Saltar al contenido
06 · Especializados06 · Specialised

Bug Bounty ProgramBug Bounty Programme

Alcance, reglas, plataforma, triage y recompensas.Scope, rules, platform, triage and rewards.

Bug BountyBug Bounty Servicios verticales para riesgos específicosVertical services for specific risks

¿Qué es este servicio?What is this service?

Es el diseño y la operación de un programa de recompensas: definir qué está dentro del alcance y qué no, escribir las reglas del juego, elegir la plataforma, fijar la tabla de pagos, y sobre todo recibir, validar, priorizar y responder los reportes que llegan de investigadores de todo el mundo.

Design and operation of a rewards programme: defining what is in scope and what is not, writing the rules of engagement, choosing the platform, setting the payout table and, above all, receiving, validating, prioritising and answering the reports arriving from researchers worldwide.

¿Para qué se usa?What is it used for?

Permite tener muchos ojos mirando de forma continua, con un modelo donde solo se paga por hallazgo válido. Ahora la advertencia: abrir un programa sin capacidad de triaje y respuesta hace más daño que bien. El investigador que espera tres meses una respuesta se frustra y publica, y ahí el problema deja de ser técnico. La organización que todavía no tiene ese músculo debería empezar por una VDP.

It puts many eyes on the systems continuously, on a model where payment only follows valid findings. Now the warning: opening a programme without the capacity to triage and respond does more harm than good. A researcher who waits three months for an answer gets frustrated and publishes, and at that point the problem stops being technical. An organisation without that muscle should start with a VDP.

Qué beneficios traeBenefits it delivers

  • Cobertura continua y con gran variedad de enfoques, en vez de una foto puntual una vez al año.
  • Se paga por resultado: si nadie encuentra nada explotable, no hay factura por hallazgos.
  • Atrae perfiles muy especializados que ninguna consultora tiene en plantilla completa.
  • Bien llevado, mejora la relación con la comunidad de investigadores, que es la que decide si un fallo se reporta o se publica.
  • Continuous coverage with a wide variety of approaches, instead of a snapshot once a year.
  • Payment follows results: if nobody finds anything exploitable, there is no findings invoice.
  • Attracts highly specialised profiles no consultancy keeps permanently on staff.
  • Run well, it improves the relationship with the research community, which decides whether a flaw gets reported or published.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No es obligatorio en Costa Rica ni lo exige ningún regulador local.
  • Las reglas del programa deben dejar por escrito la autorización para probar, porque sin ella una prueba consentida y un delito informático se parecen demasiado.
  • Si un investigador accede a datos personales durante una prueba, aplican igual las obligaciones de la Ley 8968: eso se regula en las reglas, no se improvisa.
  • It is not mandatory in Costa Rica and no local regulator requires it.
  • The programme rules must set out the authorisation to test in writing, because without it an authorised test and a computer crime look far too similar.
  • If a researcher accesses personal data during a test, the obligations of Law 8968 still apply: that is governed by the rules, not improvised.

InternacionalInternational

  • Ningún marco lo exige, y no sustituye al pentest obligatorio: PCI-DSS pide pruebas de intrusión internas y externas al menos cada doce meses y tras cambios significativos, con metodología documentada.
  • Un bug bounty no cubre por sí solo esa exigencia porque no garantiza cobertura ni alcance.
  • La referencia para la parte de recepción y manejo de reportes es ISO/IEC 29147.
  • No framework requires it, and it does not replace mandatory pentesting: PCI-DSS calls for internal and external penetration testing at least every twelve months and after significant changes, with a documented methodology.
  • A bug bounty does not cover that requirement on its own because it guarantees neither coverage nor scope.
  • The reference for the report intake and handling side is ISO/IEC 29147.

Requisitos mínimosMinimum requirements

  • Capacidad real de triaje: alguien que valide y responda en días, no en meses. Este es el requisito que hunde a la mayoría de los programas.
  • Un proceso de remediación que funcione, porque recibir el reporte y no arreglar el fallo es la peor combinación posible.
  • Presupuesto asignado para las recompensas y reglas claras de pago, publicadas de antemano.
  • Alcance definido con precisión y respaldo legal por escrito para quien pruebe dentro de él.
  • Real triage capacity: somebody validating and answering within days, not months. This is the requirement that sinks most programmes.
  • A remediation process that works, because receiving the report and not fixing the flaw is the worst possible combination.
  • Allocated budget for rewards and clear payment rules, published in advance.
  • A precisely defined scope and written legal protection for anyone testing within it.

Plazo típico de entregaTypical delivery time

4 a 8 semanas 4 to 8 weeks rango habitual del mercado usual market range

Montar el programa lleva de cuatro a ocho semanas: definir alcance, redactar reglas, acordar la tabla de recompensas y preparar el flujo de triaje. Después es una operación continua y sin fecha de fin. Lo recomendable es arrancar en modo privado con un grupo reducido de investigadores durante los primeros meses, para medir cuánto volumen aguanta el equipo antes de abrir la puerta a todo el mundo.

Setting the programme up takes four to eight weeks: defining scope, drafting rules, agreeing the reward table and preparing the triage flow. After that it is a continuous operation with no end date. The sensible move is to start private with a small group of researchers for the first months, to measure how much volume the team can absorb before opening the door to everyone.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

Bug bountyBug bounty
Programa que paga a investigadores externos por reportar fallos de seguridad válidos, con reglas publicadas. A programme paying external researchers for reporting valid security flaws, under published rules.
TriajeTriage
Validar el reporte, reproducir el fallo, descartar duplicados y asignarle severidad antes de pagar y arreglar. Validating the report, reproducing the flaw, discarding duplicates and assigning severity before paying and fixing.
AlcanceScope
La lista de sistemas donde se puede probar y de técnicas prohibidas. Todo lo que no está listado, está fuera. The list of systems that may be tested and of forbidden techniques. Anything not listed is out.
Safe harbourSafe harbour
El compromiso escrito de no emprender acciones legales contra quien investigue respetando las reglas. The written commitment not to pursue legal action against anyone researching within the rules.
DuplicadoDuplicate
Reporte de un fallo que otro investigador ya había enviado antes. Solo cobra el primero, y es la principal fuente de fricción. A report of a flaw another researcher already submitted. Only the first is paid, and it is the main source of friction.