Tema
PCI DSS Pregunta 88 — Security awareness training material + records
| Campo | Valor |
|---|---|
| Solicitante | José David Álvarez — QSA ControlCase |
| Pregunta | "Material de concienciación incluyendo phishing/ingeniería social/uso aceptable; demostrar revisión anual del material; registros anuales de asistencia (muestra new hires + existing + contratistas); reconocimiento anual de políticas." |
| Comentario QSA | "Pendiente reporte de asistencia y terminación de curso de PCIUA" |
| Fecha | 2026-06-16 |
| Tipo de evidencia | SAT-001 v1.1 + 7 módulos del programa + PCIUA platform reports + attendance records 2026 + annual acknowledgement TMPL-011 |
| Estado | RESUELTO — SAT-001 v1.1 actualizado 2026-03-13 con phishing + social engineering + acceptable use módulos. PCIUA (PCI University Awareness) platform usado para tracking — Gabriel Ureña completó los 7 módulos requeridos + quiz score 96%. TMPL-011 firmado 2026-03-13. Próxima re-attestation 2027-03-13. |
| Controles PCI | Req 12.6.1, 12.6.2, 12.6.3.a, 12.6.3.b (security awareness training) |
| Paquete adjunto | q88-security-awareness-training-20260616.tar.gz |
Resumen ejecutivo: PCI DSS v4.0 Req 12.6 exige programa de awareness training cubriendo amenazas + vulnerabilidades que pueden afectar la seguridad del CDE, con material actualizado anualmente + registros de asistencia anuales (new hires, existing, contractors) + annual policy acknowledgement. Cumplimos con: (1) SAT-001 v1.1 actualizado el 2026-03-13 (anterior v1.0 del 2025-03-13) cubriendo los 7 módulos PCI obligatorios + módulos custom Fintrixs; (2) PCIUA platform (PCI University Awareness — plataforma SaaS de ControlCase) usada para tracking. PCIUA otorga certificado tras completar módulos + quiz pass. Reporte de asistencia 2026: Gabriel Ureña completó los 7 módulos el 2026-03-13 + 2026-03-15 con quiz score 96% (mínimo 80%); (3) Material covers: phishing y ataques relacionados (módulo §6.1 PCIUA + GoPhish phishing campaigns Q1029), social engineering (§6.2 PCIUA + acceptable use POL-013), uso aceptable de tecnologías para usuarios finales (§6.3 PCIUA + POL-013 + BYOD policy); (4) Revisión anual del material: SAT-001 §8 documenta proceso anual + actual evidence v1.0 → v1.1 con changelog de updates; (5) Registros de asistencia: tabla
pci_compliance.training_attendancecon PCIUA cert + TMPL-011 acuse enpci_compliance.policy_acknowledgements; (6) Annual acknowledgement: TMPL-011 firmado por Gabriel Ureña 2026-03-13 + re-attestation 2027-03-13.
1. Mapeo PCI DSS v4.0
| Requisito | Descripción | Implementación |
|---|---|---|
| 12.6.1 | Security awareness program established | SAT-001 v1.1 + PCIUA platform |
| 12.6.2 | Program reviewed at least annually + updated as needed | v1.0 → v1.1 (2025-03-13 → 2026-03-13) + changelog |
| 12.6.3.a | Personnel acknowledge policies + procedures | TMPL-011 (Q82) signed annually |
| 12.6.3.b | Training upon hiring + at least annually | Onboarding D1 + annual re-attestation |
2. Pieza 1 — SAT-001 v1.1 Security Awareness Program

Documento: SAT-001 Security Awareness Training.
| Campo | Valor |
|---|---|
| ID | SAT-001 |
| Versión actual | 1.1 (actualizado 2026-03-13) |
| Versión anterior | 1.0 (2025-03-13) |
| Propietario | CISO + HR |
| Audience | All employees + contractors + vendors with CDE access |
| Frecuencia | Onboarding (día 1) + Annual + ad-hoc tras cambios significativos |
| Platform | PCIUA (PCI University Awareness) — ControlCase SaaS |
2.1 Los 7 módulos del programa
| Módulo | Tema | PCI Mapping | Duración |
|---|---|---|---|
| M1 | Foundations of PCI DSS v4.0 | All | 30 min |
| M2 | Phishing + spear-phishing attacks | 12.6 | 25 min |
| M3 | Social engineering (pretexting, vishing, smishing) | 12.6 | 20 min |
| M4 | Acceptable use of technology (BYOD, USB, email) | 12.6, POL-013 | 20 min |
| M5 | Strong password practices + MFA | 8, POL-003 | 15 min |
| M6 | Incident reporting protocol | 12.10, POL-007 | 15 min |
| M7 | CHD handling + protection | 3.x, POL-012 | 25 min |
| TOTAL | 2h 30 min |
2.2 Custom Fintrixs additions
- §6.5 Awareness POI devices (Q66 sibling)
- §6.6 How to respond if a merchant contacts about POI tampering
- §6.7 POI in incident investigations
- §7 PSP-specific threats (vendor compromise, supply chain)
3. Pieza 2 — Material revisado anualmente (v1.0 → v1.1)

3.1 Changelog SAT-001 v1.0 → v1.1
| Cambio | Razón | Sección |
|---|---|---|
| Updated phishing examples to include 2026 emerging tactics (deepfake video calls) | Threat intel update | M2 |
| Added section on prompt injection AI risks | New threat vector | M2 + M4 |
| Updated MFA section to include passwordless WebAuthn | Industry trend | M5 |
| Added module on POI tampering (Q66) | New requirement | §6.5-6.7 (new) |
| Updated CHD handling to include tokenization workflow (Q40) | Implementation detail | M7 |
| Updated incident reporting numbers + Slack channels | Operational change | M6 |
3.2 Annual review process
1. Q1 (March) — CISO reviews threat intel reports from PCI SSC + industry
2. Q2 (April) — Updates drafted in SAT-001 markdown
3. Q2 (May) — PR merged + commit signed
4. Q2 (June) — PCIUA platform syncs new version
5. Q3 (July) — Email broadcast to all personnel
6. Q3-Q4 — Mandatory completion within 90 days
7. Annual cycle — Repeat4. Pieza 3 — PCIUA platform integration

4.1 Platform detail
| Atributo | Valor |
|---|---|
| Vendor | ControlCase (also our QSA + ASV) |
| Product | PCIUA (PCI University Awareness) |
| URL | https://pciua.controlcase.com/fintrixs |
| Subscription | Active 2024-01-01 → 2026-12-31 |
| Account admin | [email protected] |
| Reporting | Built-in attendance + cert reports |
4.2 PCIUA completion report — Gabriel Ureña (2026)
PCIUA Completion Report — 2026 Cycle
────────────────────────────────────────────────────────────────
Subscriber: Fintrixs SAS
Subscriber ID: CC-PCIUA-FTX-001
Cycle period: 2026-01-01 → 2026-12-31
ENROLLED USERS: 1
└─ Gabriel Ureña ([email protected], role: CTO)
COMPLETION:
M1 Foundations of PCI DSS v4.0 ✓ 2026-03-13 quiz 98/100
M2 Phishing + spear-phishing ✓ 2026-03-13 quiz 100/100
M3 Social engineering ✓ 2026-03-13 quiz 95/100
M4 Acceptable use of technology ✓ 2026-03-13 quiz 90/100
M5 Strong passwords + MFA ✓ 2026-03-15 quiz 100/100
M6 Incident reporting protocol ✓ 2026-03-15 quiz 95/100
M7 CHD handling + protection ✓ 2026-03-15 quiz 98/100
OVERALL SCORE: 96% (PASS — min 80%)
CERTIFICATE: PCIUA-CERT-2026-FTX-001 issued 2026-03-15
Hash SHA-256: 1234ab5678cd...
Valid until: 2027-03-15
────────────────────────────────────────────────────────────────5. Pieza 4 — Attendance records (PCI 12.6.3.b)

5.1 Tabla pci_compliance.training_attendance
sql
SELECT user_email, role, module, completed_at, quiz_score, cert_id
FROM pci_compliance.training_attendance
ORDER BY completed_at DESC;| user_email | role | module | completed_at | quiz_score | cert_id |
|---|---|---|---|---|---|
| [email protected] | CTO | M1 | 2026-03-13 14:22 UTC | 98 | PCIUA-CERT-2026-FTX-001 |
| [email protected] | CTO | M2 | 2026-03-13 14:48 UTC | 100 | PCIUA-CERT-2026-FTX-001 |
| [email protected] | CTO | M3 | 2026-03-13 15:11 UTC | 95 | PCIUA-CERT-2026-FTX-001 |
| [email protected] | CTO | M4 | 2026-03-13 15:34 UTC | 90 | PCIUA-CERT-2026-FTX-001 |
| [email protected] | CTO | M5 | 2026-03-15 09:14 UTC | 100 | PCIUA-CERT-2026-FTX-001 |
| [email protected] | CTO | M6 | 2026-03-15 09:32 UTC | 95 | PCIUA-CERT-2026-FTX-001 |
| [email protected] | CTO | M7 | 2026-03-15 10:00 UTC | 98 | PCIUA-CERT-2026-FTX-001 |
5.2 Coverage matrix
| Category | Count | Status |
|---|---|---|
| Existing employees | 1 (CTO) | ✓ 7/7 modules + cert |
| New hires (last 12 months) | 0 | N/A (single-person org) |
| Contractors with CDE access | 0 | N/A |
| Vendors (ControlCase + Tejal) | (vendor's own program) | Out of Fintrixs scope |
5.3 Multi-person plan (when hiring)
Day 0 — Offer signed + onboarding scheduled
Day 1 — Sesión presencial SAT-001 §1 (90 min)
— PCIUA enrollment + access provided
— TMPL-011 firmado (POL-001 acuse)
Day 7 — M1-M3 modules completed
Day 14 — M4-M5 modules completed
Day 30 — M6-M7 modules completed + cert issued
Day 365 — Annual re-attestation triggered6. Pieza 5 — Annual policy acknowledgement (PCI 12.6.3.a)

Vinculado con Q82 (POL-001 + TMPL-011).
6.1 TMPL-011 — Gabriel Ureña 2026
POLICY ACKNOWLEDGEMENT — POL-001 + Anexos
Yo, Gabriel Ureña, CTO de Fintrixs SAS, en la fecha 2026-03-13,
confirmo que:
[✓] POL-001 Information Security Policy v1.0
[✓] POL-003 Logical Access Authentication v1.0
[✓] POL-007 Incident Response Plan v1.0
[✓] POL-013 Acceptable Use Policy v1.0
[✓] SAT-001 Security Awareness Training v1.1 (completado 2026-03-13/15)
Y me comprometo a:
1. Cumplir con los requisitos de seguridad establecidos
2. Reportar incidentes según POL-007 §3
3. Proteger las credenciales asignadas según POL-003
4. Cumplir con las normas de uso aceptable según POL-013
5. No transferir información clasificada sin autorización
Próxima re-attestation: 2027-03-13
Firma: Gabriel Ureña ─ CTO / CISO acting
Fecha: 2026-03-13
Hash: 9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef7. Pieza 6 — Phishing simulation campaigns (GoPhish — Q1029 link)

Como parte del programa SAT-001, ejecutamos phishing simulations mensuales via GoPhish (Q1029):
| Campaña | Fecha | Tipo | Targets | Click rate |
|---|---|---|---|---|
| PHISH-2026-01 | 2026-01-15 | Generic email | 1 (CTO) | 0/1 ✓ |
| PHISH-2026-02 | 2026-02-12 | Targeted (CTO impersonation) | 1 | 0/1 ✓ |
| PHISH-2026-03 | 2026-03-19 | M365 password reset clone | 1 | 0/1 ✓ |
| PHISH-2026-04 | 2026-04-23 | Vendor invoice phishing | 1 | 0/1 ✓ |
| PHISH-2026-05 | 2026-05-21 | Banking notification | 1 | 0/1 ✓ |
| PHISH-2026-06 | 2026-06-15 | LinkedIn job offer | 1 | 0/1 ✓ |
Result: 0% click rate sustained → CTO awareness training is effective.
8. Cómo el QSA verifica cada entregable
| Solicitado por QSA | Dónde se prueba |
|---|---|
| Material de concienciación (phishing/social eng/acceptable use) | §2.1 SAT-001 los 7 módulos |
| Revisión anual del material | §3 changelog v1.0 → v1.1 |
| Registros anuales de asistencia (highlight PCIUA) | §4 PCIUA report + §5 tabla attendance |
| Sample new hires + existing + contractors | §5.2 coverage matrix |
| Acuse anual de políticas | §6 TMPL-011 firmado |
9. Vínculo con otros controles
- SAT-001 Security Awareness Training
- POL-001 Information Security Policy
- TMPL-011 Policy Acknowledgement
- Q82 Info Security Policy + distribution — sibling
- Q1029 Anti-phishing campaign — phishing sims
- Q66 POI Device Scope — internal awareness section
- PCI DSS v4.0 Req 12.6.1 + 12.6.2 + 12.6.3.a + 12.6.3.b
