Procedure 01  ADMINISTRATIVE

Information Security Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 01  ·  PCI DSS Req 12.1  ·  1 of 4 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 01 — Information Security PolicyThe rule this procedure implements

How Revique implements this today

The 21 policies in this register are Revique's information security program. Each one names the PCI DSS requirement it satisfies, and each has a matching procedure in this section describing how the rule is actually implemented in the three AWS accounts that make up the estate: dev (292****), UAT (559****) and production (501****), each spanning us-e****-1 (the native Revique API — ECS Fargate and Aurora PostgreSQL) and us-e****-2 (the legacy platform — API Gateway, Lambda, EC2 and MySQL). Both tiers hold CHD/PHI, so both are in scope for every policy in this register.

The rule against the current state

Each row takes a statement from Policy 01 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Documented security program approved by management, reviewed annuallyThe 21-policy register exists and is published here. Formal executive approval and the annual review record are administrative artefacts held outside AWS.Partial
A designated Security Officer owns the programRole is named in each policy's Roles section. The appointment record is an HR artefact.Partial
Every subordinate policy maps to a PCI DSS requirementAll 21 policies carry an explicit PCI DSS mapping, shown on the policies index.Meets
Personnel acknowledge the policyAcknowledgement is collected during onboarding (see Procedure 04). Records held in HR.Partial

🔍 Auditor verification — where to log in and what you will see

The policy register itselfThis documentation site → Security Policies → 21 policies, each with PCI mapping and a linked procedure.
Scope of the estateAWS Console → sign in to each of the three accounts → the region selector shows us-e****-1 and us-e****-2 in use.
Management approval & annual reviewRequest the signed approval record and the dated review minutes — these are not stored in AWS.

Team process

The Security Officer owns this register. Any change to a policy is raised with executive management, approved, versioned, and republished here; the matching procedure is updated in the same change so the rule and the implementation never drift apart.

⚠️ Where reality does not meet the policy

Evidence location. Signed policy approval, annual review minutes, and personnel acknowledgements are HR/management records held outside AWS.
📘Back to the PolicyPolicy 01 — Information Security Policy (PCI DSS Req 12.1)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.