Saltar al contenido
03 · SOC Gestionado03 · Managed SOC

MDR — Detección y Respuesta GestionadaMDR — Managed Detection and Response

Detección, investigación y contención gestionadas de punta a punta.Fully managed detection, investigation and containment, end to end.

MDR 24×7MDR 24×7 3.1 · SOC como Servicio (SOCaaS)3.1 · SOC as a Service (SOCaaS)

¿Qué es este servicio?What is this service?

Es el servicio gestionado que detecta, investiga y además contiene: no solo avisa de que hay un problema sino que actúa sobre él, aislando un equipo o bloqueando una cuenta según lo acordado de antemano.

A managed service that detects, investigates and also contains: it does not merely warn that there is a problem but acts on it, isolating a machine or blocking an account according to what was agreed in advance.

¿Para qué se usa?What is it used for?

Sirve para cerrar la brecha entre detectar y responder. Un SOC tradicional llama al cliente y espera su decisión; a las tres de la mañana esa llamada puede tardar cuarenta minutos en ser atendida, y en cuarenta minutos un ransomware cifra media red. Con MDR, la contención inicial ya está autorizada y se ejecuta en minutos.

It closes the gap between detecting and responding. A traditional SOC calls the client and waits for a decision; at three in the morning that call can take forty minutes to be answered, and in forty minutes ransomware encrypts half the network. With MDR, initial containment is pre-authorised and executes within minutes.

Qué beneficios traeBenefits it delivers

  • Reduce el tiempo de contención de horas a minutos, que es la variable que más determina el costo del incidente.
  • Incluye la tecnología en el servicio, así que no hay que comprar y operar la plataforma por separado.
  • Es la forma en que hoy se compra este servicio: nombrarlo así importa porque es lo que el mercado busca.
  • Da acceso a capacidad de respuesta sin contratar un equipo propio de respuesta a incidentes.
  • Cuts containment time from hours to minutes, the variable that most determines incident cost.
  • Includes the technology in the service, so there is no separate platform to buy and operate.
  • It is how this service is bought today: naming it this way matters because it is what the market searches for.
  • Provides response capability without hiring an in-house incident response team.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No es obligatorio en Costa Rica.
  • Cubre la exigencia de capacidades de detección y respuesta que el Acuerdo CONASSIF 5-24 espera de las entidades supervisadas.
  • Atención al componente de subcontratación: el marco exige gestionar la relación con terceros proveedores de tecnología, así que el contrato del MDR entra en ese inventario.
  • It is not mandatory in Costa Rica.
  • It covers the detection and response capability CONASSIF Agreement 5-24 expects from supervised entities.
  • The outsourcing angle deserves attention: the framework requires managing third-party technology provider relationships, so the MDR contract belongs in that inventory.

InternacionalInternational

  • Ningún marco exige MDR por nombre.
  • DORA y NIS2 exigen capacidades de detección y respuesta, y someten a los proveedores críticos de TIC a requisitos propios.
  • Bajo DORA, un proveedor de estos servicios puede quedar sujeto al régimen de terceros, lo que hay que revisar en el contrato.
  • No framework requires MDR by name.
  • DORA and NIS2 require detection and response capabilities, and subject critical ICT providers to their own requirements.
  • Under DORA, a provider of these services may fall under the third-party regime, which should be reviewed in the contract.

Requisitos mínimosMinimum requirements

  • Agentes desplegados en los equipos, porque la contención se ejecuta desde ahí.
  • Autorización previa y por escrito de qué acciones puede tomar el proveedor sin consultar: es la decisión central del servicio.
  • Una lista de sistemas que nunca se aíslan automáticamente, porque hay servidores donde la cura sería peor que la enfermedad.
  • Contacto de escalado disponible 24×7 del lado del cliente.
  • Agents deployed on endpoints, since containment executes from there.
  • Prior written authorisation of which actions the provider may take without asking: it is the service's central decision.
  • A list of systems that are never isolated automatically, because there are servers where the cure would be worse than the disease.
  • A 24×7 escalation contact on the client side.

Plazo típico de entregaTypical delivery time

Servicio continuo Ongoing service rango habitual del mercado usual market range

Es un servicio continuo, normalmente por doce o veinticuatro meses. El despliegue va de tres a seis semanas: instalar agentes, conectar fuentes, acordar el manual de respuesta y afinar. La parte que más discusión genera no es técnica sino el alcance de la autorización para actuar.

This is a continuous service, usually for twelve or twenty-four months. Deployment takes three to six weeks: installing agents, connecting sources, agreeing the response playbook and tuning. The part that generates most discussion is not technical but the scope of the authorisation to act.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

MDRMDR
Detección y respuesta gestionadas: el proveedor detecta, investiga y contiene, no solo avisa. Managed detection and response: the provider detects, investigates and contains, not merely alerts.
ContenciónContainment
Acción que corta el avance del atacante, como aislar un equipo de la red o deshabilitar una cuenta. Action cutting off the attacker's progress, such as isolating a machine or disabling an account.
PlaybookPlaybook
Procedimiento acordado que define qué se hace ante cada tipo de incidente y quién lo autoriza. An agreed procedure defining what happens for each incident type and who authorises it.
MTTRMTTR
Tiempo medio de respuesta: cuánto se tarda desde que se detecta hasta que se contiene. Mean time to respond: how long from detection to containment.