These two sections answer two different questions, and keeping them apart is deliberate.
| Section | Question it answers | Example |
|---|---|---|
| Policy | What must be true? | “Cryptographic keys must be managed securely, with restricted access and defined rotation.” — “Passwords must be at least [X] characters and changed at least every [X] days.” |
| Procedure | What do we actually do, and where does an auditor look? | “Five of six customer-managed KMS keys rotate automatically every 365 days. Verify: Console → KMS → Customer managed keys → the key → Key rotation.” |
A rule must sit at or above the PCI DSS minimum. A procedure must describe reality — including where reality currently falls short. Where the two diverge, the procedure says so plainly rather than paraphrasing the policy back.
Policy 01 is the master policy that authorises all the others. Policies 02–05 carry a priority badge. Each row links both to the rule and to its implementation.