Skip to content

Evidence request lists

Laos Law on Prevention and Combating Cybercrime (2015)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Laos Cybercrime - Content Offences - Article 13 - Social Media - National Security

LAOS-CC-Content-Offences-Online-Social-Media-Damage-Article-13-Misinformation-National-Security
Laos Cybercrime Content Offences + Online Social Media Damage + Article 13 + Misinformation + National Security

Laos Cybercrime Law Article 13 content-related offences (broader than Budapest Convention Articles 9-10 + reflecting Lao state regulation of online space). Online Social Media Damage Article 13 prohibits use of computer systems + Internet + social media to: (1) disseminate false information undermining national stability + economy + national defence + national security; (2) post content contrary to laws + traditions + national culture; (3) post content harmful to honour + dignity + reputation of persons + organisations + state; (4) Lao PDR political and economic interests; (5) information that promotes anti-state activity. Article 14 child sexual exploitation material (parallel to Budapest Convention Article 9) including production + distribution + possession + access. Article 15 misuse of devices + tools + software designed for committing cybercrime. Article 16 computer-related forgery

Artefacts an auditor will ask for
  • Content moderation policy
  • Takedown SLA evidence
  • User-reporting mechanism
  • CSAM detection + reporting
  • Misinformation labelling
  • NetzDG-style transparency reports
Where this commonly fails
  • No takedown SLA
  • No CSAM detection
  • No user reporting
  • Inadequate transparency

Laos Cybercrime - Investigation - Procedural Powers - Articles 40-53

LAOS-CC-Investigation-Procedural-Powers-Inspection-Articles-40-53-MoPS-Search-Seizure-Production
Laos Cybercrime Investigation + Procedural Powers + Inspection + Articles 40-53

Laos Cybercrime Law Articles 40-53 investigation procedures + procedural powers. Article 40 investigation procedures aligned with Lao Code of Criminal Procedure + Ministry of Public Security (MoPS) Police Cybercrime Investigation Department lead authority + Office of Public Prosecutor supervision + judicial warrant requirements. Article 41 expedited preservation of stored computer data (parallel to Budapest Convention Article 16) + 90-day preservation order + extension. Article 42 expedited preservation + partial disclosure of traffic data. Article 43 production orders + Article 44 search and seizure of computer systems + storage media + Article 45 real-time collection of traffic data + Article 46 interception of content data subject to higher judicial threshold. Article 53 inspection powers including authorised MoPT/MoPS inspectors + on-site inspection of Service Providers + CII operato

Artefacts an auditor will ask for
  • Investigation SOPs
  • MoPS coordination records
  • Production order response procedures
  • Article 53 inspection response plan
  • Digital evidence handling chain of custody
  • MLA coordination records
Where this commonly fails
  • No production order SOP
  • No MoPS liaison
  • Inadequate digital evidence handling
  • No inspection response plan

Laos Cybercrime - LaoCERT - Article 22 - Incident Response - National Coordination

LAOS-CC-LaoCERT-Incident-Response-National-Cybersecurity-Coordination-Article-22
Laos Cybercrime LaoCERT + Incident Response + National Cybersecurity Coordination + Article 22

Laos Cybercrime Law Article 22 establishes Lao Computer Emergency Response Team (LaoCERT) as national cybersecurity coordination body under Ministry of Posts and Telecommunications (MoPT). LaoCERT responsibilities: (1) national incident response coordination + 24/7 hotline; (2) threat intelligence collection + analysis + dissemination; (3) vulnerability disclosure coordination + advisories; (4) public-sector cybersecurity capacity building + training + awareness; (5) international coordination including ASEAN-CERT + APCERT (Asia Pacific Computer Emergency Response Team) + FIRST (Forum of Incident Response and Security Teams); (6) cybersecurity exercises + drills + Cyber SEA Games participation; (7) coordination with sectoral CSIRTs + private sector. Mandatory incident notification by Service Providers + CII operators to LaoCERT for significant incidents (typically within 24-72 hours) + s

Artefacts an auditor will ask for
  • LaoCERT liaison records
  • Incident notification log (24-72 hour)
  • ASEAN-CERT + APCERT membership
  • Cyber SEA Games participation
  • Annual tabletop exercises
  • Sectoral CSIRT coordination
Where this commonly fails
  • Late or no LaoCERT notification
  • No CSIRT
  • No tabletop exercises
  • No ASEAN-CERT coordination

Laos Cybercrime - Network Security - Article 21 - Service Provider Duties

LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties
Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties

Laos Cybercrime Law Article 21 network security and information security obligations. Computer system owners + operators + administrators + service providers required to implement appropriate technical + organisational security measures proportionate to risk + nature of services + data + systems. Security measures include: access control + authentication + network segmentation + encryption of sensitive data + secure configuration + vulnerability management + patching + logging + monitoring + backup + business continuity + incident detection + response capability. Service Provider duties under Article 20 + 21 include: register with MoPT + maintain user identification records + retain traffic + content data for periods specified by regulation (typically 90 days to 1 year) + provide data to law enforcement on lawful request + cooperate with LaoCERT + Police Cybersecurity Unit on investigati

Artefacts an auditor will ask for
  • Security architecture documentation
  • Article 21 compliance attestation
  • Data retention policy (90 days to 1 year)
  • Lao representative + contact records
  • Localisation evidence where applicable
  • Encryption configuration
Where this commonly fails
  • No security baseline
  • No Lao representative
  • Missing data retention
  • Unencrypted personal/transaction data

Laos Cybercrime - Penalties - Article 56 - International Cooperation

LAOS-CC-Penalties-International-Cooperation-Article-56-Fines-Imprisonment-Aggravating-Circumstances
Laos Cybercrime Penalties + International Cooperation + Article 56 + Fines + Imprisonment

Laos Cybercrime Law Chapter VI Article 56 penalties + sanctions framework. Categories: (1) Educational measures (warnings + retraining + community service) for minor first offences; (2) Administrative sanctions (fines LAK 1M-100M + revocation of operating licence for Service Providers + content removal orders + temporary suspension); (3) Criminal penalties (fines LAK 5M-500M + imprisonment 6 months to 15 years depending on offence + aggravating circumstances + special circumstances). Aggravating circumstances: targeting critical infrastructure + government systems + significant economic harm above LAK 10 billion + organised criminal group involvement + transnational scope + repeat offending + targeting children + abuse of trust + use against state authority. Corporate criminal liability for legal entities with monetary penalties up to LAK 5 billion + revocation of business licence + diss

Artefacts an auditor will ask for
  • Penalty exposure register
  • Compliance attestation
  • Corporate criminal liability mitigation evidence
  • Asset recovery procedures
  • ASEAN MLAT engagement
  • Bilateral treaty awareness
Where this commonly fails
  • No penalty exposure analysis
  • No corporate liability mitigation
  • Inadequate MLA framework
  • No asset recovery plan

Laos Cybercrime - Prevention - Awareness - Article 20 - Education - Capacity

LAOS-CC-Prevention-Awareness-Education-Article-20-Public-Campaigns-Capacity-Building
Laos Cybercrime Prevention + Awareness + Education + Article 20 + Public Campaigns + Capacity Building

Laos Cybercrime Law Article 20 prevention through awareness campaigns + education + capacity building. State responsibility to promote public awareness of cybersecurity threats + safe internet use + responsible online behaviour. Targeted programmes: (1) school + university cybersecurity curriculum integration coordinated with Ministry of Education and Sports; (2) public service announcements via national media + Lao National Television + Lao National Radio + social media; (3) sector-specific training for government + banking + healthcare + education + telecommunications employees; (4) youth-focused programmes + Cyber Wellness for Children + online safety + age-appropriate content guidance + parental awareness; (5) workforce capacity building via Lao Institute of Information Technology + Lao National University + scholarships + international exchange programmes; (6) cybersecurity professi

Artefacts an auditor will ask for
  • Annual training records
  • Phishing simulation results
  • Public awareness campaign evidence
  • School/university curriculum integration
  • Cybersecurity Awareness Month participation
  • Certification programme records
Where this commonly fails
  • No annual training
  • No phishing simulation
  • No public awareness
  • No certification programme

Laos Cybercrime - Scope - Law 61/NA - 15 July 2015 - Chapters 1-7

LAOS-CC-Scope-Application-Law-61-NA-15-July-2015-Lao-National-Assembly-MoPT-7-Chapters-Cybercrime
Laos Cybercrime Law Scope and Application + Law 61/NA + 15 July 2015 + Lao National Assembly + MoPT

Lao Peoples Democratic Republic Law on Prevention and Combating Cybercrime Law No. 61/NA dated 15 July 2015 adopted by Lao National Assembly. Foundational Lao Cybercrime statute. 7 chapters covering Chapter I General Provisions + Chapter II Forms of Cybercrime + Chapter III Prevention + Chapter IV Combating + Chapter V Investigation Procedures + Chapter VI Penalties + Chapter VII Final Provisions. Ministry of Posts and Telecommunications (MoPT) lead regulator + Ministry of Public Security (MoPS) law enforcement role + LaoCERT (Lao Computer Emergency Response Team) under MoPT for incident response. Article 1 purpose + Article 2 scope (cyber-dependent crimes + cyber-enabled crimes) + Article 3 definitions (computer system + computer data + service provider + cybercrime + content data + traffic data). Article 4 principles + Article 5 jurisdiction (territorial + nationality + protective + un

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • MoPT/MoPS engagement records
  • Service Provider registration evidence
  • ASEAN CERT coordination records
  • Jurisdiction analysis
Where this commonly fails
  • Failure to identify Lao nexus
  • Missing MoPT registration
  • No LaoCERT coordination
  • Inadequate jurisdictional analysis

Laos Cybercrime - Substantive Offences - Articles 8-12 - Access - Interception - Interference - Forgery

LAOS-CC-Substantive-Offences-Unauthorized-Access-Interception-Interference-Data-Articles-8-12
Laos Cybercrime Substantive Offences + Unauthorized Access + Interception + Interference + Articles 8-12

Laos Cybercrime Law Articles 8-12 substantive computer-integrity offences. Article 8 unauthorized access to computer system (parallel to Budapest Convention Article 2 illegal access) - prohibition of accessing computer system or part thereof without authorisation or in excess of authorisation. Article 9 unauthorized access to computer data + protected by security measure. Article 10 unauthorized interception of non-public transmissions of computer data (parallel to Budapest Convention Article 3 illegal interception) + technical means + including electromagnetic emissions. Article 11 computer system interference (parallel to Budapest Convention Article 5) - serious hindering of functioning of computer system by inputting + transmitting + damaging + deleting + altering + suppressing computer data. Article 12 computer data forgery (parallel to Budapest Convention Article 7) - inputting + al

Artefacts an auditor will ask for
  • Access control configuration
  • Authorisation policies
  • Audit logs (1 year minimum)
  • Incident response runbook
  • Unauthorised access detection
  • Anti-fraud controls
Where this commonly fails
  • No access logging
  • Excessive default privileges
  • No anti-forgery controls
  • Inadequate detection capability
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Laos Law on Prevention and Combating Cybercrime (2015) framework page.