Monitorización 24×724×7 Monitoring
Vigilancia continua desde SIEM, EDR, firewalls, IDS/IPS.Continuous surveillance across SIEM, EDR, firewalls and IDS/IPS.
¿Qué es este servicio?What is this service?
Es la vigilancia continua de los registros y las alertas de los sistemas de seguridad de la organización —SIEM, EDR, cortafuegos, sistemas de detección— por un equipo que trabaja en turnos las veinticuatro horas, todos los días del año.
Continuous watch over the logs and alerts of the security systems in place — SIEM, EDR, firewalls, detection systems — by a team working shifts twenty-four hours a day, every day of the year.
¿Para qué se usa?What is it used for?
Sirve porque los ataques no respetan el horario de oficina. La mayoría del despliegue de ransomware ocurre de madrugada, en fin de semana o en feriado, precisamente porque el atacante sabe que no hay nadie mirando. Tener herramientas de detección sin nadie que atienda sus alertas fuera de horario es tener la mitad del control.
It matters because attacks do not respect office hours. Most ransomware deployment happens overnight, at weekends or on holidays, precisely because the attacker knows nobody is watching. Having detection tooling with nobody attending its alerts out of hours is having half the control.
Qué beneficios traeBenefits it delivers
- Cubre la franja donde ocurre la mayoría de los incidentes graves, que es justo la que un equipo interno pequeño no puede cubrir.
- Sale mucho más barato que montar turnos propios: un servicio 24×7 interno necesita al menos cinco o seis personas para ser sostenible.
- El equipo ve incidentes de muchos clientes, así que reconoce patrones que un analista de una sola organización no ha visto nunca.
- Da continuidad: no se cae porque alguien renunció o se enfermó.
- Covers the window where most serious incidents happen, which is exactly the one a small in-house team cannot cover.
- Costs far less than running in-house shifts: a sustainable internal 24×7 needs at least five or six people.
- The team sees incidents across many clients, so it recognises patterns a single-organisation analyst has never seen.
- Provides continuity: it does not collapse because somebody resigned or fell ill.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal de monitorizar 24×7 en Costa Rica.
- El Acuerdo CONASSIF 5-24 exige a las entidades supervisadas capacidades de monitoreo y respuesta ante incidentes, y añadió al perfil tecnológico una tabla de funciones de ciberseguridad donde esto se declara.
- La nueva clase de datos 56 pide el histórico de incidentes de seguridad, que solo se puede construir si alguien los está registrando.
- There is no legal obligation to monitor 24×7 in Costa Rica.
- CONASSIF Agreement 5-24 requires supervised entities to have monitoring and incident response capabilities, and added a cybersecurity functions table to the technology profile where this is disclosed.
- The new data class 56 asks for the security incident history, which can only be built if somebody is recording them.
InternacionalInternational
- PCI-DSS exige revisión diaria de registros de los componentes críticos y mecanismos de detección.
- NIS2 y DORA exigen capacidades de detección y notificación de incidentes en plazos cortos, que sin vigilancia continua no se cumplen.
- ISO 27001 exige monitorizar, medir y evaluar el desempeño de la seguridad.
- PCI-DSS requires daily log review of critical components and detection mechanisms.
- NIS2 and DORA require detection and incident notification within short deadlines, unachievable without continuous watch.
- ISO 27001 requires monitoring, measuring and evaluating security performance.
Requisitos mínimosMinimum requirements
- Fuentes de registro accesibles y con retención suficiente: sin datos no hay nada que vigilar.
- Conectividad hacia la plataforma de monitoreo y permisos de lectura sobre las fuentes.
- Un inventario de activos con su criticidad, para saber qué alerta importa más.
- Un procedimiento acordado de escalado: a quién llamar a las tres de la mañana y con qué autoridad para actuar.
- Accessible log sources with sufficient retention: without data there is nothing to watch.
- Connectivity to the monitoring platform and read permissions over the sources.
- An asset inventory with criticality, to know which alert matters most.
- An agreed escalation procedure: who to call at three in the morning and with what authority to act.
Plazo típico de entregaTypical delivery time
No es un proyecto sino un servicio continuo, contratado normalmente por doce o veinticuatro meses. La puesta en marcha va de cuatro a ocho semanas: conectar fuentes, afinar reglas y bajar el ruido inicial, que siempre es alto. El servicio se estabiliza hacia el segundo o tercer mes.
This is not a project but a continuous service, usually contracted for twelve or twenty-four months. Onboarding takes four to eight weeks: connecting sources, tuning rules and reducing the initial noise, which is always high. The service settles around the second or third month.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.