Procedure 06 ADMINISTRATIVE
Security Training & Awareness Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 06 · PCI DSS Req 12.6 · 0 of 4 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 06 — Security Training & Awareness PolicyThe rule this procedure implements
How Revique implements this today
Security awareness training is delivered as part of onboarding and repeated annually. It is a people process with no AWS footprint: nothing in the three accounts records who has been trained. The training content is required by policy to cover CHD/PHI handling, phishing, password hygiene and incident reporting — the last of which connects directly to the reporting channel in Procedure 03.
The rule against the current state
Each row takes a statement from Policy 06 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Training on joining and at least annually thereafter | Administrative process; completion records held outside AWS. | Partial |
| Covers CHD/PHI handling, phishing, password hygiene, incident reporting | Defined by the training content; not verifiable in AWS. | Partial |
| Completion documented and retained | Administrative record. | Partial |
| Awareness of emerging threats | Communicated ad hoc by the Security Officer. | Partial |
🔍 Auditor verification — where to log in and what you will see
Training recordsAsk the Security Officer for the training register: who was trained, on what content, on what date. Sample against the current IAM user list in each account.
Content coverageReview the training material against the four required topics named in the policy.
Team process
The Security Officer defines the curriculum, delivers or assigns the training, and tracks completion. New joiners complete it during onboarding before access is granted (Procedure 04); everyone repeats it annually. Threat bulletins — for example an active phishing campaign — are sent out as needed.
⚠️ Where reality does not meet the policy
- There is no evidence trail linking training completion to system access. An auditor sampling the 17 console-capable IAM identities across the three accounts cannot confirm that each has completed current training.
- The annual refresh cadence is asserted by policy but the last completed cycle is not evidenced.
Evidence location. Training register, course content and completion certificates are held by the Security Officer outside AWS.
📘Back to the PolicyPolicy 06 — Security Training & Awareness Policy (PCI DSS Req 12.6)←