Saltar al contenido
02 · Auditoría02 · Auditing

Análisis de Configuraciones SegurasSecure Configuration Review

Hardening de SO, bases de datos, servidores web, firewalls.Hardening of operating systems, databases, web servers and firewalls.

CIS Benchmarks · DISA STIGCIS Benchmarks · DISA STIG 2.2 · Auditorías de Código y Configuración2.2 · Code and Configuration Audits

¿Qué es este servicio?What is this service?

Es la revisión de cómo están configurados los sistemas operativos, las bases de datos, los servidores web y los cortafuegos, contrastada contra guías de referencia como los CIS Benchmarks o las STIG del Departamento de Defensa estadounidense.

A review of how operating systems, databases, web servers and firewalls are configured, benchmarked against reference guides such as the CIS Benchmarks or the US Department of Defense STIGs.

¿Para qué se usa?What is it used for?

Importa porque la mayoría de los sistemas se instalan con la configuración de fábrica y ahí se quedan. Los valores por defecto están pensados para que todo funcione a la primera, no para que sea seguro: servicios de más encendidos, cifrado débil aceptado, permisos amplios y registros apagados.

It matters because most systems are installed with factory settings and stay that way. Defaults are designed so everything works first time, not so it is secure: extra services enabled, weak ciphers accepted, broad permissions and logging switched off.

Qué beneficios traeBenefits it delivers

  • Cierra la superficie de ataque sin comprar nada: se trata de apagar lo que sobra y endurecer lo que queda.
  • Genera una línea base reutilizable, para que los sistemas nuevos nazcan bien configurados.
  • Detecta el registro de auditoría apagado, sin el cual no hay forma de investigar un incidente después.
  • Es de las medidas con mejor relación entre costo y reducción de riesgo que existen.
  • Closes attack surface without buying anything: it is about switching off what is unnecessary and hardening what remains.
  • Produces a reusable baseline so new systems are born correctly configured.
  • Detects disabled audit logging, without which there is no way to investigate an incident afterwards.
  • It is among the best cost-to-risk-reduction measures available.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal directa en Costa Rica.
  • Para entidades supervisadas es evidencia del control técnico que exige el marco de gestión de TI del Acuerdo CONASSIF 5-24.
  • There is no direct legal obligation in Costa Rica.
  • For supervised entities it evidences the technical control required by the IT management framework of CONASSIF Agreement 5-24.

InternacionalInternational

  • PCI-DSS exige estándares de configuración segura para todos los componentes del sistema y cambiar los valores por defecto del proveedor.
  • ISO 27001 exige gestión de la configuración segura.
  • Los CIS Benchmarks son la referencia aceptada por auditores para demostrar cumplimiento.
  • PCI-DSS requires secure configuration standards for all system components and changing vendor defaults.
  • ISO 27001 requires secure configuration management.
  • CIS Benchmarks are the reference auditors accept to demonstrate compliance.

Requisitos mínimosMinimum requirements

  • Inventario de sistemas y acceso de lectura a su configuración.
  • Definir contra qué guía se compara, porque los CIS Benchmarks tienen niveles con exigencias distintas.
  • Saber qué sistemas soportan qué aplicaciones, para no proponer un endurecimiento que rompa la operación.
  • Una ventana de mantenimiento si se va a aplicar y no solo diagnosticar.
  • A system inventory and read access to their configuration.
  • Deciding which guide to benchmark against, since CIS Benchmarks have levels with different demands.
  • Knowing which systems support which applications, so hardening does not break operations.
  • A maintenance window if the changes are to be applied and not just diagnosed.

Plazo típico de entregaTypical delivery time

2 a 5 semanas 2 to 5 weeks rango habitual del mercado usual market range

El rango habitual del mercado va de dos a cinco semanas para el diagnóstico, según la cantidad de sistemas y su diversidad. Aplicar el endurecimiento es un proyecto aparte y se hace por olas, con pruebas entre una y otra, porque un cambio de configuración mal probado tumba servicios.

The usual market range runs from two to five weeks for the assessment, depending on the number and diversity of systems. Applying the hardening is a separate project run in waves with testing between them, because a badly tested configuration change takes services down.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

HardeningHardening
Endurecimiento: reducir la superficie de ataque de un sistema apagando lo innecesario y ajustando su configuración. Reducing the attack surface of a system by disabling the unnecessary and tightening its configuration.
CIS BenchmarksCIS Benchmarks
Guías de configuración segura por producto publicadas por el Center for Internet Security. Secure configuration guides per product published by the Center for Internet Security.
STIGSTIG
Guías de configuración del Departamento de Defensa de Estados Unidos, más estrictas que las de uso general. US Department of Defense configuration guides, stricter than general-purpose ones.
Línea baseBaseline
Configuración segura estándar que se aplica a todo sistema nuevo del mismo tipo. A standard secure configuration applied to every new system of the same type.
DerivaDrift
La pérdida progresiva de la configuración segura por cambios manuales acumulados con el tiempo. The gradual loss of secure configuration through manual changes accumulated over time.