Tema
SOP-008: Procedimiento de revisión semestral del scope (Service Provider)
| Campo | Valor |
|---|---|
| ID | SOP-008 |
| Versión | 1.0 |
| Fecha de emisión | 2026-06-16 |
| Propietario | CISO + CTO + Executive Management |
| PCI DSS | Req 12.5.2.1 (Service Provider — semi-annual + significant changes) |
| Frecuencia | Semestral (H1 junio · H2 diciembre) + ad-hoc tras significant changes |
1. Propósito
PCI DSS v4.0 Req 12.5.2.1 exige que Service Providers revisen sus documentos de scope al menos cada 6 meses + tras cambios significativos. Esta SOP define el proceso de:
- Revisión periódica del scope (documentos Q1-Q8 del cuestionario ControlCase)
- Aprobación por la Gerencia Ejecutiva
- Comunicación de cambios significativos a la dirección
- Archivo y retención
2. Documentos en alcance de la revisión
Los siguientes documentos definen el scope PCI DSS de Fintrixs:
| # | Q | Documento | Owner | Updated when |
|---|---|---|---|---|
| 1 | Q1 | Business overview + payment flow | CTO | Significant change in business |
| 2 | Q2 | Network diagram (CDE + segmentation) | CTO | Significant change in network |
| 3 | Q4 | Cardholder data flow diagram | CTO | Change in CHD handling |
| 4 | Q5 | List of all in-scope systems (INV-002) | CTO | Continuous (auto) + verified semestral |
| 5 | Q7 | List of TPSPs (POL-008 §2) | CTO | TPSP onboarding/termination |
| 6 | Q8 | Policy + procedure inventory | CISO | When policies updated |
3. Cadencia
| Ciclo | Window | Deadline absoluto |
|---|---|---|
| H1 | 1 – 30 junio | 30 junio 23:59 UTC |
| H2 | 1 – 31 diciembre | 31 diciembre 23:59 UTC |
Adicional: revisión ad-hoc tras cualquier significant change:
- Cambio en arquitectura del CDE
- Nuevo TPSP crítico onboarded
- Cambio organizacional (M&A, leadership transition)
- Cambio de QSA
- Cambio de cloud provider
- Incident severity Critical (per POL-007)
4. Participantes
| Rol | Responsabilidad |
|---|---|
| CTO | Proponente — colecta los documentos actuales + identifica cambios desde el último ciclo |
| CISO | Revisor — valida que el scope sigue siendo apropiado |
| Executive Management (Gerencia Ejecutiva) | Aprobador — firma de aceptación final |
| QSA (ControlCase) | Auditor externo (años pares + ad-hoc) |
En single-person org: CTO = CISO = Executive Management. La compensating control es:
- QSA externo en años pares
- Inversionista actuando como reviewer (board) en cada ciclo
- Acuses con timestamps verificables via git signed commits
5. Workflow
Day 0 — Ciclo trigger (Jun 1 / Dec 1)
└── Calendar reminder + email
Day 7 — CTO colecta Q1-Q8 documents
└── Identifica cambios desde el último ciclo
Day 14 — CISO revisa
└── Acepta/Rechaza/Pide ajustes
Day 21 — Executive Management firma
└── Storage + audit log
Day 30 — Deadline → SOP-008 cycle CLOSED6. Outputs obligatorios
- Scope confirmation report — versión actualizada de Q1-Q8 + diff vs cycle anterior
- Executive Management signed approval — TMPL-013 (acuse)
- Communication to executive management — email con resumen + significant changes (PCI 12.5.2.1)
- Archive —
s3://fintrix-compliance-archive/scope-reviews/YYYY-HX/con SHA-256
7. Sample H1 2026 cycle
─────────────────────────────────────────────────
Service Provider Scope Review — H1 2026
─────────────────────────────────────────────────
Cycle: H1 2026
Period: 2026-01-01 → 2026-06-30
Owner: Gabriel Ureña (CTO + CISO)
Approver: Inversionista (board representation) + CTO
Documents reviewed:
Q1 Business overview → ✓ no changes
Q2 Network diagram → ✓ updated 2026-05-27 (WAF added)
Q4 CHD data flow diagram → ✓ updated 2026-04-15 (tokenization Q40 changes)
Q5 In-scope systems INV-002 → ✓ updated continuous
Q7 TPSPs list → ✓ updated 2026-04-10 (Rapid7 added)
Q8 Policy inventory → ✓ updated 2026-06-16 (POL-016 + SOP-006/007/008 added)
Significant changes since last cycle:
• 2026-04-10 Rapid7 Collector onboarded as new TPSP
• 2026-04-15 Tokenization workflow updated (Q40 changes)
• 2026-05-27 Coraza WAF deployed (Q43 changes)
• 2026-06-16 POL-016 + new SOPs (Q66, Q67, Q234, Q1031, Q1032)
Impact on PCI DSS scope:
✓ No expansion of CDE network — all in same VPC
✓ No new card-present operations
✓ New controls reduce risk (WAF, audit logging, review processes)
Approval:
CTO: Gabriel Ureña 2026-06-16 19:42 UTC
Executive: Inversionista 2026-06-16 20:00 UTC (board)
Hash SHA-256: 9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef
Archive path: s3://fintrix-compliance-archive/scope-reviews/2026-H1/
─────────────────────────────────────────────────8. Vínculos
- POL-001 Information Security Policy
- POL-008 Third-Party Management
- TMPL-013 Scope Approval Acknowledgement (nuevo)
- PCI DSS v4.0 Req 12.5.2.1
