Despliegue de Zero TrustZero Trust Deployment
ZTNA, microsegmentación, verificación continua.ZTNA, microsegmentation and continuous verification.
¿Qué es este servicio?What is this service?
Es un modelo de arquitectura que parte de no confiar en nadie por estar dentro de la red: cada acceso se verifica, cada sesión se evalúa según el usuario, el dispositivo y el contexto, y los permisos se otorgan al mínimo y por tiempo limitado. Se implementa combinando identidad fuerte, acceso a aplicaciones sin VPN tradicional, segmentación y verificación continua.
An architecture model that starts from trusting nobody merely for being inside the network: every access is verified, every session is evaluated on user, device and context, and permissions are granted minimally and for a limited time. It is implemented by combining strong identity, application access without traditional VPN, segmentation and continuous verification.
¿Para qué se usa?What is it used for?
Sirve porque el perímetro dejó de existir: la gente trabaja desde su casa, las aplicaciones están en tres nubes distintas y la red interna ya no es un lugar seguro. Ahora lo incómodo: Zero Trust es una arquitectura, no un producto. Cualquier proveedor que ofrezca un Zero Trust en una caja está vendiendo humo. El despliegue real es progresivo, se hace por dominios y toma años.
It matters because the perimeter is gone: people work from home, applications sit across three clouds and the internal network is no longer a safe place. Now the uncomfortable part: Zero Trust is an architecture, not a product. Any vendor offering Zero Trust in a box is selling smoke. Real deployment is progressive, runs domain by domain and takes years.
Qué beneficios traeBenefits it delivers
- Quita valor a la credencial robada: tenerla ya no basta si el dispositivo no cumple y el contexto no cuadra.
- El acceso por aplicación en vez de por red hace que un proveedor externo entre solo al sistema que le toca, y no a toda la red interna.
- Cada fase entrega valor por su cuenta, así que no hay que esperar al final del programa para ver resultado.
- Da un criterio de decisión estable para los próximos años de inversión, en vez de comprar por moda.
- Devalues the stolen credential: having it is no longer enough if the device fails posture and the context does not add up.
- Access by application instead of by network means an external supplier reaches only their own system, not the whole internal network.
- Each phase delivers value on its own, so there is no need to wait for the end of the programme to see results.
- Provides a stable decision criterion for the coming years of investment, instead of buying by fashion.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay ninguna obligación legal de adoptar Zero Trust en Costa Rica, ni la va a haber pronto.
- Lo que sí exige el Acuerdo CONASSIF 5-24 a las entidades supervisadas es un marco de gestión de riesgo tecnológico con control de accesos, y Zero Trust es una forma coherente de estructurarlo, no un requisito.
- There is no legal obligation to adopt Zero Trust in Costa Rica, nor will there be one soon.
- What CONASSIF Agreement 5-24 does require from supervised entities is a technology risk framework with access control, and Zero Trust is a coherent way of structuring it, not a requirement.
InternacionalInternational
- Ningún marco regulatorio exige Zero Trust por nombre.
- En Estados Unidos hay mandatos de adopción para agencias federales, que arrastran a sus proveedores por vía contractual, pero eso no aplica al sector privado en general.
- Los controles concretos que lo componen —autenticación multifactor, mínimo privilegio, segregación de redes— sí están exigidos por PCI-DSS e ISO 27001 cada uno por su lado.
- No regulatory framework requires Zero Trust by name.
- In the United States there are adoption mandates for federal agencies, which pull their suppliers along contractually, but that does not apply to the private sector at large.
- The individual controls it is built from — multi-factor authentication, least privilege, network segregation — are each required by PCI-DSS and ISO 27001 in their own right.
Requisitos mínimosMinimum requirements
- Una identidad centralizada y confiable: sin eso no hay Zero Trust, hay marketing.
- Capacidad de evaluar el estado del dispositivo, que en la práctica significa tener EDR y gestión de equipos desplegados.
- Un inventario de aplicaciones y de quién debe acceder a cada una, que casi siempre hay que construir desde cero.
- Aceptar que es un programa plurianual con fases, y no un proyecto con fecha de cierre.
- Centralised, trustworthy identity: without it there is no Zero Trust, only marketing.
- The ability to assess device posture, which in practice means having EDR and device management deployed.
- An inventory of applications and who should reach each one, which nearly always has to be built from scratch.
- Accepting that it is a multi-year phased programme, not a project with a closing date.
Plazo típico de entregaTypical delivery time
El rango honesto de un programa completo va de doce a treinta y seis meses. La primera fase —identidad fuerte y acceso a aplicaciones para usuarios remotos— se entrega en dos o tres meses y ya cambia la postura de forma visible. Lo que estira el plazo son los sistemas antiguos que no soportan autenticación moderna: ahí hay que decidir entre modernizar, aislar o convivir con la excepción documentada.
The honest range for a full programme runs from twelve to thirty-six months. The first phase — strong identity and application access for remote users — lands in two or three months and already shifts the posture visibly. What stretches the timeline are legacy systems that cannot handle modern authentication: there the choice lies between modernising, isolating or living with a documented exception.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.