A/74/120
Policy document no. 3701, “Policy guidelines for cybersecurity and cyberdefence”.
This policy has focused the country’s efforts to counter the increase in digital threats,
which were affecting it significantly, and to develop a regulatory and institutional
framework to address cybersecurity-related challenges. The following is an overview
of the progress made in the implementation of these policy guidelines, and the
revision of the guidelines in 2014 and 2015.
The overall objective of document no. 3701 was to strengthen State capacity to
address threats to national security and defence in the cyberdomain (cybersecurity
and cyberdefence), to create an environment and conditions where cyberspace is
protected. Three specific objectives were set in order to achieve this general objective:
(a) establish suitable bodies for prevention, coordination, response, monitoring and
control of cyberincidents and emergencies and the formulation of recommendation s
to address threats or risks to national cybersecurity and cyberdefence; (b) provide
specialized training on information security and broaden the scope of cyberdefence
and cybersecurity research; and (c) strengthen legislation on cybersec urity and
cyberdefence, and international cooperation; and accelerate the accession of
Colombia to the various international instruments in this area.
To develop this policy, and with a new vision based on international best
practice and, in particular, on principles and recommendations of multilat eral
organizations such as the North Atlantic Treaty Association (NATO), the Organizatio n
for Economic Cooperation and Development, the International Telecommunicat io n
Union and the OAS, and global private sector organizations which have analysed how
to address digital security in the current digital environment, the national
Government, in 2016, issued National Council for Economic and Social Policy
document no. 3854, “National digital security policy”, which is valid up to December
2019 and in which the following objective is set: to enhance the capacity of the
various stakeholders to identify, manage, address and mitigate the risks to the digital
safety in their online socioeconomic activities, in a framework o f cooperation,
collaboration and assistance. It is expected that this will contribute to the growth of
the national digital economy, which in turn will boost the country's economic and
social prosperity.
To develop the overarching objective of this public policy, the following specific
objectives were set:
(a) establish an institutional framework for digital security consistent with an
emphasis on risk management;
(b) create the conditions to enable the various stakeholders to manage the
digital security risk in their socioeconomic activities, and build confidence in the use
of the digital environment;
(c) enhance the security of individuals and the State in the digital
environment, at the national and transnational levels, with an emphasis on ris k
management;
(d) strengthen national defence and sovereignty in the digital environment,
with an emphasis on risk management; and
(e) establish permanent and strategic mechanisms to promote cooperation,
collaboration and assistance in digital security matters at the national and
international levels.
From the time the National Council for Economic and Social Policy adopted the
action and monitoring plan for the national digital security policy, in April 2016, the
competent public entities have been carrying out the activities envisaged in the Plan ,
with a view to achieving the overall goal and specific objectives of the policy.
8/39
19-10580