royal Thai Government, Personal Data Protection Act B.E. 2562, 2019. Accessed: Apr. 13, 2026. [Online]. Available: https://ratchakitcha.soc.go.th/documents/17082307.pdf

U. Kishnani and S. Das, “Securing the Web: Analysis of HTTP Security Headers in Popular Global Websites,” in Information Systems Security, V. T. Patil, R. Krishnan, and R. K. Shyamasundar, Eds. Cham, Switzerland: Springer Nature Switzerland, pp. 87–106, 2025.

A. Lavrenovs and F. J. R. Mel´on, “HTTP security headers analysis of top one million websites,” in Proceedings of the 2018 10th International Conference on Cyber Conflict (CyCon), pp. 345–370, May 2018.

J. Barreto, P. Rutecka, K. Cicha and P. Pinto, “The Status and Management of Web-Related Security at Higher Education Institutions in Poland,” in Proceedings of the 10th International Conference on Information Systems Security and Privacy, Rome, Italy: SCITEPRESS Science and Technology Publications, pp. 789–798, 2024.

International Telecommunication Union, “Global Cybersecurity Index 2024,” International Telecommunication Union (ITU), Jun. 2024. Accessed: Apr. 13, 2026. [Online]. Available: https://www.itu.int/epublications/publication/ global-cybersecurity-index-2024

M. Weissbacher, T. Lauinger and W. Robertson, “Why Is CSP Failing? Trends and Challenges in CSP Adoption,” in Research in Attacks, Intrusions and Defenses, Lecture Notes in Computer Science, vol. 8688, pp. 212–233, 2014.

L. Weichselbaum, M. Spagnuolo, S. Lekies and A. Janc, “CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS ’16), New York, NY, USA: Association for Computing Machinery, pp. 1376–1387, Oct. 2016.

J. B. Ulven and G. Wangen, “A Systematic Review of Cybersecurity Risks in Higher Education,” Future Internet, vol. 13, no. 2, p. 39, Feb. 2021.

N. S. Fouad, “Securing higher education against cyberthreats: from an institutional risk to a national policy challenge,” Journal of Cyber Policy, vol. 6, no. 2, pp. 137–154, May 2021.

J. Barreto, S. Neef and P. Pinto, “A Two-Wave Evaluation of the Web-Related Security Standards Implemented by Higher Education Institutions in Germany,” in IEEE Access, vol. 14, pp. 41552-41578, 2026.

J. Barreto, H. Almeida and P. Pinto, “An Overview of HTTPS and DNSSEC Services Adoption in Higher Education Institutions in Brazil,” 2023 25th International Conference on Advanced Communication Technology (ICACT), Pyeongchang, Korea, Republic of, pp. 180-185, 2023.

K. Moriarty and S. Farrell, “Deprecating TLS 1.0 and TLS 1.1,” Internet Engineering Task Force, Request for Comments RFC 8996, Mar. 2021.

S. Boeyen, S. Santesson, T. Polk, R. Housley, S. Farrell and D. Cooper, “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile,” Internet Engineering Task Force, Request for Comments RFC 5280, May 2008.

“Baseline Requirements,” CA/Browser Forum. Accessed: Apr. 13, 2026. [Online]. Available: https://cabforum.org/working-groups/server/baseline-requirements/

M. Tracy, W. Jansen, K. Scarfone and T. Winograd, “Guidelines on Securing Public Web Servers,” National Institute of Standards and Technology, NIST Special Publication (SP) 800-44 Version 2, Oct. 2007.

“OWASP Secure Headers Project — OWASP Foundation.” Accessed: Apr. 13, 2026. [Online]. Available: https: //owasp.org/www-project-secure-headers/

“OWASP Top 10:2025.” Accessed: Apr. 13, 2026. [Online]. Available: https://owasp.org/Top10/2025/

“World University Rankings 2026,” Times Higher Education (THE). Accessed: Apr. 16, 2026. [Online]. Available: https://www.timeshighereducation.com/world-university-rankings/latest/ world-ranking

S. Helme, “Analyse your HTTP response headers.” Accessed: Apr. 16, 2026. [Online]. Available: https://securityheaders.com/

“SSL Server Test (Powered by Qualys SSL Labs).” Accessed: Apr. 16, 2026. [Online]. Available: https://www.ssllabs.com/ssltest/

sucuri.net, “Sucuri Security,” Sucuri Security. Accessed: Apr. 16, 2026. [Online]. Available: https://sitecheck.sucuri.net

A. Field, Discovering Statistics Using IBM SPSS Statistics. London, U.K.: SAGE Publications Ltd, 2024.