Costa Rica · CONASSIF/SUGEF · 2024 comprehensive reform (formerly 5-17)

CONASSIF 5-24: mandatory external IT audit, every three years

The General Regulation on IT Governance and Management applies to all four supervised sectors. Its audit cycle turns change-control evidence into a need with a calendar.

CONASSIF 5-24 · Article 21

Requires controls related to “the acquisition or development of the software life cycle and secure coding.”

The clock: external IT audit at least every three years, by CISA-certified auditors. After the supervision report: an action plan within 30 business days, with an effectiveness indicator per action.

What the regulation demands of software development

  • Art. 48. External IT audit at least every three years.
  • Art. 54. Action plan within 30 business days of the supervision report.
  • Art. 18. Life-cycle controls, including emergency changes.
  • Arts. 43-44, 50. Auditable processes and working papers with verifiable evidence.

How LineBreak answers

  • Nothing reaches production with known vulnerabilities. Every change is scanned before merging; if the scanner cannot run, the change does not pass. Exceptions are human, scoped to one exact finding, with name and reason on the record.
  • The AI writes the code; an identified person signs. Approved criteria carry the name of who approved them. The AI writing code can read them, but cannot modify them.
  • Every approval is cryptographically signed. Your auditor verifies it independently, without relying on us or on the team's word, years later if needed.
  • The evidence lives in YOUR infrastructure. Not on our servers. The record of every change (who approved what, when, with what result) travels with the code itself.

What LineBreak is NOT

  • LineBreak does not certify or guarantee compliance with any regulation: it produces the evidence your accountable people answer with.
  • It does not replace the roles your regulation requires (security officers, internal audit, regulatory reporting).
  • Decisions and accountability remain human. That is the product's design principle.

An AI-generated change is blocked, a person approves it by name, and the audit report is generated in front of you. With your risk team or your auditor present.