Procedure 08 TECHNICAL
Authentication & Password Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 08 · PCI DSS Req 8 · 3 of 8 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 08 — Authentication & Password PolicyThe rule this procedure implements
How Revique implements this today
Authentication is through AWS IAM, with a password policy set independently in each account. Production enforces a 12-character minimum with uppercase, lowercase, numbers and symbols all required, 90-day expiry, and prevention of the last 5 passwords being reused — this meets the PCI DSS floor. Dev enforces the same complexity, expiry and reuse rules but only a 6-character minimum. UAT is the weakest: 6 characters, no complexity requirements and no expiry. The root account has MFA enabled in all three accounts and is not used for routine operations. Application and service credentials are held in AWS Secrets Manager (8 secrets in production us-e****-1, 2 in us-e****-2, 13 in dev, 7 in UAT) rather than hard-coded.
The rule against the current state
Each row takes a statement from Policy 08 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Passwords at least [X] characters, never below the PCI minimum | Production: 12 — meets. Dev: 6. UAT: 6. | Partial |
| Complexity requirements enforced | Production and dev require upper, lower, number and symbol. UAT requires none. | Partial |
| Passwords changed at least every [X] days | Production and dev expire at 90 days. UAT has expiry disabled. | Partial |
| Password reuse prevented | Production and dev prevent reuse of the last 5. UAT has no reuse prevention. | Partial |
| MFA enforced for all administrative and remote access | 1 of 17 console-capable IAM users across the three accounts has MFA active. | Gap |
| Root account has MFA and is not used routinely | Root MFA is enabled in all three accounts; root holds no access keys in any of them. | Meets |
| Every user has a unique ID; no shared accounts | Human identities are individually named. Machine identities are separate and console-disabled. | Meets |
| Service credentials stored securely, never hard-coded | AWS Secrets Manager is in use across all accounts and regions (30 secrets total). | Meets |
🔍 Auditor verification — where to log in and what you will see
Production password policyConsole → IAM → Account settings → Password policy, in the production account (501****). Expect: minimum length 12, all four character classes required, expiry 90 days, prevent reuse of 5.
Dev and UAT password policiesSame screen in accounts 292**** and 559****. Dev shows minimum length 6 with full complexity and 90-day expiry; UAT shows minimum length 6, no complexity, no expiry.
Root MFAConsole → IAM → dashboard, each account → Root user has MFA. Also visible in the credential report as <root_account>, mfa_active = true.
Per-user MFAConsole → IAM → Credential report (Download report) → column mfa_active against column password_enabled. Only one console-capable user shows true.
Secrets are managed, not hard-codedConsole → Secrets Manager → Secrets, per account and region. Names and metadata only — secret values are never retrieved during an assessment.
Team process
The Security Officer sets and owns the password policy per account. Individuals are responsible for their own credentials and for enabling MFA. New service credentials are created in Secrets Manager by DevOps; no credential is committed to source control.
⚠️ Where reality does not meet the policy
- MFA is effectively absent. Of the 17 IAM users with console passwords across the three accounts, one has MFA active — and none of the four console users in the production account do. The policy requires MFA for all administrative and remote access; this is the single largest authentication gap in the estate. (Root MFA is correctly enabled everywhere.)
- UAT's password policy does not meet the policy at all: 6-character minimum, no complexity requirement, no expiry, no reuse prevention. UAT holds CHD/PHI and is therefore in scope.
- Dev's 6-character minimum is below the PCI floor, even though its complexity and expiry settings are correct.
- Access keys are not rotated. Active keys across the estate were last rotated as long ago as 2019, with many dating from 2020–2022. The policy's periodic-change requirement is applied to console passwords but not to programmatic credentials.
- No secret rotation. All 30 Secrets Manager secrets have automatic rotation disabled.
Evidence location. All evidence for this procedure is in AWS IAM; no external records are required.
📘Back to the PolicyPolicy 08 — Authentication & Password Policy (PCI DSS Req 8)←