A/76/187
• Prepare a current assessment and a plan for the continuous improvement of its
operational, administrative, human and scientific capacities and technological
infrastructure.
• Formulate guidelines for the establishment of a digital civic participation
network through which various stakeholders can interact and cooperate in
addressing cyberthreats, in order to strengthen and expand digital security
capacities in Colombia in accordance with international law.
• Coordinate the development of guidelines for digital security improvement
plans with the aim of strengthening the capacities of the comprehensive social
security system to handle, manage and exchange information, as that system
constitutes critical cyberinfrastructure.
• Establish, under the national incident management model, guidelines indicating
the special conditions for managing risks and addressing digital security
incidents related to the handling, management and exchange of information
from the comprehensive social security system; those conditions would have to
be incorporated into the general incident management procedure established by
the Digital Security Committee.
• Coordinate the incorporation of appropriate technical, legal, organizational and
other mechanisms for gathering necessary digital evidence in the event of a
cybersecurity incident in the handling, management and exchange of
information from the health subsystem of the comprehensive social security
system.
• Design, develop and present the draft plan for the establishment of the computer
security incident response team for the comprehensive social security sector.
• Design, develop and present the draft plan for the establishment of the computer
security incident response team for the intelligence sector, to help ensure
national digital security.
• Design a proposal for a single central registry of digital security incidents at the
national level, in order to analyse incident types and periodically assess the need
to prioritize strategies and resources for incident management. This registry
should include existing reports on the subject from various stakeholders and
should be aimed at simplifying the sending of information, establishing secure
means of delivery and ensuring the confidentiality, conservation and appropriate
use of the information exchanged between parties.
Colombia is seeking to protect citizens’ constitutional rights and freedoms with
respect to obtaining and using information.
Colombia has adopted the legislative measures necessary to establish as
criminal offences: (i) intentional and unauthorized access to the whole or any part of
a computer system; (ii) the intentional and unauthorized damaging, deletion,
deterioration, alteration or suppression of computer data; (iii) the in tentional and
unauthorized interception, by technical means, of computer data; and (iv) the
production, dissemination or transmission of child pornography.
Colombia is developing clear definitions of national and international critical
infrastructure, is identifying sectors whose products or services qualify as critical
infrastructure and maintains a list of critical assets. It is sharing those definitions with
the international community as a confidence-building measure.
Colombia is also working to establish crisis resolution networks among relevant
public sector stakeholders that request support. In addition, it is planning to
8/46
21-10045