Procedure 09  TECHNICAL

Data Protection & Encryption Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 09  ·  PCI DSS Req 3, 4  ·  2 of 6 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 09 — Data Protection & Encryption PolicyThe rule this procedure implements

How Revique implements this today

Encryption at rest is applied through KMS and service-native encryption. The estate holds 6 customer-managed KMS keys; 5 have automatic rotation enabled on a 365-day period — the four in the dev account and the production external-lead bridge key. All remaining keys in use are AWS-managed keys, which AWS rotates on its own schedule. The production Aurora PostgreSQL cluster and all its instances are encrypted at rest; all 22 production S3 buckets have default encryption enabled; and EBS encryption-by-default is switched on in both production regions. In transit, the application load balancers in all three accounts use the ELBSecurityPolicy-TLS13-1-2-2021-06 policy — a TLS 1.2 floor with TLS 1.3 available — and all seven production CloudFront distributions enforce a TLS 1.2 minimum with redirect-to-https viewer policy.

The rule against the current state

Each row takes a statement from Policy 09 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Cryptographic keys managed securely with defined rotation5 of 6 customer-managed keys rotate automatically every 365 days.Partial
CHD/PHI encrypted at rest with strong cryptographyProduction Aurora PostgreSQL: encrypted. Production S3: 22 of 22 buckets. Production EBS: encryption-by-default on, zero unencrypted volumes.Meets
Encryption at rest across all in-scope environmentsOne production legacy MySQL instance, four UAT buckets and two dev volumes are unencrypted.Gap
CHD/PHI encrypted in transit using TLS [X] or higherALBs: TLS 1.2 floor with TLS 1.3 (ELBSecurityPolicy-TLS13-1-2-2021-06). CloudFront: TLS 1.2 minimum, redirect-to-https.Meets
No plaintext path to in-scope systemsThe production API load balancer's port-80 listener forwards to the target group rather than redirecting to HTTPS.Gap
Sensitive authentication data not stored after authorisation; PAN maskedApplication-layer control, not verifiable from infrastructure configuration.N/A
A cryptographic inventory is maintainedThe KMS key list is the de facto inventory; no maintained document exists.Partial

🔍 Auditor verification — where to log in and what you will see

KMS key rotation — the headline checkConsole → KMS → production account, us-e****-1 → Customer managed keys → select the external-lead bridge key (alias begins rev****) → Key rotation tab → Automatically rotate this KMS key every year is checked, rotation period 365 days. The same is true of all four customer-managed keys in the dev account.
The key that does not rotateConsole → KMS → production account, us-e****-2 → Customer managed keys → the CloudTrail log-encryption key (alias begins aud****) → Key rotation is not enabled.
Database encryptionConsole → RDS → production us-e****-1 → the Aurora PostgreSQL cluster → Configuration → Encryption: Enabled. Then us-e****-2 → the second MySQL instance shows Encryption: Not enabled.
S3 default encryptionConsole → S3 → any production bucket → Properties → Default encryption — enabled on all 22.
EBS default encryptionConsole → EC2 → EBS encryption (Account attributes, right-hand panel), production account, each region → Always encrypt new EBS volumes: Enabled.
TLS in transitConsole → EC2 → Load balancers → production ALB → Listeners → the HTTPS:443 listener shows security policy ELBSecurityPolicy-TLS13-1-2-2021-06. And CloudFront → each distribution → Settings → Minimum origin SSL / viewer protocol policy.
The plaintext listenerSame load balancer → Listeners → HTTP:80 → its default action is Forward, not Redirect.

Team process

The Security Officer defines the encryption standard and owns key policy; DevOps implements it in CDK so new resources inherit encryption by default. Key rotation is automatic once enabled — no manual step is required — which is why the exception below matters: it is a one-time configuration miss, not a recurring task.

⚠️ Where reality does not meet the policy

Evidence location. All evidence is in AWS (KMS, RDS, S3, EC2, ELB, CloudFront). Application-layer PAN handling requires code review, not covered here.
📘Back to the PolicyPolicy 09 — Data Protection & Encryption Policy (PCI DSS Req 3, 4)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.