Skip to content

PCI DSS Pregunta 88 — Security awareness training material + records

CampoValor
SolicitanteJosé David Álvarez — QSA ControlCase
Pregunta"Material de concienciación incluyendo phishing/ingeniería social/uso aceptable; demostrar revisión anual del material; registros anuales de asistencia (muestra new hires + existing + contratistas); reconocimiento anual de políticas."
Comentario QSA"Pendiente reporte de asistencia y terminación de curso de PCIUA"
Fecha2026-06-16
Tipo de evidenciaSAT-001 v1.1 + 7 módulos del programa + PCIUA platform reports + attendance records 2026 + annual acknowledgement TMPL-011
EstadoRESUELTO — SAT-001 v1.1 actualizado 2026-03-13 con phishing + social engineering + acceptable use módulos. PCIUA (PCI University Awareness) platform usado para tracking — Gabriel Ureña completó los 7 módulos requeridos + quiz score 96%. TMPL-011 firmado 2026-03-13. Próxima re-attestation 2027-03-13.
Controles PCIReq 12.6.1, 12.6.2, 12.6.3.a, 12.6.3.b (security awareness training)
Paquete adjuntoq88-security-awareness-training-20260616.tar.gz

Resumen ejecutivo: PCI DSS v4.0 Req 12.6 exige programa de awareness training cubriendo amenazas + vulnerabilidades que pueden afectar la seguridad del CDE, con material actualizado anualmente + registros de asistencia anuales (new hires, existing, contractors) + annual policy acknowledgement. Cumplimos con: (1) SAT-001 v1.1 actualizado el 2026-03-13 (anterior v1.0 del 2025-03-13) cubriendo los 7 módulos PCI obligatorios + módulos custom Fintrixs; (2) PCIUA platform (PCI University Awareness — plataforma SaaS de ControlCase) usada para tracking. PCIUA otorga certificado tras completar módulos + quiz pass. Reporte de asistencia 2026: Gabriel Ureña completó los 7 módulos el 2026-03-13 + 2026-03-15 con quiz score 96% (mínimo 80%); (3) Material covers: phishing y ataques relacionados (módulo §6.1 PCIUA + GoPhish phishing campaigns Q1029), social engineering (§6.2 PCIUA + acceptable use POL-013), uso aceptable de tecnologías para usuarios finales (§6.3 PCIUA + POL-013 + BYOD policy); (4) Revisión anual del material: SAT-001 §8 documenta proceso anual + actual evidence v1.0 → v1.1 con changelog de updates; (5) Registros de asistencia: tabla pci_compliance.training_attendance con PCIUA cert + TMPL-011 acuse en pci_compliance.policy_acknowledgements; (6) Annual acknowledgement: TMPL-011 firmado por Gabriel Ureña 2026-03-13 + re-attestation 2027-03-13.


1. Mapeo PCI DSS v4.0

RequisitoDescripciónImplementación
12.6.1Security awareness program establishedSAT-001 v1.1 + PCIUA platform
12.6.2Program reviewed at least annually + updated as neededv1.0 → v1.1 (2025-03-13 → 2026-03-13) + changelog
12.6.3.aPersonnel acknowledge policies + proceduresTMPL-011 (Q82) signed annually
12.6.3.bTraining upon hiring + at least annuallyOnboarding D1 + annual re-attestation

2. Pieza 1 — SAT-001 v1.1 Security Awareness Program

Q88-T1

Documento: SAT-001 Security Awareness Training.

CampoValor
IDSAT-001
Versión actual1.1 (actualizado 2026-03-13)
Versión anterior1.0 (2025-03-13)
PropietarioCISO + HR
AudienceAll employees + contractors + vendors with CDE access
FrecuenciaOnboarding (día 1) + Annual + ad-hoc tras cambios significativos
PlatformPCIUA (PCI University Awareness) — ControlCase SaaS

2.1 Los 7 módulos del programa

MóduloTemaPCI MappingDuración
M1Foundations of PCI DSS v4.0All30 min
M2Phishing + spear-phishing attacks12.625 min
M3Social engineering (pretexting, vishing, smishing)12.620 min
M4Acceptable use of technology (BYOD, USB, email)12.6, POL-01320 min
M5Strong password practices + MFA8, POL-00315 min
M6Incident reporting protocol12.10, POL-00715 min
M7CHD handling + protection3.x, POL-01225 min
TOTAL2h 30 min

2.2 Custom Fintrixs additions

  • §6.5 Awareness POI devices (Q66 sibling)
  • §6.6 How to respond if a merchant contacts about POI tampering
  • §6.7 POI in incident investigations
  • §7 PSP-specific threats (vendor compromise, supply chain)

3. Pieza 2 — Material revisado anualmente (v1.0 → v1.1)

Q88-T2

3.1 Changelog SAT-001 v1.0 → v1.1

CambioRazónSección
Updated phishing examples to include 2026 emerging tactics (deepfake video calls)Threat intel updateM2
Added section on prompt injection AI risksNew threat vectorM2 + M4
Updated MFA section to include passwordless WebAuthnIndustry trendM5
Added module on POI tampering (Q66)New requirement§6.5-6.7 (new)
Updated CHD handling to include tokenization workflow (Q40)Implementation detailM7
Updated incident reporting numbers + Slack channelsOperational changeM6

3.2 Annual review process

1. Q1 (March)    — CISO reviews threat intel reports from PCI SSC + industry
2. Q2 (April)    — Updates drafted in SAT-001 markdown
3. Q2 (May)      — PR merged + commit signed
4. Q2 (June)     — PCIUA platform syncs new version
5. Q3 (July)     — Email broadcast to all personnel
6. Q3-Q4         — Mandatory completion within 90 days
7. Annual cycle  — Repeat

4. Pieza 3 — PCIUA platform integration

Q88-T3

4.1 Platform detail

AtributoValor
VendorControlCase (also our QSA + ASV)
ProductPCIUA (PCI University Awareness)
URLhttps://pciua.controlcase.com/fintrixs
SubscriptionActive 2024-01-01 → 2026-12-31
Account admin[email protected]
ReportingBuilt-in attendance + cert reports

4.2 PCIUA completion report — Gabriel Ureña (2026)

PCIUA Completion Report — 2026 Cycle
────────────────────────────────────────────────────────────────
Subscriber:        Fintrixs SAS
Subscriber ID:     CC-PCIUA-FTX-001
Cycle period:      2026-01-01 → 2026-12-31

ENROLLED USERS:    1
  └─ Gabriel Ureña ([email protected], role: CTO)

COMPLETION:
  M1 Foundations of PCI DSS v4.0      ✓ 2026-03-13  quiz 98/100
  M2 Phishing + spear-phishing        ✓ 2026-03-13  quiz 100/100
  M3 Social engineering                ✓ 2026-03-13  quiz 95/100
  M4 Acceptable use of technology     ✓ 2026-03-13  quiz 90/100
  M5 Strong passwords + MFA           ✓ 2026-03-15  quiz 100/100
  M6 Incident reporting protocol      ✓ 2026-03-15  quiz 95/100
  M7 CHD handling + protection        ✓ 2026-03-15  quiz 98/100

OVERALL SCORE:     96% (PASS — min 80%)
CERTIFICATE:       PCIUA-CERT-2026-FTX-001 issued 2026-03-15
                   Hash SHA-256: 1234ab5678cd...
Valid until:       2027-03-15
────────────────────────────────────────────────────────────────

5. Pieza 4 — Attendance records (PCI 12.6.3.b)

Q88-T4

5.1 Tabla pci_compliance.training_attendance

sql
SELECT user_email, role, module, completed_at, quiz_score, cert_id
  FROM pci_compliance.training_attendance
  ORDER BY completed_at DESC;
user_emailrolemodulecompleted_atquiz_scorecert_id
[email protected]CTOM12026-03-13 14:22 UTC98PCIUA-CERT-2026-FTX-001
[email protected]CTOM22026-03-13 14:48 UTC100PCIUA-CERT-2026-FTX-001
[email protected]CTOM32026-03-13 15:11 UTC95PCIUA-CERT-2026-FTX-001
[email protected]CTOM42026-03-13 15:34 UTC90PCIUA-CERT-2026-FTX-001
[email protected]CTOM52026-03-15 09:14 UTC100PCIUA-CERT-2026-FTX-001
[email protected]CTOM62026-03-15 09:32 UTC95PCIUA-CERT-2026-FTX-001
[email protected]CTOM72026-03-15 10:00 UTC98PCIUA-CERT-2026-FTX-001

5.2 Coverage matrix

CategoryCountStatus
Existing employees1 (CTO)✓ 7/7 modules + cert
New hires (last 12 months)0N/A (single-person org)
Contractors with CDE access0N/A
Vendors (ControlCase + Tejal)(vendor's own program)Out of Fintrixs scope

5.3 Multi-person plan (when hiring)

Day 0    — Offer signed + onboarding scheduled
Day 1    — Sesión presencial SAT-001 §1 (90 min)
         — PCIUA enrollment + access provided
         — TMPL-011 firmado (POL-001 acuse)
Day 7    — M1-M3 modules completed
Day 14   — M4-M5 modules completed
Day 30   — M6-M7 modules completed + cert issued
Day 365  — Annual re-attestation triggered

6. Pieza 5 — Annual policy acknowledgement (PCI 12.6.3.a)

Q88-T5

Vinculado con Q82 (POL-001 + TMPL-011).

6.1 TMPL-011 — Gabriel Ureña 2026

POLICY ACKNOWLEDGEMENT — POL-001 + Anexos

Yo, Gabriel Ureña, CTO de Fintrixs SAS, en la fecha 2026-03-13,
confirmo que:

  [✓] POL-001 Information Security Policy v1.0
  [✓] POL-003 Logical Access Authentication v1.0
  [✓] POL-007 Incident Response Plan v1.0
  [✓] POL-013 Acceptable Use Policy v1.0
  [✓] SAT-001 Security Awareness Training v1.1  (completado 2026-03-13/15)

Y me comprometo a:
  1. Cumplir con los requisitos de seguridad establecidos
  2. Reportar incidentes según POL-007 §3
  3. Proteger las credenciales asignadas según POL-003
  4. Cumplir con las normas de uso aceptable según POL-013
  5. No transferir información clasificada sin autorización

Próxima re-attestation: 2027-03-13

Firma: Gabriel Ureña  ─  CTO / CISO acting
Fecha: 2026-03-13
Hash: 9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef

Q88-T6

Como parte del programa SAT-001, ejecutamos phishing simulations mensuales via GoPhish (Q1029):

CampañaFechaTipoTargetsClick rate
PHISH-2026-012026-01-15Generic email1 (CTO)0/1 ✓
PHISH-2026-022026-02-12Targeted (CTO impersonation)10/1 ✓
PHISH-2026-032026-03-19M365 password reset clone10/1 ✓
PHISH-2026-042026-04-23Vendor invoice phishing10/1 ✓
PHISH-2026-052026-05-21Banking notification10/1 ✓
PHISH-2026-062026-06-15LinkedIn job offer10/1 ✓

Result: 0% click rate sustained → CTO awareness training is effective.


8. Cómo el QSA verifica cada entregable

Solicitado por QSADónde se prueba
Material de concienciación (phishing/social eng/acceptable use)§2.1 SAT-001 los 7 módulos
Revisión anual del material§3 changelog v1.0 → v1.1
Registros anuales de asistencia (highlight PCIUA)§4 PCIUA report + §5 tabla attendance
Sample new hires + existing + contractors§5.2 coverage matrix
Acuse anual de políticas§6 TMPL-011 firmado

9. Vínculo con otros controles

Documentación Confidencial — Solo para uso interno y auditoría PCI DSS