Procedure 01 ADMINISTRATIVE
Information Security Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 01 · PCI DSS Req 12.1 · 1 of 4 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 01 — Information Security PolicyThe rule this procedure implements
How Revique implements this today
The 21 policies in this register are Revique's information security program. Each one names the PCI DSS requirement it satisfies, and each has a matching procedure in this section describing how the rule is actually implemented in the three AWS accounts that make up the estate: dev (292****), UAT (559****) and production (501****), each spanning us-e****-1 (the native Revique API — ECS Fargate and Aurora PostgreSQL) and us-e****-2 (the legacy platform — API Gateway, Lambda, EC2 and MySQL). Both tiers hold CHD/PHI, so both are in scope for every policy in this register.
The rule against the current state
Each row takes a statement from Policy 01 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Documented security program approved by management, reviewed annually | The 21-policy register exists and is published here. Formal executive approval and the annual review record are administrative artefacts held outside AWS. | Partial |
| A designated Security Officer owns the program | Role is named in each policy's Roles section. The appointment record is an HR artefact. | Partial |
| Every subordinate policy maps to a PCI DSS requirement | All 21 policies carry an explicit PCI DSS mapping, shown on the policies index. | Meets |
| Personnel acknowledge the policy | Acknowledgement is collected during onboarding (see Procedure 04). Records held in HR. | Partial |
🔍 Auditor verification — where to log in and what you will see
The policy register itselfThis documentation site → Security Policies → 21 policies, each with PCI mapping and a linked procedure.
Scope of the estateAWS Console → sign in to each of the three accounts → the region selector shows us-e****-1 and us-e****-2 in use.
Management approval & annual reviewRequest the signed approval record and the dated review minutes — these are not stored in AWS.
Team process
The Security Officer owns this register. Any change to a policy is raised with executive management, approved, versioned, and republished here; the matching procedure is updated in the same change so the rule and the implementation never drift apart.
⚠️ Where reality does not meet the policy
- Executive approval and the annual-review record are not yet attached to this register — an auditor asking “who approved this and when?” cannot currently be answered from the documentation alone.
Evidence location. Signed policy approval, annual review minutes, and personnel acknowledgements are HR/management records held outside AWS.
📘Back to the PolicyPolicy 01 — Information Security Policy (PCI DSS Req 12.1)←