Formación para CISO y ResponsablesTraining for CISOs and Security Leads
Gobierno, gestión de riesgos, normativa, incidentes.Governance, risk management, regulation and incident handling.
¿Qué es este servicio?What is this service?
Es formación especializada para quien dirige la seguridad: gobierno y marcos de control, gestión de riesgo tecnológico, cumplimiento aplicable, gestión de incidentes y crisis, relación con auditoría y con el regulador, y cómo defender un presupuesto ante la dirección. Se trabaja con casos y con documentación real del cliente cuando se puede.
Specialised training for whoever leads security: governance and control frameworks, technology risk management, applicable compliance, incident and crisis management, dealing with audit and the regulator, and how to defend a budget in front of the board. It works from cases and, where possible, the client's own documentation.
¿Para qué se usa?What is it used for?
Sirve porque la mayoría de los responsables de seguridad llegan al puesto desde lo técnico y se encuentran con que el trabajo real es riesgo, presupuesto, proveedores y política interna. El salto no es de conocimiento técnico sino de lenguaje: hay que traducir amenaza en riesgo de negocio y riesgo en decisión de inversión.
Most security leaders arrive from a technical background and discover the real job is risk, budget, suppliers and internal politics. The jump is not about technical knowledge but about language: turning threat into business risk and risk into an investment decision.
Qué beneficios traeBenefits it delivers
- Cierra la brecha entre saber de tecnología y saber gobernar seguridad, que es donde se atasca la mayoría.
- Da un método de gestión de riesgo defendible ante auditoría, en vez de una matriz improvisada en una hoja de cálculo.
- Entrena la conversación con la dirección, que suele ser el punto donde se pierden los presupuestos buenos.
- Se adapta al marco que la organización ya usa, así que lo aprendido se aplica el lunes siguiente.
- Closes the gap between knowing technology and knowing how to govern security, where most people get stuck.
- Provides a risk management method that stands up to audit, rather than a matrix improvised in a spreadsheet.
- Rehearses the conversation with the board, usually the point where good budgets are lost.
- Adapts to the framework the organisation already uses, so what is learned applies the following Monday.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal de formar al responsable de seguridad en Costa Rica.
- En entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE, el Acuerdo CONASSIF 5-24 incorporó al perfil tecnológico una tabla de funciones de ciberseguridad y la actualización anual del perfil según su artículo 42: quien firme esa información necesita entender lo que declara.
- La nueva clase de datos 56, el reporte histórico de seguridad de la información y seguridad cibernética, exige un responsable que sepa construirlo y sostenerlo.
- There is no legal obligation to train the security lead in Costa Rica.
- In entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE, CONASSIF Agreement 5-24 added a cybersecurity functions table to the technology profile and annual updating of that profile under its article 42: whoever signs off that information needs to understand what they are declaring.
- The new data class 56, the historical information security and cybersecurity report, requires an owner who knows how to build and sustain it.
InternacionalInternational
- ISO 27001 exige que quien tiene responsabilidades de seguridad sea competente, y la competencia hay que poder evidenciarla.
- DORA y NIS2 exigen formación en riesgo tecnológico para la función de gestión y para el órgano de dirección de las entidades cubiertas.
- PCI-DSS asigna responsabilidades formales de seguridad que alguien tiene que estar preparado para asumir.
- ISO 27001 requires whoever holds security responsibilities to be competent, and competence has to be evidenced.
- DORA and NIS2 require technology risk training for the management function and the board of covered entities.
- PCI-DSS assigns formal security responsibilities somebody has to be prepared to take on.
Requisitos mínimosMinimum requirements
- Saber qué marco rige a la organización: no es lo mismo preparar a un responsable de banco supervisado que a uno de una empresa de retail.
- Acceso a la documentación interna real, aunque sea anonimizada, porque los casos genéricos enseñan la mitad.
- Disponibilidad sostenida del participante: son sesiones de trabajo, no una charla que se escucha de fondo.
- Claridad sobre el mandato del puesto, incluido a quién reporta y qué puede decidir por sí solo.
- Knowing which framework governs the organisation: preparing the lead of a supervised bank is not the same as preparing one in retail.
- Access to real internal documentation, anonymised if need be, because generic cases teach half the lesson.
- Sustained availability from the participant: these are working sessions, not a talk playing in the background.
- Clarity about the role's mandate, including who it reports to and what it can decide alone.
Plazo típico de entregaTypical delivery time
El rango habitual va de cuatro a ocho semanas repartidas en sesiones semanales, porque entre una y otra hay trabajo que hacer sobre la documentación propia. Cae en el extremo bajo cuando es un solo responsable con base previa; sube cuando participa un equipo completo o cuando hay que cubrir un marco regulatorio específico en profundidad.
The usual range runs four to eight weeks spread over weekly sessions, because between them there is work to do on the participant's own documentation. It lands at the low end for a single lead with prior grounding; it rises when a whole team takes part or when a specific regulatory framework has to be covered in depth.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.