← All 21 policies
This page is the rule, not the implementation. It states what Revique
must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in
Procedure 08. Values shown as [X] are placeholders still to be set.
Purpose
To ensure all users are uniquely identified and strongly authenticated before accessing Revique systems and data.
Scope
Applies to all user, administrative, and service accounts across all environments.
Policy statements
Each statement below is mandatory. The bolded must marks the obligation.
1Every user must have a unique ID; shared accounts are prohibited.
2Passwords must be at least [X] characters and meet defined complexity requirements (never below the PCI minimum).
3Passwords must be changed at least every [X] days where applicable.
4Multi-factor authentication (MFA) must be enforced for all administrative and remote access.
5The root/master account must have MFA enabled and must not be used for routine operations.
6Service and application credentials must be stored securely (e.g. a secrets manager), never hard-coded.
Roles & responsibilities
| Role | Responsibility |
|---|
| Security Officer | Define and enforce authentication standards. |
| All Personnel | Protect their credentials and use MFA. |
Enforcement
This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.
⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→