Saltar al contenido
01 · Consultoría01 · Consulting

NIST CSF 2.0NIST CSF 2.0

Adopción del marco del NIST, incluida la función Gobernar.Adoption of the NIST framework, including the Govern function.

NIST CSF 2.0NIST CSF 2.0 1.2 · Consultoría Normativa y de Cumplimiento1.2 · Regulatory and Compliance Consulting

¿Qué es este servicio?What is this service?

Es la adopción del marco de ciberseguridad del NIST en su versión 2.0, que organiza la seguridad en seis funciones: Gobernar, Identificar, Proteger, Detectar, Responder y Recuperar. La función Gobernar es la novedad de esta versión.

Adoption of the NIST Cybersecurity Framework version 2.0, which organises security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. The Govern function is what is new in this version.

¿Para qué se usa?What is it used for?

Sirve como columna vertebral cuando no hay un regulador que imponga un marco concreto. Es flexible, no se certifica y se entiende rápido en una junta directiva. Se usa para medir madurez, ordenar el programa de seguridad y comunicar avance hacia arriba.

It works as the backbone when no regulator imposes a specific framework on the organisation. It is flexible, not certifiable and easy to explain to a board. It is used to measure maturity, structure the security programme and communicate progress upwards.

Qué beneficios traeBenefits it delivers

  • Es gratuito y de uso libre, sin costo de licencia ni de certificación.
  • La función Gobernar pone el foco en el punto donde más organizaciones fallan: decidir y rendir cuentas.
  • Su lenguaje es comprensible para no técnicos, lo que facilita conversar con la dirección.
  • Mapea bien contra ISO 27001, CIS y los requisitos de la mayoría de reguladores.
  • It is free to use, with no licensing or certification cost.
  • The Govern function focuses on where most organisations fail: deciding and being accountable.
  • Its language is understandable to non-technical people, which makes board conversations easier.
  • It maps well against ISO 27001, CIS and most regulators' requirements.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No es obligatorio en Costa Rica ni existe certificación oficial contra él.
  • Es una de las referencias habituales para sustentar el marco de gestión que pide el Acuerdo CONASSIF 5-24.
  • It is not mandatory in Costa Rica and there is no official certification against it.
  • It is one of the usual references used to evidence the management framework CONASSIF Agreement 5-24 requires.

InternacionalInternational

  • No es obligatorio con carácter general; es voluntario por diseño.
  • En Estados Unidos hay contratos y regulaciones sectoriales que lo toman como referencia.
  • Muchos cuestionarios de clientes y de aseguradoras preguntan directamente por el nivel alcanzado en sus funciones.
  • Not generally mandatory; it is voluntary by design.
  • In the United States, contracts and sector regulations reference it.
  • Many client and insurer questionnaires ask directly about the level reached across its functions.

Requisitos mínimosMinimum requirements

  • Definir el perfil objetivo: no todas las organizaciones necesitan el mismo nivel en cada función.
  • Inventario de activos y de procesos críticos.
  • Participación de negocio para la función Gobernar, que no es un tema técnico.
  • Un punto de partida medido, para poder demostrar avance después.
  • Defining the target profile: not every organisation needs the same level in every function.
  • An inventory of assets and critical processes.
  • Business participation for the Govern function, which is not a technical topic.
  • A measured starting point, so progress can be demonstrated later.

Plazo típico de entregaTypical delivery time

3 a 8 semanas 3 to 8 weeks rango habitual del mercado usual market range

El rango de mercado va de tres a ocho semanas para el perfil actual, el perfil objetivo y el plan para cerrar la distancia. Implantar lo que salga de ahí es otro proyecto y depende por completo de las brechas encontradas.

The market range runs from three to eight weeks for the current profile, target profile and the plan to close the gap. Implementing what comes out of it is a separate project and depends entirely on the gaps found.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

NISTNIST
National Institute of Standards and Technology, el instituto de estándares de Estados Unidos. National Institute of Standards and Technology, the US standards institute.
CSFCSF
Cybersecurity Framework. Su versión 2.0 agregó la función Gobernar a las cinco originales. Cybersecurity Framework. Version 2.0 added the Govern function to the original five.
PerfilProfile
La descripción del nivel que la organización tiene, o quiere tener, en cada categoría del marco. The description of the level an organisation has, or wants, in each framework category.
TierTier
Nivel de rigor con el que la organización gestiona el riesgo, de parcial a adaptativo. The degree of rigour with which the organisation manages risk, from partial to adaptive.