Policy 04  PRIORITY

Onboarding / Hiring Policy
PCI DSS Req 12.6, 12.7  ·  the rule Revique must follow
← All 21 policies
This page is the rule, not the implementation. It states what Revique must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in Procedure 04. Values shown as [X] are placeholders still to be set.

Purpose

To ensure that every new team member is properly screened, provisioned, trained, and formally acknowledges their security responsibilities before being granted access to Revique systems or data.

Scope

Applies to all new employees, contractors, and third-party personnel joining Revique in any role that touches systems, code, or data.

Policy statements

Each statement below is mandatory. The bolded must marks the obligation.

1Every new team member must complete a defined onboarding process before being granted access to production systems or sensitive data.
2Background screening must be completed for personnel in roles with access to CHD/PHI, subject to local law.
3Access for new members must be provisioned on the principle of least privilege, granting only what the role requires.
4New members must formally acknowledge the Information Security Policy and all applicable policies before receiving access.
5New members must complete initial security awareness training during onboarding.
6Onboarding records (screening, acknowledgement, access granted) must be documented and retained.

Roles & responsibilities

RoleResponsibility
HR / Hiring ManagerInitiate screening and the onboarding checklist.
Security OfficerVerify training and policy acknowledgement before access is granted.
DevOps / ITProvision least-privilege access only after onboarding is complete.

Enforcement

This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.

⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.