A/76/187 The project to relocate and optimize the Government’s computer security incident response team is also under way. In response to the recommendation that States should encourage responsible reporting of ICT vulnerabilities and share associated information on av ailable remedies for such vulnerabilities in order to limit and possibly eliminate potential threats to ICTs and ICT-dependent infrastructure, Colombia, in conjunction with OAS and the Organisation for Economic Co-operation and Development, is encouraging the responsible reporting of ICT vulnerabilities, and is taking reasonable steps to ensure the integrity of the supply chain and prevent the proliferation of malicious ICT tools, techniques and harmful hidden functions. The new public policy document (National Council for Economic and Social Policy document No. 3995/2020) entitled “National Digital Trust and Security Policy” established specific measures for the development of a model for the periodic reporting of vulnerabilities in all sectors between th e points of contact of owners and operators of assets that support critical activities and relevant national government bodies. Many stakeholders will be involved, and international experiences will be taken into account in the development of this model. In response to the recommendation that States should not conduct or knowingly support activity to harm the information systems of the authorized emergency response teams (sometimes known as computer emergency response teams or cybersecurity incident response teams) of another State, and that a State should not use authorized emergency response teams to engage in malicious international activity, Colombia has taken steps in accordance with international law and the Charter of the United Nations, recognizing that it has a primary responsibility for maintaining a secure and peaceful ICT environment. The Government of Colombia also issued decision No. 500 and Presidential Directive No. 3 of March 2021 in order to establish guidelines and standards for the digital security strategy and to adopt the security and privacy model as an enabler of the digital government policy. Article 16 of Decree No. 2106 of 2019 sets forth rules to simplify, eliminate and reform unnecessary public administration formalities, proc esses and procedures, and states that authorities must have a digital security strategy for electronic document management and the preservation of information, in accordance with the guidelines issued by the Ministry of Information and Communications Techn ology. As an enabler of the digital government policy, the Ministry of Information and Communications Technology sets out guidelines for the implementation of the information security and privacy model and the management of information security risks, as well as procedures for the management of digital security incidents and guidelines and standards for the digital security strategy. Colombia has opted for measures involving law enforcement, intelligence and diplomatic tools for stopping cyberattacks and preventing the destruction of property and loss of life, exhausting all options for defending the network before carrying out an operation in cyberspace. In developing the national digital security policy, the Government of Colombia focused on three basic areas: (i) building capacities for risk management in the digital environment; (ii) establishing institutions that support governance; and (iii) evaluating activity frameworks and international best practices. In order to implement the policy, the Government’s strategy is to: 21-10045 7/46

Select target paragraph3