Política de Divulgación de Vulnerabilidades (VDP)Vulnerability Disclosure Policy (VDP)
Canal formal para que terceros reporten fallos de forma segura.A formal channel for third parties to report flaws safely.
¿Qué es este servicio?What is this service?
Es el canal formal y público para que cualquiera que encuentre un fallo en los sistemas de la organización pueda reportarlo sin miedo: una dirección de contacto conocida, reglas escritas de qué se puede probar, un compromiso de no tomar acciones legales contra quien respete esas reglas y un proceso interno que garantiza que el reporte llegue a alguien y se responda.
The formal, public channel for anyone who finds a flaw in the systems of the organisation to report it without fear: a known contact address, written rules on what may be tested, a commitment not to pursue legal action against those who follow them, and an internal process ensuring the report reaches somebody and gets answered.
¿Para qué se usa?What is it used for?
Cubre el caso que probablemente ya está ocurriendo sin que la organización lo sepa: alguien encontró un fallo en un sistema y no tiene cómo avisar. Sin canal, esa persona escribe a una dirección genérica que nadie lee, se cansa y publica. Una VDP es más barata y más sensata que un bug bounty como primer paso: no paga recompensas, no genera volumen incontrolable y establece el músculo de recibir y arreglar. Ese músculo es el requisito para todo lo demás.
It covers the case already happening without the organisation knowing: somebody found a flaw in a system and has no way to report it. With no channel, that person writes to a generic address nobody reads, gets tired and publishes. A VDP is cheaper and more sensible than a bug bounty as a first step: it pays no rewards, generates no uncontrollable volume and builds the muscle of receiving and fixing. That muscle is the prerequisite for everything else.
Qué beneficios traeBenefits it delivers
- Convierte a quien iba a publicar el fallo en alguien que lo reporta primero.
- Cuesta poco: es proceso y documento, no una plataforma con presupuesto de recompensas.
- Da certeza legal a ambas partes sobre qué está permitido y qué no, que es lo que hoy frena a la mayoría de los que quieren reportar.
- Es el paso previo natural a un bug bounty, y sirve para medir si la organización aguanta ese ritmo antes de pagar por él.
- Turns somebody who was going to publish the flaw into somebody who reports it first.
- Costs little: it is process and paperwork, not a platform with a rewards budget.
- Gives both sides legal certainty about what is allowed, which is what stops most would-be reporters today.
- It is the natural step before a bug bounty, and it measures whether the organisation can take that pace before paying for it.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal de publicar una VDP en Costa Rica.
- Sí es relevante que el documento deje por escrito la autorización para probar dentro del alcance, porque delimita lo que de otro modo podría verse como acceso no autorizado.
- Conviene incluir instrucciones sobre qué hacer si el investigador tropieza con datos personales, para no convertir un reporte de buena fe en un incidente bajo la Ley 8968.
- There is no legal obligation to publish a VDP in Costa Rica.
- It does matter that the document sets out in writing the authorisation to test within scope, since it delimits what might otherwise look like unauthorised access.
- It is wise to include instructions on what to do if the researcher stumbles upon personal data, so a good-faith report does not become an incident under Law 8968.
InternacionalInternational
- La norma de referencia es ISO/IEC 29147, sobre divulgación de vulnerabilidades: define cómo recibir los reportes y cómo publicar la información.
- Cada vez más contratos corporativos y licitaciones piden un canal de divulgación publicado como requisito de proveedor.
- Varias jurisdicciones han empujado la publicación de canales de este tipo en sectores regulados y en el sector público.
- The reference standard is ISO/IEC 29147 on vulnerability disclosure: it defines how to receive reports and how to publish the information.
- More and more corporate contracts and tenders ask for a published disclosure channel as a supplier requirement.
- Several jurisdictions have pushed the publication of such channels in regulated sectors and the public sector.
Requisitos mínimosMinimum requirements
- Una dirección de contacto que alguien lea de verdad, publicada donde se pueda encontrar sin buscar diez minutos.
- Alcance escrito: qué sistemas entran, qué técnicas están prohibidas y qué se espera de quien reporta.
- Visto bueno legal del texto, sobre todo del compromiso de no accionar contra quien investigue de buena fe.
- Un responsable interno con plazo de respuesta comprometido, aunque la primera respuesta sea solo un acuse de recibo.
- A contact address somebody actually reads, published where it can be found without a ten-minute search.
- Written scope: which systems are in, which techniques are forbidden and what is expected from the reporter.
- Legal sign-off on the text, especially on the commitment not to act against good-faith researchers.
- An internal owner with a committed response time, even if the first reply is only an acknowledgement.
Plazo típico de entregaTypical delivery time
El rango habitual va de dos a cinco semanas: redactar la política, acordar el alcance, pasar la revisión legal y publicar el canal. Lo que suele alargarlo no es el trabajo técnico sino la revisión jurídica del compromiso de no accionar, que en organizaciones grandes puede llevar más tiempo que todo el resto junto.
The usual range runs from two to five weeks: drafting the policy, agreeing scope, clearing legal review and publishing the channel. What tends to stretch it is not the technical work but the legal review of the no-action commitment, which in large organisations can take longer than everything else combined.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.