Gestión de VulnerabilidadesVulnerability Management
Tenable, Qualys, OpenVAS.Tenable, Qualys and OpenVAS.
¿Qué es este servicio?What is this service?
Es el ciclo completo sobre plataformas como Tenable, Qualys u OpenVAS: descubrir los activos, escanearlos, priorizar los hallazgos por riesgo real, asignar la remediación a un responsable, verificar que se cerró y reportar la tendencia.
The full cycle on platforms such as Tenable, Qualys or OpenVAS: discovering assets, scanning them, prioritising findings by real risk, assigning remediation to an owner, verifying closure and reporting the trend.
¿Para qué se usa?What is it used for?
Escanear es la parte fácil y barata. Lo difícil es cerrar. Un informe de cuatro mil hallazgos ordenados por puntuación teórica no se remedia nunca: el equipo lo abre, se abruma y lo archiva. El valor está en decir cuáles cuarenta importan esta semana, quién las arregla y cómo se comprueba que quedaron cerradas.
Scanning is the easy, cheap part. Closing is the hard part. A four-thousand-finding report sorted by theoretical score never gets remediated: the team opens it, feels overwhelmed and files it away. The value is in saying which forty matter this week, who fixes them and how closure gets verified.
Qué beneficios traeBenefits it delivers
- Prioriza por explotación real y exposición del activo, no por la puntuación de fábrica, que trata igual a un servidor público que a una impresora interna.
- Cierra el ciclo: cada hallazgo tiene responsable, fecha comprometida y verificación posterior, así que deja de reaparecer en cada informe.
- Genera métricas de tendencia que sirven para hablar con la dirección: cuántas se abren, cuántas se cierran y en cuánto tiempo.
- Depura falsos positivos, que en escaneos autenticados sobre sistemas con parches retroportados son una porción enorme del ruido.
- Prioritises by real exploitation and asset exposure, not by the out-of-the-box score, which treats a public server the same as an internal printer.
- Closes the loop: every finding has an owner, a committed date and later verification, so it stops reappearing in every report.
- Produces trend metrics that can be taken to the board: how many open, how many close and how long it takes.
- Weeds out false positives, which on authenticated scans of back-ported systems are a large slice of the noise.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal general en Costa Rica de escanear vulnerabilidades.
- El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE gestionar el riesgo tecnológico de forma documentada, y el estado de las vulnerabilidades es parte de esa evidencia.
- Muchos contratos con clientes corporativos y con casas matrices lo exigen por escrito aunque ninguna ley local lo haga.
- There is no general legal obligation in Costa Rica to scan for vulnerabilities.
- CONASSIF Agreement 5-24 requires entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE to manage technology risk in a documented way, and vulnerability status is part of that evidence.
- Many contracts with corporate clients and parent companies demand it in writing even where no local law does.
InternacionalInternational
- PCI-DSS v4.0.1 exige escaneos de vulnerabilidades internos y externos con una periodicidad definida y tras cualquier cambio significativo. Todos los requisitos con fecha futura de la versión 4 son obligatorios desde el 31 de marzo de 2025.
- PCI-DSS también exige pruebas de intrusión interna y externa al menos cada doce meses y tras cambios significativos, que son el complemento del escaneo, no su sustituto.
- ISO 27001 exige gestionar las vulnerabilidades técnicas: obtener información oportuna sobre ellas, evaluar la exposición y tomar medidas.
- PCI-DSS v4.0.1 requires internal and external vulnerability scans at a defined frequency and after any significant change. All future-dated version 4 requirements have been mandatory since 31 March 2025.
- PCI-DSS also requires internal and external penetration testing at least every twelve months and after significant changes, which complements scanning rather than replacing it.
- ISO 27001 requires managing technical vulnerabilities: obtaining timely information about them, assessing exposure and taking action.
Requisitos mínimosMinimum requirements
- Un inventario de activos razonablemente completo: lo que no está inventariado no se escanea y es justo lo que suele estar roto.
- Credenciales de escaneo autenticado, porque sin ellas los resultados son superficiales y llenos de falsos positivos.
- Ventanas y permisos de red para que los escaneos alcancen todos los segmentos, incluidos los aislados.
- Dueños asignados por sistema, con capacidad real de aplicar el cambio. Sin eso el programa se detiene en el informe.
- A reasonably complete asset inventory: what is not inventoried is not scanned, and that is usually what is broken.
- Credentials for authenticated scanning, without which results are shallow and full of false positives.
- Windows and network permissions so scans reach every segment, including isolated ones.
- Assigned system owners with real authority to apply the change. Without that the programme stops at the report.
Plazo típico de entregaTypical delivery time
Es un servicio continuo con ciclos mensuales o trimestrales de escaneo. El arranque va de tres a seis semanas: desplegar los escáneres, conseguir credenciales, calibrar el alcance y depurar el primer informe, que siempre es el más ruidoso. La curva de cierre se vuelve manejable hacia el tercer o cuarto ciclo.
This is a continuous service with monthly or quarterly scanning cycles. Ramp-up takes three to six weeks: deploying scanners, obtaining credentials, calibrating scope and cleaning up the first report, always the noisiest. The closure curve becomes manageable around the third or fourth cycle.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.