Skip to content

PCI DSS Pregunta 1036 — Service provider scope review (semi-annual)

CampoValor
SolicitanteJosé David Álvarez — QSA ControlCase
Pregunta"Esta pregunta aplica únicamente a proveedores de servicios. Proporcionar evidencia que demuestre que todos los documentos de alcance (Q1, 2, 4, 5, 7, 8) son revisados y confirmados al menos cada seis meses y tras cambios significativos. Tras cambios significativos en estructura organizativa, mostrar que el resultado de la revisión del impacto en el alcance PCI DSS y la aplicabilidad de los controles se comunicó a la dirección ejecutiva."
Comentario QSA"Esto incluye la revisión y aprobación de los archivos cargados en las preguntas 1 a 8 del scope."
Fecha2026-06-16
Tipo de evidenciaSOP-008 emitida + sample H1 2026 review completo + TMPL-013 acknowledgement firmado + significant change communications
EstadoRESUELTO — SOP-008 v1.0 emitida documentando el proceso semestral + ad-hoc. H1 2026 review ejecutado el 2026-06-16 cubriendo Q1, Q2, Q4, Q5, Q7, Q8 con changes documentados y aprobación de la "Executive Management" (inversionista actuando como board representation + CTO en single-person org). 4 significant changes comunicados: WAF deployment + tokenization + Rapid7 onboarding + new policies.
Controles PCIReq 12.5.2.1 (semi-annual scope review for SP) + 12.5.1 (PCI DSS scope documented)
Paquete adjuntoq1036-sp-scope-review-20260616.tar.gz

Resumen ejecutivo: PCI DSS v4.0 Req 12.5.2.1 aplica únicamente a Service Providers y exige: revisión de scope cada 6 meses + tras cambios significativos + comunicación de impacto a executive management. Cumplimos con: (1) SOP-008 v1.0 emitida documentando el proceso completo — workflow Day 0→30, los 6 documentos en scope (Q1 business overview, Q2 network diagram, Q4 CHD data flow, Q5 in-scope systems, Q7 TPSPs, Q8 policy inventory), participantes (CTO + CISO + Executive Management + QSA años pares), single-person org compensating control (inversionista como board representation); (2) H1 2026 Review ejecutado 2026-06-16: los 6 documentos revisados + diff vs cycle anterior + 4 significant changes identificados (WAF deployment 2026-05-27, tokenization workflow Q40, Rapid7 onboarding 2026-04-10, new policies POL-016 + SOPs); (3) TMPL-013 Scope Approval Acknowledgement firmado por CTO Gabriel Ureña (2026-06-16 19:42 UTC) + Executive Management aprobación (inversionista 2026-06-16 20:00 UTC); (4) Communication evidence: email enviado a [email protected] con resumen de significant changes + Slack mensaje en #fintrixs-board con changelog; (5) Cobertura H1 2026: impacto en PCI scope evaluado — no expansion del CDE network, no nuevas card-present operations, new controls (WAF + audit + reviews) reducen risk; (6) Próximo ciclo H2 2026 deadline 2026-12-31 + calendar reminder configurado.


1. Mapeo PCI DSS v4.0

RequisitoDescripciónImplementación
12.5.1PCI DSS scope documented + confirmedDocumentos Q1-Q8 versionados en git
12.5.2.1Service provider scope reviewed every 6 months + after significant changeSOP-008 + H1 2026 cycle completed
12.5.2.1.aReview communicated to executive managementTMPL-013 + email + Slack §4

2. Pieza 1 — SOP-008 (process documented)

Q1036-T1

SOP emitida: SOP-008 Scope Review SP.

2.1 Los 6 documentos en alcance

#QDocumentoOwner
1Q1Business overview + payment flowCTO
2Q2Network diagram (CDE + segmentation)CTO
3Q4Cardholder data flow diagramCTO
4Q5List of all in-scope systems (INV-002)CTO
5Q7List of TPSPs (POL-008 §2)CTO
6Q8Policy + procedure inventoryCISO

2.2 Cadencia

CicloWindowDeadline
H11 – 30 junio30 junio 23:59 UTC
H21 – 31 diciembre31 diciembre 23:59 UTC
  • Ad-hoc tras significant change.

2.3 Single-person org compensating control

CTO = CISO = Executive Management (same individual)


Compensating:
  1. Inversionista (Fintrixs Holdings SAS) actúa como board representation
  2. QSA externo en años pares (ControlCase 2026)
  3. Acuses con timestamps verificables via git signed commits
  4. Hash SHA-256 of each cycle archived

3. Pieza 2 — H1 2026 Review (sample ejecutado)

Q1036-T2

3.1 Report completo

─────────────────────────────────────────────────
   Service Provider Scope Review — H1 2026
─────────────────────────────────────────────────
   Cycle:    H1 2026
   Period:   2026-01-01 → 2026-06-30
   Owner:    Gabriel Ureña (CTO + CISO)
   Approver: Inversionista (board) + CTO

   ─── Documents reviewed ───
   Q1 Business overview        → ✓ no changes since last cycle (H2 2025)
   Q2 Network diagram          → ✓ updated 2026-05-27 (WAF added)
   Q4 CHD data flow diagram    → ✓ updated 2026-04-15 (tokenization workflow Q40)
   Q5 In-scope systems INV-002 → ✓ updated continuous (PG removed, Rapid7 added)
   Q7 TPSPs list                → ✓ updated 2026-04-10 (Rapid7 added as TPSP)
   Q8 Policy inventory          → ✓ updated 2026-06-16 (POL-016 + 3 SOPs added)

   ─── Significant changes ───
   • 2026-04-10  Rapid7 Collector onboarded as new TPSP
                  Impact: extra TPSP for monitoring services
                  Scope: CDE log forwarding inbound
                  No expansion of CDE proper

   • 2026-04-15  Tokenization workflow updated (Q40 changes)
                  Impact: improved security via Credibanco PANs vs Stripe
                  Scope: no change in PCI scope, internal implementation

   • 2026-05-27  Coraza WAF deployed (Q43 changes)
                  Impact: new control layer in CDE perimeter
                  Scope: enhances 11.6.1 (Q1037 sibling)

   • 2026-06-16  POL-016 + new SOPs added
                  Impact: improved policy coverage
                  Scope: no change in CDE, only documentation

   ─── PCI scope impact assessment ───
   ✓ No expansion of CDE network — all in same VPC
   ✓ No new card-present operations
   ✓ New controls (WAF, audit, reviews) REDUCE risk
   ✓ All TPSPs maintain valid PCI/SOC2 attestations

   ─── Approval ───
   CTO:                Gabriel Ureña    2026-06-16 19:42 UTC
   Executive (board):  Inversionista     2026-06-16 20:00 UTC

   ─── Storage ───
   Hash SHA-256:  9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef
   Archive path:  s3://fintrix-compliance-archive/scope-reviews/2026-H1/
                  Files: scope-report.md + signatures.json + diff-vs-h2-2025.diff

─────────────────────────────────────────────────
   Next cycle: H2 2026 — Deadline 2026-12-31
─────────────────────────────────────────────────

4. Pieza 3 — Executive Management communication

Q1036-T3

4.1 Email a Executive Management (inversionista)

From:    [email protected]
To:      [email protected]
Cc:      [email protected]  (QSA cc)
Subject: [REQUIRED REVIEW] H1 2026 PCI DSS Scope Review — Action: sign acknowledgement
Date:    2026-06-16 19:45 UTC

Estimado/a Inversionista,

Como parte del proceso semestral exigido por PCI DSS v4.0 Req 12.5.2.1
para Service Providers, adjunto el reporte de revisión H1 2026 del scope
de la auditoría PCI.

RESUMEN EJECUTIVO:
  • Período: 2026-01-01 → 2026-06-30
  • Documentos revisados: 6 (Q1, Q2, Q4, Q5, Q7, Q8)
  • Significant changes identificados: 4

CAMBIOS SIGNIFICATIVOS (con impacto en scope):
  1. 2026-04-10 — Rapid7 Collector onboarded
                   → Extra TPSP (services monitoring), no CDE expansion
  2. 2026-04-15 — Tokenization workflow updated (Q40)
                   → Cambio en implementación, no cambio en PCI scope
  3. 2026-05-27 — Coraza WAF deployed (Q43)
                   → New control layer, REDUCE risk
  4. 2026-06-16 — POL-016 + 3 SOPs added (Q66, Q67, Q234)
                   → Mejor cobertura de policies, no cambio en CDE

EVALUACIÓN PCI DSS:
  ✓ No expansion del CDE network
  ✓ No new card-present operations
  ✓ Risk reducido por los new controls
  ✓ All TPSPs maintain valid PCI/SOC2 attestations

ACCIÓN REQUERIDA:
  Por favor firme el acuse adjunto (TMPL-013) confirmando que ha revisado
  el reporte de scope y aprueba las decisiones tomadas.

Gracias,
Gabriel Ureña
CTO / CISO acting
Fintrixs SAS

4.2 Inversionista reply (acuse)

From:    [email protected]
To:      [email protected]
Subject: Re: [REQUIRED REVIEW] H1 2026 PCI DSS Scope Review — Acknowledgement signed
Date:    2026-06-16 20:00 UTC

Gabriel,

Confirmo que he revisado el reporte H1 2026 PCI DSS Scope Review.

APROBADO. Los significant changes son consistentes con el plan estratégico
y los new controls añaden valor en términos de risk reduction.

Acuse signed (TMPL-013) adjunto.

Próximo ciclo: H2 2026 deadline 2026-12-31.

Saludos,
Inversionista
(representando Board of Fintrixs SAS)

4.3 Slack message

[2026-06-16 20:05 UTC]  #fintrixs-board

@gabriel @inversionista @qsa

H1 2026 PCI DSS Scope Review COMPLETED ✓

📋 Documents reviewed: Q1, Q2, Q4, Q5, Q7, Q8
🔄 Significant changes: 4 (WAF + tokenization + Rapid7 + policies)
🎯 PCI scope impact: net REDUCTION of risk
✍️  Acknowledgement: signed by CTO + Inversionista

📁 Archive: s3://fintrix-compliance-archive/scope-reviews/2026-H1/
🔒 Hash: 9c4f2b78ae...

⏰ Next cycle: H2 2026 — Deadline 2026-12-31

5. Pieza 4 — TMPL-013 Scope Approval Acknowledgement

Q1036-T4

TMPL-013 — SCOPE APPROVAL ACKNOWLEDGEMENT

Cycle:              H1 2026
Period:             2026-01-01 → 2026-06-30
Documents reviewed: Q1, Q2, Q4, Q5, Q7, Q8

──────────────────────────────────────────────────
CTO ACKNOWLEDGEMENT
──────────────────────────────────────────────────

Yo, Gabriel Ureña, CTO/CISO de Fintrixs SAS, confirmo que:
  1. He revisado personalmente los 6 documentos de scope
  2. He identificado los 4 significant changes desde el último ciclo
  3. He evaluado el impacto en el PCI DSS scope
  4. Los new controls (WAF, audit, reviews) REDUCEN el risk
  5. Los TPSPs mantienen valid PCI/SOC2 attestations

Firma:       Gabriel Ureña
Fecha:       2026-06-16T19:42:00Z
Mecanismo:   git signed commit

──────────────────────────────────────────────────
EXECUTIVE MANAGEMENT ACKNOWLEDGEMENT
──────────────────────────────────────────────────

Yo, [Inversionista], representando el Board of Fintrixs SAS:
  1. He revisado el reporte H1 2026 PCI DSS Scope Review
  2. He revisado los 4 significant changes
  3. APRUEBO las decisiones tomadas
  4. APRUEBO que no hay expansion del CDE
  5. Confirmo que el risk profile es aceptable

Firma:       Inversionista (Board representation)
Fecha:       2026-06-16T20:00:00Z
Email:       [email protected]

──────────────────────────────────────────────────
ARCHIVE
──────────────────────────────────────────────────
Hash SHA-256:  9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef
Storage:       s3://fintrix-compliance-archive/scope-reviews/2026-H1/
Retention:     7 years (PCI 10.5.1)

6. Pieza 5 — Próximo ciclo + significant change triggers

Q1036-T5

HitoFecha
H2 2026 calendar reminder2026-12-01 09:00 UTC
H2 2026 deadline2026-12-31 23:59 UTC
H1 2027 deadline2027-06-30
H2 2027 deadline2027-12-31

6.1 Ad-hoc triggers (review inmediato)

TriggerAction
Nuevo TPSP crítico onboardedReview Q7 + comunicar a board en ≤7 días
Cambio en arquitectura del CDEReview Q2 + Q4 + Q5 + comunicar en ≤7 días
Cambio organizacionalReview Q8 + comunicar inmediatamente
Incident severity CriticalReview por incident scope + comunicar al board
QSA changeReview by new QSA + comunicar
Significant code release (>500 LOC change)Review Q2 + Q4

7. Cómo el QSA verifica cada entregable

Solicitado por QSADónde se prueba
Documents Q1-Q8 reviewed every 6 months§3 H1 2026 + SOP-008 cadence
Scope confirmed semestralmente§3 review report
Cambios significativos comunicados a executive§4 email + Slack + TMPL-013
Aprobación de gerencia executive§4.2 inversionista reply + §5 TMPL-013 signed
Tras significant change§6 trigger list

8. Vínculo con otros controles

Documentación Confidencial — Solo para uso interno y auditoría PCI DSS