Diseño de Arquitectura de SeguridadSecurity Architecture Design
Segmentación, perímetro, autenticación, monitorización.Segmentation, perimeter, authentication and monitoring.
¿Qué es este servicio?What is this service?
Es el diseño de cómo encajan entre sí las piezas de seguridad de la organización: cómo se segmenta la red, dónde están los puntos de control, cómo se autentican las personas y los servicios, qué se registra y hacia dónde va ese registro. El entregable es un plano, con decisiones justificadas y una hoja de ruta para llegar ahí.
The design of how the security pieces of an organisation fit together: how the network is segmented, where the control points sit, how people and services authenticate, what gets logged and where those logs go. The deliverable is a blueprint, with justified decisions and a roadmap to reach it.
¿Para qué se usa?What is it used for?
Sirve para dejar de comprar herramientas sueltas. La mayoría de las organizaciones acumulan productos comprados en momentos distintos, por gente distinta, que no se hablan entre sí y dejan huecos que nadie ve porque nadie miró el conjunto. Diseñar la arquitectura antes de comprar sale más barato que integrar después lo que ya se compró mal.
It stops the habit of buying isolated tools. Most organisations accumulate products purchased at different times, by different people, that do not talk to each other and leave gaps nobody sees because nobody looked at the whole. Designing the architecture before buying costs less than integrating what was already bought badly.
Qué beneficios traeBenefits it delivers
- Evita comprar dos veces lo mismo: es habitual encontrar tres productos con funciones solapadas y ninguno bien configurado.
- Deja explícitos los supuestos de confianza, que es donde se esconden los huecos: qué sistema confía en cuál y por qué.
- Da un orden de ejecución con criterio de riesgo, en vez de hacer primero lo que el proveedor tiene en promoción.
- Sirve de argumento ante la dirección: un plano con fases y costos se defiende mejor que una lista de compras.
- Avoids buying the same thing twice: finding three products with overlapping functions and none properly configured is routine.
- Makes trust assumptions explicit, which is where the gaps hide: which system trusts which, and why.
- Provides an execution order based on risk rather than on whatever the vendor is discounting this quarter.
- Works as an argument to the board: a phased blueprint with costs defends itself better than a shopping list.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay una norma costarricense que exija un documento de arquitectura de seguridad como tal.
- El Acuerdo CONASSIF 5-24 obliga a las entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE a mantener un perfil tecnológico y actualizarlo cada año, y ese perfil describe justamente la arquitectura que se declara.
- Desde el perfil tecnológico 2026 hay tablas específicas de funciones de ciberseguridad, activos de información, bases de datos y nube: si la arquitectura no está documentada, esas tablas se llenan a ciegas.
- No Costa Rican rule requires a security architecture document as such.
- CONASSIF Agreement 5-24 obliges entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE to maintain a technology profile and update it annually, and that profile describes precisely the architecture being declared.
- From the 2026 technology profile onward there are specific tables for cybersecurity functions, information assets, databases and cloud: if the architecture is undocumented, those tables get filled in blind.
InternacionalInternational
- ISO 27001 no pide un plano de arquitectura, pero sí exige controles de seguridad en redes y en el desarrollo de sistemas que sin diseño previo quedan improvisados.
- PCI-DSS exige diagramas de red y de flujo de datos de tarjeta actualizados: eso ya es arquitectura documentada, aunque el estándar no la llame así.
- En contratos corporativos y procesos de debida diligencia con clientes grandes es habitual que pidan el diagrama de arquitectura antes de firmar.
- ISO 27001 does not ask for an architecture blueprint, but it does require network security and secure development controls that end up improvised without prior design.
- PCI-DSS requires up-to-date network and cardholder data flow diagrams: that is documented architecture, even if the standard does not call it that.
- Corporate contracts and due diligence processes with large clients routinely ask for the architecture diagram before signing.
Requisitos mínimosMinimum requirements
- Un inventario razonablemente honesto de lo que hay: si el inventario miente, el plano nace mal.
- Acceso a las personas que operan cada plataforma, porque la documentación existente casi nunca refleja la realidad.
- Claridad sobre los procesos de negocio críticos, para saber qué se protege primero.
- Un patrocinador con autoridad para decidir, porque la arquitectura toca presupuestos y territorios de varias áreas.
- A reasonably honest inventory of what exists: if the inventory lies, the blueprint is born wrong.
- Access to the people who operate each platform, because existing documentation almost never reflects reality.
- Clarity on the critical business processes, to know what gets protected first.
- A sponsor with authority to decide, because architecture touches budgets and territory across several areas.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de seis a doce semanas para el diseño. Cae en el extremo bajo cuando el entorno es de un solo centro de datos y hay documentación decente; se va al alto cuando hay nube híbrida, fusiones sin integrar o entornos industriales. La ejecución del plano es aparte y se mide en trimestres, no en semanas.
The usual market range runs from six to twelve weeks for the design. It lands at the low end with a single data centre and decent documentation; it stretches to the high end with hybrid cloud, unintegrated mergers or industrial environments. Executing the blueprint is a separate matter, measured in quarters rather than weeks.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.