Policy 09
Data Protection & Encryption Policy
PCI DSS Req 3, 4 · the rule Revique must follow
← All 21 policies
This page is the rule, not the implementation. It states what Revique
must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in
Procedure 09. Values shown as [X] are placeholders still to be set.
Purpose
To ensure CHD/PHI is protected through strong encryption at rest and in transit, and that cryptographic keys are managed securely.
Scope
Applies to all CHD/PHI stored, processed, or transmitted by Revique in any environment.
Policy statements
Each statement below is mandatory. The bolded must marks the obligation.
1CHD/PHI must be encrypted at rest using strong, industry-accepted cryptography.
2CHD/PHI must be encrypted in transit over open/public networks using TLS [X] or higher.
3Sensitive authentication data (e.g. full track data, CVV) must not be stored after authorization.
4The primary account number (PAN) must be masked when displayed and rendered unreadable when stored.
5Cryptographic keys must be managed securely, with restricted access and defined rotation.
6A cryptographic inventory must be maintained.
Roles & responsibilities
| Role | Responsibility |
|---|
| Security Officer | Define encryption standards and manage key policy. |
| Engineering / DevOps | Implement encryption and secure key handling. |
Enforcement
This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.
⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→