Laos Law on Prevention and Combating Cybercrime (2015)
Laos Cybercrime - Network Security - Article 21 - Service Provider Duties

Laos Law on Prevention and Combating Cybercrime (2015) LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties: Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties

Laos Cybercrime Law Article 21 network security and information security obligations. Computer system owners + operators + administrators + service providers required to implement appropriate technical + organisational security measures proportionate to risk + nature of services + data + systems. Security measures include: access control + authentication + network segmentation + encryption of sensitive data + secure configuration + vulnerability management + patching + logging + monitoring + backup + business continuity + incident detection + response capability. Service Provider duties under Article 20 + 21 include: register with MoPT + maintain user identification records + retain traffic + content data for periods specified by regulation (typically 90 days to 1 year) + provide data to law enforcement on lawful request + cooperate with LaoCERT + Police Cybersecurity Unit on investigations. ISPs + telecommunications operators + cloud providers + social media platforms operating in Laos subject to localisation requirements + Lao representative office + Lao-resident contact person for legal process. Critical Information Infrastructure (CII) sector designation pending under successor regulations + sectoral focus on government + banking + telecommunications + energy + healthcare.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.