A/67/167 • Integrity: safeguarding the accuracy and completeness of anything of value to an organization. • Availability: ensuring that information is accessible and usable on demand by authorized entities. The benefits of ISO/IEC 27001 can be seen in: (a) The establishment of a clear and well-structured information security management methodology; (b) The reduced risk of information being lost or stolen; (c) Secure access to information by users; (d) The review of risks to information and the respective security controls on an ongoing basis; (e) The ability to run external and internal audits that can identify potential weaknesses in information security systems; (f) Guaranteed compliance with existing legislation and regulations regarding information management; (g) People have increased awareness of information security matters. In an effort to enhance legal and operational frameworks for information security, on 5 January 2009, the Congress of the Republic of Colombia enacted Act No. 1273 which amended the Criminal Code, created a new legally protected interest, namely information and data protection, and ensured the comprehensive protection of systems that use information and communication technologies, among other provisions. This important Act is divided into two chapters concerning “attacks on the confidentiality, integrity and availability of data and computer systems” and “computer attacks and other offences”. The first chapter states the following: • Wrongful access to a computer system: Any person who, without authorization or exceeding the authorization granted, accesses all or part of a computer system, whether protected by a security measure or not, or remains within the aforementioned system against the wishes of anyone who has the legitimate right to forbid it, shall be liable to a term of imprisonment of between fortyeight (48) and ninety-six (96) months and a fine of between 100 and 1,000 times the current minimum statutory monthly wage. • Illegitimate obstruction of computer systems or telecommunications networks: Anyone who, without being authorized to do so, prevents or hinders the normal functioning of or access to a computer system, computer data contained therein or a telecommunications network, shall be liable to a term of imprisonment of between forty-eight (48) and ninety-six (96) months and a fine of between 100 and 1,000 times the current minimum statutory monthly wage, provided that the action does not constitute an offence punishable by a heavier penalty. • Computer data interception: Anyone who, without a prior court order, intercepts computer data at its point of origin, destination or within a computer 12-43414 3

Select target paragraph3