Myanmar Cybersecurity Law (2023)
Content Controls

Myanmar Cybersecurity Law (2023) MMCL-5: Content Moderation, Removal Requests, and Lawful Access

Comply with MoTC content removal requests, takedown orders, and lawful access requests within statutory timeframes (typically 24 to 72 hours per order class). Maintain content moderation operations capable of handling Burmese language and minority language content (Shan, Karen, Kachin, Mon, Rakhine, Chin). Preserve evidence of compliance with each order and retain user data subject to requests for the periods specified by the Cybersecurity Law and Electronic Transactions Law. Document any objections to overbroad requests through formal channels noting significant international criticism from Reporters Without Borders, Amnesty International, and the UN Special Rapporteur on Myanmar.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 41 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery
  • CAT-D3-1 Preventative controls
  • FFIEC-06 Network security and segmentation

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring

ISO/IEC 27043:2015 · 1 control

  • ISO27043-27 Network security management

ISO/SAE 21434 · 1 control

  • ISO21434-27 Network security management

MTCS (Singapore) · 1 control

  • MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA

OWASP ASVS · 1 control

OWASP MASVS · 1 control

South Korea ISMS-P · 1 control

  • ISMSP-AC-04 Network Access Control
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.