Security Policies

The rule book. Twenty-one policies stating what Revique must do to protect cardholder data and protected health information, each mapped to the PCI DSS requirement it satisfies and each paired with a procedure describing how it is actually implemented.
accounts 292**** (dev) · 559**** (UAT) · 501**** (prod)  ·  regions us-e****-1 / us-e****-2  ·  values masked

Policy versus procedure

These two sections answer two different questions, and keeping them apart is deliberate.

SectionQuestion it answersExample
PolicyWhat must be true?“Cryptographic keys must be managed securely, with restricted access and defined rotation.”  —  “Passwords must be at least [X] characters and changed at least every [X] days.”
ProcedureWhat do we actually do, and where does an auditor look?“Five of six customer-managed KMS keys rotate automatically every 365 days. Verify: Console → KMS → Customer managed keys → the key → Key rotation.”

A rule must sit at or above the PCI DSS minimum. A procedure must describe reality — including where reality currently falls short. Where the two diverge, the procedure says so plainly rather than paraphrasing the policy back.

21
Policies
4
Priority
11
Technical
3
Hybrid
7
Administrative

The register

Policy 01 is the master policy that authorises all the others. Policies 02–05 carry a priority badge. Each row links both to the rule and to its implementation.

01
Information Security Policy MASTER
PCI DSS Req 12.1  ·  implementation is administrative
02
Change Management Policy PRIORITY
PCI DSS Req 6.5  ·  implementation is technical
03
Incident Response Policy PRIORITY
PCI DSS Req 12.10  ·  implementation is hybrid
04
Onboarding / Hiring Policy PRIORITY
PCI DSS Req 12.6, 12.7  ·  implementation is administrative
05
Vulnerability Management Policy PRIORITY
PCI DSS Req 6.3, 11.3  ·  implementation is technical
06
Security Training & Awareness Policy
PCI DSS Req 12.6  ·  implementation is administrative
07
Access Control Policy
PCI DSS Req 7  ·  implementation is technical
08
Authentication & Password Policy
PCI DSS Req 8  ·  implementation is technical
09
Data Protection & Encryption Policy
PCI DSS Req 3, 4  ·  implementation is technical
10
Anti-Malware Policy
PCI DSS Req 5  ·  implementation is technical
11
Logging & Monitoring Policy
PCI DSS Req 10  ·  implementation is technical
12
Network Security Policy
PCI DSS Req 1  ·  implementation is technical
13
Secure Configuration Policy
PCI DSS Req 2  ·  implementation is technical
14
Security & Penetration Testing Policy
PCI DSS Req 11.4  ·  implementation is hybrid
15
Third-Party / Vendor Management Policy
PCI DSS Req 12.8  ·  implementation is administrative
16
Risk Assessment Policy
PCI DSS Req 12.3  ·  implementation is administrative
17
Data Retention & Disposal Policy
PCI DSS Req 3.2, 9.4  ·  implementation is technical
18
Acceptable Use Policy
PCI DSS Req 12.2  ·  implementation is administrative
19
Physical & Media Security Policy
PCI DSS Req 9  ·  implementation is hybrid
20
Backup & Business Continuity Policy
PCI DSS Req 12.10 (contingency)  ·  implementation is technical
21
Personnel Security / Screening Policy
PCI DSS Req 12.7  ·  implementation is administrative
Placeholders. Several policies contain bracketed values such as [X] days or [X] characters. These are deliberate — the numeric thresholds are management decisions still to be set. The matching procedure states the value that is actually configured today, so the gap between the two is visible even before the placeholder is filled in.
⚙️Procedures — how each rule is implementedReal AWS configuration, current values against the rule, honest gaps, and the exact verification path for an auditor→
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.