Saltar al contenido
02 · Auditoría02 · Auditing

Pentest como Servicio (PTaaS)Penetration Testing as a Service (PTaaS)

Pruebas continuas por suscripción con portal de hallazgos en vivo.Continuous subscription-based testing with a live findings portal.

Suscripción anualAnnual subscription 2.1 · Auditorías Técnicas (Hacking Ético)2.1 · Technical Audits (Ethical Hacking)

¿Qué es este servicio?What is this service?

Es el pentest contratado como suscripción en vez de como proyecto suelto: pruebas recurrentes durante el año, con los hallazgos publicados en un portal a medida que aparecen en vez de en un PDF al final.

Penetration testing bought as a subscription instead of a one-off project: recurring testing across the year, with findings published to a portal as they appear rather than in a PDF at the end.

¿Para qué se usa?What is it used for?

Sirve cuando el sistema cambia más rápido de lo que se prueba. Un pentest anual fotografía un momento; si la organización despliega cada dos semanas, esa foto caduca enseguida. Con suscripción, cada cambio relevante se prueba, el equipo de desarrollo ve el hallazgo el mismo día y el retest está incluido.

It fits when the system changes faster than it gets tested. An annual test photographs a moment; where the organisation deploys every two weeks, that photograph expires immediately. With a subscription, each significant change gets tested, the development team sees the finding the same day and retesting is included.

Qué beneficios traeBenefits it delivers

  • Acorta el tiempo entre que se introduce un fallo y que se detecta, que es la métrica que realmente importa.
  • El hallazgo llega al desarrollador mientras todavía recuerda el código, lo que abarata la corrección de forma considerable.
  • Convierte un gasto puntual grande en un costo mensual previsible.
  • El retest incluido evita la discusión de si la corrección funcionó o no.
  • Shortens the time between a flaw being introduced and being detected, the metric that actually matters.
  • The finding reaches the developer while they still remember the code, which makes fixing it far cheaper.
  • Turns a large one-off expense into a predictable monthly cost.
  • Included retesting removes the argument over whether the fix worked.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal en Costa Rica.
  • Sirve igual que un pentest tradicional como evidencia ante entidades supervisadas, siempre que se conserven los informes de cada ciclo.
  • There is no legal obligation in Costa Rica.
  • It serves as evidence for supervised entities just like a traditional test, provided the reports from each cycle are retained.

InternacionalInternational

  • PCI-DSS acepta la modalidad siempre que se cumpla la frecuencia mínima y la metodología exigidas: al menos cada doce meses y tras cambios significativos.
  • Conviene atender un detalle contractual: si el auditor pide un informe formal de pentest, la suscripción tiene que emitirlo y no limitarse a dejar tiquetes en un portal.
  • PCI-DSS accepts the model provided the required minimum frequency and methodology are met: at least every twelve months and after significant changes.
  • One contractual detail deserves attention: if the auditor asks for a formal penetration test report, the subscription has to issue one and not merely leave tickets in a portal.

Requisitos mínimosMinimum requirements

  • Un alcance estable definido al inicio, con un procedimiento para incorporar activos nuevos.
  • Autorización marco que cubra todo el periodo, en vez de una por cada prueba.
  • Un canal con el equipo de desarrollo, porque el valor del modelo está en la velocidad de reacción.
  • Ambientes de prueba disponibles de forma continua, no solo durante una ventana anual.
  • A stable scope defined at the outset, with a procedure for adding new assets.
  • A framework authorisation covering the whole period rather than one per test.
  • A channel to the development team, since the model's value lies in reaction speed.
  • Test environments continuously available, not only during an annual window.

Plazo típico de entregaTypical delivery time

Suscripción anual Annual subscription rango habitual del mercado usual market range

No es un proyecto con fecha de cierre sino un servicio continuo, normalmente contratado por doce meses. El primer ciclo completo se entrega entre dos y cuatro semanas después del arranque, y a partir de ahí los hallazgos se publican de forma continua con ciclos de prueba mensuales o trimestrales según el plan.

This is not a project with an end date but a continuous service, usually contracted for twelve months. The first full cycle is delivered two to four weeks after kickoff, and from then on findings are published continuously with monthly or quarterly testing cycles depending on the plan.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

PTaaSPTaaS
Penetration Testing as a Service: pentest entregado como suscripción continua con portal de hallazgos. Penetration Testing as a Service: testing delivered as a continuous subscription with a findings portal.
Ventana de pruebasTesting window
El periodo acordado durante el cual se puede atacar. En este modelo es amplio o permanente. The agreed period during which testing may occur. In this model it is broad or permanent.
RetestRetest
Verificación de que una corrección realmente cerró el hallazgo. En este modelo va incluido en la suscripción. Verification that a fix genuinely closed the finding. In this model it is included in the subscription.
PentestPentest
Prueba de intrusión: se ataca el sistema con autorización previa y por escrito, para encontrar lo que encontraría un atacante real. Penetration test: the system is attacked with prior written authorisation, to find what a real attacker would find.
RoERoE
Reglas de compromiso: el documento que define qué se puede atacar, cuándo, con qué técnicas y a quién avisar. Rules of Engagement: the document defining what may be attacked, when, with which techniques and who to notify.
MITRE ATT&CKMITRE ATT&CK
Base de conocimiento pública de tácticas y técnicas usadas por atacantes reales. Public knowledge base of tactics and techniques used by real attackers.