Skip to content

SOP-008: Procedimiento de revisión semestral del scope (Service Provider)

CampoValor
IDSOP-008
Versión1.0
Fecha de emisión2026-06-16
PropietarioCISO + CTO + Executive Management
PCI DSSReq 12.5.2.1 (Service Provider — semi-annual + significant changes)
FrecuenciaSemestral (H1 junio · H2 diciembre) + ad-hoc tras significant changes

1. Propósito

PCI DSS v4.0 Req 12.5.2.1 exige que Service Providers revisen sus documentos de scope al menos cada 6 meses + tras cambios significativos. Esta SOP define el proceso de:

  • Revisión periódica del scope (documentos Q1-Q8 del cuestionario ControlCase)
  • Aprobación por la Gerencia Ejecutiva
  • Comunicación de cambios significativos a la dirección
  • Archivo y retención

2. Documentos en alcance de la revisión

Los siguientes documentos definen el scope PCI DSS de Fintrixs:

#QDocumentoOwnerUpdated when
1Q1Business overview + payment flowCTOSignificant change in business
2Q2Network diagram (CDE + segmentation)CTOSignificant change in network
3Q4Cardholder data flow diagramCTOChange in CHD handling
4Q5List of all in-scope systems (INV-002)CTOContinuous (auto) + verified semestral
5Q7List of TPSPs (POL-008 §2)CTOTPSP onboarding/termination
6Q8Policy + procedure inventoryCISOWhen policies updated

3. Cadencia

CicloWindowDeadline absoluto
H11 – 30 junio30 junio 23:59 UTC
H21 – 31 diciembre31 diciembre 23:59 UTC

Adicional: revisión ad-hoc tras cualquier significant change:

  • Cambio en arquitectura del CDE
  • Nuevo TPSP crítico onboarded
  • Cambio organizacional (M&A, leadership transition)
  • Cambio de QSA
  • Cambio de cloud provider
  • Incident severity Critical (per POL-007)

4. Participantes

RolResponsabilidad
CTOProponente — colecta los documentos actuales + identifica cambios desde el último ciclo
CISORevisor — valida que el scope sigue siendo apropiado
Executive Management (Gerencia Ejecutiva)Aprobador — firma de aceptación final
QSA (ControlCase)Auditor externo (años pares + ad-hoc)

En single-person org: CTO = CISO = Executive Management. La compensating control es:

  1. QSA externo en años pares
  2. Inversionista actuando como reviewer (board) en cada ciclo
  3. Acuses con timestamps verificables via git signed commits

5. Workflow

Day 0  — Ciclo trigger (Jun 1 / Dec 1)
         └── Calendar reminder + email
Day 7  — CTO colecta Q1-Q8 documents
         └── Identifica cambios desde el último ciclo
Day 14 — CISO revisa
         └── Acepta/Rechaza/Pide ajustes
Day 21 — Executive Management firma
         └── Storage + audit log
Day 30 — Deadline → SOP-008 cycle CLOSED

6. Outputs obligatorios

  1. Scope confirmation report — versión actualizada de Q1-Q8 + diff vs cycle anterior
  2. Executive Management signed approval — TMPL-013 (acuse)
  3. Communication to executive management — email con resumen + significant changes (PCI 12.5.2.1)
  4. Archives3://fintrix-compliance-archive/scope-reviews/YYYY-HX/ con SHA-256

7. Sample H1 2026 cycle

─────────────────────────────────────────────────
   Service Provider Scope Review — H1 2026
─────────────────────────────────────────────────
   Cycle:    H1 2026
   Period:   2026-01-01 → 2026-06-30
   Owner:    Gabriel Ureña (CTO + CISO)
   Approver: Inversionista (board representation) + CTO

   Documents reviewed:
     Q1 Business overview        → ✓ no changes
     Q2 Network diagram          → ✓ updated 2026-05-27 (WAF added)
     Q4 CHD data flow diagram    → ✓ updated 2026-04-15 (tokenization Q40 changes)
     Q5 In-scope systems INV-002 → ✓ updated continuous
     Q7 TPSPs list                → ✓ updated 2026-04-10 (Rapid7 added)
     Q8 Policy inventory          → ✓ updated 2026-06-16 (POL-016 + SOP-006/007/008 added)

   Significant changes since last cycle:
     • 2026-04-10  Rapid7 Collector onboarded as new TPSP
     • 2026-04-15  Tokenization workflow updated (Q40 changes)
     • 2026-05-27  Coraza WAF deployed (Q43 changes)
     • 2026-06-16  POL-016 + new SOPs (Q66, Q67, Q234, Q1031, Q1032)

   Impact on PCI DSS scope:
     ✓ No expansion of CDE network — all in same VPC
     ✓ No new card-present operations
     ✓ New controls reduce risk (WAF, audit logging, review processes)

   Approval:
     CTO:                Gabriel Ureña    2026-06-16 19:42 UTC
     Executive:          Inversionista     2026-06-16 20:00 UTC (board)

   Hash SHA-256:  9c4f2b78aebbd1c0f2a3b4c5d6e7f8901234567890abcdef
   Archive path:  s3://fintrix-compliance-archive/scope-reviews/2026-H1/

─────────────────────────────────────────────────

8. Vínculos

Documentación Confidencial — Solo para uso interno y auditoría PCI DSS