Gestión de EDR / XDREDR / XDR Management
CrowdStrike, Defender, SentinelOne.CrowdStrike, Defender and SentinelOne.
¿Qué es este servicio?What is this service?
Es la administración de la plataforma de detección en equipos —CrowdStrike, Defender, SentinelOne— por parte de un equipo externo: desplegar y mantener los agentes, endurecer las políticas, revisar las exclusiones, atender las detecciones y medir la cobertura real.
The administration of the endpoint detection platform — CrowdStrike, Defender, SentinelOne — by an external team: deploying and maintaining agents, hardening policies, reviewing exclusions, handling detections and measuring real coverage.
¿Para qué se usa?What is it used for?
Sirve porque comprar las licencias no es tenerlo. Es frecuente encontrar consolas de marcas excelentes corriendo en modo de solo detección desde el día de la instalación, con exclusiones de carpetas enteras que alguien agregó en 2021 para que dejara de molestar a un sistema contable. Y siempre hay un porcentaje de equipos sin agente: ahí es exactamente por donde entra el atacante.
It matters because buying the licences is not the same as having it. Consoles from excellent vendors are routinely found running in detect-only mode since installation day, with whole folders excluded because somebody added them in 2021 to stop it bothering an accounting system. And there is always a share of machines with no agent: that is exactly where the attacker gets in.
Qué beneficios traeBenefits it delivers
- Mide la cobertura de agentes contra el inventario real y persigue los equipos que faltan, que es donde está el hueco.
- Lleva las políticas de detección a bloqueo de forma gradual y controlada, en vez de dejarlas eternamente en observación.
- Revisa y depura las exclusiones heredadas, que son el atajo favorito del que quiere evadir el control.
- Convierte las detecciones en incidentes gestionados, no en una lista roja que nadie abre.
- Measures agent coverage against the real inventory and chases the missing machines, which is where the gap sits.
- Moves detection policies into blocking gradually and under control, instead of leaving them in observation forever.
- Reviews and prunes inherited exclusions, the favourite shortcut for anybody wanting to evade the control.
- Turns detections into managed incidents rather than a red list nobody opens.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal de tener EDR o XDR en Costa Rica.
- El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas capacidades de detección y respuesta, que en la práctica se sostienen sobre la telemetría de los equipos.
- La nueva tabla de funciones de ciberseguridad del perfil tecnológico, de actualización anual, es donde esa capacidad se declara ante el supervisor.
- There is no legal obligation to have EDR or XDR in Costa Rica.
- CONASSIF Agreement 5-24 requires supervised entities to have detection and response capabilities, which in practice rest on endpoint telemetry.
- The new cybersecurity functions table in the annually updated technology profile is where that capability is declared to the supervisor.
InternacionalInternational
- PCI-DSS v4.0.1 exige protección contra software malicioso en los sistemas del alcance, mantenida al día y sin que el usuario pueda deshabilitarla.
- ISO 27001 exige controles de protección contra malware y gestión de la configuración de los equipos.
- NIS2 y DORA exigen capacidades de detección y respuesta, sin nombrar tecnología concreta.
- PCI-DSS v4.0.1 requires anti-malware protection on in-scope systems, kept current and not disableable by the user.
- ISO 27001 requires malware protection controls and endpoint configuration management.
- NIS2 and DORA require detection and response capabilities, without naming a specific technology.
Requisitos mínimosMinimum requirements
- Un inventario de equipos contra el cual medir cobertura: sin él, el porcentaje de despliegue es una adivinanza.
- Un mecanismo de distribución de software para instalar y actualizar los agentes a escala.
- Ventanas acordadas para endurecer políticas, porque el paso a bloqueo puede romper aplicaciones legítimas.
- Decidir qué queda fuera de alcance y asumirlo por escrito: servidores viejos, sistemas industriales, equipos de terceros.
- A device inventory to measure coverage against: without one, the deployment percentage is guesswork.
- A software distribution mechanism to install and update agents at scale.
- Agreed windows for hardening policies, because moving to blocking can break legitimate applications.
- Deciding what stays out of scope and accepting it in writing: legacy servers, industrial systems, third-party devices.
Plazo típico de entregaTypical delivery time
Es un servicio continuo. El despliegue inicial va de tres a ocho semanas según el tamaño del parque y la calidad del inventario. Lo que alarga el plazo casi nunca es instalar el agente sino el endurecimiento: pasar las políticas a bloqueo exige probar por grupos y aguantar las quejas de las primeras semanas.
This is a continuous service. Initial deployment runs from three to eight weeks depending on estate size and inventory quality. What stretches the timeline is almost never installing the agent but the hardening: moving policies into blocking requires testing by groups and absorbing the complaints of the first weeks.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.