Procedure 16  ADMINISTRATIVE

Risk Assessment Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 16  ·  PCI DSS Req 12.3  ·  0 of 4 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 16 — Risk Assessment PolicyThe rule this procedure implements

How Revique implements this today

Risk assessment is a documented management activity. What exists today in place of a formal assessment is a set of point-in-time technical reviews — the PCI DSS requirement reports and the HIPAA gap-assessment published elsewhere on this site, and this procedures section, which enumerates the estate's actual control state and its gaps. These are inputs to a risk assessment, not a substitute for one: they identify weaknesses but do not rank them by likelihood and impact, assign owners, or record management's acceptance or treatment decision.

The rule against the current state

Each row takes a statement from Policy 16 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
A formal risk assessment at least annually and on significant changeNo formal risk assessment document exists.Gap
Risks documented, ranked and assigned treatment actionsGaps are documented here and in the PCI/HIPAA reports, but are not ranked by risk or assigned owners and deadlines.Partial
A cryptographic and asset inventory maintained and reviewedThe KMS key list and account resource inventories exist in AWS but no maintained inventory document is kept. AWS Config, which would provide the asset inventory automatically, is not enabled.Gap
Risk treatment progress tracked to closureNo risk register exists to track.Gap

🔍 Auditor verification — where to log in and what you will see

What technical input existsThis documentation site → the PCI DSS requirement reports, the HIPAA gap-assessment, and this Procedures section — each lists concrete, dated findings.
Cryptographic inventory sourceConsole → KMS → Customer managed keys, per account and region — 6 keys total, which is the raw material for the inventory.
Asset inventory sourceConsole → AWS Config → expect not enabled; without it, inventory must be assembled per service.
The risk assessment itselfAsk for the dated risk assessment, the risk register with rankings and owners, and management's acceptance decisions. Not stored in AWS.

Team process

The Security Officer conducts and documents the risk assessment at least annually and after significant change, drawing on the technical findings in this section. Management reviews the ranked risks and either accepts them or funds treatment; the Security Officer tracks treatment to closure.

⚠️ Where reality does not meet the policy

Evidence location. Risk assessment, risk register and management acceptance decisions are documents held by the Security Officer.
📘Back to the PolicyPolicy 16 — Risk Assessment Policy (PCI DSS Req 12.3)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.