Procedure 06  ADMINISTRATIVE

Security Training & Awareness Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 06  ·  PCI DSS Req 12.6  ·  0 of 4 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 06 — Security Training & Awareness PolicyThe rule this procedure implements

How Revique implements this today

Security awareness training is delivered as part of onboarding and repeated annually. It is a people process with no AWS footprint: nothing in the three accounts records who has been trained. The training content is required by policy to cover CHD/PHI handling, phishing, password hygiene and incident reporting — the last of which connects directly to the reporting channel in Procedure 03.

The rule against the current state

Each row takes a statement from Policy 06 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Training on joining and at least annually thereafterAdministrative process; completion records held outside AWS.Partial
Covers CHD/PHI handling, phishing, password hygiene, incident reportingDefined by the training content; not verifiable in AWS.Partial
Completion documented and retainedAdministrative record.Partial
Awareness of emerging threatsCommunicated ad hoc by the Security Officer.Partial

🔍 Auditor verification — where to log in and what you will see

Training recordsAsk the Security Officer for the training register: who was trained, on what content, on what date. Sample against the current IAM user list in each account.
Content coverageReview the training material against the four required topics named in the policy.

Team process

The Security Officer defines the curriculum, delivers or assigns the training, and tracks completion. New joiners complete it during onboarding before access is granted (Procedure 04); everyone repeats it annually. Threat bulletins — for example an active phishing campaign — are sent out as needed.

⚠️ Where reality does not meet the policy

Evidence location. Training register, course content and completion certificates are held by the Security Officer outside AWS.
📘Back to the PolicyPolicy 06 — Security Training & Awareness Policy (PCI DSS Req 12.6)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.