Saltar al contenido
05 · Arquitectura05 · Architecture

Implementación de SIEMSIEM Implementation

Arquitectura, instalación, fuentes, casos de uso.Architecture, installation, log sources and use cases.

DespliegueDeployment Diseño y despliegue de tecnología de seguridadDesign and deployment of security technology

¿Qué es este servicio?What is this service?

Es el despliegue completo de la plataforma que centraliza los registros: dimensionar la arquitectura, instalarla, conectar las fuentes de datos, normalizar lo que llega, construir los casos de uso de detección y dejar al equipo del cliente en condiciones de operarla.

The full deployment of the platform that centralises logs: sizing the architecture, installing it, connecting data sources, normalising what arrives, building detection use cases and leaving the client team able to operate it.

¿Para qué se usa?What is it used for?

Sirve para tener un lugar donde mirar cuando algo pasa. Sin correlación central, investigar un incidente significa entrar a quince consolas distintas con quince relojes desincronizados. Dicho eso: un SIEM comprado y no afinado es un gasto puro. El valor no está en la licencia sino en las fuentes conectadas y en los casos de uso escritos.

It provides a single place to look when something happens. Without central correlation, investigating an incident means logging into fifteen consoles with fifteen unsynchronised clocks. That said: a SIEM bought and left untuned is pure expense. The value is not in the licence but in the connected sources and the use cases written.

Qué beneficios traeBenefits it delivers

  • Unifica el tiempo y el formato de todos los registros, que es lo que hace posible reconstruir una cadena de eventos.
  • Habilita la detección correlacionada: cosas que por separado no son nada y juntas sí lo son.
  • Da la retención de evidencia que después piden la auditoría, el seguro y, si hay que llegar ahí, el peritaje.
  • Es el prerrequisito de casi todo lo demás del SOC: sin él no hay triaje, ni caza, ni métricas.
  • Unifies the timing and format of every log, which is what makes reconstructing a chain of events possible.
  • Enables correlated detection: things that mean nothing separately and plenty together.
  • Provides the evidence retention later demanded by auditors, insurers and, if it comes to that, forensic experts.
  • It is the prerequisite for nearly everything else in a SOC: without it there is no triage, no hunting, no metrics.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • Ninguna ley costarricense obliga a tener un SIEM.
  • A las entidades supervisadas, el Acuerdo CONASSIF 5-24 les exige capacidades de monitoreo y respuesta, y la clase de datos 56 pide un histórico de seguridad de la información que en la práctica se construye con los registros centralizados.
  • No Costa Rican law obliges an organisation to have a SIEM.
  • For supervised entities, CONASSIF Agreement 5-24 requires monitoring and response capabilities, and data class 56 asks for an information security history that in practice is built from centralised logs.

InternacionalInternational

  • Ningún marco exige la herramienta por nombre; todos exigen el resultado.
  • PCI-DSS obliga a registrar los accesos a los datos de tarjeta, a proteger esos registros contra alteración y a revisarlos diariamente. Hacerlo a mano en un entorno mediano no es viable.
  • ISO 27001 exige registro de eventos, protección de los registros y monitorización, y NIS2 y DORA exigen detectar y notificar incidentes en plazos que sin centralización no se cumplen.
  • No framework requires the tool by name; all of them require the outcome.
  • PCI-DSS mandates logging access to cardholder data, protecting those logs against tampering and reviewing them daily. Doing that by hand in a mid-sized environment is not viable.
  • ISO 27001 requires event logging, log protection and monitoring, while NIS2 and DORA impose incident detection and notification deadlines unachievable without centralisation.

Requisitos mínimosMinimum requirements

  • Una decisión previa sobre volumen y retención, porque de ahí sale el costo real y casi siempre se subestima.
  • Acceso administrativo a las fuentes que se van a conectar y ventanas de cambio para tocarlas.
  • Sincronización horaria en toda la infraestructura: sin relojes en hora, la correlación es ficción.
  • Alguien del lado del cliente que se apropie de la plataforma, o en un año vuelve a estar desactualizada.
  • A prior decision on volume and retention, since that drives the real cost and is almost always underestimated.
  • Administrative access to the sources being connected and change windows to touch them.
  • Time synchronisation across the infrastructure: without clocks in sync, correlation is fiction.
  • Someone on the client side who takes ownership of the platform, or within a year it is stale again.

Plazo típico de entregaTypical delivery time

8 a 16 semanas 8 to 16 weeks rango habitual del mercado usual market range

El rango habitual del mercado va de ocho a dieciséis semanas. Lo que empuja al extremo alto no es la instalación, que es rápida, sino conectar fuentes que nadie sabe cómo exportan y limpiar el ruido inicial. Los primeros dos meses de operación siempre son de afinado: cualquiera que prometa un SIEM listo en dos semanas está vendiendo la instalación, no el servicio.

The usual market range runs from eight to sixteen weeks. What pushes it to the high end is not installation, which is quick, but connecting sources nobody knows how to export from and clearing the initial noise. The first two months of operation are always tuning: anyone promising a SIEM ready in a fortnight is selling the installation, not the service.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

SIEMSIEM
Plataforma que recoge los registros de todos los sistemas, los ordena y los correlaciona para generar alertas. Platform that collects logs from every system, orders them and correlates them to raise alerts.
Fuente de datosData source
Cada sistema que envía registros: cortafuegos, servidores, directorio, aplicaciones, nube. Each system sending logs: firewalls, servers, directory, applications, cloud.
NormalizaciónNormalisation
Traducir formatos distintos a uno común para poder compararlos entre sí. Translating different formats into a common one so they can be compared.
EPSEPS
Eventos por segundo: la medida de volumen con la que se dimensiona y se factura la plataforma. Events per second: the volume measure used to size and bill the platform.
RetenciónRetention
Cuánto tiempo se guardan los registros. Determina hasta dónde se puede investigar hacia atrás. How long logs are kept. It determines how far back an investigation can reach.