Saltar al contenido
01 · Consultoría01 · Consulting

Plan Director de SeguridadSecurity Master Plan

Estrategia a 1, 2 y 3 años alineada con el negocio.One, two and three year strategy aligned with the business.

Roadmap + matriz RACIRoadmap and RACI matrix 1.1 · Consultoría Estratégica de Seguridad1.1 · Strategic Security Consulting

¿Qué es este servicio?What is this service?

Es el plan que define qué va a hacer la organización en seguridad durante los próximos uno, dos y tres años, con iniciativas priorizadas, responsables, presupuesto estimado y orden de ejecución.

The plan defining what the organisation will do in security over the next one, two and three years, with prioritised initiatives, owners, estimated budget and execution order.

¿Para qué se usa?What is it used for?

Sirve para convertir una lista de hallazgos en un programa ejecutable. Un diagnóstico dice qué está mal; el plan director dice en qué orden se arregla, con qué presupuesto, quién responde y qué se deja para después de forma consciente. Sin él, la seguridad avanza por urgencias y por lo que se le ocurra al proveedor de turno.

It turns a list of findings into an executable programme. An assessment says what is wrong; the master plan says in what order it gets fixed, with what budget, who owns it and what is consciously deferred. Without it, security advances by emergencies and by whatever the current vendor suggests.

Qué beneficios traeBenefits it delivers

  • Da previsibilidad presupuestaria: la dirección ve el gasto de seguridad de tres años, no una sorpresa por trimestre.
  • Ordena las dependencias, porque hay controles que no se pueden montar antes que otros.
  • Convierte la seguridad en un tema de negocio, con iniciativas atadas a riesgo y no a moda tecnológica.
  • Sirve de evidencia ante reguladores y auditores de que hay un enfoque planificado y no reactivo.
  • Provides budget predictability: management sees three years of security spend instead of a quarterly surprise.
  • Sorts out dependencies, since some controls cannot be built before others.
  • Turns security into a business conversation, with initiatives tied to risk rather than to technology fashion.
  • Serves as evidence to regulators and auditors that the approach is planned rather than reactive.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal general de tener un plan director de seguridad con ese nombre.
  • El Acuerdo CONASSIF 5-24 exige que el marco de gobierno y gestión de TI esté alineado con la estrategia y la complejidad del negocio, y que el órgano de dirección lo apruebe: eso en la práctica se materializa en un plan.
  • En el sector público, la planificación de TI es parte de lo que revisa la Contraloría.
  • There is no general legal obligation to have a security master plan under that name.
  • CONASSIF Agreement 5-24 requires the IT governance and management framework to be aligned with business strategy and complexity and approved by the board: in practice that materialises as a plan.
  • In the public sector, IT planning is part of what the Comptroller reviews.

InternacionalInternational

  • ISO 27001 exige objetivos de seguridad y planes para alcanzarlos, que es exactamente esto.
  • DORA y NIS2 exigen a las entidades cubiertas una gestión de riesgos con planificación demostrable.
  • Muchos contratos corporativos y pólizas de ciberseguro piden ver el plan antes de firmar.
  • ISO 27001 requires security objectives and plans to achieve them, which is exactly this.
  • DORA and NIS2 require covered entities to have risk management with demonstrable planning.
  • Many corporate contracts and cyber insurance policies ask to see the plan before signing.

Requisitos mínimosMinimum requirements

  • Un diagnóstico previo o al menos un inventario de brechas conocidas; sin punto de partida no hay plan.
  • Claridad sobre el apetito de riesgo y las prioridades del negocio para los próximos años.
  • Un rango de presupuesto realista, aunque sea aproximado: un plan sin cifras no se ejecuta.
  • Interlocución con dirección, porque el plan se aprueba arriba o no se aprueba.
  • A prior assessment or at least an inventory of known gaps; without a starting point there is no plan.
  • Clarity on risk appetite and business priorities for the coming years.
  • A realistic budget range, even approximate: a plan without figures does not get executed.
  • Access to senior management, because the plan is approved at the top or not at all.

Plazo típico de entregaTypical delivery time

4 a 8 semanas 4 to 8 weeks rango habitual del mercado usual market range

El rango de mercado va de cuatro a ocho semanas cuando ya existe un diagnóstico. Si el diagnóstico hay que hacerlo primero, conviene sumar entre tres y seis semanas más. La parte lenta no es escribir el plan sino acordar prioridades entre áreas que compiten por el mismo presupuesto.

The market range runs from four to eight weeks when an assessment already exists. If the assessment has to be done first, another three to six weeks should be added. The slow part is not writing the plan but agreeing priorities across areas competing for the same budget.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

Plan directorMaster plan
Documento maestro que ordena todas las iniciativas de seguridad en el tiempo, con responsables y presupuesto. Master document that sequences all security initiatives over time, with owners and budget.
Hoja de rutaRoadmap
La representación temporal del plan: qué se hace en cada trimestre o año. The plan's timeline view: what gets done each quarter or year.
RACIRACI
Matriz que define para cada tarea quién la ejecuta, quién responde por ella, a quién se consulta y a quién se informa. Matrix defining, for each task, who performs it, who is accountable, who is consulted and who is informed.
Apetito de riesgoRisk appetite
Cuánto riesgo está dispuesta a aceptar la organización antes de tener que actuar. How much risk the organisation is willing to accept before it must act.