A/69/112
Four years later, the Congress of the Republic of Colombia enacted Act
No. 1273 of 2009, which amended the Criminal Code by creating a new legally
protected interest, namely “information and data protection”. The amendment
enabled the establishment of a national legal framework for the relevant authorities
to prosecute and try information technology-related offences.
Within this framework, Colombia criminalized, inter alia, illegal access; illegal
interception; attacks on data integrity; attacks on system integrity; device abuse;
computer counterfeiting; computer fraud; child pornography; and crimes against
intellectual property and related rights.
In 2011, through the CONPES
3701
document,
Colombia launched its national
cyberdefence and cybersecurity policy based on three fundamental pillars:
(a)
Adopting an appropriate inter-institutional framework for prevention,
coordination and monitoring and the formulation of recommendations to address
any threats and risks that arise;
and,
(b)
Developing specialized training programmes on information security;
(c)
Strengthening legislation on those matters and international cooperation,
within
that
framework,
accelerating
Colombia’s
accession
to
the
various
international instruments, namely, the Budapest Convention.
In
order
to
implement
the
aforementioned _ strategic
comprehensively, Colombia designed and established four authorities:
principles
1.
The Intersectoral Commission, responsible for formulating the strategic
vision of information management and setting policy guidelines for the management
of public information technology infrastructure, cybersecurity and cyberdefence;
2.
The Colombian Computer Emergency Response Team (colCERT),
national coordinating agency on matters of cybersecurity and cyberdefence;
the
3.
The Armed Forces Joint Cyber Command (CCOC), which is tasked with
preventing and countering any cyber threat or attack that affects national values and
interests;
4,
The
Cyber
Police
Centre,
which
is responsible
for Colombia’s
cybersecurity, offering information, support and protection from cybercrime.
Similarly, Colombia has a legal framework for the protection of personal data,
established by means of Act No. 1581 of 2012 and Decree No. 1377 of 2013, which
partially regulates the Act. Furthermore, a Department for Personal Data Protection
was established in the Superintendence for Industry and Trade.
The Ministry of Information Technology and Communications also set up and
implemented a Government Online strategy incorporating the requirements for
entities to adopt information security management systems. Similarly, since 2008,
the Ministry has trained around 6,300 civil servants on information technology
management-related processes.
It should also be noted that, in the area of capacities, progress is being made
with
the
identification
of
critical
infrastructure
(the
infrastructure
which,
if
damaged, could potentially lead to a loss of human life, economic damage or
reduced governability of the country) with a view to safeguarding cybersecurity at
those locations.
14-56479
5/18