Procedure 08  TECHNICAL

Authentication & Password Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 08  ·  PCI DSS Req 8  ·  3 of 8 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 08 — Authentication & Password PolicyThe rule this procedure implements

How Revique implements this today

Authentication is through AWS IAM, with a password policy set independently in each account. Production enforces a 12-character minimum with uppercase, lowercase, numbers and symbols all required, 90-day expiry, and prevention of the last 5 passwords being reused — this meets the PCI DSS floor. Dev enforces the same complexity, expiry and reuse rules but only a 6-character minimum. UAT is the weakest: 6 characters, no complexity requirements and no expiry. The root account has MFA enabled in all three accounts and is not used for routine operations. Application and service credentials are held in AWS Secrets Manager (8 secrets in production us-e****-1, 2 in us-e****-2, 13 in dev, 7 in UAT) rather than hard-coded.

The rule against the current state

Each row takes a statement from Policy 08 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Passwords at least [X] characters, never below the PCI minimumProduction: 12 — meets. Dev: 6. UAT: 6.Partial
Complexity requirements enforcedProduction and dev require upper, lower, number and symbol. UAT requires none.Partial
Passwords changed at least every [X] daysProduction and dev expire at 90 days. UAT has expiry disabled.Partial
Password reuse preventedProduction and dev prevent reuse of the last 5. UAT has no reuse prevention.Partial
MFA enforced for all administrative and remote access1 of 17 console-capable IAM users across the three accounts has MFA active.Gap
Root account has MFA and is not used routinelyRoot MFA is enabled in all three accounts; root holds no access keys in any of them.Meets
Every user has a unique ID; no shared accountsHuman identities are individually named. Machine identities are separate and console-disabled.Meets
Service credentials stored securely, never hard-codedAWS Secrets Manager is in use across all accounts and regions (30 secrets total).Meets

🔍 Auditor verification — where to log in and what you will see

Production password policyConsole → IAM → Account settings → Password policy, in the production account (501****). Expect: minimum length 12, all four character classes required, expiry 90 days, prevent reuse of 5.
Dev and UAT password policiesSame screen in accounts 292**** and 559****. Dev shows minimum length 6 with full complexity and 90-day expiry; UAT shows minimum length 6, no complexity, no expiry.
Root MFAConsole → IAM → dashboard, each account → Root user has MFA. Also visible in the credential report as <root_account>, mfa_active = true.
Per-user MFAConsole → IAM → Credential report (Download report) → column mfa_active against column password_enabled. Only one console-capable user shows true.
Secrets are managed, not hard-codedConsole → Secrets Manager → Secrets, per account and region. Names and metadata only — secret values are never retrieved during an assessment.

Team process

The Security Officer sets and owns the password policy per account. Individuals are responsible for their own credentials and for enabling MFA. New service credentials are created in Secrets Manager by DevOps; no credential is committed to source control.

⚠️ Where reality does not meet the policy

Evidence location. All evidence for this procedure is in AWS IAM; no external records are required.
📘Back to the PolicyPolicy 08 — Authentication & Password Policy (PCI DSS Req 8)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.