Formación para Junta DirectivaBoard of Directors Training
Responsabilidad del órgano de dirección sobre el riesgo tecnológico.Board level accountability for technology risk.
¿Qué es este servicio?What is this service?
Es una sesión específica para el órgano de dirección sobre su propia responsabilidad en el riesgo tecnológico: qué tiene que vigilar, qué preguntas hacer a la administración, qué información exigir y con qué frecuencia, y cómo queda registrada esa vigilancia en actas. No es una charla técnica.
A dedicated session for the board on its own responsibility for technology risk: what it must oversee, what questions to put to management, what information to demand and how often, and how that oversight is recorded in the minutes. It is not a technical talk.
¿Para qué se usa?What is it used for?
Sirve porque la responsabilidad ya está asignada, sepan o no. En Costa Rica, el Acuerdo CONASSIF 5-24 —el Reglamento General de Gobierno y Gestión de la Tecnología de Información, que sustituyó al 5-17— le da al órgano de dirección de las entidades supervisadas un papel activo de vigilancia sobre la tecnología y su riesgo. Una junta que no puede explicar cómo ejerce esa vigilancia tiene un problema de gobierno, no de tecnología.
The responsibility is already assigned, whether the board knows it or not. In Costa Rica, CONASSIF Agreement 5-24 — the General Regulation on Information Technology Governance and Management, which replaced 5-17 — gives the board of supervised entities an active oversight role over technology and its risk. A board that cannot explain how it exercises that oversight has a governance problem, not a technology one.
Qué beneficios traeBenefits it delivers
- Deja claro qué le corresponde vigilar a la junta y qué le corresponde ejecutar a la administración, que es la confusión más común.
- Da un guion de preguntas concretas para pedirle cuentas al área de tecnología sin necesidad de saber de tecnología.
- Ordena qué información debe llegar a la junta, en qué formato y con qué periodicidad, para que quede evidencia en actas.
- Reduce la exposición personal de los miembros del órgano ante un incidente grave o una revisión del supervisor.
- Makes clear what the board oversees and what management executes, the most common confusion.
- Provides a script of concrete questions to hold the technology function to account without needing technical knowledge.
- Sets out what information must reach the board, in what format and how often, so evidence exists in the minutes.
- Reduces the personal exposure of board members in a serious incident or a supervisory review.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- La formación en sí no es obligatoria, pero la responsabilidad del órgano de dirección sí lo es en el sector financiero supervisado.
- El Acuerdo CONASSIF 5-24 aplica a entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE, y su artículo 42 exige un perfil tecnológico con actualización anual que se remite por SICVECA con firma digital, en las ventanas de febrero, mayo y agosto.
- El perfil tecnológico 2026 pasó de diecisiete a veintiuna tablas, con nuevas tablas de funciones de ciberseguridad, activos de información, bases de datos y nube, más la clase de datos 56 de reporte histórico de seguridad. Todo eso se declara bajo la vigilancia del órgano de dirección.
- The training itself is not mandatory, but the board's responsibility is, in the supervised financial sector.
- CONASSIF Agreement 5-24 applies to entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE, and its article 42 requires an annually updated technology profile filed through SICVECA with a digital signature, in the February, May and August windows.
- The 2026 technology profile went from seventeen to twenty-one tables, adding cybersecurity functions, information assets, databases and cloud, plus data class 56 for the historical security report. All of it is declared under board oversight.
InternacionalInternational
- DORA hace responsable al órgano de dirección de la gestión del riesgo tecnológico y le exige mantener conocimientos suficientes y actualizados sobre la materia.
- NIS2 exige que los órganos de dirección aprueben las medidas de gestión de riesgo, supervisen su aplicación y reciban formación específica.
- ISO 27001 exige liderazgo demostrable de la alta dirección sobre el sistema de gestión, y demostrable significa que quede registro.
- DORA makes the management body responsible for technology risk management and requires it to keep sufficient, up-to-date knowledge of the subject.
- NIS2 requires management bodies to approve the risk management measures, oversee their implementation and receive specific training.
- ISO 27001 requires demonstrable top management leadership of the management system, and demonstrable means it has to be recorded.
Requisitos mínimosMinimum requirements
- Confirmar el marco que aplica a la entidad, porque el contenido cambia por completo entre una entidad supervisada y una empresa que no lo está.
- Un espacio en la agenda del órgano, idealmente dentro de una sesión ordinaria para que quede en acta.
- La documentación actual que la junta recibe sobre tecnología y riesgo, para revisar si sirve o si es un adorno.
- Presencia de quien dirige la seguridad, porque el objetivo también es ordenar la relación entre ambos.
- Confirming which framework applies to the entity, because the content changes completely between a supervised entity and one that is not.
- A slot in the board agenda, ideally inside an ordinary session so it is minuted.
- The current documentation the board receives on technology and risk, to review whether it is useful or decorative.
- The presence of whoever leads security, because part of the goal is ordering the relationship between the two.
Plazo típico de entregaTypical delivery time
Desde el encargo hasta la sesión pasan de dos a cuatro semanas, casi todas en preparar el material a la medida del marco que aplica y de la información que la junta ya recibe. La sesión ocupa entre noventa minutos y media jornada. Sube al extremo alto cuando hay que revisar antes el reporte regulatorio o coordinar con comités de riesgo y auditoría.
From engagement to the session takes two to four weeks, mostly spent tailoring the material to the applicable framework and to the information the board already receives. The session runs from ninety minutes to half a day. It reaches the top of the range when the regulatory filing has to be reviewed first or when risk and audit committees must be coordinated.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.