A/76/187
The project to relocate and optimize the Government’s computer security incident
response team is also under way.
In response to the recommendation that States should encourage responsible
reporting of ICT vulnerabilities and share associated information on av ailable
remedies for such vulnerabilities in order to limit and possibly eliminate potential
threats to ICTs and ICT-dependent infrastructure, Colombia, in conjunction with OAS
and the Organisation for Economic Co-operation and Development, is encouraging
the responsible reporting of ICT vulnerabilities, and is taking reasonable steps to
ensure the integrity of the supply chain and prevent the proliferation of malicious ICT
tools, techniques and harmful hidden functions.
The new public policy document (National Council for Economic and Social
Policy document No. 3995/2020) entitled “National Digital Trust and Security
Policy” established specific measures for the development of a model for the periodic
reporting of vulnerabilities in all sectors between th e points of contact of owners and
operators of assets that support critical activities and relevant national government
bodies. Many stakeholders will be involved, and international experiences will be
taken into account in the development of this model.
In response to the recommendation that States should not conduct or knowingly
support activity to harm the information systems of the authorized emergency
response teams (sometimes known as computer emergency response teams or
cybersecurity incident response teams) of another State, and that a State should not
use authorized emergency response teams to engage in malicious international
activity, Colombia has taken steps in accordance with international law and the
Charter of the United Nations, recognizing that it has a primary responsibility for
maintaining a secure and peaceful ICT environment.
The Government of Colombia also issued decision No. 500 and Presidential
Directive No. 3 of March 2021 in order to establish guidelines and standards for the
digital security strategy and to adopt the security and privacy model as an enabler of
the digital government policy.
Article 16 of Decree No. 2106 of 2019 sets forth rules to simplify, eliminate and
reform unnecessary public administration formalities, proc esses and procedures, and
states that authorities must have a digital security strategy for electronic document
management and the preservation of information, in accordance with the guidelines
issued by the Ministry of Information and Communications Techn ology.
As an enabler of the digital government policy, the Ministry of Information and
Communications Technology sets out guidelines for the implementation of the
information security and privacy model and the management of information security
risks, as well as procedures for the management of digital security incidents and
guidelines and standards for the digital security strategy.
Colombia has opted for measures involving law enforcement, intelligence and
diplomatic tools for stopping cyberattacks and preventing the destruction of property
and loss of life, exhausting all options for defending the network before carrying out
an operation in cyberspace.
In developing the national digital security policy, the Government of Colombia
focused on three basic areas: (i) building capacities for risk management in the digital
environment; (ii) establishing institutions that support governance; and
(iii) evaluating activity frameworks and international best practices. In order to
implement the policy, the Government’s strategy is to:
21-10045
7/46