A/67/167
• Integrity: safeguarding the accuracy and completeness of anything of value to
an organization.
• Availability: ensuring that information is accessible and usable on demand by
authorized entities.
The benefits of ISO/IEC 27001 can be seen in:
(a) The establishment of a clear and well-structured information security
management methodology;
(b)
The reduced risk of information being lost or stolen;
(c)
Secure access to information by users;
(d) The review of risks to information and the respective security controls on
an ongoing basis;
(e) The ability to run external and internal audits that can identify potential
weaknesses in information security systems;
(f) Guaranteed compliance with existing legislation and regulations
regarding information management;
(g)
People have increased awareness of information security matters.
In an effort to enhance legal and operational frameworks for information
security, on 5 January 2009, the Congress of the Republic of Colombia enacted Act
No. 1273 which amended the Criminal Code, created a new legally protected
interest, namely information and data protection, and ensured the comprehensive
protection of systems that use information and communication technologies, among
other provisions.
This important Act is divided into two chapters concerning “attacks on the
confidentiality, integrity and availability of data and computer systems” and
“computer attacks and other offences”.
The first chapter states the following:
• Wrongful access to a computer system: Any person who, without authorization
or exceeding the authorization granted, accesses all or part of a computer
system, whether protected by a security measure or not, or remains within the
aforementioned system against the wishes of anyone who has the legitimate
right to forbid it, shall be liable to a term of imprisonment of between fortyeight (48) and ninety-six (96) months and a fine of between 100 and 1,000
times the current minimum statutory monthly wage.
• Illegitimate obstruction of computer systems or telecommunications networks:
Anyone who, without being authorized to do so, prevents or hinders the
normal functioning of or access to a computer system, computer data
contained therein or a telecommunications network, shall be liable to a term of
imprisonment of between forty-eight (48) and ninety-six (96) months and a
fine of between 100 and 1,000 times the current minimum statutory monthly
wage, provided that the action does not constitute an offence punishable by a
heavier penalty.
• Computer data interception: Anyone who, without a prior court order,
intercepts computer data at its point of origin, destination or within a computer
12-43414
3