Alineamiento con Marcos de ReferenciaAlignment with Reference Frameworks
NIST CSF, CIS Controls, ISO 27001, ENS, PCI-DSS.NIST CSF, CIS Controls, ISO 27001, ENS and PCI-DSS.
¿Qué es este servicio?What is this service?
Es el trabajo de comparar los controles existentes contra uno o varios marcos de referencia —NIST CSF, CIS Controls, ISO 27001, PCI-DSS— y producir el análisis de brechas y el plan para cerrarlas.
The work of comparing the controls already in place against one or more reference frameworks — NIST CSF, CIS Controls, ISO 27001, PCI-DSS — and producing the gap analysis and the plan to close it.
¿Para qué se usa?What is it used for?
Sirve sobre todo cuando a la organización le exigen varios marcos a la vez. La mayoría de los controles se repiten entre normas con distinto nombre, así que mapearlos una sola vez evita hacer tres veces el mismo trabajo. El resultado es una matriz que indica qué control propio satisface qué requisito de qué marco.
It matters most when several frameworks are demanded at once. Most controls repeat across standards under different names, so mapping them once avoids doing the same work three times. The result is a matrix stating which control satisfies which requirement of which framework.
Qué beneficios traeBenefits it delivers
- Elimina trabajo duplicado entre certificaciones y auditorías, que es donde se va la mayor parte del presupuesto de cumplimiento.
- Permite responder cuestionarios de clientes en horas y no en semanas.
- Deja claro qué controles cubren varios marcos a la vez, que son los que conviene reforzar primero.
- Facilita agregar un marco nuevo después sin empezar de cero.
- Removes duplicated work across certifications and audits, where most of the compliance budget goes.
- Allows answering client questionnaires in hours instead of weeks.
- Makes clear which controls cover several frameworks at once, which are the ones worth strengthening first.
- Makes adding a new framework later possible without starting from scratch.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- Ningún marco es obligatorio por sí mismo en Costa Rica para el sector privado general.
- Se vuelve obligatorio de forma indirecta: a las entidades supervisadas les aplica el Acuerdo CONASSIF 5-24, a las organizaciones que procesan tarjetas les aplica PCI-DSS y a las instituciones públicas les aplican las normas técnicas de la Contraloría.
- No framework is mandatory in itself in Costa Rica for the general private sector.
- It becomes mandatory indirectly: supervised entities fall under CONASSIF 5-24, organisations that process cards fall under PCI-DSS, and public institutions fall under the technical standards of the Comptroller.
InternacionalInternational
- PCI-DSS es obligatorio por contrato para quien almacene, procese o transmita datos de tarjetas de pago.
- ISO 27001 no es obligatorio por ley pero sí por exigencia de clientes en buena parte del mercado corporativo.
- NIS2 y DORA imponen requisitos concretos a las entidades que cubren en la Unión Europea.
- PCI-DSS is contractually mandatory for anyone storing, processing or transmitting payment card data.
- ISO 27001 is not legally mandatory but is demanded by clients across much of the corporate market.
- NIS2 and DORA impose concrete requirements on the entities they cover in the European Union.
Requisitos mínimosMinimum requirements
- Definir cuáles marcos aplican de verdad; mapear contra marcos que nadie exige es gasto puro.
- Inventario de controles existentes y de la evidencia que los respalda.
- Acceso a las políticas vigentes y a quien las opera.
- Alcance claro: qué unidades, sistemas y ubicaciones entran.
- Defining which frameworks genuinely apply; mapping against frameworks nobody requires is pure cost.
- An inventory of existing controls and the evidence backing them.
- Access to current policies and to whoever operates them.
- A clear scope: which units, systems and locations are included.
Plazo típico de entregaTypical delivery time
El rango de mercado va de tres a siete semanas según cuántos marcos entren y qué tan documentado esté el control actual. Un mapeo contra un solo marco se hace en dos o tres semanas; tres marcos cruzados con evidencia revisada se va a siete u ocho.
The market range runs from three to seven weeks depending on how many frameworks are in scope and how well documented current controls are. Mapping against a single framework takes two or three weeks; three cross-mapped frameworks with reviewed evidence stretches to seven or eight.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.