{"id":17374,"date":"2018-07-06T10:12:05","date_gmt":"2018-07-06T08:12:05","guid":{"rendered":"http:\/\/www.mtp.es\/?p=17374"},"modified":"2026-08-30T21:32:16","modified_gmt":"2026-08-30T19:32:16","slug":"las-6-practicas-para-el-cumplimiento-con-la-gdpr","status":"publish","type":"post","link":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/","title":{"rendered":"Cumplimiento RGPD: 6 pr\u00e1cticas clave para proteger los datos"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">El <\/span><b>cumplimiento RGPD<\/b><span style=\"font-weight: 400;\"> no se consigue mediante una acci\u00f3n puntual. Requiere revisar de manera continua c\u00f3mo una organizaci\u00f3n recopila, utiliza, almacena, comparte y protege los datos personales durante todo su ciclo de vida.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">El Reglamento General de Protecci\u00f3n de Datos \u2014<\/span><b>RGPD o GDPR, por sus siglas en ingl\u00e9s<\/b><span style=\"font-weight: 400;\">\u2014 establece un modelo basado en la responsabilidad proactiva: las empresas no solo deben aplicar las medidas necesarias para proteger los datos, sino tambi\u00e9n ser capaces de demostrar que las han implantado de acuerdo con los riesgos existentes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Esto hace que protecci\u00f3n de datos y<\/span><a href=\"https:\/\/mtp.global\/es\/servicios\/ciberseguridad\/\"> <span style=\"font-weight: 400;\">ciberseguridad<\/span><\/a><span style=\"font-weight: 400;\"> est\u00e9n estrechamente relacionadas. Controles de acceso, formaci\u00f3n, auditor\u00edas, desarrollo seguro, gesti\u00f3n de vulnerabilidades y respuesta ante incidentes son algunas de las piezas que permiten reducir los riesgos asociados al tratamiento de informaci\u00f3n personal.<\/span><\/p>\n<h2><b>El cumplimiento RGPD, de un vistazo<\/b><\/h2>\n<table>\n<tbody>\n<tr>\n<td><b>\u00c1rea<\/b><\/td>\n<td><b>Medida clave<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>Personas<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Formaci\u00f3n y concienciaci\u00f3n<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Accesos<\/b><\/td>\n<td><span style=\"font-weight: 400;\">M\u00ednimo privilegio y autenticaci\u00f3n robusta<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Riesgos<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Evaluaci\u00f3n peri\u00f3dica<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Aplicaciones<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Seguridad y privacidad desde el dise\u00f1o<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Infraestructura<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Auditor\u00edas y monitorizaci\u00f3n<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>Brechas<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Detecci\u00f3n, respuesta y documentaci\u00f3n<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">\u2705 <\/span><b>Idea clave:<\/b><span style=\"font-weight: 400;\"> cumplir el RGPD significa mantener un proceso continuo de <\/span><b>identificaci\u00f3n de riesgos, implantaci\u00f3n de controles, supervisi\u00f3n y mejora<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><b>\u00bfQu\u00e9 significa cumplir con el RGPD?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">El <\/span><b>cumplimiento RGPD<\/b><span style=\"font-weight: 400;\"> implica aplicar los principios y obligaciones de protecci\u00f3n de datos durante toda la vida de un tratamiento.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Entre sus principios fundamentales se encuentran:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Licitud, lealtad y transparencia.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limitaci\u00f3n de la finalidad.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Minimizaci\u00f3n de datos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exactitud.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limitaci\u00f3n del plazo de conservaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integridad y confidencialidad.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Responsabilidad proactiva.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">La empresa debe poder responder a preguntas como:<\/span><\/p>\n<p><b>\u00bfQu\u00e9 datos personales tratamos?<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>\u00bfPara qu\u00e9 los necesitamos?<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>\u00bfQui\u00e9n puede acceder?<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>\u00bfDurante cu\u00e1nto tiempo los conservamos?<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>\u00bfQu\u00e9 riesgos existen?<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>\u00bfQu\u00e9 controles hemos implantado?<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>\u00bfPodemos demostrarlo?<\/b><\/p>\n<p><span style=\"font-weight: 400;\">El cumplimiento, por tanto, no consiste \u00fanicamente en disponer de documentos legales. Debe reflejarse en el funcionamiento real de la organizaci\u00f3n.<\/span><\/p>\n<h2><b>1. Formar y concienciar a los empleados<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Las personas que trabajan con datos personales toman diariamente decisiones que pueden afectar a su seguridad.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Un empleado puede:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recibir un correo de phishing.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compartir un documento.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enviar informaci\u00f3n al destinatario equivocado.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Utilizar una contrase\u00f1a insegura.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perder un dispositivo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Facilitar datos a una persona no autorizada.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detectar una posible brecha.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Por ello, la formaci\u00f3n forma parte de cualquier estrategia eficaz de protecci\u00f3n de datos.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Los programas de<\/span><a href=\"https:\/\/ciberso.com\/servicios\/concienciacion-sobre-ciberseguridad\/\"> <span style=\"font-weight: 400;\">concienciaci\u00f3n sobre ciberseguridad<\/span><\/a><span style=\"font-weight: 400;\"> ayudan a que los empleados reconozcan amenazas y sepan c\u00f3mo proteger la informaci\u00f3n que manejan.<\/span><\/p>\n<h3><b>\u00bfQu\u00e9 deber\u00eda conocer un empleado?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">\u2713 C\u00f3mo identificar datos personales y sensibles.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 C\u00f3mo compartir informaci\u00f3n de manera segura.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 C\u00f3mo detectar phishing e ingenier\u00eda social.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 C\u00f3mo utilizar correctamente contrase\u00f1as y MFA.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 Qu\u00e9 herramientas corporativas puede utilizar.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 C\u00f3mo informar de una posible brecha.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 Qu\u00e9 hacer si env\u00eda informaci\u00f3n por error.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 A qui\u00e9n debe acudir cuando tiene dudas.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La formaci\u00f3n debe adaptarse al puesto.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Un profesional de Recursos Humanos, por ejemplo, maneja riesgos diferentes a los de un desarrollador, un administrador de sistemas o un comercial.<\/span><\/p>\n<h2><b>2. Gestionar correctamente identidades, accesos y privilegios<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">No todas las personas necesitan acceder a todos los datos.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Uno de los principios t\u00e9cnicos m\u00e1s importantes consiste en aplicar el <\/span><b>m\u00ednimo privilegio<\/b><span style=\"font-weight: 400;\">: cada usuario debe disponer \u00fanicamente de los permisos necesarios para desarrollar sus funciones.<\/span><\/p>\n<h3><b>Un modelo adecuado deber\u00eda controlar:<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Altas de usuarios.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Modificaciones de permisos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cambios de puesto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accesos privilegiados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cuentas administrativas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Usuarios externos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cuentas inactivas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bajas de empleados.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">El ciclo deber\u00eda ser:<\/span><\/p>\n<p><b>Alta<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Asignaci\u00f3n de permisos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Revisi\u00f3n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Cambio de funciones<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Actualizaci\u00f3n de permisos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Baja<\/b><\/p>\n<h3><b>Autenticaci\u00f3n multifactor<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">La autenticaci\u00f3n multifactor a\u00f1ade una capa adicional frente al robo de credenciales.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Una contrase\u00f1a comprometida no deber\u00eda convertirse autom\u00e1ticamente en acceso a informaci\u00f3n sensible.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Por eso, MFA resulta especialmente importante en:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cuentas administrativas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceso remoto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Servicios cloud.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Correo corporativo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Aplicaciones con datos sensibles.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sistemas cr\u00edticos.<\/span><\/li>\n<\/ul>\n<h3><b>Revisar tambi\u00e9n el comportamiento an\u00f3malo<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Las organizaciones pueden complementar los controles de identidad con sistemas capaces de detectar comportamientos inusuales.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Por ejemplo:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u26a0\ufe0f Accesos desde ubicaciones inesperadas.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u26a0\ufe0f Descargas masivas.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u26a0\ufe0f Actividad fuera del horario habitual.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u26a0\ufe0f Uso extra\u00f1o de privilegios.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u26a0\ufe0f Acceso a informaci\u00f3n no utilizada normalmente.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La finalidad no es vigilar indiscriminadamente a los empleados, sino identificar comportamientos que puedan indicar una cuenta comprometida o un incidente, respetando siempre los requisitos legales aplicables.<\/span><\/p>\n<h2><b>3. Realizar una evaluaci\u00f3n de riesgos de protecci\u00f3n de datos<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">No todos los tratamientos presentan el mismo nivel de riesgo.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Una organizaci\u00f3n debe analizar qu\u00e9 consecuencias podr\u00eda tener para las personas una p\u00e9rdida de confidencialidad, integridad o disponibilidad de sus datos.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La evaluaci\u00f3n deber\u00eda considerar:<\/span><\/p>\n<p><b>Activos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Datos personales tratados<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Amenazas<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Vulnerabilidades<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Probabilidad<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Impacto sobre las personas<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Medidas de reducci\u00f3n del riesgo<\/b><\/p>\n<h3><b>\u00bfQu\u00e9 debemos analizar?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Entre otros elementos:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tipo de datos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cantidad de informaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Finalidad del tratamiento.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">N\u00famero de personas afectadas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sistemas utilizados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accesos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proveedores.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transferencias.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nivel de exposici\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Consecuencias de una posible brecha.<\/span><\/li>\n<\/ul>\n<h3><b>Evaluaciones de impacto<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cuando un tratamiento pueda entra\u00f1ar un <\/span><b>alto riesgo para los derechos y libertades de las personas<\/b><span style=\"font-weight: 400;\">, puede resultar necesaria una Evaluaci\u00f3n de Impacto relativa a la Protecci\u00f3n de Datos (EIPD).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No se trata de evaluar \u00fanicamente el riesgo t\u00e9cnico para la empresa.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La pregunta fundamental es:<\/span><\/p>\n<p><b>\u00bfQu\u00e9 consecuencias podr\u00eda tener este tratamiento para las personas cuyos datos estamos utilizando?<\/b><\/p>\n<h2><b>4. Incorporar privacidad y seguridad desde el dise\u00f1o<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Una de las principales evoluciones introducidas por el RGPD es el concepto de <\/span><b>protecci\u00f3n de datos desde el dise\u00f1o y por defecto<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La privacidad no deber\u00eda a\u00f1adirse cuando una aplicaci\u00f3n ya est\u00e1 terminada.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Debe considerarse desde el momento en que se dise\u00f1a:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una aplicaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Un nuevo servicio.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Un formulario.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una base de datos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una integraci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una automatizaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Un proceso empresarial.<\/span><\/li>\n<\/ul>\n<h3><b>Privacidad desde el dise\u00f1o<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Antes de desarrollar debemos preguntarnos:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u2713 \u00bfNecesitamos realmente todos estos datos?<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 \u00bfQui\u00e9n necesita acceder?<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 \u00bfDurante cu\u00e1nto tiempo deben conservarse?<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 \u00bfPodemos reducir la cantidad de informaci\u00f3n?<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 \u00bfEs posible aplicar seudonimizaci\u00f3n o cifrado?<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2713 \u00bfQu\u00e9 ocurrir\u00eda si estos datos quedaran expuestos?<\/span><\/p>\n<h3><b>Privacidad por defecto<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Las opciones iniciales deber\u00edan ofrecer un nivel adecuado de protecci\u00f3n sin obligar al usuario a modificar configuraciones innecesariamente.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Por ejemplo:<\/span><\/p>\n<p><b>Menos datos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">+<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Menos accesos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">+<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Menor conservaci\u00f3n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">+<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Mayor protecci\u00f3n por defecto<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incorporar estas comprobaciones dentro de metodolog\u00edas de<\/span><a href=\"https:\/\/ciberso.com\/servicios\/devsecops\/\"> <span style=\"font-weight: 400;\">DevOps<\/span><\/a><span style=\"font-weight: 400;\"> ayuda a integrar seguridad y protecci\u00f3n de datos durante las diferentes fases del ciclo de vida del software.<\/span><\/p>\n<h3><b>Auditor\u00edas de seguridad para aplicaciones<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Las aplicaciones que procesan informaci\u00f3n personal pueden contener vulnerabilidades que pongan en riesgo los datos.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Las<\/span><a href=\"https:\/\/ciberso.com\/servicios\/auditorias-aplicaciones-y-software\/\"> <span style=\"font-weight: 400;\">auditor\u00edas, aplicaciones y software<\/span><\/a><span style=\"font-weight: 400;\"> permiten analizar posibles debilidades mediante diferentes aproximaciones.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Seg\u00fan el sistema, pueden combinarse:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An\u00e1lisis est\u00e1tico de c\u00f3digo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An\u00e1lisis din\u00e1mico.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revisi\u00f3n de dependencias.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pruebas manuales.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pentesting.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revisi\u00f3n de configuraciones.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">El objetivo debe ser identificar las vulnerabilidades y establecer un proceso para:<\/span><\/p>\n<p><b>Detectar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Priorizar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Corregir<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Verificar<\/b><\/p>\n<h2><b>5. Auditar infraestructuras y monitorizar amenazas<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">La protecci\u00f3n de datos tampoco termina en la aplicaci\u00f3n.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Servidores, redes, dispositivos, servicios cloud y sistemas de acceso forman parte del entorno que soporta los tratamientos.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Las<\/span><a href=\"https:\/\/ciberso.com\/servicios\/auditorias-de-infraestructuras\/\"> <span style=\"font-weight: 400;\">auditor\u00edas de infraestructuras<\/span><\/a><span style=\"font-weight: 400;\"> ayudan a identificar vulnerabilidades, configuraciones inseguras y servicios expuestos que podr\u00edan afectar a la protecci\u00f3n de la informaci\u00f3n.<\/span><\/p>\n<h3><b>\u00bfQu\u00e9 conviene revisar?<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sistemas expuestos a Internet.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Servicios innecesarios.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuraciones.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segmentaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accesos remotos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Equipos sin actualizar.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilegios.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sistemas antiguos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Activos desconocidos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controles de monitorizaci\u00f3n.<\/span><\/li>\n<\/ul>\n<h3><b>Auditor\u00edas internas y externas<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Ambas perspectivas aportan informaci\u00f3n diferente.<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Auditor\u00eda externa<\/b><\/td>\n<td><b>Auditor\u00eda interna<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Analiza la exposici\u00f3n desde Internet<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Analiza riesgos desde dentro de la red<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Identifica servicios p\u00fablicos<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Revisa accesos internos<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Simula una perspectiva externa<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Eval\u00faa posibles movimientos internos<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Revisa superficie de ataque<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Ayuda a comprobar segmentaci\u00f3n y privilegios<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">La combinaci\u00f3n permite obtener una imagen m\u00e1s completa de la exposici\u00f3n tecnol\u00f3gica.<\/span><\/p>\n<h3><b>Monitorizaci\u00f3n y detecci\u00f3n<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Las medidas preventivas deben complementarse con capacidad para detectar posibles incidentes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Una organizaci\u00f3n necesita saber cu\u00e1ndo se produce:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Un acceso an\u00f3malo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una elevaci\u00f3n de privilegios.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una descarga inesperada.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una conexi\u00f3n sospechosa.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una actividad inusual.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una posible fuga de informaci\u00f3n.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">El objetivo es reducir el tiempo entre:<\/span><\/p>\n<p><b>Inicio del incidente \u2192 detecci\u00f3n \u2192 an\u00e1lisis \u2192 respuesta<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cuanto antes se detecta un incidente, mayores son las posibilidades de limitar sus consecuencias.<\/span><\/p>\n<h2><b>Ciberinteligencia para conocer amenazas relevantes<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">No todas las organizaciones se enfrentan exactamente a las mismas amenazas.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La<\/span><a href=\"https:\/\/ciberso.com\/servicios\/ciberinteligencia\/\"> <span style=\"font-weight: 400;\">ciberinteligencia<\/span><\/a><span style=\"font-weight: 400;\"> permite aportar contexto sobre vulnerabilidades, campa\u00f1as, t\u00e9cnicas y actores que pueden afectar a determinados sectores o activos.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Esto ayuda a priorizar.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">En lugar de intentar tratar todos los riesgos de la misma manera, una organizaci\u00f3n puede concentrar recursos en aquellos escenarios que resultan m\u00e1s relevantes.<\/span><\/p>\n<p><b>Informaci\u00f3n sobre amenazas<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Contexto empresarial<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Priorizaci\u00f3n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Controles espec\u00edficos<\/b><\/p>\n<h2><b>6. Prepararse para gestionar una brecha de datos personales<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Incluso una organizaci\u00f3n con buenos controles puede sufrir un incidente.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Por eso, el <\/span><b>cumplimiento RGPD<\/b><span style=\"font-weight: 400;\"> tambi\u00e9n exige preparaci\u00f3n para responder.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Una brecha de datos personales puede afectar a:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">La confidencialidad.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">La integridad.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">La disponibilidad.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">No se limita, por tanto, al robo de informaci\u00f3n.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La p\u00e9rdida accidental de datos, su modificaci\u00f3n no autorizada o la indisponibilidad de determinada informaci\u00f3n tambi\u00e9n pueden constituir incidentes relevantes.<\/span><\/p>\n<h3><b>\u00bfQu\u00e9 hacer ante una posible brecha?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">El proceso deber\u00eda estar definido antes del incidente.<\/span><\/p>\n<p><b>Detectar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Contener<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Analizar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Determinar los datos afectados<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Evaluar el riesgo para las personas<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Documentar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Notificar cuando corresponda<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2193<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Corregir y aprender<\/b><\/p>\n<h3><b>El plazo de 72 horas<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Cuando una brecha de datos personales pueda suponer un riesgo para los derechos y libertades de las personas, el responsable debe notificarla a la autoridad de control <\/span><b>sin dilaci\u00f3n indebida y, cuando sea posible, dentro de las 72 horas desde que tenga conocimiento de ella<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Adem\u00e1s, determinadas brechas de alto riesgo pueden requerir comunicaci\u00f3n a las personas afectadas.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Esto convierte la preparaci\u00f3n previa en un elemento fundamental.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Una empresa que comienza a decidir qui\u00e9n hace qu\u00e9 cuando ya ha ocurrido el incidente pierde un tiempo valioso.<\/span><\/p>\n<h2><b>Crear un procedimiento de respuesta ante brechas<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">El procedimiento deber\u00eda definir:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Qui\u00e9n recibe las alertas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Qui\u00e9n coordina el incidente.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">C\u00f3mo se eval\u00faa la informaci\u00f3n afectada.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Qui\u00e9n determina el riesgo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Qu\u00e9 evidencias deben conservarse.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Qui\u00e9n contacta con el DPD, si procede.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">C\u00f3mo se realizan las notificaciones.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">C\u00f3mo se comunica internamente.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Qu\u00e9 acciones se realizan despu\u00e9s.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Tambi\u00e9n es necesario documentar las brechas de datos personales de acuerdo con las obligaciones aplicables.<\/span><\/p>\n<h2><b>Gobierno de la seguridad y cumplimiento RGPD<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Todas estas pr\u00e1cticas necesitan coordinaci\u00f3n.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">El<\/span><a href=\"https:\/\/ciberso.com\/servicios\/gobierno-de-la-ciberseguridad\/\"> <span style=\"font-weight: 400;\">gobierno de la ciberseguridad<\/span><\/a><span style=\"font-weight: 400;\"> permite transformar medidas aisladas en un modelo organizado de gesti\u00f3n.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">La organizaci\u00f3n debe establecer:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Responsabilidades.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pol\u00edticas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Procedimientos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Propietarios de los datos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Criterios de aceptaci\u00f3n del riesgo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Indicadores.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revisiones.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Procesos de mejora.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">El objetivo es que seguridad y protecci\u00f3n de datos formen parte de las decisiones empresariales y no dependan \u00fanicamente de actuaciones puntuales del departamento t\u00e9cnico.<\/span><\/p>\n<h2><b>Las 6 pr\u00e1cticas clave para el cumplimiento RGPD<\/b><\/h2>\n<table>\n<tbody>\n<tr>\n<td><b>Pr\u00e1ctica<\/b><\/td>\n<td><b>Objetivo<\/b><\/td>\n<\/tr>\n<tr>\n<td><b>1. Concienciar<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Reducir errores y mejorar la detecci\u00f3n<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>2. Controlar accesos<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Evitar permisos innecesarios<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>3. Evaluar riesgos<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Priorizar medidas de protecci\u00f3n<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>4. Dise\u00f1ar con privacidad<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Prevenir problemas desde el origen<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>5. Auditar y monitorizar<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Detectar vulnerabilidades y amenazas<\/span><\/td>\n<\/tr>\n<tr>\n<td><b>6. Gestionar brechas<\/b><\/td>\n<td><span style=\"font-weight: 400;\">Responder r\u00e1pidamente ante incidentes<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Estas pr\u00e1cticas no funcionan de manera independiente.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Forman un ciclo:<\/span><\/p>\n<p><b>Conocer los datos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Evaluar riesgos<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Aplicar controles<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Formar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Monitorizar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Responder<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Revisar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Mejorar<\/b><\/p>\n<h2><b>Checklist de cumplimiento RGPD y ciberseguridad<\/b><\/h2>\n<h3><b>Datos<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sabemos qu\u00e9 datos personales tratamos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tenemos identificadas las finalidades.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revisamos los plazos de conservaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Aplicamos minimizaci\u00f3n de datos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conocemos d\u00f3nde se almacena la informaci\u00f3n.<\/span><\/li>\n<\/ul>\n<h3><b>Accesos<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los permisos siguen el m\u00ednimo privilegio.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revisamos peri\u00f3dicamente los accesos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminamos cuentas innecesarias.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Utilizamos MFA cuando corresponde.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Controlamos cuentas privilegiadas.<\/span><\/li>\n<\/ul>\n<h3><b>Personas<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Existe formaci\u00f3n peri\u00f3dica.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los empleados conocen el procedimiento de incidentes.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Se realizan acciones de concienciaci\u00f3n.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los diferentes perfiles reciben formaci\u00f3n adaptada.<\/span><\/li>\n<\/ul>\n<h3><b>Tecnolog\u00eda<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sistemas y aplicaciones est\u00e1n actualizados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Se realizan an\u00e1lisis de vulnerabilidades.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revisamos aplicaciones cr\u00edticas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Auditamos la infraestructura.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Monitorizamos comportamientos an\u00f3malos.<\/span><\/li>\n<\/ul>\n<h3><b>Desarrollo<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Aplicamos privacidad desde el dise\u00f1o.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Utilizamos configuraciones protectoras por defecto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limitamos los datos recopilados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incorporamos seguridad durante el desarrollo.<\/span><\/li>\n<\/ul>\n<h3><b>Brechas<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Existe un procedimiento de respuesta.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los responsables est\u00e1n identificados.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Podemos evaluar r\u00e1pidamente el impacto.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sabemos cu\u00e1ndo y c\u00f3mo escalar una brecha.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Documentamos los incidentes.<\/span><\/li>\n<\/ul>\n<h2><b>Errores frecuentes en el cumplimiento RGPD<\/b><\/h2>\n<p><b>\u274c Considerar el RGPD un proyecto terminado<\/b><\/p>\n<p><span style=\"font-weight: 400;\">El cumplimiento necesita mantenerse durante todo el ciclo de vida de los tratamientos.<\/span><\/p>\n<p><b>\u274c Centrarse \u00fanicamente en documentos<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Las pol\u00edticas deben corresponder con las medidas que realmente utiliza la organizaci\u00f3n.<\/span><\/p>\n<p><b>\u274c Proteger todos los datos exactamente igual<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Las medidas deber\u00edan adaptarse al nivel de riesgo.<\/span><\/p>\n<p><b>\u274c Dar permisos excesivos<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cada usuario debe acceder \u00fanicamente a la informaci\u00f3n necesaria.<\/span><\/p>\n<p><b>\u274c Dejar la protecci\u00f3n de datos para el final del desarrollo<\/b><\/p>\n<p><span style=\"font-weight: 400;\">La privacidad debe contemplarse desde el dise\u00f1o.<\/span><\/p>\n<p><b>\u274c Pensar que una auditor\u00eda puntual es suficiente<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Nuevos sistemas, vulnerabilidades y cambios de configuraci\u00f3n modifican continuamente el riesgo.<\/span><\/p>\n<p><b>\u274c No preparar la gesti\u00f3n de brechas<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Las decisiones cr\u00edticas no deber\u00edan improvisarse durante un incidente.<\/span><\/p>\n<h2><b>Cumplimiento RGPD: un proceso continuo de mejora<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">El <\/span><b>cumplimiento RGPD<\/b><span style=\"font-weight: 400;\"> no deber\u00eda entenderse como una lista que se completa una sola vez.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Los tratamientos evolucionan.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Tambi\u00e9n cambian:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Las aplicaciones.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Las personas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los proveedores.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los sistemas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Las amenazas.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los datos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los riesgos.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Por eso, el modelo debe ser continuo:<\/span><\/p>\n<p><b>Identificar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Evaluar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Proteger<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Formar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Monitorizar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Responder<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Demostrar<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">\u2192 <\/span><b>Mejorar<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrar protecci\u00f3n de datos, seguridad, auditor\u00edas, desarrollo seguro, concienciaci\u00f3n y gesti\u00f3n de incidentes ayuda a construir una organizaci\u00f3n capaz no solo de cumplir sus obligaciones, sino tambi\u00e9n de proteger de forma m\u00e1s efectiva la informaci\u00f3n personal que gestiona.<\/span><\/p>\n<p><!-- end HubSpot Call-to-Action Code --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>El cumplimiento RGPD no se consigue mediante una acci\u00f3n puntual. Requiere revisar de manera continua c\u00f3mo una organizaci\u00f3n recopila, utiliza, almacena, comparte y protege los datos personales durante todo su ciclo de vida. El Reglamento General de Protecci\u00f3n de Datos \u2014RGPD o GDPR, por sus siglas en ingl\u00e9s\u2014 establece un modelo basado en la responsabilidad [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":17414,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[146],"tags":[145],"class_list":["post-17374","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-seguridad-informatica","tag-ciberseguridad"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cumplimiento RGPD: 6 pr\u00e1cticas clave para empresas<\/title>\n<meta name=\"description\" content=\"El cumplimiento RGPD exige controles continuos sobre datos, accesos, riesgos, empleados, aplicaciones y brechas para proteger la informaci\u00f3n personal.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cumplimiento RGPD: 6 pr\u00e1cticas clave para empresas\" \/>\n<meta property=\"og:description\" content=\"El cumplimiento RGPD exige controles continuos sobre datos, accesos, riesgos, empleados, aplicaciones y brechas para proteger la informaci\u00f3n personal.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/\" \/>\n<meta property=\"og:site_name\" content=\"MTP Espa\u00f1a\" \/>\n<meta property=\"article:published_time\" content=\"2018-07-06T08:12:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-30T19:32:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1346\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"MTP\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"MTP\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutos\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cumplimiento RGPD: 6 pr\u00e1cticas clave para empresas","description":"El cumplimiento RGPD exige controles continuos sobre datos, accesos, riesgos, empleados, aplicaciones y brechas para proteger la informaci\u00f3n personal.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/","og_locale":"es_ES","og_type":"article","og_title":"Cumplimiento RGPD: 6 pr\u00e1cticas clave para empresas","og_description":"El cumplimiento RGPD exige controles continuos sobre datos, accesos, riesgos, empleados, aplicaciones y brechas para proteger la informaci\u00f3n personal.","og_url":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/","og_site_name":"MTP Espa\u00f1a","article_published_time":"2018-07-06T08:12:05+00:00","article_modified_time":"2026-08-30T19:32:16+00:00","og_image":[{"width":1920,"height":1346,"url":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg","type":"image\/jpeg"}],"author":"MTP","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"MTP","Tiempo de lectura":"10 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#article","isPartOf":{"@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/"},"author":{"name":"MTP","@id":"https:\/\/mtp.global\/es\/#\/schema\/person\/1186350db6f59e8360dd481150654813"},"headline":"Cumplimiento RGPD: 6 pr\u00e1cticas clave para proteger los datos","datePublished":"2018-07-06T08:12:05+00:00","dateModified":"2026-08-30T19:32:16+00:00","mainEntityOfPage":{"@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/"},"wordCount":2339,"publisher":{"@id":"https:\/\/mtp.global\/es\/#organization"},"image":{"@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg","keywords":["ciberseguridad"],"articleSection":["Ciberseguridad"],"inLanguage":"es"},{"@type":"WebPage","@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/","url":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/","name":"Cumplimiento RGPD: 6 pr\u00e1cticas clave para empresas","isPartOf":{"@id":"https:\/\/mtp.global\/es\/#website"},"primaryImageOfPage":{"@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#primaryimage"},"image":{"@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#primaryimage"},"thumbnailUrl":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg","datePublished":"2018-07-06T08:12:05+00:00","dateModified":"2026-08-30T19:32:16+00:00","description":"El cumplimiento RGPD exige controles continuos sobre datos, accesos, riesgos, empleados, aplicaciones y brechas para proteger la informaci\u00f3n personal.","breadcrumb":{"@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#primaryimage","url":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg","contentUrl":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg","width":1920,"height":1346,"caption":"ciberseguridad"},{"@type":"BreadcrumbList","@id":"https:\/\/mtp.global\/es\/blog\/seguridad-informatica\/las-6-practicas-para-el-cumplimiento-con-la-gdpr\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/mtp.global\/es\/home\/"},{"@type":"ListItem","position":2,"name":"Cumplimiento RGPD: 6 pr\u00e1cticas clave para proteger los datos"}]},{"@type":"WebSite","@id":"https:\/\/mtp.global\/es\/#website","url":"https:\/\/mtp.global\/es\/","name":"MTP Global","description":"","publisher":{"@id":"https:\/\/mtp.global\/es\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/mtp.global\/es\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/mtp.global\/es\/#organization","name":"MTP Global","url":"https:\/\/mtp.global\/es\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/mtp.global\/es\/#\/schema\/logo\/image\/","url":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2024\/07\/MTP-global.png","contentUrl":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2024\/07\/MTP-global.png","width":1200,"height":400,"caption":"MTP Global"},"image":{"@id":"https:\/\/mtp.global\/es\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/mtp.global\/es\/#\/schema\/person\/1186350db6f59e8360dd481150654813","name":"MTP","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/9f80fcebb065607a1066a38846083841707346cf76ca0c1df24aea7a0c5d4047?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f80fcebb065607a1066a38846083841707346cf76ca0c1df24aea7a0c5d4047?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f80fcebb065607a1066a38846083841707346cf76ca0c1df24aea7a0c5d4047?s=96&d=mm&r=g","caption":"MTP"},"url":"https:\/\/mtp.global\/es\/blog\/author\/marketing\/"}]}},"fimg_url":"https:\/\/mtp.global\/es\/wp-content\/uploads\/2018\/07\/practicas-gdpr.jpg","_links":{"self":[{"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/posts\/17374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/comments?post=17374"}],"version-history":[{"count":0,"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/posts\/17374\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/media\/17414"}],"wp:attachment":[{"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/media?parent=17374"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/categories?post=17374"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mtp.global\/es\/wp-json\/wp\/v2\/tags?post=17374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}