A/67/167 Leaving national information security capacities to one side, it is important to mention a series of measures that, in Colombia’s view, should be taken at the international level to strengthen information security. • Strengthen communication channels between United Nations Member States in order to coordinate efforts in the transnational fight against crimes that affect information and data. • Formulate international and regional instruments focused on the legal definition of punishable acts that threaten cybersecurity and cyberdefence in each State. • Formulate and codify protocols to address computer incidents, leading to global policies on information security. • Strengthen preventative and legislative activities in relation to “hacktivist” groups, particularly at universities and colleges, in order to reduce young people’s involvement in these organizations that threaten the normal development of States’ digital infrastructure. • Standardize legislation with emphasis on prevention, assistance and follow-up of activities relating to information security. • Consolidate and implement technology, with a focus on the adoption of best practices in information security management. It is important to note here that plans for investment in cutting-edge technology must be in place, together with Government support for technology development projects. • Provide opportunities for the exchange of information and knowledge regarding the universal standards on the matter. Legislation of the Republic of Colombia on information security 12-43414 Act/Resolution Subject Act No. 527 (1999) (e-Commerce) Defines and regulates access to and use of data messages, ecommerce and digital signatures, establishes certification authorities and contains other provisions. Act No. 599 (2000) Promulgates the Criminal Code, which maintains the framework of the criminal offence of “unlawful violation of communications”, establishes the legal right of copyright and includes some acts indirectly related to computer crime, such as the offer, sale or purchase of devices capable of intercepting private communications between persons. It defines wrongful access to a computer system (article 195), whereby any person who wrongfully gains entry to a computer system protected by security measures or remains within the aforementioned system against the wishes of anyone who has the legitimate right to forbid it, shall be liable to a fine. Act No. 962 (2005) Enacts provisions to streamline the administrative procedures of State agencies and entities and of individuals who perform public functions or deliver public services. It provides for an incentive for members of the public to use integrated technology in order to reduce the waiting times and costs of administrative formalities. 7

Select target paragraph3