Procedure 09 TECHNICAL
Data Protection & Encryption Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 09 · PCI DSS Req 3, 4 · 2 of 6 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 09 — Data Protection & Encryption PolicyThe rule this procedure implements
How Revique implements this today
Encryption at rest is applied through KMS and service-native encryption. The estate holds 6 customer-managed KMS keys; 5 have automatic rotation enabled on a 365-day period — the four in the dev account and the production external-lead bridge key. All remaining keys in use are AWS-managed keys, which AWS rotates on its own schedule. The production Aurora PostgreSQL cluster and all its instances are encrypted at rest; all 22 production S3 buckets have default encryption enabled; and EBS encryption-by-default is switched on in both production regions. In transit, the application load balancers in all three accounts use the ELBSecurityPolicy-TLS13-1-2-2021-06 policy — a TLS 1.2 floor with TLS 1.3 available — and all seven production CloudFront distributions enforce a TLS 1.2 minimum with redirect-to-https viewer policy.
The rule against the current state
Each row takes a statement from Policy 09 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Cryptographic keys managed securely with defined rotation | 5 of 6 customer-managed keys rotate automatically every 365 days. | Partial |
| CHD/PHI encrypted at rest with strong cryptography | Production Aurora PostgreSQL: encrypted. Production S3: 22 of 22 buckets. Production EBS: encryption-by-default on, zero unencrypted volumes. | Meets |
| Encryption at rest across all in-scope environments | One production legacy MySQL instance, four UAT buckets and two dev volumes are unencrypted. | Gap |
| CHD/PHI encrypted in transit using TLS [X] or higher | ALBs: TLS 1.2 floor with TLS 1.3 (ELBSecurityPolicy-TLS13-1-2-2021-06). CloudFront: TLS 1.2 minimum, redirect-to-https. | Meets |
| No plaintext path to in-scope systems | The production API load balancer's port-80 listener forwards to the target group rather than redirecting to HTTPS. | Gap |
| Sensitive authentication data not stored after authorisation; PAN masked | Application-layer control, not verifiable from infrastructure configuration. | N/A |
| A cryptographic inventory is maintained | The KMS key list is the de facto inventory; no maintained document exists. | Partial |
🔍 Auditor verification — where to log in and what you will see
KMS key rotation — the headline checkConsole → KMS → production account, us-e****-1 → Customer managed keys → select the external-lead bridge key (alias begins rev****) → Key rotation tab → Automatically rotate this KMS key every year is checked, rotation period 365 days. The same is true of all four customer-managed keys in the dev account.
The key that does not rotateConsole → KMS → production account, us-e****-2 → Customer managed keys → the CloudTrail log-encryption key (alias begins aud****) → Key rotation is not enabled.
Database encryptionConsole → RDS → production us-e****-1 → the Aurora PostgreSQL cluster → Configuration → Encryption: Enabled. Then us-e****-2 → the second MySQL instance shows Encryption: Not enabled.
S3 default encryptionConsole → S3 → any production bucket → Properties → Default encryption — enabled on all 22.
EBS default encryptionConsole → EC2 → EBS encryption (Account attributes, right-hand panel), production account, each region → Always encrypt new EBS volumes: Enabled.
TLS in transitConsole → EC2 → Load balancers → production ALB → Listeners → the HTTPS:443 listener shows security policy ELBSecurityPolicy-TLS13-1-2-2021-06. And CloudFront → each distribution → Settings → Minimum origin SSL / viewer protocol policy.
The plaintext listenerSame load balancer → Listeners → HTTP:80 → its default action is Forward, not Redirect.
Team process
The Security Officer defines the encryption standard and owns key policy; DevOps implements it in CDK so new resources inherit encryption by default. Key rotation is automatic once enabled — no manual step is required — which is why the exception below matters: it is a one-time configuration miss, not a recurring task.
⚠️ Where reality does not meet the policy
- One customer-managed key does not rotate. The CloudTrail log-encryption key in production us-e****-2 has automatic rotation disabled, while the other five customer-managed keys rotate at 365 days. This is the key protecting the audit trail, so it is the least desirable exception.
- The UAT account has no customer-managed keys at all — everything there relies on AWS-managed keys, so Revique controls neither the rotation period nor the key policy for UAT data.
- One production legacy MySQL instance is unencrypted at rest. Its primary is encrypted; the second instance is not.
- The production API load balancer accepts plaintext HTTP. Its port-80 listener forwards traffic to the application instead of redirecting to HTTPS, so a client that fails to use TLS is served rather than corrected.
- EBS encryption-by-default is off in dev and UAT, and 2 of 3 dev volumes in us-e****-2 are unencrypted. Four of 17 UAT buckets have no default encryption.
- No maintained cryptographic inventory document exists, as required by both this policy and Policy 16.
Evidence location. All evidence is in AWS (KMS, RDS, S3, EC2, ELB, CloudFront). Application-layer PAN handling requires code review, not covered here.
📘Back to the PolicyPolicy 09 — Data Protection & Encryption Policy (PCI DSS Req 3, 4)←